Communication system and method based on quantum key

By establishing a communication tunnel between the terminal device and the cloud server and using preset quantum keys for quantum encryption communication, the problems of high cost and difficult implementation in the prior art are solved, and low-cost quantum encryption communication is realized.

CN120528587APending Publication Date: 2025-08-22ECARX (HUBEI) TECHCO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510572239.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The prior art requires classical communication support in quantum encrypted communication between terminal devices and the cloud, which leads to high cost and difficult to implement.

Method used

The quantum key-based communication system is adopted to establish a communication tunnel between terminal devices, quantum gateways and quantum distribution servers, and quantum encryption communication is performed using preset terminal quantum keys and preset gateway quantum keys to avoid dependence on dedicated optical fibers or free space communication.

Benefits of technology

It effectively reduces communication costs, improves implementation difficulty, improves the ease of use and reliability of quantum encrypted communication, and reduces dependence on classic communication support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528587A_ABST
    Figure CN120528587A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a communication system and method based on a quantum key, and relates to the technical field of encryption communication. The system comprises terminal equipment, a quantum gateway and a quantum distribution server, the quantum gateway is deployed in a cloud server, and communication tunnels are established among all parts of the system based on an equipment security communication protocol; the terminal device obtains the quantum session key encrypted based on the preset terminal quantum key from the quantum distribution server to obtain the quantum session key; the quantum gateway obtains the quantum session key encrypted based on the preset gateway quantum key from the quantum distribution server to obtain the quantum session key; the terminal device and the quantum gateway are also used for quantum encryption communication based on the corresponding communication tunnel and the quantum session key. According to the invention, quantum encryption communication between the terminal device and the cloud server can be realized with low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of encrypted communication technology, and in particular to a communication system and method based on quantum key. Background Art

[0002] With the rapid development of intelligent and connected devices, terminal devices have transformed from single-function carriers into complex mobile data hubs. Data exchanges between terminals, the cloud, and other multiple terminals are frequent, with rich and large-scale data types, including a large amount of sensitive information. Leakage of this data poses risks such as privacy infringement and financial loss to users, and may even endanger public safety.

[0003] Currently, secure communication between end devices and the cloud is often achieved through traditional encryption techniques, whose security relies on the difficulty of solving specific mathematical problems. However, the rapid development of quantum computing technology poses a threat to traditional encryption. Quantum computers can crack the mathematical problems underlying traditional encryption at an exponential rate, making traditional encryption keys vulnerable to cracking. Therefore, existing technologies have proposed the use of quantum cryptography to achieve secure communication between end devices and the cloud.

[0004] However, when using quantum encryption communication technology to achieve secure communication between terminal devices and the cloud, classical communication support is often required, which has the disadvantages of high cost and difficulty in implementation. Summary of the Invention

[0005] The embodiments of the present application provide a communication system and method based on quantum key, which are used to achieve low-cost quantum encryption communication between terminal devices and cloud servers.

[0006] In a first aspect, an embodiment of the present application provides a communication system based on quantum keys, the system comprising a terminal device, a quantum gateway, and a quantum distribution server, the quantum gateway being deployed on a cloud server interacting with the terminal device, and each part of the system establishing a communication tunnel based on a device security communication protocol; wherein,

[0007] The terminal device is used to obtain a quantum session key encrypted based on a preset terminal quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key;

[0008] The quantum gateway is used to obtain a quantum session key encrypted based on a preset gateway quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key;

[0009] The terminal device and the quantum gateway are further configured to perform quantum encryption communication based on the corresponding communication tunnel and the quantum session key, thereby enabling data interaction between the terminal device and the cloud server.

[0010] In a possible implementation, the terminal device is specifically configured to:

[0011] Performing a key exchange with the quantum gateway based on a key exchange algorithm to obtain a first session key for a communication tunnel application between the terminal device and the quantum gateway;

[0012] Sending a key exchange request to the quantum gateway based on the first session key, and receiving key exchange information fed back by the quantum gateway in response to the key exchange request; the key exchange information is used to determine a unique quantum session key;

[0013] The quantum session key is obtained from the quantum distribution server based on the key exchange information, and the quantum session key is used to replace the first session key to achieve quantum encryption communication with the quantum gateway.

[0014] In one possible implementation, the quantum gateway is specifically used to:

[0015] Upon receiving the key exchange request, sending a first acquisition request to the quantum distribution server in response to the key exchange request, and receiving the quantum session key encrypted based on the preset gateway quantum key and the key exchange information fed back by the quantum distribution server;

[0016] The encrypted quantum session key is decrypted based on the preset gateway quantum key to obtain the quantum session key, and the key exchange information is fed back to the terminal device in response to the key exchange request.

[0017] In one possible implementation, the quantum gateway is further used to:

[0018] Before sending the first acquisition request, perform a key exchange with the quantum distribution server based on the key exchange algorithm to obtain a second session key applied in the communication tunnel between the quantum gateway and the quantum distribution server;

[0019] Sending a first network access request to the quantum distribution server based on the second session key, and receiving a network access status fed back by the quantum distribution server; the network access status is determined based on a preset gateway quantum key corresponding to the quantum gateway;

[0020] When the network access status indicates successful network access, the second session key is replaced with the preset gateway quantum key, and quantum encryption communication is performed with the quantum distribution server based on the preset gateway quantum key.

[0021] In a possible implementation, the terminal device is specifically configured to:

[0022] Upon receiving the key exchange information, sending a second acquisition request to the quantum distribution server, and receiving the quantum session key encrypted based on the preset terminal quantum key fed back by the quantum distribution server; the second acquisition request carries the key exchange information;

[0023] The encrypted quantum session key is decrypted based on the preset terminal key to obtain the quantum session key.

[0024] In a possible implementation manner, the terminal device is further configured to:

[0025] Before sending the second acquisition request, perform a key exchange with the quantum distribution server based on the key exchange algorithm to obtain a third session key applied in the communication tunnel between the terminal device and the quantum distribution server;

[0026] Sending a second network access request to the quantum distribution server based on the third session key, and receiving a network access status fed back by the quantum distribution server; the network access status is determined based on a preset terminal quantum key corresponding to the terminal device;

[0027] When the network access status indicates successful network access, the third session key is replaced with the preset terminal quantum key, and encrypted communication is performed with the quantum distribution server based on the preset terminal quantum key.

[0028] In one possible implementation, the quantum distribution server is specifically configured to:

[0029] Upon receiving a network access request from a target device, obtaining a preset device quantum key from a preset key pool according to a device identity carried in the network access request; the target device is the terminal device or the quantum gateway, the device identity is a device identifier or a gateway identifier, and the preset device quantum key is the preset terminal quantum key or the preset gateway quantum key;

[0030] In response to the network access request, feeding back to the target device the pre-set key information corresponding to the pre-set device quantum key and the first random number;

[0031] receiving a second random number fed back by the target device, and a first ciphertext generated based on the pre-set key information and the second random number; the second random number is generated by the target device, the first ciphertext is obtained by the target device encrypting a target value based on a pre-set device quantum key indicated by the pre-set key information, the target value being determined by the first random number and the second random number;

[0032] When the first ciphertext is equal to the second ciphertext, a network access status indicating successful network access is fed back to the target device; the second ciphertext is obtained by the quantum distribution server encrypting the target value based on the preset device quantum key.

[0033] In one possible implementation, the target device stores a preset quantum key pool, where the preset key information is used to indicate a key starting position and a key length; the target device is specifically configured to:

[0034] Upon receiving the preset key information and the first random number, obtaining the preset device quantum key from the preset quantum key pool according to the preset key information;

[0035] Generate a second random number, and encrypt the target value based on the preset device quantum key to obtain the first ciphertext;

[0036] Sending the first ciphertext and the second random number to the quantum distribution server.

[0037] In a possible implementation, the terminal device is specifically configured to:

[0038] Encrypting the data to be transmitted based on the quantum session key, and transmitting the encrypted data to be transmitted to the quantum gateway through the corresponding communication tunnel;

[0039] Accordingly, the quantum gateway is specifically used for:

[0040] The encrypted data to be transmitted is decrypted based on the quantum session key to obtain the data to be transmitted, thereby realizing data interaction between the terminal device and the cloud server.

