Quantum security communication method and system
By integrating the base station with a secure server, synchronous transmission of ciphertext streams and key streams is solved, and the problem of delay and concurrency quantity in existing quantum key encryption transmission systems is improved, and the efficiency and performance of the system are improved.
Patent Information
- Application Number
- CN202510421569.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-25
AI Technical Summary
In the existing quantum key encryption transmission system, asynchronous transmission of ciphertext keys leads to a huge delay, and the probability of ciphertext key data being short-packet is extremely high, resulting in the problem of low concurrency.
The base station is fused with a secure server, the ciphertext stream and the key stream are synchronized into one, and the hashing algorithm is used for verification and comparison and decryption, and the same key pool is used for encryption transmission, simplifying the processing flow, reducing delay and increasing the number of concurrency.
The delay between ciphertext keys is reduced, the total number of hops is reduced, the service concurrency and the utilization rate of single-frame transmission data is improved, and the 0 delay between ciphertext and key is achieved.
Smart Images

Figure CN120378142A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a quantum-secure communication method and system. Background Art
[0002] In daily life and work, numerous powerful intelligent devices play an increasingly important role. While these intelligent devices provide us with many conveniences, they also transmit a large amount of data. The data in these intelligent devices often involves users' privacy information, and users do not allow this privacy information to be stolen by others.
[0003] Application No. CN202311630283.3, a networking system and method for a quantum-secure local area network. In this patent, various types of quantum-secure devices in the quantum-secure local area network, such as access base stations, security servers, etc. For any access base station, through this access base station, it is possible to send the quantum-encrypted data (denoted as ciphertext data) for communication between user terminals and the quantum key through different network paths, that is, the ciphertext data is sent through the traditional network, and the key is sent through the quantum-secure local area network, ensuring the security of key relay. Thus, it can be seen that quantum key encryption is used for transmission between terminals. During the transmission process, the data output from the terminal needs to be divided into two paths for the ciphertext and the key, one is the key network, and the other is the communication network. The separate transmission paths for the ciphertext and the key and the deployment of numerous network elements result in a cost of 26 hops for the data (including the ciphertext and the key) in the entire system. It also leads to the need for the ciphertext and the key to wait, match, and decrypt on the security server, and then relay new keys and ciphertext, and again form two-way data to be sent to the destination. Additionally, at the destination, the key and the ciphertext still need to wait and match each other, ultimately resulting in extremely large latency and poor user experience. At the same time, for these 26 hops, in the event of frame loss during the transmission process (a high-probability event), although this part relies on TCP retransmission, due to the complex subsequent paths and processing procedures, once ciphertext or key frame retransmission occurs, the number of hops will be extremely large.
[0004] In addition, in the original system, messages and processes are scattered and extremely irregular. Before communication occurs, the data structure for communication transmission has been determined. Only by filling the key data or ciphertext data into the payload content can the data structure be formed. The length of the data key stream frame at the terminal is extremely short, while the length of the ciphertext stream is variable. This has led to an increase in the pps (packets per second) of the terminal and an increase in system interruptions. The upper limit for performance improvement is very limited. Moreover, the extremely short frame length of the key stream cannot fully utilize the data format space, resulting in a waste of transmission bandwidth. For the base station in the original system, all the received packets are key index packets from the terminal, which are short packets. Even with a 10 Gigabit Ethernet port, when the pps is very high, the service traffic cannot increase. In other words, the overall number of concurrent terminal services supported is not high.
[0005] In view of this, how to solve the problem of extremely large latency caused by the asynchronous transmission of ciphertext keys, resulting in the mutual waiting and matching of keys and ciphertext during the quantum key encryption transmission process; and how to solve the problem of a very high probability of short packets for ciphertext key data during the transmission process, resulting in a low number of concurrences, are currently the technical issues of concern in the industry. Summary of the Invention
[0006] Object of the Invention: To solve the related technical problems proposed in the background art, the present invention provides a quantum-secure communication method and system, which integrates the base station and the security server, and then synchronizes and combines the ciphertext stream and the key stream into one, greatly reducing the latency of data, simplifying the processing process, and increasing the number of concurrences.
