Quantum secure encryption system and method based on a rail vehicle

By using quantum-secure encryption routers and quantum key distribution networks in rail vehicles, the problem of insufficient data transmission security of traditional Ethernet switches has been solved, achieving secure encryption and decryption of data transmission and reliable communication.

CN120582774BActive Publication Date: 2026-05-05CRRC TANGSHAN CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CRRC TANGSHAN CO LTD
Filing Date
2025-05-19
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Traditional Ethernet switches pose a risk of data tampering and attack during data transmission in rail vehicles, and cannot ensure the security of transmitted data.

Method used

We replace Ethernet switches with quantum-secure encryption routers and build a point-to-many quantum key distribution network based on a star network structure. We use quantum keys to negotiate key agreements, obtain session keys to encrypt and decrypt data, and ensure that a different session key is used for each communication.

Benefits of technology

It improves the security of data transmission in rail vehicles, prevents data tampering and attacks, and enhances the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582774B_ABST
    Figure CN120582774B_ABST
Patent Text Reader

Abstract

This application provides a quantum-secure encryption system and method based on rail vehicles. The system includes: a train head server and multiple carriage servers; the train head server deploys a central server, including a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server deploys a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server; the quantum key distribution device transmitter generates a quantum key and distributes it to each quantum key distribution device receiver; when a single-vehicle server communicates with the central server, it negotiates a session key based on the quantum keys on each second quantum-secure encryption router; each second quantum-secure encryption router uses the session key to encrypt the plaintext to be transmitted and sends the ciphertext to the first quantum-secure encryption router. The first quantum-secure encryption router uses the session key to decrypt the ciphertext to obtain the plaintext, completing the communication. This improves the security of transmitted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of rail vehicle technology, and in particular to a quantum-secure encryption system and method based on rail vehicles. Background Technology

[0002] With the development of automation and intelligence in rail transit, the cybersecurity risks it faces have increased significantly. As a critical infrastructure, the security of rail transit networks is crucial to the normal operation of rail vehicles and the safety of passengers. Ensuring the security of data transmitted by rail vehicles can significantly reduce cybersecurity risks.

[0003] Currently, in related technologies, rail vehicles transmit data via traditional Ethernet switches. An independent virtual local area network (VLAN) is set up for the rail vehicle's Wi-Fi system using the in-vehicle Ethernet bus, isolated from other ports on the rail vehicle. This ensures that passengers' internet data accessing the Wi-Fi system is completely isolated from the rail vehicle's data. Furthermore, access control is implemented through firewalls and access lists to prevent network attacks.

[0004] However, traditional Ethernet switches are at risk of data tampering and attacks during data transmission, and cannot guarantee the security of transmitted data. Summary of the Invention

[0005] This application provides a quantum-secure encryption system and method based on rail vehicles to ensure the security of transmitted data.

[0006] In a first aspect, embodiments of this application provide a quantum-secure encryption system based on a rail vehicle, comprising: a train head server and multiple carriage servers; wherein the train head server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server;

[0007] The quantum key distribution device (QKD) generates a quantum key at its transmitter and distributes it to the receivers of each QKD via a quantum channel. When the single-vehicle server at each carriage service terminal communicates with the central server at the head of the train, the following steps are performed: Each second quantum-secure encryption router obtains a quantum key from the receiver of each QKD and sends the quantum key to the first quantum-secure encryption router; Each second quantum-secure encryption router and the first quantum-secure encryption router negotiate a key based on the quantum key through a quantum negotiation channel to obtain a session key; the session key includes a key block identifier and an offset; Each second quantum-secure encryption router encrypts the plaintext to be transmitted based on the session key to generate ciphertext and sends the ciphertext to the first quantum-secure encryption router; The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and the offset; If the verification is successful, the ciphertext is decrypted based on the session key to obtain the plaintext, thus completing the communication.

