Quantum security cross-domain communication method and system
Through the cross-domain communication method of quantum security, key index transmission and multi-gateway verification encryption are used to solve the security and performance problems of traditional encryption technology under the threat of quantum computing, and efficient and secure cross-domain data transmission is achieved.
Patent Information
- Application Number
- CN202510421430.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-25
AI Technical Summary
When the prior art faces the threat of quantum computing, traditional encryption technology cannot guarantee the security of cross-domain communication, and there are key data synchronization errors and delay problems, resulting in low communication performance and poor user experience.
The cross-domain communication method of quantum security is adopted. By separating key transmission and key storage, only passing the key index is passed, and data checksum encryption is used for multiple gateways to ensure the confidentiality and integrity of data transmission, and combining ciphertext streams and key streams for synchronous transmission, reducing matching operations.
Effectively reduce the risk of key exposure, improve key management flexibility and scalability, save bandwidth and system resources, improve data transmission efficiency, optimize communication performance, and avoid delays and service overload during high concurrency.
Smart Images

Figure CN120378141A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a quantum-secure cross-domain communication method and system. Background Art
[0002] With the rapid development of information technology, the demand for cross-domain communication in fields such as government affairs, finance, healthcare, and military is increasing day by day. However, traditional cross-domain communication methods usually rely on classical encryption technologies such as RSA and AES. These technologies have serious security risks when facing quantum computing attacks: the development of quantum computers makes classical encryption algorithms based on large number factorization or discrete logarithm problems likely to be quickly cracked, leading to the risk of sensitive data leakage or communication being maliciously tampered with. The quantum security defects caused by the inability of traditional encryption technologies to resist quantum computing attacks make it difficult to guarantee the long-term security of cross-domain communication.
[0003] In view of the above defects of traditional encryption technologies, in some scenarios, quantum encryption solutions have begun to be gradually sought to solve security problems in communication. For example, the patent "A Method for Sending and Receiving Quantum-Secure Network Data and a Communication System" with the application number 202211481281.8 proposes a data communication method. In this method, ciphertext information is sent to the receiving end through a first link, and key information is sent to the receiving end through a second link via a base station.
[0004] In the above application, the ciphertext data and the key data are asynchronously transmitted through two links. This is likely to have problems such as time delay caused by inconsistent arrival times of the ciphertext data and the key data, and in the case of a large amount of data, the receiving end is bound to perform matching operations on the ciphertext data and the key data to decrypt the ciphertext data with the correct key data. The asynchronous transmission method is prone to problems such as incorrect matching caused by synchronization errors between the ciphertext data and the key data, which in turn increases the probability of system interruption, makes it difficult for the service traffic to increase, limits the overall supported number of concurrent terminals, and results in poor user experience due to low communication performance.
[0005] Therefore, there is an urgent need for a data transmission scheme that can resist quantum computing threats, implement security verification, encryption, and efficient cross-domain communication to ensure the confidentiality, integrity, and reliability of data transmission. Summary of the Invention
[0006] Object of the Invention: This application provides a quantum-secure cross-domain communication method and system to solve the problems existing in the prior art.
[0007] Technical solution: The present invention provides a quantum-secure cross-domain communication method. The participants in the method include: a sender privacy computer, a receiver privacy computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway; the method includes the following steps:
[0008] Step 1: The sender privacy computer processes the initial transmission data to obtain first transmission data, and forwards the first transmission data to the first access gateway via the Internet;
[0009] Step 2: The first access gateway verifies the first transmission data. After passing the verification, it decrypts and sends it to the first border gateway for encryption to obtain second transmission data. The first border gateway forwards the second transmission data to the second border gateway via the Internet;
[0010] Step 3: The second border gateway decrypts the second transmission data and sends it to the second access gateway. The second access gateway verifies the decrypted second transmission data. After passing the verification, it encrypts it to obtain third transmission data, and forwards the third transmission data to the receiver privacy computer via the Internet;
[0011] Step 4: The receiver privacy computer decrypts and verifies the third transmission data. After passing the verification, it obtains the initial transmission data, and completes the data flow process.
[0012] As an improvement of the present invention, the step 1 includes:
[0013] Step 1-1: The sender privacy computer obtains the initial transmission data Data0, where the initial transmission data is in plaintext state and includes a frame header and data content Plain1; the sender privacy computer obtains a corresponding-sized first key Key1 from the local key pool according to the size of the data content Plain1 of the initial transmission data, and records the first key index Index1 of the first key Key1, and encrypts the data content Plain1 in the initial transmission data with the first key Key1 to obtain the first ciphertext Cipher1;
[0014] Step 1-2: The sender privacy computer calculates the checksum of the combination of the frame header, the first key index Index1, and the first key Key1 in the initial transmission data to obtain the first checksum Check1;
[0015] Step 1-3: The sender privacy computer performs data framing: packs the frame header, the first key index Index1, the first checksum Check1, and the first ciphertext Cipher1 to obtain the first transmission data Data1;
[0016] Step 1-4: The sender privacy computer forwards the first transmission data Data1 to the first access gateway via the Internet.