[0007] Technical Solution: A quantum-secure communication method of the present invention includes the following steps:
[0008] (1) The first privacy computer with quantum security as the sender encrypts the plaintext data to be sent and constructs a first data frame, and then sends the first data frame to the quantum-secure access gateway;
[0009] (2) The quantum-secure access gateway performs a first verification and comparison on the received first data frame. After the verification and comparison pass, it decrypts and then encrypts and constructs a second data frame, and sends the second data frame to the second privacy computer with quantum security as the receiver;
[0010] (3) The second privacy computer performs a second verification and comparison on the received second data frame. After the verification and comparison pass, it decrypts to obtain the plaintext data sent by the first privacy computer.
[0011] Further, the first privacy computer, the quantum-secure access gateway, and the second privacy computer are all preset with the same verification and comparison method, which is the method of calculating the checksum using the hash algorithm;
[0012] The same first key pool is preset between the first privacy computer and the quantum secure access gateway, and the same second key pool is preset between the second privacy computer and the quantum secure access gateway.
[0013] Further, the specific process of encrypting the plaintext data to be sent, constructing a first data frame, and then sending the first data frame to the quantum secure access gateway is as follows:
[0014] 1) The privacy area of the first privacy computer sends the plaintext data to be sent to the isolation area of the first privacy computer. The isolation area of the first privacy computer obtains a first key from the local first key pool and encrypts the plaintext data to be sent to obtain a first ciphertext.
[0015] 2) The isolation area of the first privacy computer generates a data header corresponding to the first ciphertext, then verifies the data header, the first key, and the key index of the first key to generate a first checksum. Then, the data header, the key index of the first key, the first checksum, and the first ciphertext are constructed into a first data frame.
[0016] 3) The isolation area of the first privacy computer sends the first data frame to the communication area of the first privacy computer, and the communication area of the first privacy computer then sends the first data frame to the quantum secure access gateway via the Internet.
[0017] Further, the specific process of step (2) is as follows:
[0018] After the communication area of the quantum secure access gateway receives the first data frame, the communication area of the quantum secure access gateway forwards it to the isolation area of the quantum secure access gateway.
[0019] The isolation area of the quantum secure access gateway uses the key index of the first key in the first data frame to obtain a second key from the preset first key pool that is the same as that of the first privacy computer, and then verifies the data header, the second key, and the key index of the first key in the first data frame to generate a second checksum. Compare whether the second checksum is consistent with the first checksum in the first data frame. If they are consistent, decrypt the first ciphertext in the first data frame with the second key to obtain the first plaintext data.
[0020] The isolation area of the quantum secure access gateway sends the first plaintext data to the privacy area of the quantum secure access gateway for storage. Then, the isolation area of the quantum secure access gateway obtains a third key from the preset second key pool that is the same as that of the second privacy computer, encrypts the first plaintext data with the third key to obtain a second ciphertext. Then, verify the data header, the third key, and the key index of the third key to generate a third checksum. Then, construct the data header, the key index of the third key, the third checksum, and the second ciphertext into a second data frame.
[0021] The isolation area of the quantum-secure access gateway sends the second data frame to the communication area of the quantum-secure access gateway, and the communication area of the quantum-secure access gateway then sends the second data frame to the second private computer via the Internet.
[0022] Further, the specific process of the second private computer performing a second verification comparison on the received second data frame and decrypting it to obtain the plaintext data sent by the first private computer after passing the verification comparison is as follows:
[0023] After the communication area of the second private computer receives the second data frame, the communication area of the second private computer forwards it to the isolation area of the second private computer;
[0024] The isolation area of the second private computer uses the key index of the third key in the second data frame to obtain the fourth key in the pre-set second key pool that is the same as the quantum-secure access gateway, and then verifies the data header, the fourth key, and the key index of the third key in the second data frame to generate a fourth checksum; compares whether the fourth checksum is consistent with the third checksum in the second data frame. If they are consistent, the second ciphertext in the second data frame is decrypted with the fourth key to obtain the second plaintext data, and the second plaintext data is the plaintext data sent by the first private computer.
[0025] Further, the data header includes the network access code RID of the first private computer.
[0026] Further, the hash algorithm is a hash function based on a linear feedback shift register obtained by selecting an irreducible polynomial and an input random number, or a traditional hash algorithm, including one of MD4, MD5, SHA2, SHA3, RIPEMD, and MASH-1 algorithms.
[0027] Further, the encryption method for encrypting the plaintext data to be sent is one-time pad.
