Key generation method, device, equipment and medium based on BB84 protocol
By block processing and dynamic key derivation of the intermediate key of the BB84 protocol, the problems of low key generation efficiency and high resource consumption are solved, and efficient and secure quantum communication is achieved.
Patent Information
- Application Number
- CN202510938487.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-08
AI Technical Summary
The existing BB84 protocol's key generation method is inefficient in the face of channel noise and eavesdropping interference, and statically stored keys are easily leaked, resulting in excessive consumption of quantum communication resources. This makes it difficult to apply in large-scale networks or resource-constrained scenarios.
By dividing the intermediate key into blocks, the first key block and the second key block are generated. After processing and error correction respectively, the initial key and the third key block are used to derive the key and generate the quantum key, reducing the consumption of quantum hardware and realizing dynamic key update.
It has improved the speed of quantum key generation, enhanced the utilization rate of quantum communication resources, reduced the consumption of hardware such as single-photon sources and detectors, and enhanced the security of the key system and communication efficiency.
Smart Images

Figure CN120455002B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum communication technology, and in particular to a key generation method, apparatus, device and medium based on the BB84 protocol. Background Art
[0002] Quantum key distribution (QKD), as one of the core technologies of quantum communication, can achieve secure shared key distribution between communicating parties based on the principles of quantum mechanics. Among them, the BB84 protocol is one of the earliest and most widely used protocols.
[0003] In the related art, the BB84 protocol requires communicating between Alice and Bob (Alice and Bob) by transmitting a large number of quantum states (such as photons) over a quantum channel. The final key is generated through basis comparison and subsequent error correction and privacy amplification processes. However, due to channel noise and eavesdropping interference, a large number of quantum states are discarded during the basis comparison phase, resulting in inefficient key generation. To meet long-term communication requirements, the complete BB84 protocol must be repeatedly executed, significantly increasing the resource overhead of quantum state preparation, transmission, and detection. This makes it particularly difficult to implement in large-scale networks or resource-constrained scenarios (such as satellite communications and the Internet of Things).
[0004] In addition, in the field of quantum communication, the final key generated based on the BB84 protocol is usually stored and used in a static form. However, the static storage method easily causes the leakage of the final key. In order to prevent leakage, the BB84 protocol needs to be executed frequently to refresh the final key. However, the above operation also aggravates the consumption of quantum communication resources. Summary of the Invention
[0005] The present application provides a key generation method, apparatus, device and medium based on the BB84 protocol to solve the problem of excessive consumption of quantum communication resources caused by current key generation methods.
[0006] In order to solve the above problems, the present application discloses a key generation method based on the BB84 protocol, comprising:
[0007] Get the intermediate key;
[0008] Divide the intermediate key into blocks according to a block rule to obtain a first key block and a second key block;
[0009] Processing the first key block to obtain an initial key;
[0010] processing the second key block to obtain a third key block;
[0011] Key derivation is performed based on the initial key and the third key block to generate a quantum key.
[0012] Optionally, the second key block includes a plurality of key seed blocks;
[0013] The processing of the second key block to obtain a third key block includes:
[0014] Calculate the bit error rate of each key seed block;
[0015] sorting the bit error rates to obtain sorted key seed blocks;
[0016] The sorted key seed blocks are used as the third key blocks.
[0017] Optionally, the method further includes:
[0018] The initial key is divided according to the key distribution ratio to form a first key and a first key seed, where the first key is a key allocated to the user for use, and the first key seed is a remaining key after the first key is allocated to the user.
[0019] Optionally, the performing key derivation according to the first key seed and the third key block to generate a quantum key includes:
[0020] A hash algorithm is used to perform key derivation on the first key seed and multiple key seed blocks in the third key block to generate a quantum key.