[0041] In a second aspect, an embodiment of the present application provides a quantum key-based communication method, which is applied to a terminal device, wherein the terminal device stores a preset terminal quantum key and is used to interact with a corresponding cloud server; the method includes:

[0042] Obtaining a quantum session key encrypted based on the preset terminal quantum key from a quantum distribution server, and decrypting the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; the terminal device establishes a communication tunnel with the quantum distribution server based on a device secure communication protocol;

[0043] Based on the quantum session key, quantum encryption communication is performed with the quantum gateway deployed on the cloud server to achieve quantum encryption communication with the cloud server; the terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

[0044] In a third aspect, an embodiment of the present application provides a quantum key-based communication method, which is applied to a cloud server, wherein the cloud server is used to interact with a corresponding terminal device; the cloud server is deployed with a quantum gateway, and the quantum gateway stores a pre-set gateway quantum key; the method includes:

[0045] Based on the quantum gateway, obtaining a quantum session key encrypted based on the preset gateway quantum key from a quantum distribution server, and decrypting the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key;

[0046] Through the quantum gateway, quantum encryption communication is performed with the terminal device based on the quantum session key to achieve quantum encryption communication with the terminal device; communication tunnels are established between the quantum gateway and the terminal device, as well as between the quantum gateway and the quantum distribution server based on the device security communication protocol.

[0047] In a fourth aspect, an embodiment of the present application provides a quantum key-based communication method, which is applied to a quantum distribution server, wherein the quantum distribution server stores at least one preset terminal quantum key and at least one preset gateway quantum key; the method includes:

[0048] Encrypting a quantum session key based on the preset terminal quantum key, and sending the encrypted quantum session key to the corresponding terminal device;

[0049] The quantum session key is encrypted based on the preset gateway quantum key, and the encrypted quantum session key is sent to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

[0050] In a fifth aspect, an embodiment of the present application provides a terminal device, wherein the terminal device stores a preset terminal quantum key, and the terminal device is configured to obtain a quantum session key encrypted based on the preset terminal quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; the terminal device establishes a communication tunnel with the quantum distribution server based on a device secure communication protocol;

[0051] The terminal device is also used to perform quantum encryption communication with a quantum gateway deployed on a corresponding cloud server based on the quantum session key, thereby realizing quantum encryption communication with the cloud server; the terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

[0052] In a sixth aspect, an embodiment of the present application provides a cloud server, wherein the cloud server is deployed with a quantum gateway, wherein the quantum gateway stores a preset gateway quantum key, and wherein the quantum gateway is configured to obtain a quantum session key encrypted based on the preset gateway quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key;

[0053] The quantum gateway is also used to perform quantum encryption communication with the corresponding terminal device based on the quantum session key, thereby realizing quantum encryption communication between the cloud server and the terminal device; communication tunnels are established between the quantum gateway and the terminal device, as well as between the quantum gateway and the quantum distribution server, based on the device security communication protocol.

[0054] In a seventh aspect, an embodiment of the present application provides a quantum distribution server, wherein the quantum distribution server stores at least one preset terminal quantum key and at least one preset gateway quantum key;

[0055] The quantum distribution server is used to encrypt the quantum session key based on the preset terminal quantum key and send the encrypted quantum session key to the corresponding terminal device; it is also used to encrypt the quantum session key based on the preset gateway quantum key and send the encrypted quantum session key to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

[0056] The quantum key-based communication system and method provided in the embodiments of the present application are used to implement quantum encryption communication between terminal devices and cloud servers at a low cost. Specifically, in the communication system of the present application, a quantum gateway is deployed on the cloud server, and communication tunnels are established between the terminal devices, quantum gateways, and quantum distribution servers based on the device security communication protocol. On this basis, quantum encryption communication is carried out between the terminal devices and the quantum distribution server based on the corresponding communication tunnels using pre-set terminal quantum keys to obtain quantum session keys from the quantum distribution server; quantum encryption communication is carried out between the quantum gateway and the quantum distribution server based on the corresponding communication tunnels using pre-set gateway quantum keys to obtain quantum session keys from the quantum distribution server. Furthermore, quantum encryption communication is implemented between the terminal devices and the quantum gateway based on the corresponding communication tunnels using quantum session keys. This communication system combines the original communication methods of the quantum gateway and the device to implement quantum encryption communication, without relying on dedicated optical fiber or free-space communication, avoiding the infrastructure, maintenance, and other costs and technical difficulties generated by classical communication support, thereby effectively saving costs and having the advantage of being easy to implement. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0058] Figure 1 Schematic diagram of the application scenario of the quantum key-based communication system provided in this application;

[0059] Figure 2 Schematic diagram of the structure of the quantum key communication system provided in this application Figure 1 ;

[0060] Figure 3 A communication principle diagram of the quantum key-based communication system provided in this application;

[0061] Figure 4A Signaling process of the quantum key-based communication system provided in this application Figure 1 ;

[0062] Figure 4B Signaling process of the quantum key-based communication system provided in this application Figure 2 ;

[0063] Figure 4C Signaling process of the quantum key-based communication system provided in this application Figure 3 ;

[0064] Figure 5 Schematic diagram of the structure of the quantum key communication system provided in this application Figure 2 .

[0065] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0066] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present application.

[0067] First, let’s explain the terms involved in this application:

[0068] Quantum Key Distribution (QKD): The core principles of QKD are based on the no-cloning theorem and the uncertainty principle in quantum mechanics. The no-cloning theorem stipulates that quantum states cannot be accurately copied, which means that eavesdroppers cannot clone quantum information to eavesdrop without being detected; the uncertainty principle shows that measuring a quantum state will inevitably change its state, and the eavesdropper's measurement operation on the quantum state will introduce detectable interference, allowing the communicating parties to detect the occurrence of eavesdropping. The Heisenberg uncertainty principle limits the possibility of an eavesdropper measuring a quantum state without being detected. These principles provide theoretical unconditional security guarantees for QKD;

[0069] BB84 protocol: As a typical QKD protocol, in BB84, the sender uses the different polarization states of single photons to encode information bits. For example, horizontal and vertical polarization states represent 0 and 1, respectively, or 45° and 135° polarization states represent 0 and 1, respectively. The receiver randomly selects a measurement basis to measure the single photons. Using classical communication, the measurement basis and measurement results are compared to perform data filtering, error correction, and privacy amplification operations, ultimately generating a secure shared key.

[0070] The E91 protocol, another typical QKD protocol, exploits the properties of entangled photon pairs. When two photons are entangled, measuring one photon instantly affects the state of the other, regardless of the distance between them. The sender and receiver each measure one photon in the entangled pair, generating a key through classical communication and subsequent data processing.

[0071] In addition to the above terms, the terms "first," "second," and the like are used for descriptive purposes only and are not to be construed as indicating or implying relative importance or implicitly specifying the quantity of the technical features being referred to. In the following descriptions of the embodiments, "plurality" means more than two, unless otherwise specifically defined.

[0072] Driven by the wave of digitalization, the intelligence and connectivity of terminal devices are developing rapidly. Terminal devices, exemplified by automobiles, have evolved from simple functional tools into mobile data hubs. Data flows frequently between terminals, the cloud, and the cockpit, encompassing a wide range of data types and volumes, including a vast amount of sensitive information such as user identity, behavioral habits, device status, and location. Leakage of this data poses risks to user privacy and property, and can even threaten public safety.

[0073] Currently, traditional encryption technologies, such as those based on algorithms like RSA and AES, are widely used in data security for terminal devices like automobiles. On the one hand, the security of traditional encryption relies on the difficulty of solving specific mathematical problems. However, the rapid development of quantum computing technology can exponentially crack the data problems that traditional encryption relies on, making traditional encryption keys vulnerable to cracking. On the other hand, the current network structure of terminal devices involves multiple electronic control units (such as ECUs), communication networks (such as the CAN bus), and external communication interfaces (such as vehicle-to-vehicle, vehicle-to-cloud, and vehicle-to-infrastructure communications). While current terminal device network security protection systems focus on network intrusion detection, access control, and software vulnerability remediation, they lack the ability to ensure key security during data transmission. For example, in vehicle-to-cloud communications, when vehicles upload large amounts of driving data to the cloud for analysis or software updates, the secure distribution and storage of keys often become vulnerable to cyberattacks.

[0074] To address these issues, known technologies have proposed quantum cryptography for communication between end devices and the cloud. Specifically, these technologies utilize classical communication methods, such as optical fiber or free space, to transmit quantum keys and implement quantum cryptography between the end device and the cloud.