[0008] In one possible implementation, the session key includes a first session key and a second session key, wherein the first session key and the second session key are identical. Accordingly, each second quantum-secure encryption router and the first quantum-secure encryption router, through a quantum negotiation channel, negotiates a key based on the quantum key to obtain the session key. This includes: each second quantum-secure encryption router and the first quantum-secure encryption router negotiating a block-splitting algorithm in the quantum negotiation channel; the first quantum-secure encryption router using the block-splitting algorithm to generate a first shared key pool based on the quantum key; each second quantum-secure encryption router using the block-splitting algorithm to generate a second shared key pool based on the quantum key; wherein the second shared key pool is identical to the first shared key pool; each second quantum-secure encryption router sending a session key request to the first quantum-secure encryption router; the first quantum-secure encryption router responding to the session key request negotiating a key block identifier and offset with each second quantum-secure encryption router through the quantum negotiation channel; the first quantum-secure encryption router obtaining a first session key from the first shared key pool based on the key block identifier and offset; and each second quantum-secure encryption router obtaining a second session key from the second shared key pool based on the key block identifier and offset.

[0009] In one possible implementation, the first quantum-secure encryption router uses a block-splitting algorithm to generate a first shared key pool based on the quantum key, including: the first quantum-secure encryption router uses a block-splitting algorithm to divide the quantum key into multiple key blocks; the first quantum-secure encryption router encrypts and saves each key block to generate the first shared key pool.

[0010] In one possible implementation, the ciphertext carries a message code; the message code is generated by each of the second quantum-secure encryption routers using a cryptographic algorithm based on the second session key and the ciphertext; correspondingly, the first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset, including: the first quantum-secure encryption router re-obtaining the first session key from the first shared key pool based on the key block identifier and offset; the first quantum-secure encryption router generating a verification message code using the same cryptographic algorithm based on the first session key and the ciphertext; the first quantum-secure encryption router determining whether the verification message code and the message code are the same; if the first quantum-secure encryption router verifies that the message code and the message code are the same, the verification passes.

[0011] In one possible implementation, the method further includes the following steps during the process of each second quantum-secure encryption router sending a quantum key to the first quantum-secure encryption router: each second quantum-secure encryption router and the first quantum-secure encryption router determine whether there is interference in the quantum state; if each second quantum-secure encryption router and the first quantum-secure encryption router determine that there is interference in the quantum state, they notify the transmitter of the quantum key distribution device to suspend the distribution of the quantum key; the first quantum-secure encryption router reinitializes the quantum channel; the transmitter of the quantum key distribution device regenerates the quantum key and distributes the regenerated quantum key to the receiver of each quantum key distribution device through the initialized quantum channel.

[0012] In one possible implementation, after determining whether interference exists in the quantum state, the method further includes: if it is determined that no interference exists in the quantum state, then determining whether the usage time of the quantum key exceeds a preset time threshold, or / and whether the amount of plaintext data to be transmitted exceeds a preset data amount threshold; if it is determined that the usage time of the quantum key exceeds the preset time threshold, or / and the amount of plaintext data to be transmitted exceeds the preset data amount threshold, then sending a quantum key replacement request to the transmitter of the quantum key distribution device; the transmitter of the quantum key distribution device responds to the quantum key replacement request, regenerates the quantum key, and distributes the quantum key to the receivers of each quantum key distribution device through the quantum channel.

[0013] In one possible implementation, the method further includes: when the vehicle server at each carriage service terminal communicates with the central server at the head of the train, each second quantum-secure encryption router checks whether a session key exists; if each second quantum-secure encryption router checks that a session key exists, it does not perform key negotiation, but encrypts the plaintext to be transmitted according to the session key to generate ciphertext, and sends the ciphertext to the first quantum-secure encryption router; the first quantum-secure encryption router verifies the ciphertext according to the key block identifier and offset; if the verification is successful, it decrypts the ciphertext according to the session key to obtain the plaintext, thereby completing the communication.