[0028] The present invention further includes a system based on the above-mentioned quantum-secure communication method. The system includes a quantum-secure first private computer as the sender, a quantum-secure access gateway, and a quantum-secure second private computer as the receiver; wherein, the first private computer is connected to the quantum-secure access gateway via the Internet, and the quantum-secure access gateway is connected to the second private computer via the Internet;
[0029] The first private computer is used to encrypt the plaintext data to be sent, construct a first data frame, and then send the first data frame to the quantum-secure access gateway;
[0030] The quantum-secure access gateway is used to verify and compare the first data frame. After the verification and comparison pass, it decrypts and then encrypts the data frame and constructs a second data frame, and sends the second data frame to the second private computer.
[0031] The second private computer is used to verify and compare the second data frame. After the verification and comparison pass, it decrypts the second data frame to obtain the plaintext data sent by the first private computer.
[0032] Further, both the first private computer and the second private computer include a communication area, an isolation area, and a privacy area that are connected in sequence.
[0033] The communication area of the private computer is used for the private computer to transmit data with the outside world.
[0034] The isolation area of the private computer is used to encrypt the plaintext data to be sent and construct a data frame, and then send the data frame to the communication area of the private computer; and to verify and compare the received data frame. After the verification and comparison pass, it decrypts the data frame to obtain the plaintext data, and then sends the plaintext data to the privacy area of the private computer.
[0035] The privacy area of the private computer is used to send the plaintext data to be sent to the isolation area of the private computer; and to receive the plaintext data from the isolation area of the private computer.
[0036] Advantages of the present invention: The present invention integrates the base station and the security server. After integration, the ciphertext key is on the same stream, the number of frames is reduced, and the overall average frame length is doubled, saving the CPU, improving service concurrency and the utilization rate of single-frame transmission data; at the same time, the ciphertext key is synchronously transmitted, greatly reducing the delay between ciphertext keys, and the total number of hops is halved or even more, truly achieving 0 delay between ciphertext and key. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0038] Figure 1 It is a schematic structural diagram of the quantum-secure communication system of the present invention;
[0039] Figure 2 It is a schematic flow diagram of the quantum-secure communication method of the present invention;
[0040] Figure 3 It is a schematic structural diagram of the first data frame of the present invention;
[0041] Figure 4 Schematic diagram for the quantum-secure access gateway of the present invention to process data;
[0042] Figure 5 Schematic diagram for the receiving party of the present invention to process data. Detailed implementation manners
[0043] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.
[0044] As described in the background art, in the currently adopted system for quantum key encrypted transmission, there are problems such as asynchronous transmission of ciphertext keys during the transmission process, resulting in mutual waiting and matching of key ciphertexts and extremely large time delays; and the probability that the ciphertext key data is a short packet during the transmission process is extremely high, resulting in a low concurrency number. Therefore, how to solve these problems during the process of quantum key encrypted transmission is an important problem currently faced.
[0045] In view of this, the present invention proposes a quantum-secure communication system, which includes a quantum-secure first privacy computer 1 as the sender, a quantum-secure access gateway 2, and a quantum-secure second privacy computer 3 as the receiver; wherein, as Figure 1 shown, the first privacy computer 1 is connected to the quantum-secure access gateway 2 through the Internet, and the quantum-secure access gateway 2 is connected to the second privacy computer 3 through the Internet; the quantum-secure access gateway 2 integrates a base station and a security server, and makes a deep integration at the architecture and program levels, effectively reducing the consumption of bandwidth and hardware resources.
[0046] The first privacy computer 1 is used to encrypt the plaintext data to be sent and construct a first data frame, and then send the first data frame to the quantum-secure access gateway 2; the quantum-secure access gateway 2 is used to perform verification and comparison on the first data frame, decrypt and then encrypt it after passing the verification and comparison and construct a second data frame, and send the second data frame to the second privacy computer 3; the second privacy computer 3 is used to perform verification and comparison on the second data frame, and decrypt it to obtain the plaintext data sent by the first privacy computer 1 after passing the verification and comparison. The entire system simplifies the topological structure of the global quantum-secure network, reduces the total number of hops by half or more, reduces the deployment complexity, and reduces the configuration.
[0047] Among them, the first privacy computer 1 and the second privacy computer 3 both include a communication area 11, an isolation area 12, and a privacy area 13 that are connected in sequence; the communication area 11 of the privacy computer is used for the privacy computer to transmit data with the outside world; the isolation area 12 of the privacy computer is used to encrypt the plaintext data to be sent and construct a data frame, and then send the data frame to the communication area 11 of the privacy computer; and to perform verification and comparison on the received data frame, decrypt it to obtain plaintext data after passing the verification and comparison, and then send the plaintext data to the privacy area 13 of the privacy computer; the privacy area 13 of the privacy computer is used to send the plaintext data to be sent to the isolation area 12 of the privacy computer; and to receive the plaintext data from the isolation area 12 of the privacy computer.