[0021] Optionally, the using a hash algorithm to perform key derivation on the first key seed and multiple key seed blocks in the third key block to generate a quantum key includes:
[0022] Obtaining the remaining key quantity of the first key;
[0023] If the remaining key amount is less than the user's required key amount, selecting a first key seed block from the third key block;
[0024] Processing the first key seed and the first key seed block using a hash algorithm to obtain a first pseudo-random key;
[0025] Splitting the first pseudo-random key to obtain a second key and a second key seed;
[0026] If the remaining key amount of the second key is less than the key amount required by the user, selecting a second key seed block from the third key block, where the first key seed block is different from the second key seed block;
[0027] Processing the second key seed and the second key seed block using a hash algorithm to obtain a second pseudo-random key;
[0028] Splitting the second pseudo-random key to obtain a third key and a third key seed;
[0029] If the remaining key amount of the third key is greater than the key amount required by the user, saving the third key seed;
[0030] The first key, the second key and the third key are concatenated to generate a quantum key.
[0031] Optionally, the performing block processing on the intermediate key according to a block rule to obtain a first key block and a second key block includes:
[0032] The intermediate key is divided according to a fixed length or a non-fixed length to obtain a first key block and a second key block.
[0033] In order to solve the above problems, the present application also discloses a key generation device based on the BB84 protocol, comprising:
[0034] An acquisition module, used to obtain an intermediate key;
[0035] a segmentation module, configured to segment the intermediate key into blocks according to a segmentation rule to obtain a first key block and a second key block;
[0036] A first processing module, configured to process the first key block to obtain an initial key;
[0037] a second processing module, configured to process the second key block to obtain a third key block;
[0038] A derivation module is used to perform key derivation based on the initial key and the third key block to generate a quantum key.
[0039] Optionally, the second key block includes a plurality of key seed blocks;
[0040] The second processing module includes:
[0041] a calculation unit, configured to calculate a bit error rate of each key seed block;
[0042] A sorting unit is used to sort the bit error rates to obtain sorted key seed blocks, and use the sorted key seed blocks as the third key block.
[0043] In order to solve the above problems, the present application also discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the computer program, the key generation method based on the BB84 protocol is implemented.
[0044] In order to solve the above problems, the present application also discloses a computer-readable storage medium, which stores a computer program that implements the key generation method based on the BB84 protocol when executed by a processor.
[0045] Compared with the prior art, this application has the following advantages:
[0046] First, this application fully utilizes the utilization value of the intermediate key in the BB84 protocol, divides the intermediate key into a first key block and a second key block according to the block rule, processes the first key block to obtain an initial key, and processes the second key block to obtain a third key block; performs key derivation based on the initial key and the third key block to generate a quantum key, that is, uses the third key block as a seed block to become an entropy source reserve for quantum key generation. Through the above processing, the potential value of the intermediate key is fully tapped, the speed of quantum key generation is improved, and the utilization rate of quantum communication resources is thereby improved.
[0047] Secondly, dynamic key derivation is performed through the initial key and the third key block to generate quantum keys, thereby reducing the consumption of quantum hardware such as single-photon sources and detectors, thereby improving the efficiency of quantum communication.
[0048] Of course, any product implementing the present application does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 This is an overall flow chart of a key generation method based on the BB84 protocol described in an embodiment of the present application;
[0050] Figure 2 This is a flowchart of a key generation method based on the BB84 protocol described in an embodiment of the present application;
[0051] Figure 3 This is a flowchart of a key generation method based on the BB84 protocol described in an embodiment of the present application;
[0052] Figure 4 1 is a schematic diagram of the process of generating a quantum key according to an embodiment of the present application;
[0053] Figure 5 This is a structural diagram of a key generation device based on the BB84 protocol described in an embodiment of the present application. DETAILED DESCRIPTION
[0054] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0055] See also Figure 1, which shows an overall flow chart of a key generation method based on the BB84 protocol according to an embodiment of the present invention, specifically including:
[0056] Step 101: Obtain the original key.
[0057] Step 102: Quantum state preparation and measurement.
[0058] In the BB84 protocol, during the quantum state preparation phase, the sender (Alice) randomly selects two basis vectors (e.g., the rectangular basis "+" or the diagonal basis "×") and encodes the key bit (0 or 1) into the photon polarization state corresponding to the basis vector (e.g., horizontal, vertical, 45°, or 135°). The photon is then transmitted to the receiver (Bob) via a quantum channel (e.g., optical fiber or free space). During the quantum state measurement phase, Bob randomly selects a measurement basis vector to detect the received photon. Only when the measurement basis vector matches Alice's encoding basis vector can the bit value be correctly decoded; otherwise, the result is random.