[0075] It should be understood that laying a fiber optic network requires significant upfront investment. For vehicle applications, this means building extensive fiber optic networks along roads or in specific areas. From fiber production and transportation to installation and maintenance, every step involves significant costs. For example, laying fiber optic cables in cities requires road excavation and pipeline laying, which not only incurs material costs but also incurs additional costs such as traffic diversion and construction personnel. Furthermore, in remote areas or those with harsh natural conditions, the difficulty and cost of laying fiber optic cables increase exponentially. Furthermore, vehicles may encounter complex road conditions during operation. In the event of a traffic accident, natural disaster (such as an earthquake or flood), or vandalism (such as construction errors), optical fibers can easily break or become damaged. Fiber optic maintenance requires specialized technicians and equipment. Detecting fiber faults and performing fiber splicing operations require high-precision instruments and skilled techniques, which contributes to high maintenance costs. Furthermore, the maintenance process may impact quantum key transmission services in the relevant area, disrupting quantum encryption communications within the vehicle.

[0076] Furthermore, optical fiber is a fixed physical connection, making it difficult to quickly adjust or expand once it's laid. For highly mobile applications like vehicles, their routes can change based on factors like traffic planning and user demand. For example, when new logistics routes are established or new urban areas are developed, it's difficult to quickly provide fiber-based quantum key services to vehicles traveling along these routes without pre-existing optical fiber. This limits the scope and adaptability of quantum key applications in vehicles.

[0077] Furthermore, using fiber optics requires specialized fiber optic access equipment to receive quantum keys. These devices are typically large and complex, making installation within the limited space of a vehicle challenging. Furthermore, the movement of terminal devices can cause vibrations and temperature fluctuations, which can affect the performance and stability of the fiber optic access equipment, increasing the risk of equipment failure and, in turn, hindering the reception and use of quantum keys.

[0078] It should be understood that free-space quantum key transmission involves complex satellite communications and space optics technologies. Launching and maintaining quantum communication satellites requires enormous capital investment. From satellite R&D, manufacturing, and launch to on-orbit monitoring and maintenance, every step is costly. For example, the manufacture of quantum satellites requires high-precision instruments and specialized materials, a long R&D cycle, and the involvement of a large number of scientific researchers. Furthermore, the cost of each satellite launch is in the billions, not including the subsequent operating costs.

[0079] At the same time, quantum key transmission over free space is significantly affected by the environment and suffers from poor transmission stability. Specifically, weather conditions significantly impact quantum key transmission in space. Inclement weather conditions such as heavy rain, snow, and fog can severely interfere with the transmission of optical signals in space, significantly increasing the bit error rate (BER) of quantum key transmission. Atmospheric turbulence can also scatter and distort optical signals, reducing the efficiency and reliability of quantum key transmission. For example, in areas of high altitude where atmospheric flow is unstable, quantum key transmission may be frequently interrupted, making it impossible to meet the requirements for continuous and stable encrypted communication while vehicles are in motion. Quantum key transmission in space also suffers from signal attenuation. As optical signals travel greater distances in space, signal strength gradually weakens, requiring more powerful transmitters and more sensitive receivers. Furthermore, the orbital motion and relative position changes of satellites can cause intermittent interruptions in communication links. When a vehicle needs a quantum key, it may not be able to obtain it in a timely manner because the satellite is not in an appropriate communication position, impacting the normal operation of the vehicle's encryption system.

[0080] Furthermore, using space-based quantum key transmission requires high-precision spatial optical reception and processing equipment to obtain the quantum key. This equipment is not only expensive but also requires specialized technicians to install and debug. Changes in the terminal's posture during movement (such as turning, climbing, and bumping) can affect the optical receiving equipment's alignment and reception of satellite signals. For example, a vehicle traveling on a rough road may experience frequent shaking, making it difficult to stably receive quantum key signals from a satellite.

[0081] In summary, in the known technologies, when using quantum encryption communication technology to achieve secure communication between terminal devices and the cloud, it requires classical communication support, which has the defects of high cost and difficulty in implementation.

[0082] Therefore, the present application provides a quantum key-based communication system and method to solve the above-mentioned problems. Specifically, in the present application, the quantum key-based communication system includes a terminal device, a quantum gateway, and a quantum distribution system. The quantum gateway is deployed in a cloud server that interacts with the terminal device, and communication tunnels are established between each part of the system based on the device security communication protocol. On this basis, the terminal device and the quantum gateway respectively obtain their quantum session keys encrypted based on the preset terminal quantum key or the preset gateway quantum key from the quantum distribution server through the corresponding communication tunnels, and perform quantum encryption communication based on the obtained quantum session key through the corresponding communication tunnels, thereby realizing quantum encryption communication between the terminal device and the cloud server.

[0083] It is understandable that the communication system of the present application can be applied to any interactive scenario between a terminal device and a cloud server, where a communication tunnel is established between the terminal device and the cloud server based on a device security communication protocol. As an example, Figure 1 The schematic diagram of the application scenario of the quantum key-based communication system provided in this application is as follows: Figure 1 As shown, the terminal device is specifically a vehicle, and the cloud server is specifically a business cloud server used by the automobile company.

[0084] Based on the communication system of the present application, when a vehicle interacts with a business cloud server, with the support of a communication tunnel established based on a device security communication protocol, the vehicle and the quantum gateway deployed on the business cloud server respectively obtain quantum session keys encrypted by corresponding preset quantum keys from the quantum distribution server. The vehicle and the quantum gateway obtain the quantum session keys after decryption based on the corresponding preset quantum keys, and realize quantum encryption communication based on the quantum session keys.

[0085] Through the above settings, it is possible to eliminate the dependence on dedicated optical fiber or free-space communication, combine the quantum gateway and the vehicle's original equipment security communication protocol to realize quantum encrypted communication between the vehicle and the business cloud server, thereby avoiding the cost issues and technical difficulties brought by classical communication support, thereby effectively saving costs and having the advantage of being easy to implement.

[0086] As another example, the quantum key-based communication system provided in this application can also be applied to smart home device scenarios. The smart home devices installed in the home are terminal devices, which perform quantum encryption communication with the corresponding smart home cloud server.

[0087] The following describes in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems using specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following describes the embodiments of the present application using an electronic device as the execution subject in conjunction with the accompanying drawings.

[0088] This embodiment provides a communication system based on quantum key. Figure 2 Schematic diagram of the structure of the quantum key communication system provided in this application Figure 1 ,like Figure 2 As shown, the communication system of this embodiment includes a terminal device, a quantum gateway, and a quantum distribution server. Communication tunnels are established between the terminal device, the quantum gateway, and the quantum distribution server based on a device security communication protocol.

[0089] Specifically, in this embodiment, SSL is used to establish a communication tunnel between the terminal device and the quantum gateway, and TLS is used to establish a communication tunnel between the terminal device and the quantum distribution server, and between the quantum gateway and the quantum distribution server. It should be understood that in actual applications, the device security communication protocol is specifically the terminal device's existing security communication protocol, which can be SSL, TLS, or other security communication protocols, and this embodiment is not limited to this.

[0090] It should be understood that the quantum gateway is deployed on the cloud server that interacts with the terminal device. It should be understood that the quantum gateway is part of the cloud server, and quantum encrypted communication between the terminal device and the quantum gateway means that quantum encrypted communication is implemented between the terminal device and the cloud server.

[0091] In this embodiment, the terminal device is used to obtain a quantum session key encrypted based on a preset terminal quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key.

[0092] The quantum gateway is used to obtain the quantum session key encrypted based on the preset gateway quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key.

[0093] Specifically, in this embodiment, the terminal device stores a device key pool, including at least one pre-set terminal quantum key. The quantum gateway stores a gateway key pool, including at least one pre-set gateway quantum key. The quantum distribution server stores a pre-set key pool, including at least one pre-set terminal quantum key and at least one pre-set gateway quantum key.

[0094] More specifically, as a possible implementation, the quantum distribution server also stores the key starting positions and key lengths corresponding to the device identifiers of different terminal devices, as well as the key starting positions and key lengths corresponding to the identities of different quantum gateways. Based on this, when the quantum distribution server knows the identity of the quantum gateway, it can obtain the unique pre-set gateway quantum key from the pre-set key pool based on the corresponding key starting position and key length. Similarly, the quantum distribution server can also obtain the unique pre-set terminal quantum key from the pre-set key pool based on the device identifier of the terminal device.

[0095] At this point, the quantum distribution server encrypts the quantum session key based on the preset terminal quantum key and feeds the encrypted quantum session key back to the terminal device. The terminal device obtains the unique preset terminal quantum key from the device key pool based on the corresponding key starting position and key length, and decrypts the encrypted quantum session key using this preset terminal quantum key to obtain the quantum session key. The quantum distribution server encrypts the quantum session key based on the preset gateway quantum key and feeds the encrypted quantum session key back to the quantum gateway. The quantum gateway obtains the unique preset gateway quantum key from the gateway key pool based on the corresponding key starting position and key length, and decrypts the encrypted quantum session key using this preset gateway quantum key to obtain the quantum session key.