[0048] The quantum-secure access gateway 2 is also divided into a communication area, an isolation area, and a privacy area; the communication area of the quantum-secure access gateway 2 is also used for data transmission with the outside world; the isolation area of the quantum-secure access gateway 2 is used to perform verification and comparison on the received data frame, decrypt it, encrypt it again, and construct a transmission data frame after passing the verification and comparison, and send the transmission data frame to the communication area; while the privacy area of the quantum-secure access gateway 2 is used to store the decrypted plaintext data.
[0049] It can be seen that after the integration, the ciphertext key hash tables in the original base station and the security server no longer exist, the timeout threads of the two devices are no longer necessary, the number of frames is reduced, the number of checksum calculations is reduced, and the cpu consumed by communication is reduced. At the same time, both the privacy computer and the quantum-secure access gateway have the hardware device structures of the three areas of the communication area, the isolation area, and the privacy area, so that the transmission data involved in the communication work process is transmitted in an encrypted and secure manner; any third-party device attacks it, and can only reach its communication area and cannot pass through the isolation area smoothly, so the attack cannot reach the privacy area and thus cannot affect the operation of the system.
[0050] As Figure 2 shown, the present invention also includes a communication method based on the above-mentioned quantum-secure communication system, including the following steps:
[0051] First, the first privacy computer 1, the quantum-secure access gateway 2, and the second privacy computer 3 are all preset with the same verification and comparison method, which is the method of calculating the checksum using the hash algorithm; the hash algorithm is a hash function based on a linear feedback shift register obtained by selecting an irreducible polynomial and an input random number, or a traditional hash algorithm, including one of MD4, MD5, SHA2, SHA3, RIPEMD, and MASH-1 algorithms. Moreover, for the need of encrypted transmission, the same first key pool is preset between the first privacy computer 1 and the quantum-secure access gateway 2, and the same second key pool is preset between the second privacy computer 3 and the quantum-secure access gateway 2; next is the data transmission:
[0052] (1) The quantum-secure first privacy computer 1, as the sender, encrypts the plaintext data to be sent and constructs a first data frame, and then sends the first data frame to the quantum-secure access gateway 2. The specific process is as follows:
[0053] 1) The privacy area 13 of the first privacy computer 1 sends the plaintext data to be sent to the isolation area 12 of the first privacy computer 1. The isolation area 12 of the first privacy computer 1 obtains the first key from the local first key pool and encrypts the plaintext data to be sent to obtain the first ciphertext. The encryption method for encrypting the plaintext data to be sent is one-time pad.
[0054] 2) The isolation area 12 of the first privacy computer 1 generates a data header corresponding to the first ciphertext. The data header includes the network access code RID of the first privacy computer 1, etc.; then it verifies the data header, the first key, and the key index of the first key to generate a first checksum; then it constructs the data header, the key index of the first key, the first checksum, and the first ciphertext into a first data frame, as Figure 3 shown; the frame header part in the first data frame is not shown, which is common knowledge in this field, so it is ignored. The frame header contains conventional source IP, destination IP, transport protocol, etc. Among them, the key index of the first key is information such as the offset, encryption ratio, and file location of the key used to encrypt the first ciphertext.
[0055] 3) The isolation area 12 of the first privacy computer 1 sends the first data frame to the communication area 11 of the first privacy computer 1, and the communication area 11 of the first privacy computer 1 then sends the first data frame to the quantum-secure access gateway 2 through the Internet.