[0059] Step 103: Alignment.
[0060] During the basis matching process, the two communicating parties (Alice and Bob) publicly compare the basis vectors (such as the "+" basis or the "×" basis) randomly selected by each party during the quantum state preparation and measurement phase through the classical channel, and only retain the measurement results with consistent basis vectors to form an intermediate key (preprocessing key).
[0061] The number of intermediate keys generated after the base is completed is much larger than the final key, but it contains transmission errors and potential leakage risks, and needs to be compressed into a small number of high-security final intermediate keys through error correction and privacy amplification.
[0062] Step 104: Obtain the intermediate key.
[0063] Step 105: Divide the intermediate key into blocks to obtain a first key block (key seed block Seed1) and a second key block (key seed blocks Seed2-SeedN).
[0064] Step 106: Perform error detection on the key seed blocks Seed2-SeedN to generate a third key block.
[0065] Step 107: The key seed block Seed1 is post-processed to generate an initial key.
[0066] Among them, post-processing includes: parameter estimation, error correction, and privacy amplification. Among them, parameter estimation is to pre-process the key by randomly sampling part of the channel, evaluate the channel error rate, and determine whether there is eavesdropping (if the error rate exceeds the threshold, the protocol will be terminated).
[0067] Error correction uses an error correction algorithm (such as Cascade or LDPC code) to correct transmission errors so that the keys of both parties are consistent.
[0068] Privacy amplification is to compress the preprocessed key through a hash function, eliminate potential leaked information, and generate an initial key that is information-theoretically secure.
[0069] Step 108: Perform key derivation and iterative update based on the initial key and the second key block to generate a quantum key.
[0070] Based on the above concept, Figure 2 , which shows a flowchart of a key generation method based on the BB84 protocol according to an embodiment of the present application, specifically including:
[0071] Step 201: Obtain an intermediate key.
[0072] In the BB84 protocol, the intermediate key after basis matching is usually regarded as a one-time material and is discarded after the final key is generated. This "generation-exhaustion" mode leads to the potential value of the intermediate key not being fully tapped. Therefore, the inventors innovatively proposed to generate quantum keys based on the intermediate keys, which fully utilizes the potential value of the intermediate keys and generates the intermediate keys through a single quantum state transmission.
[0073] Step 202: Divide the intermediate key into blocks according to a block division rule to obtain a first key block and a second key block.
[0074] The intermediate key is divided into blocks according to the block rules to obtain the first key block and the second key block. That is, the first key block can be understood as the real-time use block, and the second key block is the seed block. The second key block is used as the entropy source reserve for quantum key generation.
[0075] The first key block includes a key seed block, and the second key block includes multiple key seed blocks.
[0076] In a specific application, step 202 is to divide the intermediate key according to a fixed length or a non-fixed length to obtain a first key block and a second key block.
[0077] Among them, the determination of fixed length and non-fixed length can be determined according to the specific application scenario, and this application does not impose any specific restrictions on this.
[0078] For example: Take the fixed length as an example to illustrate the process of dividing the intermediate key. The fixed length is 256 bits / block. The obtained intermediate key is divided into multiple seed blocks Seed1~SeedN according to 256 bits / block. Seed1 is defined as the first key block, and Seed2~SeedN are defined as the second key block. That is, the second key block includes: multiple key seed blocks, namely Seed2~SeedN.
[0079] Step 203: Process the first key block to obtain an initial key.
[0080] In a specific application, the first key block Seed1 is used as a real-time usage block for the post-processing process of the BB84 protocol. The post-processing mainly includes: parameter estimation, error correction, privacy amplification and other operations, thereby obtaining the initial key K0 of the first key block Seed1.
[0081] Step 204: Process the second key block to obtain a third key block.
[0082] The second key block includes multiple key seed blocks, Seed2 to SeedN. The second key block is used as the "seed block" in the subsequent key derivation process. Because the key seed blocks Seed2 to SeedN are intermediate keys, the key seed blocks Seed2 to SeedN sent by both parties in communication may be subject to transmission errors. To reduce the impact of transmission errors on the error propagation caused by subsequent key derivation and iterative updates, certain measures need to be taken to process the second key block:
[0083] One of the methods is: calculating the bit error rate of each key seed block; sorting the bit error rates to obtain sorted key seed blocks; using the sorted key seed blocks as the third key blocks, and the communicating parties physically and securely store the sorted key seed blocks. The above processing method does not require the execution of a complete error correction process (Cascade error correction or LDPC code error correction), thereby reducing system latency and energy consumption.