[0096] As another possible implementation, the quantum distribution server's pre-set key pool stores different device identifiers and their corresponding pre-set terminal quantum keys, as well as different identity identifiers and their corresponding pre-set gateway quantum keys. Accordingly, the terminal device's device key pool only contains the pre-set terminal quantum key corresponding to its device identifier, and the quantum gateway's gateway key pool only contains the pre-set gateway quantum key corresponding to its identity identifier.

[0097] At this point, the quantum distribution server encrypts the quantum session key using the preset terminal quantum key corresponding to the terminal device and feeds the encrypted quantum session key back to the terminal device. The terminal device decrypts the encrypted quantum session key using the stored preset terminal quantum key to obtain the quantum session key. The quantum distribution server encrypts the quantum session key using the preset gateway quantum key corresponding to the quantum gateway and feeds the encrypted quantum session key back to the quantum gateway. The quantum gateway decrypts the encrypted quantum session key using the corresponding preset gateway quantum key to obtain the quantum session key.

[0098] In practical applications, the quantum distribution server can also set up a key update mechanism to ensure the security of the key. For pre-set terminal quantum keys and pre-set gateway quantum keys, the quantum distribution server will generate new keys regularly (for example, every 30 days). The specific process is as follows:

[0099] After the quantum distribution server generates a new pre-set terminal quantum key and a pre-set gateway quantum key, it encrypts the new pre-set terminal quantum key based on the currently valid pre-set terminal quantum key and the new pre-set gateway quantum key based on the currently valid pre-set gateway quantum key. The quantum distribution server then sends the encrypted new keys to the corresponding terminal device and quantum gateway, respectively.

[0100] After receiving the encrypted new preset terminal quantum key, the terminal device decrypts it based on the currently stored preset terminal quantum key to obtain a new preset terminal quantum key, stores it in the device key pool, and deletes the old preset terminal quantum key. After receiving the encrypted new preset gateway quantum key, the quantum gateway decrypts it based on the currently stored preset gateway quantum key to obtain a new preset gateway quantum key, stores it in the gateway key pool, and deletes the old preset gateway quantum key.

[0101] Furthermore, in this embodiment, the terminal device and the quantum gateway are also used to perform quantum encryption communication based on the corresponding communication tunnel and quantum session key to realize data interaction between the terminal device and the cloud server.

[0102] Specifically, the terminal device is used to encrypt the data to be transmitted based on the quantum session key, and transmit the encrypted data to be transmitted to the quantum gateway through the corresponding communication tunnel.

[0103] The quantum gateway is specifically used to decrypt the encrypted data to be transmitted based on the quantum session key, obtain the data to be transmitted, and realize data interaction between the terminal device and the cloud server.

[0104] In the communication system provided by the embodiments of the present application, a quantum gateway is deployed in the cloud server corresponding to the terminal device. The terminal device stores a preset terminal quantum key, the quantum gateway stores a preset gateway quantum key, and the quantum distribution server stores a preset terminal quantum key and a preset gateway quantum key. Furthermore, communication tunnels are established between the terminal device, the quantum gateway, and the quantum distribution server based on a secure communication protocol. Based on this, the terminal device and the quantum gateway each obtain a quantum session key encrypted using the corresponding preset quantum key from the quantum distribution server via the corresponding communication tunnel. The terminal device and the quantum gateway then decrypt the encrypted quantum session key using the corresponding preset quantum key to obtain the quantum session key. Quantum encrypted communication is then performed based on the quantum session key, thereby enabling quantum encrypted communication between the terminal device and the cloud server.

[0105] The communication system of this embodiment enables encrypted communication between terminal devices and cloud servers while reducing reliance on dedicated optical fibers or free-space communications. This approach effectively reduces communication costs and improves the feasibility and usability of quantum cryptography, while still utilizing classical communication channels to assist in the distribution and management of quantum keys.

[0106] Optionally, for quantum session keys, the quantum distribution server generates a new quantum session key after each data communication session. The quantum distribution server encrypts the new quantum session key based on the corresponding pre-set terminal quantum key or pre-set gateway quantum key and sends it to the terminal device or quantum gateway. The terminal device and quantum gateway decrypt and store the new quantum session key in the same manner as described above.

[0107] Through the above settings, a new quantum session key is generated after each session, which can significantly improve the security of the communication system, reduce the risk of quantum session key leakage, and enhance the system's reliability and responsiveness to security threats, while supporting compliance requirements of security standards.

[0108] Figure 3 The communication principle diagram of the quantum key-based communication system provided in this application is as follows: Figure 3 As shown, in the communication system of the present application, the terminal device first conducts quantum key negotiation with the quantum gateway, and then the quantum gateway and the terminal device respectively initiate network access requests to the quantum distribution server for network access authentication and obtain the quantum session key. Finally, the terminal device and the quantum gateway implement quantum encryption communication based on the quantum session key, thereby realizing quantum encryption communication between the terminal device and the cloud server.

[0109] As a detailed explanation, Figure 4A Signaling process of the quantum key-based communication system provided in this application Figure 1 ,like Figure 4AAs shown, when the terminal device conducts quantum key negotiation with the quantum gateway, it is specifically used to: send a key suite negotiation request to the quantum gateway; receive a key suite negotiation response fed back by the quantum gateway; when the quantum gateway supports quantum keys, the key suite negotiation response is used to indicate support for quantum keys.

[0110] Specifically, in this embodiment, the terminal device first establishes an SSL communication tunnel with the quantum gateway. The terminal device monitors whether it stores a preset terminal quantum key and determines whether it supports quantum keys. The terminal device sends a key suite negotiation request to the quantum gateway. The key suite negotiation request includes the cipher suites supported by the terminal device and information indicating whether the terminal device supports quantum key encryption communication.

[0111] Correspondingly, when the quantum gateway receives the key suite negotiation request, it determines whether to support quantum key encryption communication by judging whether the preset gateway quantum key is stored, and feeds back the key suite negotiation response carrying the cipher suite it confirms to use and information indicating whether the quantum gateway supports quantum key encryption communication to the terminal device.

[0112] On this basis, if the terminal device receives a key suite negotiation response carrying information indicating that the quantum gateway supports quantum key encryption communication, and the terminal device supports quantum key encryption communication, the terminal device performs a key exchange with the quantum gateway based on the key exchange algorithm, obtains a first session key for the communication tunnel application between the terminal device and the quantum gateway; sends a key exchange request to the quantum gateway based on the first session key, and receives key exchange information fed back by the quantum gateway in response to the key exchange request; the key exchange information is used to determine a unique quantum session key;

[0113] Based on the key exchange information, a quantum session key is obtained from the quantum distribution server, and the quantum session key is used to replace the first session key to realize quantum encryption communication with the quantum gateway.

[0114] The key exchange algorithm is the key exchange algorithm indicated by the cipher suite confirmed by the quantum gateway in the key suite negotiation response. In this embodiment, it is the ECDH algorithm. The terminal device performs a key exchange with the quantum gateway based on ECDH, negotiating a first session key, a non-quantum session key between the two parties. The terminal device and the quantum gateway each store this first session key.

[0115] Furthermore, the terminal device sends a key exchange request to the quantum gateway through the first session key to obtain the key exchange information fed back by it, and then obtains the quantum session key from the quantum distribution server based on the key exchange information, and replaces the first session key with the quantum session key to realize quantum encryption communication with the quantum gateway.

[0116] Specifically, in this embodiment, the key exchange information includes the key starting position and key length. When the quantum distribution server receives the key exchange information sent by the terminal device, it determines a unique quantum session key that is consistent with the key starting position and key length from the preset key pool.

[0117] In this embodiment, the terminal device obtains key exchange information through the quantum gateway and, based on this information, obtains the quantum session key from the quantum distribution server. This multi-step key acquisition mechanism enhances the security of key transmission. Furthermore, the terminal device replaces the first session key with the quantum session key without modifying the existing algorithm suite, thus enhancing the ease of implementation of this solution.

[0118] Optionally, if the terminal device receives a key suite negotiation response carrying information indicating that the quantum gateway does not support quantum key encryption communication, or the terminal device does not support quantum key encryption communication, the terminal device and the quantum gateway perform encrypted communication based on the first session key negotiated using the cipher suite.

[0119] Through this setting, when the terminal device and / or quantum gateway do not support quantum encryption communication, the terminal device and quantum gateway can also use the original encryption method for encrypted communication.

