Cross-gateway quantum security communication method and system
By transmitting ciphertext data between the access gateways and allocating different types of key pools on the sending and receiving ends, the problems of low security of plaintext data transmission and high risk of key leakage in the access gateway are solved, and more secure and efficient communication is achieved.
Patent Information
- Application Number
- CN202510421688.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-25
AI Technical Summary
During communication, plaintext data is transmitted unprotectedly in the access gateway, resulting in extremely low security. At the same time, multiple key pools preset by the sending and receiving ends increase the risk of key leakage.
The quantum secure communication method across gateways is adopted to make the data transmitted between the access gateways in the form of ciphertext, and only the transmitting end presets the encrypted and decrypted key pool and the receiving end presets the transmission key pool. Data transmission and verification are carried out through the transmission key, ensuring the security of data transmission and reducing the risk of key leakage.
Improves the security of data transmission, reduces the risk of key leakage, reduces the preset of the key pool for the plaintext data, and reduces communication consumption and key delay.
Smart Images

Figure CN120378143A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to a cross-gateway quantum secure communication method and system. Background Art
[0002] Currently, the most secure transmission is to use quantum key encryption for transmission between the sender and the receiver. However, in actual communication scenarios, the sender and the receiver are not directly connected point-to-point, but need to communicate through an access gateway as a relay. Then, as a relay network element, the access gateway must have a pre-set key with the sender or the receiver, and the sender and the receiver do not directly synchronize the pre-set key.
[0003] During the communication process, the sender converts the plaintext data into ciphertext and sends it to the access gateway connected to it. The access gateway decrypts it to obtain the plaintext data, and then transmits the plaintext data through the internal network between the access gateways and sends it to the access gateway connected to the receiver; the access gateway connected to the receiver encrypts the plaintext data, and finally decrypts it through the receiver to obtain the plaintext data. In this process, each access gateway can see the plaintext data. Once someone breaks into any one of the access gateways to steal the plaintext data, it will ultimately lead to the leakage of user data. The plaintext data is transmitted without protection in the access gateway, resulting in extremely low security.
[0004] Moreover, there will be a key pool for encrypting and decrypting the plaintext data pre-set between the sender and the access gateway connected to it; at the same time, there will also be a key pool for encrypting and decrypting the plaintext data pre-set between the receiver and the access gateway connected to it; in this case, if there are too many key pools for encrypting and decrypting the plaintext data pre-set, the risk of key leakage will increase.
[0005] In view of this, how to solve the problem that the plaintext data is transmitted without protection in the access gateway, resulting in extremely low security; and how to solve the problem that both the sender and the receiver pre-set key pools for encrypting and decrypting the plaintext data, resulting in an increased risk of key leakage are the technical problems currently concerned in the industry. Summary of the Invention
[0006] Object of the Invention: To solve the related technical problems proposed in the background art, the present invention provides a cross-gateway quantum secure communication method and system. As a relay network element, the data transmitted between the access gateways is in ciphertext form, increasing the security of data transmission; at the same time, only the sender pre-sets a key pool for encrypting and decrypting the plaintext data, and the receiver pre-sets a transmission key pool, reducing the pre-setting of key pools for encrypting and decrypting the plaintext data, and reducing the risk of key leakage.
[0007] Technical Solution: A cross-gateway quantum secure communication method of the present invention includes the following steps:
[0008] (1) The first privacy computer generates a first transmission data frame based on the plaintext data to be sent, and sends the first transmission data frame to the first quantum secure access gateway;
[0009] (2) The first quantum secure access gateway generates an intermediate data frame based on the first transmission data frame, and sends the intermediate data frame to the second quantum secure access gateway through N quantum secure access gateways; The second quantum secure access gateway generates a second transmission data frame based on the intermediate data frame and sends it to the second privacy computer;
[0010] (3) The second privacy computer verifies and decrypts the second transmission data frame, and finally obtains the plaintext data to be sent by the first privacy computer.
[0011] Furthermore, the first privacy computer and the first quantum secure access gateway are pre - set with the same encryption key pool and transmission key pool; The second privacy computer and the second quantum secure access gateway are pre - set with the same transmission key pool.