[0056] (2) The quantum-secure access gateway 2 performs a first verification and comparison on the received first data frame. After the verification and comparison pass, it decrypts and then encrypts it and constructs a second data frame, and sends the second data frame to the quantum-secure second privacy computer 3 as the receiver. The specific process is as follows:
[0057] As Figure 4 shown, after the communication area of the quantum-secure access gateway 2 receives the first data frame, the communication area of the quantum-secure access gateway 2 forwards it to the isolation area of the quantum-secure access gateway 2;
[0058] The isolation area of the quantum-secure access gateway 2 uses the key index of the first key in the first data frame to obtain the second key in the pre-set first key pool that is the same as the first privacy computer 1, and then verifies the data header, the second key, and the key index of the first key in the first data frame to generate a second checksum; compares whether the second checksum is consistent with the first checksum in the first data frame. If they are consistent, it decrypts the first ciphertext in the first data frame with the second key to obtain the first plaintext data;
[0059] The isolation area of the quantum-secure access gateway 2 sends the first plaintext data to the privacy area of the quantum-secure access gateway 2 for storage. Then, the isolation area of the quantum-secure access gateway 2 obtains a third key from a pre-set second key pool that is the same as the second privacy computer 3, and encrypts the first plaintext data with the third key to obtain a second ciphertext. Then, it verifies the data header, the third key, and the key index of the third key to generate a third checksum. Next, it constructs a second data frame with the data header, the key index of the third key, the third checksum, and the second ciphertext.
[0060] The isolation area of the quantum-secure access gateway 2 sends the second data frame to the communication area of the quantum-secure access gateway 2, and the communication area of the quantum-secure access gateway 2 then sends the second data frame to the second privacy computer 3 via the Internet. From the above process, it can be seen that for the access gateway, the key is local, and when the ciphertext arrives, the key can be found according to the index. There is no waiting delay between each other, no hash table, and no hash table lock operation. Such message processing is relatively simple.
[0061] (3) The second privacy computer 3 performs a second verification comparison on the received second data frame. After the verification comparison passes, it decrypts to obtain the plaintext data sent by the first privacy computer 1. The specific process is as follows:
[0062] As Figure 5 shown, after the communication area of the second privacy computer 3 receives the second data frame, the communication area of the second privacy computer 3 forwards it to the isolation area of the second privacy computer 3;
[0063] The isolation area of the second privacy computer 3 uses the key index of the third key in the second data frame to obtain a fourth key from a pre-set second key pool that is the same as the quantum-secure access gateway 2, and then verifies the data header, the fourth key, and the key index of the third key in the second data frame to generate a fourth checksum. It compares whether the fourth checksum is consistent with the third checksum in the second data frame. If they are consistent, it decrypts the second ciphertext in the second data frame with the fourth key to obtain the second plaintext data, and the second plaintext data is the plaintext data sent by the first privacy computer 1.
[0064] The present invention integrates the base station and the security server. After integration, it combines the ciphertext stream and the key stream into one, reducing the number of frames and doubling the overall average frame length, saving the CPU and improving concurrency. At the same time, it synchronously transmits the ciphertext key, greatly reducing the delay between the ciphertext and the key, and truly achieving zero delay between the ciphertext and the key.
Claims
1. A quantum-secure communication method, characterized in that, It includes the following steps: (1) The first quantum-secure privacy computer as the sender encrypts the plaintext data to be sent and constructs a first data frame, and then sends the first data frame to the quantum-secure access gateway; (2) The quantum-secure access gateway performs a first verification and comparison on the received first data frame. After passing the verification and comparison, it decrypts and then encrypts it and constructs a second data frame, and sends the second data frame to the second quantum-secure privacy computer as the receiver; (3) The second privacy computer performs a second verification and comparison on the received second data frame. After passing the verification and comparison, it decrypts to obtain the plaintext data sent by the first privacy computer.
2. The quantum-secure communication method according to claim 1, characterized in that, The first privacy computer, the quantum-secure access gateway, and the second privacy computer are all preset with the same verification and comparison method, which is the method of calculating the checksum using the hash algorithm; There is a same first key pool preset between the first privacy computer and the quantum-secure access gateway, and a same second key pool preset between the second privacy computer and the quantum-secure access gateway.
3. A quantum-secure communication method according to claim 1, characterized in that, The specific process of encrypting the plaintext data to be sent and constructing a first data frame, and then sending the first data frame to the quantum-secure access gateway is as follows: 1) The privacy area of the first privacy computer sends the plaintext data to be sent to the isolation area of the first privacy computer. The isolation area of the first privacy computer obtains a first key from the local first key pool and encrypts the plaintext data to be sent to obtain a first ciphertext; 2) The isolation area of the first privacy computer generates a data header corresponding to the first ciphertext, and then verifies the data header, the first key, and the key index of the first key to generate a first checksum; then constructs the data header, the key index of the first key, the first checksum, and the first ciphertext into a first data frame; 3) The isolation area of the first privacy computer sends the first data frame to the communication area of the first privacy computer, and the communication area of the first privacy computer then sends the first data frame to the quantum-secure access gateway through the Internet.