[0014] Secondly, embodiments of this application provide a quantum-secure encryption method based on rail vehicles, applied to a quantum-secure encryption system based on rail vehicles. The system includes: a head server and multiple carriage servers; wherein the head server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server.

[0015] A quantum-secure encryption method based on rail vehicles includes: a quantum key distribution device (QKD) generates a quantum key and distributes it to each QKD receiver via a quantum channel; when the single-vehicle server at each carriage server communicates with the central server at the train head server, the following steps are performed: each second quantum-secure encryption router obtains a quantum key from each QKD receiver and sends it to a first quantum-secure encryption router; each second QKD router and the first QKD router negotiate a key using a quantum negotiation channel to obtain a session key; the session key includes a key block identifier and an offset; each second QKD router encrypts the plaintext to be transmitted using the session key to generate ciphertext and sends it to the first QKD router; the first QKD router verifies the ciphertext using the key block identifier and the offset; if the verification is successful, the ciphertext is decrypted using the session key to obtain the plaintext, thus completing the communication.

[0016] In one possible implementation, the session key includes a first session key and a second session key, wherein the first session key and the second session key are identical. Accordingly, each second quantum-secure encryption router and the first quantum-secure encryption router, through a quantum negotiation channel, negotiates a key based on the quantum key to obtain the session key, including: each second quantum-secure encryption router and the first quantum-secure encryption router negotiating a block-splitting algorithm in the quantum negotiation channel; the first quantum-secure encryption router using the block-splitting algorithm generates a first shared key pool based on the quantum key; each second quantum-secure encryption router using the block-splitting algorithm generates a second shared key pool based on the quantum key; wherein the second shared key pool is identical to the first shared key pool; each second quantum-secure encryption router sends a session key request to the first quantum-secure encryption router; the first quantum-secure encryption router responds to the session key request and negotiates key block identifiers and offsets with each second quantum-secure encryption router through the quantum negotiation channel; the first quantum-secure encryption router obtains a first session key from the first shared key pool based on the key block identifier and offset; each second quantum-secure encryption router obtains a second session key from the second shared key pool based on the key block identifier and offset.

[0017] In one possible implementation, the first quantum-secure encryption router uses a block-splitting algorithm to generate a first shared key pool based on the quantum key, including: the first quantum-secure encryption router uses a block-splitting algorithm to divide the quantum key into multiple key blocks; the first quantum-secure encryption router encrypts and saves each key block to generate the first shared key pool.

[0018] The quantum-secure encryption system and method based on rail vehicles provided in this application involves a quantum key distribution device (QKD) generating quantum keys and distributing them to the receiving ends of each QKD. When the single-vehicle server at each carriage server communicates with the central server at the train head server, each second QKD router and the first QKD router negotiate a session key based on the quantum keys stored on the second QKD router side. The session key carries a key block identifier and an offset. Each second QKD router encrypts the plaintext to be transmitted according to the session key and sends the ciphertext to the first QKD router. The first QKD router verifies the ciphertext based on the key block identifier and offset. After successful verification, it decrypts the ciphertext using the session key to obtain the plaintext, completing the communication. By building a point-to-many quantum key distribution network based on a star network structure, replacing Ethernet switches with quantum-secure encryption routers for encryption and decryption of transmitted data, the security of transmitted data is improved. Furthermore, when the two parties communicate, key negotiation is performed based on quantum key distribution. By negotiating the key block identifier and offset, a session key is obtained, which ensures that a different session key is used for each communication, thereby further improving the security of transmitted data. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0020] Figure 1 A schematic diagram of the structure of a quantum-secure encryption system based on a rail vehicle provided in an embodiment of this application;

[0021] Figure 2 This is a communication diagram of a rail vehicle provided in an embodiment of this application;

[0022] Figure 3 This is a flowchart illustrating a quantum-secure encryption method based on rail vehicles, provided in an embodiment of this application.