[0012] Furthermore, the specific process of generating the first transmission data frame based on the plaintext data to be sent is as follows:
[0013] The first privacy computer obtains an encryption key from the local encryption key pool to encrypt the plaintext data to be sent to obtain a first ciphertext; then generates a frame header corresponding to the first ciphertext, and then verifies the frame header, the encryption key and the key index of the encryption key to generate a first checksum; then obtains a first transmission key from the local transmission key pool to encrypt the key index of the encryption key, the first checksum and the first ciphertext to obtain a second ciphertext, and then constructs the frame header, the key index of the first transmission key and the second ciphertext to generate a first transmission data frame.
[0014] Furthermore, the frame header includes a source IP address, a destination IP address and a transmission protocol.
[0015] Furthermore, the specific process of generating the intermediate data frame based on the first transmission data frame is as follows:
[0016] After the first quantum-secure access gateway receives the first transmission data frame, it first obtains the second transmission key from the pre-set transmission key pool using the key index of the first transmission key in the first transmission data frame, and then uses the second transmission key to decrypt the second ciphertext to obtain the key index of the encryption key, the first checksum, and the first ciphertext. Then, it obtains the decryption key from the pre-set encryption key pool using the key index of the encryption key, and performs a checksum on the frame header, the decryption key, and the key index of the encryption key in the first transmission data frame in the same way as the first privacy computer to generate a second checksum. It compares whether the second checksum is consistent with the first checksum obtained by decryption. If they are consistent, it constructs the frame header, the decryption key, and the first ciphertext obtained by decryption in the first transmission data frame to generate an intermediate data frame.
[0017] Further, the intermediate data frame is sent to the second quantum-secure access gateway through N quantum-secure access gateways, which means that the first quantum-secure access gateway transmits the intermediate data frame to the second quantum-secure access gateway through N quantum-secure access gateways. The transmission of the intermediate data frame between the quantum-secure access gateways is all internal network transmission, where N is a natural number.
[0018] Further, the specific process of generating the second transmission data frame based on the intermediate data frame is as follows:
[0019] After the second quantum-secure access gateway receives the intermediate data frame, it first obtains the third transmission key from the local transmission key pool to encrypt the decryption key in the intermediate data frame to obtain the third ciphertext, and then performs a checksum on the frame header, the third transmission key, and the key index of the third transmission key in the intermediate data frame to generate a third checksum. Then, it obtains the fourth transmission key from the local transmission key pool to encrypt the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext in the intermediate data frame to obtain the fourth ciphertext. Finally, it constructs the frame header, the key index of the fourth transmission key, and the fourth ciphertext in the intermediate data frame to generate the second transmission data frame.
[0020] Further, the specific process of checking and decrypting the second transmission data frame is as follows:
[0021] After the second privacy computer receives the second transmission data frame, it first obtains the fifth transmission key from the pre-set transmission key pool using the key index of the fourth transmission key in the second transmission data frame, and then uses the fifth transmission key to decrypt the fourth ciphertext to obtain the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext.
[0022] Then, use the key index of the third transmission key to obtain the sixth transmission key from the pre-set transmission key pool, and perform verification on the frame header, the sixth transmission key, and the key index of the third transmission key in the second transmission data frame in the same verification manner as the second quantum secure access gateway to generate a fourth checksum. Compare whether the fourth checksum is consistent with the third checksum obtained by decryption. If they are consistent, use the sixth transmission key to decrypt the third ciphertext obtained by decryption to obtain the decryption key, and finally use the decryption key to decrypt the first ciphertext obtained by decryption to obtain the plaintext data to be sent.
[0023] The present invention further includes a cross-gateway quantum secure communication system, and the system is used to execute the workflow of the above quantum secure communication method.
[0024] Advantages of the present invention: The data transmitted between the access gateways of the present invention is in ciphertext form. Except for the sending end and the receiving end, the intermediate access gateways do not know the content of the transmitted plaintext, which increases the security of data transmission. At the same time, only the sending end pre-sets a key pool for encrypting and decrypting plaintext data, and the receiving end pre-sets a transmission key pool. The key for encrypting and decrypting plaintext data is transmitted through the transmission key, and then its integrity is verified, so that the receiving end can decrypt it, and the pre-setting of the key pool for encrypting and decrypting plaintext data is reduced, making the risk of key leakage lower. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0026] Figure 1 It is a schematic structural diagram of the cross-gateway quantum secure communication system of the present invention;
[0027] Figure 2 It is a schematic flowchart of the cross-gateway quantum secure communication method of the present invention;
[0028] Figure 3 It is a schematic diagram of the structural changes of the first transmission data frame, the intermediate data frame, and the second transmission data frame of the present invention;
[0029] Figure 4 It is a schematic diagram of the receiving party processing data. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] In order to make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail in conjunction with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.