[0017] As an improvement of the present invention, the step 2 includes:
[0018] Step 2-1: The first access gateway receives the first transmission data Data1, obtains the corresponding key Key′1 in the local key pool according to the first key index Index1, calculates the checksum Check′1 of the combination of the frame header, the first key index Index1 and the key Key′1, and compares whether the value of the first checksum Check1 is consistent with the calculated checksum Check′1. If so, the verification passes and proceed to the next step; otherwise, feedback verification failure to the sender privacy computer and end the data transmission process;
[0019] Step 2-2: The first access gateway decrypts the first ciphertext Cipher1 in the first transmission data Data1 using the key Key′1 to obtain the data content Plain1, and sends the frame header and the data content Plain1 to the first border gateway;
[0020] Step 2-3: The first border gateway obtains the corresponding second key Key2 of the corresponding size in the local key pool according to the size of the data content Plain1, records the second key index Index2 of the second key Key2, and encrypts the data content Plain1 using the second key Key2 to obtain the second ciphertext Cipher2;
[0021] Step 2-4: The first border gateway calculates the checksum of the combination of the frame header, the second key index Index2 and the second key Key2 to obtain the second checksum Check2;
[0022] Step 2-5: The first border gateway performs data framing: packs the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2;
[0023] Step 2-6: The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet.
[0024] As an improvement of the present invention, the step 3 includes:
[0025] Step 3-1: The second border gateway receives the second transmission data Data2, obtains the corresponding key Key'2 from the local key pool according to the second key index Index2 in the second transmission data Data2, calculates the checksum Check'2 of the combination of the frame header, the second key index Index2, and the key Key'2, and compares whether the value of the second checksum Check2 is consistent with the calculated checksum Check'2. If so, the verification passes and proceeds to the next step; otherwise, feedback the verification failure to the sender privacy computer via the first border gateway and the first access gateway, and end the data transmission process;
[0026] Step 3-2: The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key'2 to obtain the data content Plain1, and sends the frame header and the data content Plain1 to the second access gateway;
[0027] Step 3-3: The second access gateway obtains the corresponding third key Key3 of the corresponding size from the local key pool according to the size of the data content Plain1, records the third key index Index3 of the third key Key3, and encrypts the data content Plain1 using the third key Key3 to obtain the third ciphertext Cipher3;
[0028] Step 3-4: The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3, and the third key Key3 to obtain the third checksum Check3;
[0029] Step 3-5: The second access gateway performs data framing: packs the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3;
[0030] Step 3-6: The second access gateway forwards the third transmission data Data3 to the receiver privacy computer via the Internet.
[0031] As an improvement of the present invention, the said step 4 includes:
[0032] Step 4-1: The receiver privacy computer receives the third transmission data Data3, obtains the corresponding key Key'3 from the local key pool according to the third key index Index3, calculates the checksum Check'3 of the combination of the frame header, the third key index Index3, and the key Key'3, and compares whether the value of the third checksum Check3 is consistent with the calculated checksum Check'3. If so, the verification passes and proceeds to the next step; otherwise, feedback the verification failure to the sender privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process;
[0033] Step 4-2: The receiving party's privacy computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key′3 to obtain the data content Plain1 of the initial transmission data, thus completing the data stream process.
[0034] As an improvement of the present invention, the step 2 includes:
[0035] Step 2-(1): The first access gateway receives the first transmission data Data1, obtains the corresponding key Key″1 in the local key pool according to the first key index Index1, calculates the checksum Check″1 of the combination of the frame header, the first key index Index1, and the key Key″1, and compares whether the value of the first checksum Check1 is consistent with the calculated checksum Check″1. If so, the verification passes, and the frame header, the key Key″1, and the first ciphertext Cipher1 are packed and sent to the first border gateway to enter the next step; otherwise, feedback the verification failure to the sending party's privacy computer to end the data transmission process;
[0036] Step 2-(2): The first border gateway obtains the second key Key2 of the corresponding size in the local key pool according to the size of the combination of the key Key″1 and the first ciphertext Cipher1, records the second key index Index2 of the second key Key2, and encrypts the combination of the key Key″1 and the first ciphertext Cipher1 using the second key Key2 to obtain the second ciphertext Cipher2;
[0037] Step 2-(3): The first border gateway calculates the checksum of the combination of the frame header, the second key index Index2, and the second key Key2 to obtain the second checksum Check2;
[0038] Step 2-(4): The first border gateway performs data framing: packs the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2;
[0039] Step 2-(5): The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet.
[0040] As an improvement of the present invention, the step 3 includes:
[0041] Step 3-(1): The second border gateway receives the second transmission data Data2, obtains the corresponding key Key″2 in the local key pool according to the second key index Index2 in the second transmission data Data2, calculates the checksum Check″2 of the combination of the frame header, the second key index Index2 and the key Key″2, and compares whether the value of the second checksum Check2 is consistent with the calculated checksum Check″2. If so, the verification passes and proceeds to the next step; otherwise, feedback the verification failure to the sender privacy computer via the first border gateway and the first access gateway, and end the data transmission process;
[0042] Step 3-(2): The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key″2 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and sends the frame header and the combination of the key Key″1 and the first ciphertext Cipher1 to the second access gateway;
[0043] Step 3-(3): The second access gateway obtains the corresponding-sized third key Key3 in the local key pool according to the size of the combination of the key Key″1 and the first ciphertext Cipher1, records the third key index Index3 of the third key Key3, and encrypts the combination of the key Key″1 and the first ciphertext Cipher1 using the third key Key3 to obtain the third ciphertext Cipher3;
[0044] Step 3-(4): The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3 and the third key Key3 to obtain the third checksum Check3;
[0045] Step 3-(5): The second access gateway performs data framing: packs the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3;
[0046] Step 3-(6): The second access gateway forwards the third transmission data Data3 to the receiver privacy computer via the Internet.