[0120] As a further illustration, Figure 4B Signaling process of the quantum key-based communication system provided in this application Figure 2 ,like Figure 4B As shown in the figure, when the quantum gateway receives a key exchange request, it is specifically used to:

[0121] Based on the key exchange algorithm, a key is exchanged with the quantum distribution server to obtain a second session key for the communication tunnel application between the quantum gateway and the quantum distribution server; based on the second session key, a first network access request is sent to the quantum distribution server, and the network access status fed back by the quantum distribution server is received; the network access status is determined based on the preset gateway quantum key corresponding to the quantum gateway; when the network access status indicates that the network access is successful, the second session key is replaced with the preset gateway quantum key, and quantum encryption communication is performed with the quantum distribution server based on the preset gateway quantum key.

[0122] Specifically, in this embodiment, the quantum gateway establishes a TLS communication tunnel with the quantum distribution server and negotiates a second session key based on ECDH. Based on this, the quantum gateway encrypts its identity using the second session key and sends the first network access request carrying the encrypted identity to the quantum distribution server.

[0123] The quantum gateway receives the network access status fed back by the quantum distribution server, and when the network access status indicates successful access, it replaces the second session key with the preset gateway quantum key corresponding to the quantum gateway's GateWayID to realize quantum encryption communication with the quantum distribution server.

[0124] Furthermore, the quantum gateway sends a first acquisition request to the quantum distribution server in response to the key exchange request, and receives the quantum session key encrypted based on the preset gateway quantum key and the key exchange information fed back by the quantum distribution server; decrypts the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key, and feeds back the key exchange information to the terminal device in response to the key exchange request.

[0125] Specifically, in this embodiment, the quantum gateway responds to the terminal device's key exchange request by sending a first acquisition request to the quantum distribution server for obtaining a quantum session key, and then receives the quantum session key fed back by the quantum distribution server. More specifically, the quantum session key fed back by the quantum distribution server is a quantum session key encrypted using the quantum gateway's corresponding preset gateway quantum key. Accordingly, upon receiving the encrypted quantum session key, the quantum gateway decrypts the encrypted quantum session key using its corresponding preset gateway quantum key to obtain the quantum session key.

[0126] In addition, when the quantum distribution server feeds back the encrypted quantum session key, it also feeds back key exchange information, which is used to indicate the unique quantum session key. The quantum gateway responds to the key exchange request from the terminal device and feeds back the key exchange information to the terminal device.

[0127] In the above process, before sending the first acquisition request to the quantum distribution server, the quantum gateway first performs network authentication and replaces the second session key used for communication between it and the quantum distribution server with the preset gateway quantum key. On the one hand, it realizes quantum encryption communication with the quantum distribution server, further ensuring the transmission security of the quantum session key. On the other hand, there is no need to modify the existing algorithm suite.

[0128] Figure 4C Signaling process of the quantum key-based communication system provided in this application Figure 3 ,like Figure 4C As shown, when the terminal device receives the key exchange information, it is specifically used to:

[0129] Based on the key exchange algorithm, a key is exchanged with the quantum distribution server to obtain a third session key for the communication tunnel application between the terminal device and the quantum distribution server; based on the third session key, a second network access request is sent to the quantum distribution server, and the network access status fed back by the quantum distribution server is received; the network access status is determined based on the preset terminal quantum key corresponding to the terminal device; when the network access status indicates that the network access is successful, the third session key is replaced with the preset terminal quantum key, and encrypted communication is performed with the quantum distribution server based on the preset terminal quantum key.

[0130] Specifically, in this embodiment, the terminal device establishes a TLS communication tunnel with the quantum distribution server and negotiates a third session key based on ECDH. Based on this, the terminal device encrypts its device identifier based on the third session key and sends a second network access request carrying the encrypted device identifier to the quantum distribution server.

[0131] The terminal device receives the network access status fed back by the quantum distribution server, and when the network access status indicates successful access, the terminal device replaces the third session key with the preset terminal quantum key corresponding to the device identifier of the terminal device to realize quantum encryption communication with the quantum distribution server.

[0132] Furthermore, the terminal device sends a second acquisition request to the quantum distribution server and receives the quantum session key encrypted based on the preset terminal quantum key fed back by the quantum distribution server; the second acquisition request carries key exchange information; the encrypted quantum session key is decrypted based on the preset terminal key to obtain the quantum session key.

[0133] Specifically, in this embodiment, upon receiving the key exchange information, the terminal device sends a second acquisition request carrying the key exchange information to the quantum distribution server, and receives the quantum session key fed back by the quantum distribution server. More specifically, the quantum session key fed back by the quantum distribution server is a quantum session key encrypted using the preset terminal quantum key corresponding to the terminal device. Accordingly, upon receiving the encrypted quantum session key, the terminal device decrypts the encrypted quantum session key using its corresponding preset terminal quantum key to obtain the quantum session key.

[0134] In the above process, before sending the second acquisition request to the quantum distribution server, the terminal device first performs network authentication and replaces the third session key used for communication between it and the quantum distribution server with the preset terminal quantum key. On the one hand, it realizes quantum encryption communication with the quantum distribution server, further ensuring the transmission security of the quantum session key. On the other hand, there is no need to modify the existing algorithm suite.

[0135] In this embodiment, if Figure 4B and Figure 4CAs shown in the figure, when the quantum distribution server receives a network access request from a terminal device or quantum gateway, it is specifically used to:

[0136] According to the device identity carried in the network access request, the preset device quantum key is obtained from the preset key pool; in response to the network access request, the preset key information corresponding to the preset device quantum key and the first random number are fed back to the target device; the second random number fed back by the target device and the first ciphertext generated based on the preset key information and the second random number are received; the second random number is generated by the target device, and the first ciphertext is obtained by the target device encrypting the target value based on the preset device quantum key indicated by the preset key information, and the target value is determined by the first random number and the second random number; when the first ciphertext is equal to the second ciphertext, the network access status indicating successful network access is fed back to the target device; the second ciphertext is obtained by the quantum distribution server encrypting the target value based on the preset device quantum key.

[0137] Correspondingly, the target device is specifically used to: upon receiving the preset key information and the first random number, obtain the preset device quantum key from the preset quantum key pool according to the preset key information; generate a second random number, and encrypt the target value based on the preset device quantum key to obtain a first ciphertext; and send the first ciphertext and the second random number to the quantum distribution server.

[0138] The target device is a terminal device or a quantum gateway, the device identity is a device identifier or a gateway identifier, and the pre-set device quantum key is a pre-set terminal quantum key or a pre-set gateway quantum key. Furthermore, in this embodiment, the terminal device stores different pre-set terminal quantum keys, and the quantum gateway stores different pre-set gateway quantum keys.

[0139] On this basis, when the quantum distribution server receives a network access request, it obtains the pre-set device quantum key from the pre-set key pool based on the device identity carried in the network access request. In response to the network access request, it feeds back the pre-set key information corresponding to the pre-set device quantum key and the first random number generated by the quantum distribution server to the target device. The pre-set key information indicates the key starting position and key length. Upon receiving the pre-set key information, the target device can determine a unique pre-set quantum key from among the corresponding different pre-set quantum keys based on the indicated key starting position and key length.

[0140] In actual applications, if the terminal device stores different device identifiers and their corresponding preset terminal quantum keys, and the quantum gateway stores different identity identifiers and their corresponding preset gateway quantum keys, the preset key information is specifically used to indicate the device identifier or identity identifier. This embodiment does not limit it, as long as a unique preset quantum key can be determined based on the preset key information.

[0141] Furthermore, the quantum distribution server receives the second random number fed back by the target device, as well as the first ciphertext generated by it based on the preset key information and the second random number generated by it. Specifically, the target device uses the AES-GCM-256 algorithm to encrypt the target value determined by the first random number and the second random number based on the preset quantum key indicated by the preset key information to obtain the first ciphertext.

[0142] The quantum distribution server then encrypts the target value determined by the first and second random numbers using the AES-GCM-256 algorithm based on the preset key information corresponding to the target device, generating a second ciphertext. The quantum distribution server compares the first and second ciphertexts. If the first and second ciphertexts are equal, the quantum distribution server returns a network access status indicating successful network access to the target device. Otherwise, the quantum distribution server returns a network access status indicating unsuccessful network access.

[0143] In the above process, the unique preset quantum key is accurately obtained and determined using the preset key information through the device identity. The target value is generated by the first and second random numbers and encrypted using the AES-GCM-256 algorithm. This establishes a two-way verification mechanism, greatly improving security and effectively preventing key leakage and illegal communication. Bidirectional verification and clear network access status feedback enhance reliability, facilitate troubleshooting, and ensure stable system operation. The flexible preset key information indication method supports indicating the key starting position and length, as well as the device identification or identity, significantly improving compatibility and adapting to different application scenarios and device configuration requirements.