[0031] As described in the background art, quantum key pairs are currently used to encrypt and transmit plaintext between the existing sender and receiver, and the access gateway serves as a relay network element. During this process, the plaintext data is transmitted without protection in the access gateway, resulting in extremely low security. At the same time, key pools for encrypting and decrypting plaintext data are pre-set between the sender and its connected access gateway, and between the receiver and its connected access gateway, leading to a great risk of key leakage. Therefore, how to solve these problems is an important issue currently faced.
[0032] As Figure 1 and Figure 2 shown, in view of this, the present invention proposes a cross-gateway quantum secure communication method, including the following steps:
[0033] First, the first privacy computer and the first quantum secure access gateway are pre-set with the same encryption key pool and transmission key pool; the second privacy computer and the second quantum secure access gateway are pre-set with the same transmission key pool. The pre-setting of the same encryption key pool is for the need of encrypted transmission. Only the sender is pre-set with the key pool for encrypting and decrypting plaintext data, and the receiver is pre-set with the transmission key pool. The key for encrypting and decrypting plaintext data is transmitted through the transmission key, reducing the pre-setting of the key pool for encrypting and decrypting plaintext data and lowering the risk of key leakage. Next is the data transmission:
[0034] (1) The first privacy computer generates a first transmission data frame based on the plaintext data to be sent and sends the first transmission data frame to the first quantum secure access gateway; wherein, the specific process of generating the first transmission data frame based on the plaintext data to be sent is:
[0035] The first privacy computer obtains an encryption key from the local encryption key pool to encrypt the plaintext data to be sent, obtaining the first ciphertext; then generates a frame header corresponding to the first ciphertext, where the frame header includes the source IP address, destination IP address, transmission protocol, etc., and of course can also include the network access code RID of the first privacy computer. Then, the first privacy computer checks the frame header, encryption key, and key index of the encryption key to generate the first checksum; the key index of the encryption key refers to the length information and position information of the key, and the encryption key can be obtained through the key index. Then, obtain the first transmission key from the local transmission key pool to encrypt the key index of the encryption key, the first checksum, and the first ciphertext to obtain the second ciphertext, and then construct the frame header, the key index of the first transmission key, and the second ciphertext to generate the first transmission data frame, as Figure 3 shown. Finally, the first privacy computer sends the first transmission data frame to the first quantum-secure access gateway. The quantum-secure access gateway combines the functions of encrypting and decrypting data and pre-setting keys, integrating the functions of the original two network elements, namely the encryption / decryption network element and the pre-set key network element. It is a deep integration at the architecture and program levels, effectively reducing the consumption of bandwidth and hardware resources. After the integration, the ciphertext key hash table stored for pairing between the encryption / decryption network element and the pre-set key network element no longer exists, the timeout threads of the two devices are no longer necessary, the frame rate is reduced, the number of checksum calculations is reduced, and the CPU consumption for communication is reduced.