[0047] As an improvement of the present invention, the said step 4 includes:
[0048] Step 4-(1): The receiving party's privacy computer receives the third transmission data Data3, obtains the corresponding key Key″3 from the local key pool according to the third key index Index3, calculates the checksum Check″3 of the combination of the frame header, the third key index Index3, and the key Key″3, and compares whether the value of the third checksum Check3 is consistent with the calculated checksum Check″3. If so, the verification passes and proceeds to the next step; otherwise, feedback a verification failure to the sending party's privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process;
[0049] Step 4-(2): The receiving party's privacy computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key″3 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and decrypts the first ciphertext Cipher1 using the key Key″1 to obtain the data content Plain1 of the initial transmission data, completing the data flow process.
[0050] As an improvement of the present invention, the method includes a preprocessing step, and the preprocessing step includes:
[0051] The local key pool of the sending party's all-in-one machine is synchronized with the local key pool of the first access gateway with the same key file;
[0052] The local key pool of the first access gateway is synchronized with the local key pool of the first border gateway with the same key file;
[0053] The local key pool of the first border gateway is synchronized with the local key pool of the second border gateway with the same key file;
[0054] The local key pool of the second border gateway is synchronized with the local key pool of the second access gateway with the same key file;
[0055] The local key pool of the receiving party's all-in-one machine is synchronized with the local key pool of the second access gateway with the same key file.
[0056] As an improvement of the present invention, a quantum-secure cross-domain communication system is further provided, which is applied to the quantum-secure cross-domain communication method described above. The cross-domain communication system includes a sending party's privacy computer, a receiving party's privacy computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway;
[0057] The sending party's privacy computer is connected to the first access gateway, and the first border gateway is connected to the first access gateway;
[0058] The receiving - party privacy computer is connected to the second access gateway, and the second border gateway is connected to the second access gateway;
[0059] The first border gateway is connected to the second border gateway;
[0060] The sending - party privacy computer is used to receive data, perform encryption operations, and then transmit the data;
[0061] The first access gateway is used to verify data and send the verified data to the first border gateway;
[0062] The first border gateway is used to further encrypt the verified data and then transmit it to the second border gateway;
[0063] The second border gateway is used to verify data and send the verified data to the second access gateway;
[0064] The second access gateway is used to further verify the data and encrypt and transmit the verified data to the receiving - party privacy computer;
[0065] The receiving - party privacy computer is used to verify the received data and perform decryption operations after the verification passes.
[0066] Advantageous effects:
[0067] 1. During the data transmission process, by separating the key transmission and key storage, the key is not exposed in the communication channel, and only the key index is transmitted. This can not only greatly reduce the risk of key exposure, improve the flexibility and scalability of key management, but also effectively save the data - occupied bandwidth and system computing power resources, improve the data transmission efficiency, optimize the communication performance, and the system achieves a balance among security, maintainability, and performance;
[0068] 2. After merging the ciphertext stream and the key stream, they are encrypted and synchronously transmitted, which solves the delay problem caused by the inconsistent arrival times of the ciphertext data and the key data. Moreover, the one - data - stream method eliminates the matching operation of the ciphertext data and the key data during the transmission process, making the data transmission more independent and flexible. At the same time, it can also save the number of encryption and decryption operations, simplify the processing flow, effectively increase the data concurrency, and avoid delays or service overload caused by a large number of clients requesting keys from the key management system during high concurrency. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following - described drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0070] Figure 1 This is a schematic flowchart of the quantum-secure cross-domain communication method of the present application;
[0071] Figure 2 This is a schematic structural diagram of the quantum-secure cross-domain communication system of the present application. Detailed implementation manners
[0072] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0073] The present invention provides a quantum-secure cross-domain communication method. The participating parties of the method include: a sender privacy computer, a receiver privacy computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway.