[0144] Based on the above, Figure 5 Schematic diagram of the structure of the quantum key communication system provided in this application Figure 2 ,like Figure 5 As shown, in this embodiment, the terminal device is internally provided with a quantum cryptography communication SDK and a secure storage area. The quantum cryptography communication SDK is used to implement quantum cryptography communication functions between the terminal device and the quantum distribution server and quantum gateway. The secure storage area is used to store the preset terminal quantum key.

[0145] Specifically, the terminal device sends a key exchange request to the quantum gateway based on the quantum encryption communication SDK, sends a network access request to the quantum distribution server, receives the key exchange information fed back by the quantum gateway based on the quantum encryption communication SDK, and sends a second acquisition request to the quantum distribution server. When sending the network access request, the quantum encryption communication SDK of the terminal device will carry the device identity in the request so that the quantum distribution server can perform identity authentication. After receiving the key exchange information fed back by the quantum gateway, the SDK will parse and process the information according to the established encryption protocol and the preset terminal quantum key stored in the secure storage area, preparing for subsequent data encryption communication. When sending the second acquisition request to the quantum distribution server, the necessary device-related information will also be attached to the request to ensure the accuracy and traceability of the request.

[0146] Similarly, the quantum gateway also houses a quantum cryptography communication SDK and secure storage area. This SDK is used to interact with terminal devices and quantum distribution servers. Upon receiving a key exchange request from a terminal device, the quantum cryptography communication SDK retrieves the pre-set gateway quantum key from the secure storage area and, using a specific key exchange algorithm, generates and returns the corresponding key exchange information. When interacting with the quantum distribution server, the SDK ensures efficient and accurate information exchange based on specific service requirements, such as obtaining the latest quantum session key or synchronizing key update information.

[0147] The quantum distribution server also includes a quantum cryptography communication SDK, which it uses to interact with quantum gateways and terminal devices. Furthermore, the server also includes a quantum random number generator for randomly generating quantum session keys. A secure storage area is also provided for storing a pool of pre-set keys.

[0148] The quantum distribution server also houses a quantum key management system (QKM) for full lifecycle management of keys across the entire system. This includes the generation, storage, update, and distribution of pre-installed terminal and gateway quantum keys, ensuring that each device has timely access to secure and valid keys. After generating a quantum session key, the QKM accurately distributes the encrypted quantum session key to the corresponding device based on requests from the terminal device and quantum gateway, incorporating information such as the device's identity. The system also monitors key usage, such as frequency and duration of use, to ensure timely tracing and appropriate countermeasures when security risks arise. For example, if a device is detected requesting an unusually high number of quantum session keys, the QKM will issue an alert and conduct further review of the device's key requests, ensuring the security and stability of the entire quantum key communication system.

[0149] As an example, when applying the quantum encryption-based communication system of this application to the vehicle-cloud interaction scenario, it is necessary to send the preset vehicle quantum key VQPKey to the vehicle side through the vehicle PKI system and the vehicle distribution server when the vehicle is offline. The vehicle side saves the preset quantum key VQPKey in the secure storage area TEE / eSim / HSM of the ECU. The quantum gateway presets the gateway quantum key GQPKey through the vehicle distribution server and saves it in the quantum gateway secure storage area. The quantum distribution server saves the vehicle quantum preset key set VQPKeys and the quantum gateway preset quantum key set GQPKeys. On this basis, the specific plan is as follows:

[0150] 1. When the vehicle makes a request to the vehicle business cloud, the vehicle will first establish an SSL communication tunnel with the quantum gateway.

[0151] 2. The vehicle initiates a key suite negotiation request to the quantum gateway. Specifically, the key suite negotiation request includes: a. supported cipher suites; b. whether to use quantum key encryption for communication. The vehicle determines whether to use quantum key encryption for communication based on whether it detects the pre-set terminal quantum key.

[0152] 3. The quantum gateway returns a key suite negotiation response to the vehicle. Specifically, after receiving the key suite negotiation request from the vehicle, the quantum gateway returns a key suite negotiation response to the vehicle. The key suite negotiation response from the vehicle includes: a. the cipher suite to be used; b. information on whether quantum key encryption is used for communication. The quantum gateway determines whether to use quantum key encryption for communication based on whether it detects the pre-set gateway quantum key.

[0153] 4. Key exchange. The vehicle and quantum gateway exchange keys using the ECDH algorithm and negotiate the non-quantum session key SessionKey1. The vehicle and quantum gateway each save the first session key SessionKey1.

[0154] 5. The vehicle decides whether to request the quantum key based on the key negotiation results.

[0155] 6. When both parties support quantum key encryption communication, the vehicle sends a quantum key exchange request to the quantum gateway.

[0156] 7. When the quantum gateway receives the quantum key exchange request, it starts network authentication and sends the network access request to the quantum distribution server. The specific process is as follows:

[0157] a. The quantum gateway establishes TLS communication with the quantum distribution server (ECDH negotiates the second session key SessionKey2) and sends the gateway identity GateWayID;

[0158] b. The quantum distribution server searches the preset gateway quantum key pool according to GateWayID and returns the preset key information corresponding to GateWayID (including the key starting position GQPkeyIDxStart and the key length GQPKeyIDxLen). The quantum distribution server obtains the preset gateway quantum key GQPkeyIDx for this connection based on the preset key information and randomly generates a 16-byte first random number RandomA.

[0159] 8. The quantum distribution server returns the preset key information (including the key starting position GQPkeyIDxStart, the key length GQPKeyIDxLen) and the first random number RandomA to the quantum gateway. At this time, the quantum gateway performs the following process:

[0160] a. The quantum gateway obtains GQPkeyIDx from the pre-made preset quantum key pool according to the preset key information;

[0161] b. The quantum gateway generates a 16-byte second random number RandomB;

[0162] c. The quantum gateway uses the AES-GCM-256 algorithm and the preset gateway quantum key GQPKeyIDx to encrypt the target value (RandomB<<16+RandomA) and obtain the first ciphertext ChiperRandomBA.

[0163] 9. The quantum gateway returns the first ciphertext ChiperRandomBA and the second random number RandomB encrypted using the preset gateway quantum key GQPkeyIDx.

[0164] 10. The quantum distribution server returns the network access status. The specific network access status is determined through the following process:

[0165] a. The quantum distribution server uses the AES-GCM-256 algorithm to encrypt the target value (RandomB<<16+RandomA) based on the preset gateway quantum key GQPkeyIDx, obtains the second ciphertext ChiperRandomAB, and compares the second ciphertext RandomChiperAB with the first ciphertext RandomChiperBA. If they are equal, the network access status of successful access is returned; otherwise, the network access status of unsuccessful access is returned.

[0166] 11. The quantum gateway and quantum distribution server use the negotiated pre-set gateway quantum key to replace the second session key negotiated by TLS; specifically, the pre-set gateway quantum key GQKeyIDx is used to replace the second session key SessionKey2 in the TLS link established with QSC.

[0167] 12. The quantum gateway obtains the quantum key. Specifically, the process includes the following:

[0168] a. The quantum gateway sends a first acquisition request to the quantum distribution server;

[0169] b. After receiving the first acquisition request, the quantum distribution server randomly returns key exchange information from the preset key pool. The key exchange information includes the key start position QKeyStart and the key length QKeyLen. The quantum session key Qkey is obtained according to the key exchange information, and the quantum session key QKey is encrypted using the preset gateway quantum key GQPkeyIDx to obtain the encrypted quantum session key QkeyChiper.

[0170] 13. The quantum distribution server returns the encrypted quantum session key ChiperQKey and key exchange information (key start position QKeyStart and key length QKeyLen) to the quantum gateway.

[0171] 14. The quantum gateway uses the preset gateway quantum key GQPkeyIDx to decrypt the encrypted quantum session key ChiperQKey and save the quantum session key QKey.

[0172] 15. The quantum gateway responds to the vehicle's key exchange request and returns the key exchange information (key start position QKeyStart and key length QKeyLen).

[0173] 16. The vehicle sends a second network access request to the quantum distribution server. Specifically, the two parties establish TLS communication, use ECDH to negotiate the third session key SessionKey3, and the vehicle sends the vehicle VIN code to the quantum distribution server. Based on this, the quantum distribution server performs the following process:

[0174] a. The quantum distribution server searches the preset key pool according to the VIN code and returns the preset key information corresponding to the VIN code (including the key starting position VQKeyIDxStart and the key length VQKeyIDxLen);

[0175] b. The quantum distribution server obtains the preset terminal quantum key VQPkeyIDx according to the key starting position VQKeyIDxStart and the key length VQKeyIDxLen, and generates a 16-byte third random number RandomC.