[0036] (2) The first quantum-secure access gateway generates an intermediate data frame based on the first transmission data frame, and sends the intermediate data frame to the second quantum-secure access gateway through N quantum-secure access gateways;
[0037] Among them, the specific process of generating the intermediate data frame based on the first transmission data frame is as follows: after receiving the first transmission data frame, the first quantum-secure access gateway first obtains the second transmission key in the pre-set transmission key pool using the key index of the first transmission key in the first transmission data frame, and then uses the second transmission key to decrypt the second ciphertext to obtain the key index of the encryption key, the first checksum, and the first ciphertext; then uses the key index of the encryption key to obtain the decryption key in the pre-set encryption key pool, and checks the frame header, decryption key, and key index of the encryption key in the first transmission data frame in the same way as the first privacy computer to generate the second checksum, and the check method can be a hash function; compare whether the second checksum is consistent with the first checksum obtained by decryption. If they are consistent, then construct the frame header, decryption key, and the first ciphertext obtained by decryption in the first transmission data frame to generate the intermediate data frame, as Figure 3 shown. From the above process, it can be seen that the first quantum-secure access gateway does not decrypt the ciphertext, but generates an intermediate data frame based on the ciphertext, increasing the security of data transmission;
[0038] The intermediate data frame is sent to the second quantum secure access gateway through N quantum secure access gateways, which means that the first quantum secure access gateway transmits the intermediate data frame to the second quantum secure access gateway through N quantum secure access gateways. The transmission of the intermediate data frame between quantum secure access gateways is all internal network transmission. Here, N is a natural number; N can be 0, that is, the first quantum secure access gateway directly transmits the intermediate data frame to the second quantum secure access gateway; N can be 1, 2, 3... and so on, indicating that the first quantum secure access gateway transmits the intermediate data frame to the second quantum secure access gateway through N quantum secure access gateways. The data transmitted between access gateways is also in ciphertext form. Compared with plaintext, its security is greatly improved. Even if someone breaks into any one of the access gateways and steals the ciphertext data, it will not cause the leakage of user data.
[0039] The second quantum secure access gateway generates a second transmission data frame based on the intermediate data frame and sends it to the second private computer. The specific process is as follows: After receiving the intermediate data frame, the second quantum secure access gateway first obtains the third transmission key from the local transmission key pool to encrypt the decryption key in the intermediate data frame to obtain the third ciphertext, and then verifies the frame header, the third transmission key, and the key index of the third transmission key in the intermediate data frame to generate the third checksum; then it obtains the fourth transmission key from the local transmission key pool to encrypt the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext in the intermediate data frame to obtain the fourth ciphertext. Finally, it constructs the frame header, the key index of the fourth transmission key, and the fourth ciphertext in the intermediate data frame to generate the second transmission data frame. As Figure 3 shown, the second transmission data frame is sent to the second private computer.
[0040] (3) The second private computer verifies and decrypts the second transmission data frame to finally obtain the plaintext data to be sent by the first private computer; As Figure 4 shown, the specific process of verifying and decrypting the second transmission data frame is as follows:
[0041] After receiving the second transmission data frame, the second private computer first obtains the fifth transmission key in the preset transmission key pool using the key index of the fourth transmission key in the second transmission data frame, and then uses the fifth transmission key to decrypt the fourth ciphertext to obtain the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext;
[0042] Then, the key index of the third transmission key is used to obtain the sixth transmission key from the pre-set transmission key pool, and the frame header in the second transmission data frame, the sixth transmission key, and the key index of the third transmission key are verified by the same verification method as that of the second quantum security access gateway to generate the fourth checksum; compare whether the fourth checksum is consistent with the third checksum obtained by decryption. If they are consistent, the third ciphertext obtained by decryption is decrypted using the sixth transmission key to obtain the decryption key, and finally the first ciphertext obtained by decryption is decrypted using the decryption key to obtain the plaintext data to be sent. In the present invention, only the sending end pre-sets a key pool for encrypting and decrypting the plaintext data, and the receiving end pre-sets a transmission key pool. The key for encrypting and decrypting the plaintext data is transmitted through the transmission key, and then its integrity is verified, so that the receiving end can decrypt it, and the pre-setting of the key pool for encrypting and decrypting the plaintext data is reduced, making the risk of key leakage lower. At the same time, in the present invention, the ciphertext key is synchronously transmitted, greatly reducing the time delay between the ciphertext keys, and truly achieving zero time delay between the ciphertext and the key.
[0043] The present invention further includes a cross-gateway quantum security communication system, which is used to execute the working process of the above quantum security communication method.
Claims
1. A quantum secure communication method across gateways, characterized in that, Including the following steps: (1) The first privacy computer generates a first transmission data frame based on the plaintext data to be sent, and sends the first transmission data frame to the first quantum secure access gateway; (2) The first quantum secure access gateway generates an intermediate data frame based on the first transmission data frame, and sends the intermediate data frame to the second quantum secure access gateway through N quantum secure access gateways; The second quantum secure access gateway generates a second transmission data frame based on the intermediate data frame and sends it to the second privacy computer; (3) The second privacy computer checks and decrypts the second transmission data frame, and finally obtains the plaintext data to be sent by the first privacy computer.