[0074] As Figure 1 shown, the method includes the following steps:
[0075] Step 1: The sender privacy computer processes the initial transmission data to obtain first transmission data, and forwards the first transmission data to the first access gateway via the Internet;
[0076] Specifically, Step 1 includes:
[0077] Step 1-1: The sender's privacy computer obtains the initial transmission data Data0, where the initial transmission data is in plaintext state and includes a frame header and data content Plain1. The frame header includes the source data IP address, destination data IP address, source port number, and destination port number to ensure that the data can be accurately delivered to the destination in a complex network environment; it may also include information such as the device ID for the device to perform authentication when receiving data; it may also include the five-tuple, transmission protocol type, encryption ratio, etc., to provide efficient data transmission management, security control, traffic optimization, and network fault troubleshooting for data transmission. The sender's privacy computer obtains the first key Key1 of the corresponding size in the local key pool according to the size of the data content Plain1 of the initial transmission data, and records the first key index Index1 of the first key Key1. It should be noted that the corresponding size mentioned in the context embodiments of the present invention may be the same size or a different size from the plaintext to be encrypted. For example, when the encryption ratio requirement is 1:1, the first key Key1 of the same size as the data content Plain1 is obtained in the local key pool; when the encryption ratio requirement is not 1:1, the first key Key1 of the corresponding size is obtained according to the encryption ratio. The encryption ratio requirement is determined according to the actual situation of the user and is included in the frame header. The sender's privacy computer encrypts the data content Plain1 in the initial transmission data using the first key Key1 to obtain the first ciphertext Cipher1;
[0078] Step 1-2: The sender's privacy computer calculates the checksum of the combination of the frame header, the first key index Index1, and the first key Key1 in the initial transmission data to obtain the first checksum Check1;
[0079] In the prior art, the key index and data header checksum are often unprotected, which leaves a gap for attackers. Through simple collisions, it is easy to consume the keys on each end side (client and gateway). As long as the key index is constructed and injected, the end-side keys will be consumed meaninglessly. If the key integrity is not verified, it is easy to cause inconsistent encryption and decryption at both ends. Therefore, it is necessary to calculate the checksum of the data frame header, key index, and the key itself. Calculating the checksum is to perform a mathematical calculation on the data content through a specific algorithm to generate a short checksum value. The receiving party of the data verifies whether the data is correct by recalculating and comparing the checksum value, which is efficient for fast error detection in high-speed data transmission; its main purpose is to detect whether errors occur in the data during transmission or storage, such as bit flipping, loss, tampering, etc., to ensure the integrity of the data.
[0080] Since the key used for quantum security is a one-time pad, the first checksum Check1 obtained by calculating the checksum of the combination of the frame header, the first key index Index1, and the first key Key1 is unique and difficult to collide with in today's environment of frequent network attacks.
[0081] Step 1-3: The sender's privacy computer frames the data: It packs the frame header, the first key index Index1, the first checksum Check1, and the first ciphertext Cipher1 to obtain the first transmission data Data1.
[0082] Step 1-4: The sender's privacy computer forwards the first transmission data Data1 to the first access gateway via the Internet. At this time, the data content Plain1 in the initial transmission data is transmitted in ciphertext state on the Internet, and its confidentiality and anti-tampering properties are guaranteed at the quantum security level.
[0083] Step 2: The first access gateway verifies the first transmission data. After passing the verification, it decrypts and sends it to the first border gateway for encryption to obtain the second transmission data. The first border gateway forwards the second transmission data to the second border gateway via the Internet.
[0084] In an embodiment of the present invention, during the data transmission process, by separating the key transmission and key storage, the key is not exposed in the communication channel, and only the key index is transmitted. This can not only greatly reduce the risk of key exposure, improve the flexibility and scalability of key management, but also effectively save the data occupied bandwidth and system computing power resources, improve the data transmission efficiency, and optimize the communication performance. The system achieves a balance among security, maintainability, and performance, and is particularly meaningful in high-frequency communication. In this case, Step 2 specifically includes:
[0085] Step 2-1: The first access gateway receives the first transmission data Data1. First, it verifies the checksum: According to the first key index Index1, it obtains the corresponding key Key′1 from the local key pool, calculates the checksum Check′1 of the combination of the frame header, the first key index Index1, and the key Key′1, and compares whether the value of the first checksum Check1 is consistent with the calculated checksum Check′1. If so, the verification passes, indicating that the first transmission data Data1 has not been tampered with during the transmission process, and it proceeds to the next step; otherwise, it feedbacks verification failure to the sender's privacy computer and ends the data transmission process.
[0086] As can be seen in this step, for the access gateway, the key is pre-stored locally. When the ciphertext arrives, the key can be found according to the key index without waiting latency between each other. Therefore, the method of the present invention further includes a preprocessing step: the local key pool of the sender all-in-one machine is synchronized with the local key pool of the first access gateway with the same key file; the local key pool of the first access gateway is synchronized with the local key pool of the first border gateway with the same key file; the local key pool of the first border gateway is synchronized with the local key pool of the second border gateway with the same key file; the local key pool of the second border gateway is synchronized with the local key pool of the second access gateway with the same key file; the local key pool of the receiver all-in-one machine is synchronized with the local key pool of the second access gateway with the same key file.
[0087] Step 2-2: After the checksum verification passes, the first access gateway decrypts the first ciphertext Cipher1 in the first transmission data Data1 using the key Key′1 to obtain the data content Plain1 in plaintext state, and sends the frame header and the data content Plain1 in plaintext state to the first border gateway; it should be noted that the first access gateway and the first border gateway are in the same security domain, and the data transmission between them does not require encryption, which is beneficial to improving the data transmission efficiency.
[0088] Step 2-3: The first border gateway obtains the corresponding second key Key2 of the corresponding size in the local key pool according to the size of the data content Plain1, and records the second key index Index2 of the second key Key2, and encrypts the data content Plain1 using the second key Key2 to obtain the second ciphertext Cipher2;
[0089] Step 2-4: The first border gateway calculates the checksum for the combination of the frame header, the second key index Index2, and the second key Key2 to obtain the second checksum Check2;
[0090] Step 2-5: The first border gateway performs data framing: packs the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2;
[0091] Step 2-6: The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet according to the information such as the destination data IP address and the destination port number in the frame header. It should be noted that both the first border gateway and the second border gateway here are the outermost network elements for external transmission as a security domain. The first border gateway and the second border gateway are not in the same security domain, and the data transmission between them belongs to cross-domain transmission. For example, across provinces or across local area networks. Therefore, data transmission needs to be encrypted through the Internet.