4. A quantum-secure communication method according to claim 3, characterized in that The specific process of step (2) is as follows: After the communication area of the quantum-secure access gateway receives the first data frame, the communication area of the quantum-secure access gateway forwards it to the isolation area of the quantum-secure access gateway; The isolation area of the quantum-secure access gateway obtains a second key from the preset first key pool that is the same as the first privacy computer using the key index of the first key in the first data frame, and then verifies the data header, the second key, and the key index of the first key in the first data frame to generate a second checksum; compares whether the second checksum is consistent with the first checksum in the first data frame. If they are consistent, it decrypts the first ciphertext in the first data frame with the second key to obtain the first plaintext data; The isolation area of the quantum-secure access gateway sends the first plaintext data to the privacy area of the quantum-secure access gateway for storage. Then, the isolation area of the quantum-secure access gateway obtains the third key from a pre-set second key pool that is the same as that of the second privacy computer, and encrypts the first plaintext data with the third key to obtain the second ciphertext. Then, it verifies the data header, the third key, and the key index of the third key to generate the third checksum. Next, it constructs a second data frame with the data header, the key index of the third key, the third checksum, and the second ciphertext. The isolation area of the quantum-secure access gateway sends the second data frame to the communication area of the quantum-secure access gateway, and the communication area of the quantum-secure access gateway then sends the second data frame to the second privacy computer via the Internet.
5. A quantum-secure communication method according to claim 4, characterized in that, The specific process for the second privacy computer to perform a second verification comparison on the received second data frame and decrypt it to obtain the plaintext data sent by the first privacy computer after passing the verification comparison is as follows: After the communication area of the second privacy computer receives the second data frame, the communication area of the second privacy computer forwards it to the isolation area of the second privacy computer. The isolation area of the second privacy computer uses the key index of the third key in the second data frame to obtain the fourth key from a pre-set second key pool that is the same as that of the quantum-secure access gateway, and then verifies the data header, the fourth key, and the key index of the third key in the second data frame to generate the fourth checksum. Compare whether the fourth checksum is consistent with the third checksum in the second data frame. If they are consistent, decrypt the second ciphertext in the second data frame with the fourth key to obtain the second plaintext data, which is the plaintext data sent by the first privacy computer.
6. A quantum-secure communication method according to claim 3, characterized in that: The data header includes the network access code RID of the first privacy computer.
7. A quantum-secure communication method according to claim 2, characterized in that: The hash algorithm is a hash function based on a linear feedback shift register obtained by selecting an irreducible polynomial and an input random number, or a traditional hash algorithm, including one of MD4, MD5, SHA2, SHA3, RIPEMD, and MASH-1 algorithms.
8. A quantum-secure communication method according to claim 3, characterized in that: The encryption method for encrypting the plaintext data to be sent is one-time pad.
9. A system for a quantum-secure communication method according to any one of claims 1 to 8, characterized in that: The system includes a quantum-secure first privacy computer as the sender, a quantum-secure access gateway, and a quantum-secure second privacy computer as the receiver. Among them, the first privacy computer is connected to the quantum-secure access gateway via the Internet, and the quantum-secure access gateway is connected to the second privacy computer via the Internet. The first privacy computer is used to encrypt the plaintext data to be sent, construct a first data frame, and then send the first data frame to the quantum-secure access gateway. The quantum-secure access gateway is used to perform a verification comparison on the first data frame, decrypt it, encrypt it again, and construct a second data frame after passing the verification comparison, and send the second data frame to the second privacy computer. The second privacy computer is used to perform a verification comparison on the second data frame and decrypt it to obtain the plaintext data sent by the first privacy computer after passing the verification comparison.
10. The system according to claim 9, wherein: Both the first privacy computer and the second privacy computer include a communication area, an isolation area, and a privacy area connected in sequence. The communication area of the privacy computer is used for data transmission between the privacy computer and the outside world; The isolation area of the privacy computer is used to encrypt the plaintext data to be sent, construct a data frame, and then send the data frame to the communication area of the privacy computer; And perform verification and comparison on the received data frame. After the verification and comparison pass, decrypt it to obtain the plaintext data, and then send the plaintext data to the privacy area of the privacy computer; The privacy area of the privacy computer is used to send the plaintext data to be sent to the isolation area of the privacy computer; and receive the plaintext data from the isolation area of the privacy computer.
Citation Information
Patent Citations
Networking system and method of quantum security local area network
CN117394999A