[0176] 17. The quantum distribution server returns the preset key information and the third random number.

[0177] 18. The vehicle returns the target value ChiperRandomChiperDC and the fourth random number RandomD encrypted using the preset terminal quantum key VQPkeyIDx to the quantum distribution server. Specifically:

[0178] a. The vehicle obtains the preset terminal quantum key VQPkeyIDx from the preset quantum key pool VQKeyKey according to the key starting position VQKeyIDxStart and the key length VQKeyIDxLen, and generates a 16-byte fourth random number RandomD;

[0179] b. Use the AES-GCM-256 algorithm to encrypt the target value (RandomD<<16+RandomC) based on the preset terminal quantum key VQPKeyIDx to obtain the third ciphertext RandomChiperDC.

[0180] 19. The quantum distribution server returns a successful network access status. Specifically, the network access status is determined based on the following process:

[0181] The quantum distribution server uses the AES-GCM-256 algorithm to encrypt the target value (RandomD<<16+RandomC) based on the preset terminal quantum key VQPkeyIDx, obtains the fourth ciphertext RandomChiperCD, compares the third ciphertext RandomChiperDC with the fourth RandomChiperCD, and returns the network access status of successful access if they are equal; otherwise, returns the network access status of unsuccessful access.

[0182] 20. The vehicle and quantum distribution server use the negotiated pre-set terminal quantum key to replace the third session key negotiated by TLS. That is, VQPkeyIDx is used to replace the session key SessionKey3 in the TLS link established with QSC.

[0183] 21. Based on the preset terminal quantum key, the vehicle sends a second acquisition request to the quantum distribution server, requesting to obtain the quantum session key, carrying key exchange information (key starting position QKeyStart and key length QKeyLen).

[0184] 22. The quantum distribution server queries the preset key pool QKey based on the key exchange information, and uses the preset terminal quantum key VQPKeyIDx to encrypt the quantum session key, and returns the encrypted quantum session key ChiperQKey.

[0185] 23. After receiving the encrypted quantum session key ChiperQKey, the vehicle uses the preset terminal quantum key VQPkeyIDx to decrypt the encrypted quantum session key ChiperQKey to obtain the quantum session key QKey.

[0186] 24. Use the quantum session key QKey to replace the original SSL first session key SessionKey1. The quantum session key QKey is used as the communication session key between the vehicle and the quantum gateway.

[0187] At this point, quantum encrypted communication has been established between the vehicle and the quantum gateway. The vehicle service cloud then communicates with the vehicle through the quantum gateway. Based on quantum encrypted communication, the vehicle's specific encryption / decryption services can be delivered through the quantum encrypted channel.

[0188] The present application also provides a communication method based on quantum keys, which is applied to a terminal device, wherein the terminal device stores a preset terminal quantum key and is used to interact with a corresponding cloud server; the method includes:

[0189] Obtaining a quantum session key encrypted based on a preset terminal quantum key from a quantum distribution server, and decrypting the encrypted quantum session key based on the preset terminal quantum key to obtain a quantum session key; the terminal device establishes a communication tunnel with the quantum distribution server based on a device secure communication protocol;

[0190] Quantum encryption communication is carried out with the quantum gateway deployed on the cloud server based on the quantum session key to realize quantum encryption communication with the cloud server; the terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

[0191] The present application also provides a communication method based on quantum keys, which is applied to a cloud server, and the cloud server is used to interact with corresponding terminal devices; the cloud server is deployed with a quantum gateway, and the quantum gateway stores a preset gateway quantum key; the method includes:

[0192] Based on the quantum gateway, obtain the quantum session key encrypted based on the preset gateway quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key;

[0193] Through the quantum gateway, quantum encryption communication is carried out with the terminal device based on the quantum session key to realize quantum encryption communication with the terminal device; communication tunnels are established between the quantum gateway and the terminal device, as well as between the quantum gateway and the quantum distribution server based on the device security communication protocol.

[0194] The present application also provides a communication method based on quantum keys, which is applied to a quantum distribution server. The quantum distribution server stores at least one preset terminal quantum key and at least one preset gateway quantum key. The method includes:

[0195] Encrypting the quantum session key based on the preset terminal quantum key and sending the encrypted quantum session key to the corresponding terminal device;

[0196] The quantum session key is encrypted based on the preset gateway quantum key, and the encrypted quantum session key is sent to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

[0197] Specifically, how the terminal device obtains the quantum session key from the quantum distribution server, how the quantum gateway obtains the quantum session key from the quantum distribution server, and how the terminal device and the quantum gateway perform quantum encryption communication can be found in the aforementioned system embodiment and will not be repeated here.

[0198] In the method provided in the aforementioned embodiment, when the terminal device interacts with the cloud server, the terminal device obtains the quantum session key from the quantum distribution server based on quantum encryption communication, and the quantum gateway also obtains the quantum session key from the quantum distribution server based on quantum encryption communication. On this basis, the terminal device and the quantum gateway implement quantum encryption communication based on the quantum session key, thereby realizing quantum encryption communication between the terminal device and the cloud server.

[0199] Through the methods of the aforementioned embodiments, terminal devices and quantum gateways can perform quantum encrypted communication, thus avoiding the risk of rapid cracking due to quantum attacks and effectively ensuring communication security. Furthermore, quantum encrypted communication between terminal devices and quantum gateways is based on the terminal device's existing device security communication protocol, without relying on dedicated optical fiber or free-space communication. This effectively avoids the cost and technical difficulties associated with these protocols, resulting in significant cost savings and ease of implementation.

[0200] The present application also provides a terminal device, which stores a preset terminal quantum key. The terminal device is used to obtain a quantum session key encrypted based on the preset terminal quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; the terminal device establishes a communication tunnel with the quantum distribution server based on a device security communication protocol;

[0201] The terminal device is also used to conduct quantum encryption communication with the quantum gateway deployed on the corresponding cloud server based on the quantum session key, thereby realizing quantum encryption communication with the cloud server; the terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

[0202] Specifically, for the definition and description of the terminal device, please refer to the aforementioned system embodiment and will not be repeated here. The terminal device of this application can achieve quantum encrypted communication with a cloud server deployed with a quantum gateway without relying on dedicated optical fiber or free space communication.

[0203] The present application also provides a cloud server, which is deployed with a quantum gateway. The quantum gateway stores a preset gateway quantum key. The quantum gateway is used to obtain a quantum session key encrypted based on the preset gateway quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain a quantum session key.

[0204] The quantum gateway is also used to conduct quantum encryption communication with the corresponding terminal devices based on quantum session keys, realizing quantum encryption communication between cloud servers and terminal devices; communication tunnels are established between the quantum gateway and the terminal devices, as well as between the quantum gateway and the quantum distribution server, based on the device security communication protocol.

[0205] Specifically, for the definition and description of the quantum gateway, please refer to the aforementioned system embodiment and will not be repeated here. The cloud server of this application deploys a quantum gateway, which can realize quantum encrypted communication with terminal devices through the quantum gateway without relying on dedicated optical fiber or free space communication.

[0206] The present application also provides a quantum distribution server, which stores at least one preset terminal quantum key and at least one preset gateway quantum key;

[0207] The quantum distribution server is used to encrypt the quantum session key based on the preset terminal quantum key and send the encrypted quantum session key to the corresponding terminal device; it is also used to encrypt the quantum session key based on the preset gateway quantum key and send the encrypted quantum session key to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

[0208] Specifically, the definition and description of the quantum distribution server can be found in the aforementioned system embodiments and will not be repeated here. The quantum distribution server of this application distributes quantum session keys to terminal devices and quantum gateways respectively without relying on dedicated optical fiber or free-space communication, thereby enabling quantum encryption communication between terminal devices and corresponding cloud servers without relying on dedicated optical fiber or free-space communication.

[0209] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered merely as exemplary, and the true scope and spirit of the present application are indicated by the claims.

[0210] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A communication system based on quantum key, characterized in that: The system includes a terminal device, a quantum gateway, and a quantum distribution server. The quantum gateway is deployed on a cloud server that interacts with the terminal device, and communication tunnels are established between various parts of the system based on a device security communication protocol; wherein, The terminal device is used to obtain a quantum session key encrypted based on a preset terminal quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; The quantum gateway is used to obtain a quantum session key encrypted based on a preset gateway quantum key from the quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key; The terminal device and the quantum gateway are further configured to perform quantum encryption communication based on the corresponding communication tunnel and the quantum session key, thereby enabling data interaction between the terminal device and the cloud server.