[0092] Step 3: After decrypting the second transmission data, the second border gateway sends it to the second access gateway. The second access gateway verifies the decrypted second transmission data. After the verification passes, it encrypts the data to obtain the third transmission data, and forwards the third transmission data to the recipient privacy computer via the Internet;
[0093] In the above embodiment, Step 3 specifically includes:
[0094] Step 3-1: The second border gateway receives the second transmission data Data2. Similarly, it first verifies the checksum of the second transmission data Data2: According to the second key index Index2 in the second transmission data Data2, obtain the corresponding key Key′2 from the local key pool, calculate the checksum Check′2 of the combination of the frame header, the second key index Index2, and the key Key′2, and compare whether the value of the second checksum Check2 is consistent with the calculated checksum Check′2. If so, the verification passes, indicating that the second transmission data Data2 has not been tampered with during the transmission process, and proceed to the next step; otherwise, feedback a verification failure to the sender privacy computer via the first border gateway and the first access gateway, and end the data transmission process;
[0095] Step 3-2: The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key′2 to obtain the data content Plain1, and sends the frame header and the data content Plain1 to the second access gateway; Similarly, the second border gateway and the second access gateway are also in the same security domain, and the data transmission between them does not require encryption.
[0096] Step 3-3: The second access gateway obtains the corresponding third key Key3 of the corresponding size from the local key pool according to the size of the data content Plain1, and records the third key index Index3 of the third key Key3, and encrypts the data content Plain1 using the third key Key3 to obtain the third ciphertext Cipher3;
[0097] Step 3-4: The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3, and the third key Key3 to obtain the third checksum Check3;
[0098] Step 3-5: The second access gateway performs data framing: Pack the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3;
[0099] Step 3-6: The second access gateway forwards the third transmission data Data3 to the recipient privacy computer via the Internet.
[0100] Step 4: The receiving party's privacy computer decrypts and verifies the third transmission data. After the verification passes, the initial transmission data is obtained, and the data flow process is completed.
[0101] In the above embodiment, Step 4 specifically includes:
[0102] Step 4-1: The receiving party's privacy computer receives the third transmission data Data3. Similarly, it first verifies the checksum of the third transmission data Data3: Obtain the corresponding key Key′3 from the local key pool according to the third key index Index3, calculate the checksum Check′3 of the combination of the frame header, the third key index Index3, and the key Key′3, and compare whether the value of the third checksum Check3 is consistent with the calculated checksum Check′3. If so, the verification passes, indicating that the third transmission data Data3 has not been tampered with during the transmission process, and proceed to the next step; otherwise, feedback the verification failure to the sending party's privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process; the sending party's privacy computer reprocesses the original data according to the feedback failure information and then transmits it, or discards it.
[0103] Step 4-2: The receiving party's privacy computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key′3 to obtain the data content Plain1 of the initial transmission data, and completes the data flow process.
[0104] In another embodiment of the present invention, during the data transmission process, in the case where the original messages and processes are scattered and irregular, the data key stream frame length flowing out of the terminal is extremely short, and the variable length of the ciphertext stream will cause the pps (packet per second) of the terminal to increase, and then the probability of system interruption will increase, and the upper limit of improving communication performance is very limited. For the gateway, the received key index packets are all short packets, and it is difficult for the service traffic to increase, that is, the overall supported number of concurrent terminals is limited. Encrypting and transmitting after merging the ciphertext stream and the key stream can greatly reduce the time delay caused by the inconsistent arrival times of the ciphertext data and the key data and the probability of incorrect matching caused by the synchronization error of the ciphertext data and the key data. The independence and flexibility of data transmission are better. At the same time, it can also save the number of encryption and decryption operations, simplify the processing process, effectively increase the data concurrency, and avoid delays or service overload caused by a large number of clients requesting keys from the key management system during high concurrency. In this case, Step 2 in the method of the present invention may be:
[0105] Step 2-(1): The first access gateway receives the first transmission data Data1 and first performs the verification of the checksum: Obtain the corresponding key Key″1 from the local key pool according to the first key index Index1, calculate the checksum Check″1 of the combination of the frame header, the first key index Index1 and the key Key″1, and compare whether the value of the first checksum Check1 is consistent with the calculated checksum Check″1. If so, the verification passes, indicating that the first transmission data Data1 has not been tampered with during the transmission process. Then, pack the frame header, the key Key″1, and the first ciphertext Cipher1 and send them to the first border gateway to enter the next step; otherwise, feedback the verification failure to the sending privacy computer to end the data transmission process.