[0084] Specifically, the communicating parties denote the estimated bit error rate of the key seed blocks Seed2 to SeedN as δi, where δi represents the bit error rate of the i-th key seed block Seedi. The bit error rate of each key seed block is calculated separately, and the bit error rates are classified into δ2-δN. The bit error rates are sorted and classified into δ2<δ3…<δN. The key seed blocks corresponding to the sorted bit error rates are divided into Seed2' to SeedN'. The sorted key seed blocks are physically securely stored for subsequent use.
[0085] Another method is: the communicating parties directly perform BB84 protocol error correction on the key seed blocks Seed2 to SeedN. The corrected key seed blocks are recorded as Seed2'-SeedN', and the corrected key seed blocks are physically and securely stored for subsequent use.
[0086] Step 205: Perform key derivation based on the initial key and the third key block to generate a quantum key.
[0087] This embodiment first fully utilizes the value of the intermediate key in the BB84 protocol. The intermediate key is divided into a first key block and a second key block according to the block division rule. The first key block is processed to obtain an initial key, and the second key block is processed to obtain a third key block. Key derivation is performed based on the initial key and the third key block to generate a quantum key. The third key block is used as a seed block to become an entropy source reserve for quantum key generation. Through the above processing, the potential value of the intermediate key is fully exploited, the speed of quantum key generation is improved, and the utilization rate of quantum communication resources is thereby improved.
[0088] Secondly, dynamic key derivation is performed through the initial key and the third key block to generate quantum keys, thereby reducing the consumption of quantum hardware such as single-photon sources and detectors, thereby improving the efficiency of quantum communication.
[0089] Reference Figure 3 , which shows a flowchart of a key generation method based on the BB84 protocol according to an embodiment of the present application, specifically including:
[0090] Step 301: Obtain an intermediate key.
[0091] Step 302: Divide the intermediate key into blocks according to a block division rule to obtain a first key block and a second key block.
[0092] Step 303: Process the first key block to obtain an initial key.
[0093] Step 304: Process the second key block to obtain a third key block.
[0094] Step 305: Divide the initial key according to the key distribution ratio to form a first key and a first key seed.
[0095] The first key is a key allocated to the user, and the first key seed is a remaining key after the first key is allocated to the user.
[0096] The key distribution ratio can be determined according to the application scenario of the key. The initial key usage rule is: the first key will be allocated to the user, and the first key seed will be used as the subsequent derivation process. For example, assuming that a% of the initial key K0 is allocated to the user, that is, the first key has a%, then the remaining key is K0'=(1-a%) *K0, then K0'=(1-a%) *K0 will be used as the first key seed for the "key seed" of the subsequent derivation process.
[0097] Step 306: Perform key derivation based on the first key seed and the third key block to generate a quantum key.
[0098] In a specific application, a hash algorithm is used to derive keys from the first key seed and multiple key seed blocks in the third key block to generate a quantum key. That is, each key seed is used to derive keys from a different key seed block in the third key block. In this way, the multiple key seed blocks in the third key block can be fully utilized, avoiding the waste of multiple key seed blocks in the third key block, and also improving the security of key derivation.
[0099] The hash algorithm uses the HKDF algorithm, a standardized key derivation function defined by the Internet Engineering Task Force (IETF) in RFC 5869. Based on the HMAC algorithm, HKDF can extract and expand multiple keys from the input key material (IKM). These keys can be used for different encryption or authentication purposes. It generates multiple intermediate keys through a single quantum state transfer and implements dynamic key derivation using a lightweight hash chain or quantum-resistant KDF. This method will significantly reduce the energy consumption and loss of quantum hardware such as single-photon sources and detectors. It is particularly suitable for resource-constrained scenarios such as satellite communications and the Internet of Things, providing an efficient foundation for large-scale quantum network deployment.