2. The quantum secure communication method across gateways according to claim 1, wherein The first privacy computer and the first quantum secure access gateway are pre-set with the same encryption key pool and transmission key pool; the second privacy computer and the second quantum secure access gateway are pre-set with the same transmission key pool.
3. The quantum secure communication method across gateways according to claim 2, characterized in that, The specific process of generating the first transmission data frame based on the plaintext data to be sent is as follows: The first privacy computer obtains an encryption key from the local encryption key pool to encrypt the plaintext data to be sent to obtain a first ciphertext; then generates a frame header corresponding to the first ciphertext, and then checks the frame header, the encryption key, and the key index of the encryption key to generate a first checksum; then obtains a first transmission key from the local transmission key pool to encrypt the key index of the encryption key, the first checksum, and the first ciphertext to obtain a second ciphertext, and then constructs the frame header, the key index of the first transmission key, and the second ciphertext to generate a first transmission data frame.
4. A quantum secure communication method across gateways according to claim 3, characterized in that, The frame header includes a source IP address, a destination IP address, and a transmission protocol.
5. The quantum secure communication method across gateways according to claim 3, wherein The specific process of generating the intermediate data frame based on the first transmission data frame is as follows: After receiving the first transmission data frame, the first quantum secure access gateway first obtains a second transmission key in the pre-set transmission key pool using the key index of the first transmission key in the first transmission data frame, and then uses the second transmission key to decrypt the second ciphertext to obtain the key index of the encryption key, the first checksum, and the first ciphertext; then obtains a decryption key in the pre-set encryption key pool using the key index of the encryption key, and checks the frame header, the decryption key, and the key index of the encryption key in the first transmission data frame in the same way as the first privacy computer to generate a second checksum; compares whether the second checksum is consistent with the first checksum obtained by decryption, and if so, constructs the frame header, the decryption key, and the first ciphertext obtained by decryption in the first transmission data frame to generate an intermediate data frame.
6. The quantum secure communication method across gateways according to claim 5, characterized in that, The intermediate data frame is sent to the second quantum secure access gateway through N quantum secure access gateways, which means that the first quantum secure access gateway transmits the intermediate data frame to the second quantum secure access gateway through N quantum secure access gateways, and the intermediate data frame is transmitted between the quantum secure access gateways through an intranet, where N is a natural number.
7. A quantum secure communication method across gateways according to claim 5, characterized in that, The specific process of generating the second transmission data frame based on the intermediate data frame is as follows: After the second quantum-secure access gateway receives the intermediate data frame, it first obtains the third transmission key from the local transmission key pool to encrypt the decryption key in the intermediate data frame to obtain the third ciphertext, and then verifies the frame header, the third transmission key, and the key index of the third transmission key in the intermediate data frame to generate the third checksum; then it obtains the fourth transmission key from the local transmission key pool to encrypt the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext in the intermediate data frame to obtain the fourth ciphertext. Finally, it constructs the frame header, the key index of the fourth transmission key, and the fourth ciphertext in the intermediate data frame to generate the second transmission data frame.
8. A quantum secure communication method across gateways according to claim 7, characterized in that The specific process of verifying and decrypting the second transmission data frame is as follows: After the second privacy computer receives the second transmission data frame, it first obtains the fifth transmission key in the pre-set transmission key pool by using the key index of the fourth transmission key in the second transmission data frame, and then uses the fifth transmission key to decrypt the fourth ciphertext to obtain the key index of the third transmission key, the third checksum, the third ciphertext, and the first ciphertext. Then it obtains the sixth transmission key in the pre-set transmission key pool by using the key index of the third transmission key, and verifies the frame header, the sixth transmission key, and the key index of the third transmission key in the second transmission data frame in the same verification manner as the second quantum-secure access gateway to generate the fourth checksum; compares whether the fourth checksum is consistent with the decrypted third checksum. If they are consistent, it uses the sixth transmission key to decrypt the decrypted third ciphertext to obtain the decryption key, and finally uses the decryption key to decrypt the decrypted first ciphertext to obtain the plaintext data to be sent.
9. A quantum secure communication system across gateways, characterized in that: The system is used to execute the workflow of the quantum-secure communication method as described in any one of claims 1 to 8.