[0106] Step 2-(2): After the checksum verification passes, the first border gateway obtains the corresponding second key Key2 of the corresponding size from the local key pool according to the combination size of the key Key″1 and the first ciphertext Cipher1, and records the second key index Index2 of the second key Key2. Then, use the second key Key2 to encrypt the combination of the key Key″1 and the first ciphertext Cipher1 to obtain the second ciphertext Cipher2. It should be noted that the first access gateway and the first border gateway are in the same security domain, and the data transmission between them does not require encryption. The first access gateway does not perform the decryption operation and sends the key Key″1 and the first ciphertext Cipher1 to the first border gateway, and the first border gateway also does not perform the decryption operation, effectively saving the number of encryption and decryption operations and saving system computing power.
[0107] Step 2-(3): The first border gateway calculates the checksum of the combination of the frame header, the second key index Index2 and the second key Key2 to obtain the second checksum Check2.
[0108] Step 2-(4): The first border gateway performs data framing: Pack the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2.
[0109] Step 2-(5): The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet according to the information such as the destination data IP address and the destination port number in the frame header. It should be noted that the first border gateway and the second border gateway are not in the same security domain, and the data transmission between them is cross-domain transmission. For example, across provinces. Therefore, data transmission needs to be carried out through the Internet, and the data to be transmitted needs to be encrypted.
[0110] In this embodiment, step 3 specifically includes:
[0111] Step 3-(1): The second border gateway receives the second transmission data Data2. First, it also needs to verify the checksum of the second transmission data Data2: Obtain the corresponding key Key″2 from the local key pool according to the second key index Index2 in the second transmission data Data2, calculate the checksum Check″2 of the combination of the frame header, the second key index Index2, and the key Key″2, and compare whether the value of the second checksum Check2 is consistent with the calculated checksum Check″2. If so, the verification passes, indicating that the second transmission data Data2 has not been tampered with during the transmission process, and proceed to the next step; otherwise, feedback a verification failure to the sender privacy computer via the first border gateway and the first access gateway, and end the data transmission process;
[0112] Step 3-(2): The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key″2 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and sends the frame header and the combination of the key Key″1 and the first ciphertext Cipher1 to the second access gateway; Similarly, the second border gateway and the second access gateway are also in the same security domain, and the data transmission between them does not require encryption.
[0113] Step 3-(3): The second access gateway obtains the corresponding third key Key3 of the corresponding size from the local key pool according to the size of the combination of the key Key″1 and the first ciphertext Cipher1, and records the third key index Index3 of the third key Key3, and encrypts the combination of the key Key″1 and the first ciphertext Cipher1 using the third key Key3 to obtain the third ciphertext Cipher3;
[0114] Step 3-(4): The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3, and the third key Key3 to obtain the third checksum Check3;
[0115] Step 3-(5): The second access gateway performs data framing: Package the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3;
[0116] Step 3-(6): The second access gateway forwards the third transmission data Data3 to the receiver privacy computer via the Internet.
[0117] In this embodiment, step 4 specifically includes:
[0118] Step 4-(1): The receiving party's privacy computer receives the third transmission data Data3. First, it also needs to verify the checksum of the third transmission data Data3: Obtain the corresponding key Key″3 from the local key pool according to the third key index Index3, calculate the checksum Check″3 of the combination of the frame header, the third key index Index3, and the key Key″3, and compare whether the value of the third checksum Check3 is consistent with the calculated checksum Check″3. If so, the verification passes, indicating that the third transmission data Data3 has not been tampered with during the transmission process, and proceed to the next step; otherwise, feedback the verification failure to the sending party's privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process; the sending party's privacy computer reprocesses the original data according to the feedback failure information and then transmits it, or discards it.
[0119] Step 4-(2): The receiving party's privacy computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key″3 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and decrypts the first ciphertext Cipher1 using the key Key″1 to obtain the data content Plain1 of the initial transmission data, completing the data flow process.
[0120] According to the quantum-secure cross-domain communication system described above, it can be seen that the present invention also provides a quantum-secure cross-domain communication system, which is applied to the quantum-secure cross-domain communication method described above. As Figure 2As shown in the figure, the cross-domain communication system includes a sender privacy computer, a receiver privacy computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway; among them, the sender privacy computer is connected to the first access gateway, and the first border gateway is connected to the first access gateway; the receiver privacy computer is connected to the second access gateway, and the second border gateway is connected to the second access gateway; the first border gateway is connected to the second border gateway; the sender privacy computer is used to receive data and perform encryption operations before transmission. As can be seen from the above method, the first access gateway is used to verify the data and send the verified data to the first border gateway; the first border gateway is used to further encrypt the verified data and transmit it to the second border gateway; the second border gateway is used to verify the data and send the verified data to the second access gateway; the second access gateway is used to further verify the data and encrypt and transmit the verified data to the receiver privacy computer; the receiver privacy computer is used to verify the received data and perform decryption operations after verification. The local key pools between the sender all-in-one machine and the first access gateway, the first access gateway and the first border gateway, the first border gateway and the second border gateway, the second border gateway and the second access gateway, and the receiver all-in-one machine and the second access gateway are synchronized with the same key file to provide keys for encryption and decryption operations and hash calculations.