[0100] Ki=HKDF(IKM=K i-1', Salt=Seedi, info=i, L=256)
[0101] Where Ki is the key derived from the previous key, i represents a sequence number, for example, i = 1, 2, 3, ...; salt represents an optional salt value, usually used to increase randomness; IKM represents the first key; Seed represents the key seed block, and L represents the output key length.
[0102] To improve the algorithm's quantum resistance, SHA3-256 is selected as the underlying hash function of HKDF. The HKDF algorithm works as follows: Each round of operation generates a 256-bit key bit, of which a*Ki is allocated to the user. When this amount of key is insufficient to meet the user's key needs, the iterative process will continue until the user's key needs are met or the key seed block Seed is used up. The process ends and the individual keys are concatenated to output the quantum key. By using the HKDF-SHA3 hash algorithm to generate keys, even if the current key Ki is leaked, the historical key Ki-1 and the future key Ki+1 cannot be derived. See Figure 4 , a detailed description of a flow chart of using a hash algorithm to perform key derivation on the first key seed and multiple key seed blocks in the third key block to generate a quantum key, specifically including:
[0103] Step 401: Obtain the remaining key quantity of the first key.
[0104] Step 402: Determine whether the remaining key amount is less than the key amount required by the user. If the remaining key amount is less than the key amount required by the user, execute step 403. If the remaining key amount is greater than the key amount required by the user, save the first key seed and the process ends.
[0105] Step 403: Select a first key seed block from the third key block.
[0106] Step 404: Process the first key seed and the first key seed block using a hash algorithm to obtain a first pseudo-random key.
[0107] The first key seed and the first key seed block are processed using a hash algorithm to obtain a first pseudo-random key. After obtaining the first pseudo-random key, the first key seed block is directly discarded to avoid persistent leakage.
[0108] Step 405: Split the first pseudo-random key to obtain a second key and a second key seed.
[0109] Step 406: Determine whether the remaining key amount of the second key is less than the key amount required by the user. If the remaining key amount of the second key is less than the key amount required by the user, execute step 407. If the remaining key amount is greater than the key amount required by the user, save the second key seed and the process ends.
[0110] Step 407: Select a second key seed block from the third key block, where the first key seed block is different from the second key seed block.
[0111] Step 408: Process the second key seed and the second key seed block using a hash algorithm to obtain a second pseudo-random key.
[0112] Step 409: Split the second pseudo-random key to obtain a third key and a third key seed.
[0113] Step 410: If the remaining key quantity of the third key is greater than the key quantity required by the user, the third key seed is saved and the process ends.
[0114] If the remaining key quantity of the third key is less than the user's required key quantity, a third key seed block is selected from the third key block, where the third key seed block is different from the second key seed block. The third key seed and the third key seed block are processed using a hash algorithm to obtain a third pseudo-random key, which is then split. The relationship between the remaining key quantity and the user's required key quantity is repeatedly determined, and different operations are performed based on the determination results.
[0115] Step 411: Concatenate the first key, the second key, and the third key to generate a quantum key.
[0116] In this embodiment, quantum keys are generated by iteratively performing round-by-round iterations on key seeds and key seed blocks based on a hash algorithm, thereby achieving dynamic key updates. Part of the key generated in each round is distributed to the user, and the remaining part is used as the key seed for the next iteration until user needs are met or the seed blocks are exhausted. This integrates a one-way hash function for derivation and a dynamic rolling update mechanism, blocking the attack chain. Even if part of the key or quantum state is intercepted, the attacker cannot reversely deduce historical or future keys, effectively resisting quantum storage attacks and enhancing the security of the key system.
[0117] Furthermore, each key seed block is stored separately in a trusted environment, blocking both physical detection and logical access. This allows for quantum key generation, even if some key seed blocks are leaked due to storage vulnerabilities or channel attacks. Each key segment relies solely on a single key seed block and the previous key segment, with no cross-block dependencies, thus preventing local decryption paths.
[0118] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required for this application.
[0119] Based on the description of the above method embodiments, this application also provides corresponding device embodiments to implement the contents described in the above method embodiments.