[0023] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0024] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0025] With the development of automation and intelligence in rail transit, the cybersecurity risks it faces have increased significantly. As a critical infrastructure, the security of rail transit networks is crucial to the normal operation of rail vehicles and the safety of passengers. Ensuring the security of data transmission in rail vehicles can significantly reduce cybersecurity risks. Currently, related technologies use traditional Ethernet switches for data transmission in rail vehicles, utilizing the in-vehicle Ethernet bus to set up an independent virtual local area network (VLAN) for the Wi-Fi system, isolating it from other ports on the rail vehicle. This ensures that passengers' internet access data is completely isolated from the rail vehicle's data, and access control is implemented through firewalls and access lists to prevent network attacks. However, traditional Ethernet switches are susceptible to data tampering and attacks during data transmission, and cannot guarantee the security of transmitted data.

[0026] To address the aforementioned technical problems, this application proposes the following technical concept: Considering the risk of data tampering and attack during data transmission with traditional Ethernet switches, the inventors conceived of replacing Ethernet switches with quantum-secure encryption routers to encrypt and decrypt transmitted data. Furthermore, a point-to-many quantum key distribution network is established to distribute quantum keys. When the communicating parties communicate, key negotiation is performed based on the quantum key. By negotiating the key block identifier and offset, a session key is obtained, ensuring that a different session key is used for each communication. Using the session key to encrypt and decrypt transmitted data improves the security of the transmitted data. Specifically, the quantum key distribution device's transmitter generates the quantum key and distributes it to the receivers of each quantum key distribution device. When the vehicle server at each carriage service end communicates with the central server at the head of the train, each second quantum-secure encryption router and the first quantum-secure encryption router negotiate key negotiations based on the quantum key on the second quantum-secure encryption router side to obtain a session key; the session key carries the key block identifier and offset. Each second quantum-secure encryption router encrypts the plaintext to be transmitted according to the session key and sends the ciphertext to the first quantum-secure encryption router. The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset. Upon successful verification, it decrypts the ciphertext using the session key to obtain the plaintext, thus completing the communication. This improves the security of transmitted data.

[0027] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0028] refer to Figure 1 and Figure 2 , Figure 1 A schematic diagram of the structure of a quantum-secure encryption system based on a rail vehicle provided in an embodiment of this application; Figure 2 This is a communication diagram of a rail vehicle provided in an embodiment of this application. The quantum-secure encryption system based on the rail vehicle specifically includes: a train head server and multiple carriage servers; wherein the train head server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server.

[0029] In this embodiment, the quantum key distribution device transmitter and the first quantum secure encryption router are deployed in the quantum secure encryption management center of the central server. The quantum secure encryption management center manages and monitors the entire system throughout its lifecycle, and is responsible for key generation, key distribution and usage rules, and key updates. The quantum secure encryption management center also deploys a key distribution network management host, which is used to implement functions such as quantum device management, quantum key generation control, and quantum key routing control. The key distribution network management host also has a key caching function, so the quantum secure encryption router can continue to obtain keys through the key cache pool, and will not be unable to encrypt data due to quantum channel interruption. The quantum key distribution device transmitter is used for quantum key generation and distribution; the first quantum secure encryption router is used for data encryption and decryption processing and key negotiation.

[0030] Among them, the quantum key distribution device transmitter and the quantum key distribution device receiver belong to the quantum key distribution layer; the first quantum secure encryption router and the second quantum secure encryption router belong to the data encryption and decryption layer; and the bicycle server belongs to the business layer.

[0031] The transmitter of a quantum key distribution device generates a quantum key and distributes the quantum key to the receivers of each quantum key distribution device through a quantum channel.

[0032] In this embodiment, the quantum key distribution device uses a quantum random number generator as the quantum key source to randomly generate quantum keys. Quantum random numbers are generated based on the uncertainty principle of quantum mechanics, possessing randomness and being unpredictable. This randomness makes the generated quantum keys difficult to deduce, thus providing a highly secure foundation for encrypted communication.