Claims
1. A quantum-secure cross-domain communication method, the participants of the method include: A sender privacy computer, a receiver privacy computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway; characterized in that the method comprises the following steps: Step 1: The sender privacy computer processes the initial transmission data to obtain first transmission data, and forwards the first transmission data to the first access gateway via the Internet; Step 2: The first access gateway verifies the first transmission data. After the verification passes, it decrypts and sends it to the first border gateway for encryption to obtain second transmission data. The first border gateway forwards the second transmission data to the second border gateway via the Internet; Step 3: The second border gateway decrypts the second transmission data and sends it to the second access gateway. The second access gateway verifies the decrypted second transmission data. After the verification passes, it encrypts it to obtain third transmission data, and forwards the third transmission data to the receiver privacy computer via the Internet; Step 4: The receiver privacy computer decrypts and verifies the third transmission data. After the verification passes, it obtains the initial transmission data, and completes the data flow process.
2. The quantum-secure cross-domain communication method according to claim 1, wherein: The said Step 1 includes: Step 1-1: The sender privacy computer obtains the initial transmission data Data0. Among them, the initial transmission data is in plaintext state, including a frame header and data content Plain1; the sender privacy computer obtains a corresponding first key Key1 of the corresponding size in the local key pool according to the size of the data content Plain1 of the initial transmission data, and records the first key index Index1 of the first key Key1, and uses the first key Key1 to encrypt the data content Plain1 in the initial transmission data to obtain the first ciphertext Cipher1; Step 1-2: The sender privacy computer calculates the checksum of the combination of the frame header, the first key index Index1, and the first key Key1 in the initial transmission data to obtain the first checksum Check1; Step 1-3: The sender privacy computer performs data framing: packs the frame header, the first key index Index1, the first checksum Check1, and the first ciphertext Cipher1 to obtain the first transmission data Data1; Step 1-4: The sender privacy computer forwards the first transmission data Data1 to the first access gateway via the Internet.
3. The quantum-secure cross-domain communication method according to claim 1 or 2, characterized in that: The said Step 2 includes: Step 2-1: The first access gateway receives the first transmission data Data1, obtains the corresponding key Key′1 in the local key pool according to the first key index Index1, calculates the checksum Check′1 of the combination of the frame header, the first key index Index1, and the key Key′1, and compares whether the value of the first checksum Check1 is consistent with the calculated checksum Check′1. If so, the verification passes and proceeds to the next step; otherwise, it feeds back verification failure to the sender privacy computer and ends the data transmission process; Step 2-2: The first access gateway decrypts the first ciphertext Cipher1 in the first transmission data Data1 using the key Key′1 to obtain the data content Plain1, and sends the frame header and the data content Plain1 to the first border gateway; Step 2-3: The first border gateway obtains a corresponding second key Key2 of the corresponding size from the local key pool according to the size of the data content Plain1, records the second key index Index2 of the second key Key2, and encrypts the data content Plain1 using the second key Key2 to obtain the second ciphertext Cipher2; Step 2-4: The first border gateway calculates the checksum of the combination of the frame header, the second key index Index2, and the second key Key2 to obtain the second checksum Check2; Step 2-5: The first border gateway performs data framing: packs the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2; Step 2-6: The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet.
4. The quantum-secure cross-domain communication method according to claim 3, characterized in that: The said step 3 includes: Step 3-1: The second border gateway receives the second transmission data Data2, obtains the corresponding key Key′2 from the local key pool according to the second key index Index2 in the second transmission data Data2, calculates the checksum Check′2 of the combination of the frame header, the second key index Index2, and the key Key′2, and compares whether the value of the second checksum Check2 is consistent with the calculated checksum Check′2. If so, the verification passes and proceeds to the next step; otherwise, feedbacks verification failure to the sender privacy computer via the first border gateway and the first access gateway, and ends the data transmission process; Step 3-2: The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key′2 to obtain the data content Plain1, and sends the frame header and the data content Plain1 to the second access gateway; Step 3-3: The second access gateway obtains a corresponding third key Key3 of the corresponding size from the local key pool according to the size of the data content Plain1, records the third key index Index3 of the third key Key3, and encrypts the data content Plain1 using the third key Key3 to obtain the third ciphertext Cipher3; Step 3-4: The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3, and the third key Key3 to obtain the third checksum Check3; Step 3-5: The second access gateway performs data framing: packs the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3; Step 3-6: The second access gateway forwards the third transmission data Data3 to the receiver privacy computer via the Internet.
5. The quantum-secure cross-domain communication method according to claim 4, characterized in that: The said step 4 includes: Step 4-1: The receiving party's privacy computer receives the third transmission data Data3, obtains the corresponding key Key′3 from the local key pool according to the third key index Index3, calculates the checksum Check′3 of the combination of the frame header, the third key index Index3, and the key Key′3, and compares whether the value of the third checksum Check3 is consistent with the calculated checksum Check′3. If so, the verification passes and proceeds to the next step; otherwise, feedback verification failure to the sending party's privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process; Step 4-2: The receiving party's privacy computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key′3 to obtain the data content Plain1 of the initial transmission data, and completes the data flow process.