[0120] Reference Figure 5 , which shows a structural diagram of a key generation device based on the BB84 protocol according to an embodiment of the present application, specifically comprising:
[0121] An acquisition module 501 is used to obtain an intermediate key;
[0122] A splitting module 502 is configured to split the intermediate key into blocks according to a block splitting rule to obtain a first key block and a second key block;
[0123] A first processing module 503 is configured to process the first key block to obtain an initial key;
[0124] A second processing module 504 is configured to process the second key block to obtain a third key block;
[0125] The derivation module 505 is configured to perform key derivation based on the initial key and the third key block to generate a quantum key.
[0126] Optionally, the second key block includes a plurality of key seed blocks;
[0127] The second processing module includes:
[0128] a calculation unit, configured to calculate a bit error rate of each key seed block;
[0129] A sorting unit is used to sort the bit error rates to obtain sorted key seed blocks, and use the sorted key seed blocks as the third key block.
[0130] Optionally, the device further comprises:
[0131] The key division module is used to divide the initial key according to the key distribution ratio to form a first key and a first key seed, where the first key is the key allocated to the user and the first key seed is the remaining key after the first key is allocated to the user.
[0132] Optionally, the derivation module includes: a derivation unit;
[0133] The derivation unit is configured to perform key derivation on the first key seed and multiple key seed blocks in the third key block using a hash algorithm to generate a quantum key.
[0134] Optionally, the deriving unit includes:
[0135] An acquisition submodule, configured to acquire the remaining key quantity of the first key;
[0136] A first selection submodule, configured to select a first key seed block from the third key block if the remaining key amount is less than the user required key amount;
[0137] a first calculation submodule, configured to process the first key seed and the first key seed block using a hash algorithm to obtain a first pseudo-random key;
[0138] A first splitting submodule, configured to split the first pseudo-random key to obtain a second key and a second key seed;
[0139] a second selection submodule, configured to select a second key seed block from the third key block if the remaining key amount of the second key is less than the key amount required by the user, the first key seed block being different from the second key seed block;
[0140] a second calculation submodule, configured to process the second key seed and the second key seed block using a hash algorithm to obtain a second pseudo-random key;
[0141] A second splitting submodule, configured to split the second pseudo-random key to obtain a third key and a third key seed;
[0142] a storage submodule, configured to save the third key seed if the remaining key quantity of the third key is greater than the key quantity required by the user;
[0143] The splicing submodule is used to splice the first key, the second key and the third key to generate a quantum key.
[0144] Optionally, the segmentation module is specifically configured to divide the intermediate key according to a fixed length or a non-fixed length to obtain a first key block and a second key block.
[0145] This embodiment first fully utilizes the value of the intermediate key in the BB84 protocol. The intermediate key is divided into a first key block and a second key block according to the block division rule. The first key block is processed to obtain an initial key, and the second key block is processed to obtain a third key block. Key derivation is performed based on the initial key and the third key block to generate a quantum key. The third key block is used as a seed block to become an entropy source reserve for quantum key generation. Through the above processing, the potential value of the intermediate key is fully exploited, the speed of quantum key generation is improved, and the utilization rate of quantum communication resources is thereby improved.
[0146] Secondly, dynamic key derivation is performed through the initial key and the third key block to generate quantum keys, thereby reducing the consumption of quantum hardware such as single-photon sources and detectors, thereby improving the efficiency of quantum communication.
[0147] As for the above-mentioned device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0148] An embodiment of the present invention also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the key generation method based on the BB84 protocol when executing the computer program.
[0149] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program that implements the key generation method based on the BB84 protocol when executed by a processor.
[0150] Alternatively, the computer-readable storage medium may be a non-transitory computer-readable storage medium, for example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, and the like.