2. The system according to claim 1, wherein: The terminal device is specifically used for: Performing a key exchange with the quantum gateway based on a key exchange algorithm to obtain a first session key for a communication tunnel application between the terminal device and the quantum gateway; Sending a key exchange request to the quantum gateway based on the first session key, and receiving key exchange information fed back by the quantum gateway in response to the key exchange request; The key exchange information is used to determine a unique quantum session key; The quantum session key is obtained from the quantum distribution server based on the key exchange information, and the quantum session key is used to replace the first session key to achieve quantum encryption communication with the quantum gateway.

3. The system according to claim 2, characterized in that The quantum gateway is specifically used for: Upon receiving the key exchange request, sending a first acquisition request to the quantum distribution server in response to the key exchange request, and receiving the quantum session key encrypted based on the preset gateway quantum key and the key exchange information fed back by the quantum distribution server; The encrypted quantum session key is decrypted based on the preset gateway quantum key to obtain the quantum session key, and the key exchange information is fed back to the terminal device in response to the key exchange request.

4. The system according to claim 3, characterized in that The quantum gateway is also used to: Before sending the first acquisition request, perform a key exchange with the quantum distribution server based on the key exchange algorithm to obtain a second session key applied in the communication tunnel between the quantum gateway and the quantum distribution server; Sending a first network access request to the quantum distribution server based on the second session key, and receiving a network access status fed back by the quantum distribution server; the network access status is determined based on a preset gateway quantum key corresponding to the quantum gateway; When the network access status indicates successful network access, the second session key is replaced with the preset gateway quantum key, and quantum encryption communication is performed with the quantum distribution server based on the preset gateway quantum key.

5. The system according to any one of claims 2 to 4, characterized in that: The terminal device is specifically used for: Upon receiving the key exchange information, sending a second acquisition request to the quantum distribution server, and receiving the quantum session key encrypted based on the preset terminal quantum key fed back by the quantum distribution server; the second acquisition request carries the key exchange information; The encrypted quantum session key is decrypted based on the preset terminal key to obtain the quantum session key.

6. The system according to claim 5, characterized in that The terminal device is further configured to: Before sending the second acquisition request, perform a key exchange with the quantum distribution server based on the key exchange algorithm to obtain a third session key applied in the communication tunnel between the terminal device and the quantum distribution server; Sending a second network access request to the quantum distribution server based on the third session key, and receiving a network access status fed back by the quantum distribution server; the network access status is determined based on a preset terminal quantum key corresponding to the terminal device; When the network access status indicates successful network access, the third session key is replaced with the preset terminal quantum key, and encrypted communication is performed with the quantum distribution server based on the preset terminal quantum key.

7. The system according to claim 1 or 2, characterized in that The quantum distribution server is specifically used to: Upon receiving a network access request from a target device, obtaining a preset device quantum key from a preset key pool according to a device identity carried in the network access request; the target device is the terminal device or the quantum gateway, the device identity is a device identifier or a gateway identifier, and the preset device quantum key is the preset terminal quantum key or the preset gateway quantum key; In response to the network access request, feeding back to the target device the pre-set key information corresponding to the pre-set device quantum key and the first random number; receiving a second random number fed back by the target device and a first ciphertext generated based on the preset key information and the second random number; The second random number is generated by the target device, the first ciphertext is obtained by the target device encrypting a target value based on a preset device quantum key indicated by the preset key information, and the target value is determined by the first random number and the second random number; When the first ciphertext and the second ciphertext are equal, feeding back to the target device a network access status indicating successful network access; The second ciphertext is obtained by the quantum distribution server encrypting the target value based on the preset device quantum key.

8. The system according to claim 7, characterized in that The target device stores a preset quantum key pool, wherein the preset key information is used to indicate a key starting position and a key length; the target device is specifically configured to: Upon receiving the preset key information and the first random number, obtaining the preset device quantum key from the preset quantum key pool according to the preset key information; generating a second random number, and encrypting the target value based on the preset device quantum key to obtain the first ciphertext; Sending the first ciphertext and the second random number to the quantum distribution server.

9. The system according to claim 1 or 2, characterized in that The terminal device is specifically used for: Encrypting the data to be transmitted based on the quantum session key, and transmitting the encrypted data to be transmitted to the quantum gateway through the corresponding communication tunnel; Accordingly, the quantum gateway is specifically used for: The encrypted data to be transmitted is decrypted based on the quantum session key to obtain the data to be transmitted, thereby realizing data interaction between the terminal device and the cloud server.

10. The system according to claim 1 or 2, characterized in that The terminal device is further configured to: Before sending the key exchange request to the quantum gateway, sending a key suite negotiation request to the quantum gateway; receiving a key suite negotiation response fed back by the quantum gateway; When the quantum gateway supports quantum keys, the key suite negotiation response is used to indicate support for quantum keys.

11. A communication method based on quantum key, characterized in that: Applied to a terminal device, the terminal device stores a preset terminal quantum key, and the terminal device is used to interact with a corresponding cloud server; the method includes: Obtaining a quantum session key encrypted based on the preset terminal quantum key from a quantum distribution server, and decrypting the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; the terminal device establishes a communication tunnel with the quantum distribution server based on a device secure communication protocol; Based on the quantum session key, quantum encryption communication is performed with the quantum gateway deployed on the cloud server to achieve quantum encryption communication with the cloud server; the terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

12. A communication method based on quantum key, characterized in that: Applied to a cloud server, the cloud server is used to interact with corresponding terminal devices; The cloud server is deployed with a quantum gateway, and the quantum gateway stores a preset gateway quantum key; the method includes: Based on the quantum gateway, obtaining a quantum session key encrypted based on the preset gateway quantum key from a quantum distribution server, and decrypting the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key; Through the quantum gateway, quantum encryption communication is performed with the terminal device based on the quantum session key to achieve quantum encryption communication with the terminal device; communication tunnels are established between the quantum gateway and the terminal device, as well as between the quantum gateway and the quantum distribution server based on the device security communication protocol.

13. A communication method based on quantum key, characterized in that: Applied to a quantum distribution server, the quantum distribution server stores at least one preset terminal quantum key and at least one preset gateway quantum key; the method comprises: Encrypting a quantum session key based on the preset terminal quantum key, and sending the encrypted quantum session key to the corresponding terminal device; The quantum session key is encrypted based on the preset gateway quantum key, and the encrypted quantum session key is sent to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

14. A terminal device, characterized in that: The terminal device stores a preset terminal quantum key, and is used to obtain a quantum session key encrypted based on the preset terminal quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset terminal quantum key to obtain the quantum session key; The terminal device establishes a communication tunnel with the quantum distribution server based on a device security communication protocol; The terminal device is further configured to perform quantum encryption communication with a quantum gateway deployed on a corresponding cloud server based on the quantum session key, thereby achieving quantum encryption communication with the cloud server; The terminal device establishes a communication tunnel with the quantum gateway based on the device security communication protocol.

15. A cloud server, characterized in that: The cloud server is deployed with a quantum gateway, which stores a preset gateway quantum key. The quantum gateway is used to obtain a quantum session key encrypted based on the preset gateway quantum key from a quantum distribution server, and decrypt the encrypted quantum session key based on the preset gateway quantum key to obtain the quantum session key; The quantum gateway is further configured to perform quantum encryption communication with the corresponding terminal device based on the quantum session key, thereby realizing quantum encryption communication between the cloud server and the terminal device; Communication tunnels are established between the quantum gateway and the terminal device, as well as between the quantum gateway and the quantum distribution server, based on a device security communication protocol.

16. A quantum distribution server, characterized in that The quantum distribution server stores at least one preset terminal quantum key and at least one preset gateway quantum key; The quantum distribution server is used to encrypt the quantum session key based on the preset terminal quantum key and send the encrypted quantum session key to the corresponding terminal device; it is also used to encrypt the quantum session key based on the preset gateway quantum key and send the encrypted quantum session key to the corresponding quantum gateway, so that the terminal device and the quantum gateway can realize quantum encryption communication based on the quantum session key; the quantum distribution server and the terminal device, as well as the quantum distribution server and the quantum gateway, all establish communication tunnels based on the device security communication protocol.

Citation Information

Patent Citations

  • ERP networking monitoring system based on quantum key encryption and application method thereof

    CN111953492A

  • Vehicle cloud security communication method and system

    CN117119449A

  • Data interaction method based on quantum session key, electronic equipment and medium

    CN117997522A

  • Method and system for communication between terminal and cloud server

    CN119449427A