6. The quantum-secure cross-domain communication method according to claim 1 or 2, characterized in that: The said step 2 includes: Step 2-(1): The first access gateway receives the first transmission data Data1, obtains the corresponding key Key″1 from the local key pool according to the first key index Index1, calculates the checksum Check″1 of the combination of the frame header, the first key index Index1, and the key Key″1, and compares whether the value of the first checksum Check1 is consistent with the calculated checksum Check″1. If so, the verification passes, packs the frame header, the key Key″1, and the first ciphertext Cipher1 and sends them to the first border gateway, and proceeds to the next step; otherwise, feedback verification failure to the sending party's privacy computer and end the data transmission process; Step 2-(2): The first border gateway obtains the second key Key2 of the corresponding size from the local key pool according to the size of the combination of the key Key″1 and the first ciphertext Cipher1, records the second key index Index2 of the second key Key2, and encrypts the combination of the key Key″1 and the first ciphertext Cipher1 using the second key Key2 to obtain the second ciphertext Cipher2; Step 2-(3): The first border gateway calculates the checksum of the combination of the frame header, the second key index Index2, and the second key Key2 to obtain the second checksum Check2; Step 2-(4): The first border gateway performs data framing: packs the frame header, the second key index Index2, the second checksum Check2, and the second ciphertext Cipher2 to obtain the second transmission data Data2; Step 2-(5): The first border gateway forwards the second transmission data Data2 to the second border gateway via the Internet.
7. The quantum-secure cross-domain communication method according to claim 6, characterized in that: The said step 3 includes: Step 3-(1): The second border gateway receives the second transmission data Data2, obtains the corresponding key Key″2 from the local key pool according to the second key index Index2 in the second transmission data Data2, calculates the checksum Check″2 of the combination of the frame header, the second key index Index2, and the key Key″2, and compares whether the value of the second checksum Check2 is consistent with the calculated checksum Check″2. If so, the verification passes and proceeds to the next step; otherwise, feedback the verification failure to the sender privacy computer via the first border gateway and the first access gateway, and end the data transmission process; Step 3-(2): The second border gateway decrypts the second ciphertext Cipher2 in the second transmission data Data2 using the key Key″2 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and sends the frame header and the combination of the key Key″1 and the first ciphertext Cipher1 to the second access gateway; Step 3-(3): The second access gateway obtains the corresponding third key Key3 of the corresponding size from the local key pool according to the size of the combination of the key Key″1 and the first ciphertext Cipher1, records the third key index Index3 of the third key Key3, and encrypts the combination of the key Key″1 and the first ciphertext Cipher1 using the third key Key3 to obtain the third ciphertext Cipher3; Step 3-(4): The second access gateway calculates the checksum of the combination of the frame header, the third key index Index3, and the third key Key3 to obtain the third checksum Check3; Step 3-(5): The second access gateway performs data framing: packs the frame header, the third key index Index3, the third checksum Check3, and the third ciphertext Cipher3 to obtain the third transmission data Data3; Step 3-(6): The second access gateway forwards the third transmission data Data3 to the receiver privacy computer via the Internet.
8. The quantum-secure cross-domain communication method according to claim 7, characterized in that: The said step 4 includes: Step 4-(1): The receiver privacy computer receives the third transmission data Data3, obtains the corresponding key Key″3 from the local key pool according to the third key index Index3, calculates the checksum Check″3 of the combination of the frame header, the third key index Index3, and the key Key″3, and compares whether the value of the third checksum Check3 is consistent with the calculated checksum Check″3. If so, the verification passes and proceeds to the next step; otherwise, feedback the verification failure to the sender privacy computer via the second access gateway, the second border gateway, the first border gateway, and the first access gateway, and end the data transmission process; Step 4-(2): The receiving party's private computer decrypts the third ciphertext Cipher3 in the third transmission data Data3 using the key Key″3 to obtain the combination of the key Key″1 and the first ciphertext Cipher1, and decrypts the first ciphertext Cipher1 using the key Key″1 to obtain the data content Plain1 of the initial transmission data, thus completing the data flow process.
9. The quantum-secure cross-domain communication method according to any one of claims 1-8, characterized in that: The method includes a preprocessing step, and the preprocessing step includes: The local key pool of the sender's all-in-one machine is synchronized with the local key pool of the first access gateway with the same key file; The local key pool of the first access gateway is synchronized with the local key pool of the first border gateway with the same key file; The local key pool of the first border gateway is synchronized with the local key pool of the second border gateway with the same key file; The local key pool of the second border gateway is synchronized with the local key pool of the second access gateway with the same key file; The local key pool of the receiving party's all-in-one machine is synchronized with the local key pool of the second access gateway with the same key file.
10. A quantum-secure cross-domain communication system for performing the quantum-secure cross-domain communication method according to any one of claims 1-9, characterized in that: The cross-domain communication system includes a sender's private computer, a receiver's private computer, a first access gateway, a first border gateway, a second access gateway, and a second border gateway; The sender's private computer is connected to the first access gateway, and the first border gateway is connected to the first access gateway; The receiver's private computer is connected to the second access gateway, and the second border gateway is connected to the second access gateway; The first border gateway is connected to the second border gateway; The sender's private computer is used to receive data and perform an encryption operation before transmission; The first access gateway is used to verify the data and send the verified data to the first border gateway; The first border gateway is used to further encrypt the verified data and transmit it to the second border gateway; The second border gateway is used to verify the data and send the verified data to the second access gateway; The second access gateway is used to further verify the data and encrypt and transmit the verified data to the receiver's private computer; The receiver's private computer is used to verify the received data and perform a decryption operation after verification.
Citation Information
Patent Citations
Quantum security network data sending method, quantum security network data receiving method and communication system
CN115834210A