[0151] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0152] Those skilled in the art will readily appreciate that any combination of the above-described embodiments is feasible, and therefore any combination of the above-described embodiments is an embodiment of the present invention. However, due to space limitations, this specification does not describe each of the embodiments in detail. Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they understand the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as covering the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0153] The above is a detailed introduction to the key generation method, device, equipment and medium based on the BB84 protocol provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A key generation method based on the BB84 protocol, characterized in that: include: Get the intermediate key; Divide the intermediate key into blocks according to a block rule to obtain a first key block and a second key block; Processing the first key block to obtain an initial key; processing the second key block to obtain a third key block; Performing key derivation based on the initial key and the third key block to generate a quantum key; The method further comprises: Divide the initial key according to the key distribution ratio to form a first key and a first key seed, where the first key is the key allocated to the user, and the first key seed is the remaining key after the first key is allocated to the user; The performing key derivation according to the initial key and the third key block to generate a quantum key includes: Performing key derivation on the first key seed and multiple key seed blocks in the third key block using a hash algorithm to generate a quantum key; The step of using a hash algorithm to derive a key from the first key seed and multiple key seed blocks in the third key block to generate a quantum key comprises: Obtaining the remaining key quantity of the first key; If the remaining key amount is less than the user's required key amount, selecting a first key seed block from the third key block; Processing the first key seed and the first key seed block using a hash algorithm to obtain a first pseudo-random key; Splitting the first pseudo-random key to obtain a second key and a second key seed; If the remaining key amount of the second key is less than the key amount required by the user, selecting a second key seed block from the third key block, where the first key seed block is different from the second key seed block; Processing the second key seed and the second key seed block using a hash algorithm to obtain a second pseudo-random key; Splitting the second pseudo-random key to obtain a third key and a third key seed; If the remaining key amount of the third key is greater than the key amount required by the user, saving the third key seed; The first key, the second key and the third key are concatenated to generate a quantum key.
2. The method according to claim 1, characterized in that The second key block includes a plurality of key seed blocks; The processing of the second key block to obtain a third key block includes: Calculate the bit error rate of each key seed block; sorting the bit error rates to obtain sorted key seed blocks; The sorted key seed blocks are used as the third key blocks.
3. The method according to any one of claims 1-2, characterized in that The block processing of the intermediate key according to the block rule to obtain the first key block and the second key block includes: The intermediate key is divided according to a fixed length or a non-fixed length to obtain a first key block and a second key block.
4. A key generation device based on the BB84 protocol, characterized in that: include: An acquisition module, used to obtain an intermediate key; a segmentation module, configured to segment the intermediate key into blocks according to a segmentation rule to obtain a first key block and a second key block; A first processing module, configured to process the first key block to obtain an initial key; a second processing module, configured to process the second key block to obtain a third key block; A derivation module for performing key derivation based on the initial key and the third key block to generate a quantum key; The device further comprises: a key division module for dividing the initial key according to the key distribution ratio to form a first key and a first key seed, wherein the first key is the key allocated to the user for use, and the first key seed is the remaining key after the first key is allocated to the user; The derivation module includes: a derivation unit; The derivation unit is configured to perform key derivation on the first key seed and multiple key seed blocks in the third key block using a hash algorithm to generate a quantum key; The derivation unit includes: An acquisition submodule, configured to acquire the remaining key quantity of the first key; A first selection submodule, configured to select a first key seed block from the third key block if the remaining key amount is less than the user required key amount; a first calculation submodule, configured to process the first key seed and the first key seed block using a hash algorithm to obtain a first pseudo-random key; A first splitting submodule, configured to split the first pseudo-random key to obtain a second key and a second key seed; a second selection submodule, configured to select a second key seed block from the third key block if the remaining key amount of the second key is less than the key amount required by the user, the first key seed block being different from the second key seed block; a second calculation submodule, configured to process the second key seed and the second key seed block using a hash algorithm to obtain a second pseudo-random key; A second splitting submodule, configured to split the second pseudo-random key to obtain a third key and a third key seed; a storage submodule, configured to save the third key seed if the remaining key quantity of the third key is greater than the key quantity required by the user; The splicing submodule is used to splice the first key, the second key and the third key to generate a quantum key.
5. The key generation device according to claim 4, characterized in that The second key block includes a plurality of key seed blocks; The second processing module includes: a calculation unit, configured to calculate a bit error rate of each key seed block; A sorting unit is used to sort the bit error rates to obtain sorted key seed blocks, and use the sorted key seed blocks as the third key block.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method for generating a key based on the BB84 protocol according to any one of claims 1 to 3 is implemented.
7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program that, when executed by a processor, implements a key generation method based on the BB84 protocol according to any one of claims 1 to 3.
Citation Information
Patent Citations
Security industrial controller, method and device based on national cryptographic algorithm and storage medium
CN118677614A