[0033] In this embodiment, quantum key distribution follows the BB84 protocol and employs a star network structure. In this structure, the quantum key distribution device transmitter acts as the central node, and the quantum key distribution devices receivers at multiple service stations act as branch nodes, connected to the central node. The central node is responsible for distributing quantum keys to each branch node. This structure centralizes quantum key management and distribution, facilitating control and monitoring, and also improving distribution efficiency.

[0034] In this embodiment, the transmitter and receiver of the quantum key distribution device utilize quantum entanglement state preparation and measurement techniques to transmit quantum keys. Two entangled quantum particles, regardless of their distance, will have their states changed when one quantum's state changes. By preparing and measuring this entangled state, the transmitter and receiver can achieve seamless quantum key transmission. A quantum channel is established between the transmitter and receiver, ensuring absolute security of key transmission and thus enabling point-to-many quantum key distribution.

[0035] When the individual vehicle server at each carriage server communicates with the central server at the locomotive server, the following steps are performed:

[0036] S1: Each second quantum-secure encryption router obtains the quantum key from the receiving end of each quantum key distribution device and sends the quantum key to the first quantum-secure encryption router.

[0037] S2: Each of the second quantum-secure encryption routers and the first quantum-secure encryption routers negotiates a key based on the quantum key through a quantum negotiation channel to obtain a session key; wherein the session key includes a key block identifier and an offset.

[0038] In this embodiment, the session key includes a first session key and a second session key, wherein the first session key and the second session key are the same.

[0039] In this embodiment, the second quantum-secure encryption routers and the first quantum-secure encryption routers communicate securely for key negotiation via a quantum negotiation channel. The quantum negotiation channel utilizes the principles of quantum mechanics to ensure communication security.

[0040] In this embodiment, before the second quantum-secure encryption router and the first quantum-secure encryption router conduct key negotiation, calibration operations such as polarization basis alignment and time synchronization are performed. Polarization basis alignment ensures that the measurement reference of the quantum state is consistent between the two communicating parties during communication, thus enabling accurate reception and processing of the quantum key. Time synchronization ensures the consistency of time between the two communicating parties during communication, avoiding communication errors caused by time differences. In addition, the two communicating parties also need to verify their identities through digital signatures based on the SM2 elliptic curve public-key cryptography algorithm.

[0041] Specifically, the steps to obtain the session key include Sa~Sg:

[0042] Sa: Each of the second quantum-secure encryption routers and the first quantum-secure encryption router negotiates the block division algorithm in the quantum negotiation channel.

[0043] In this embodiment, the block partitioning algorithm is pre-installed in the read-only firmware of the security chips of each second quantum-secure encryption router and the first quantum-secure encryption router. Each second quantum-secure encryption router and the first quantum-secure encryption router negotiates the block partitioning algorithm and follows the same algorithm for the quantum key. For example, each block is 128 bits, such as Block 0 being bits 0-127, Block 1 being bits 128-256, etc.

[0044] Sb: The first quantum-secure encryption router uses a block-based algorithm to generate the first shared key pool based on the quantum key.

[0045] Specifically, the first quantum-secure encryption router uses a block-splitting algorithm to divide the quantum key into multiple key blocks; the first quantum-secure encryption router encrypts and saves each key block to generate a first shared key pool.

[0046] In this embodiment, a block-based algorithm is used to divide the quantum key into multiple fixed-length key blocks. This fixed block-based method ensures consistency and operability for both parties when processing the quantum key. Each key block is encrypted using the hardware key of a secure chip, and the encrypted key is stored in a tamper-proof secure chip to generate the first shared key pool. The hardware key of the secure chip has high security, and its tamper-proof feature ensures that the key will not be illegally modified during storage, further enhancing the key's security.

[0047] Sc: Each second quantum-secure encryption router uses a block-based algorithm to generate a second shared key pool based on the quantum key; the second shared key pool is the same as the first shared key pool.

[0048] Specifically, each second quantum-safe encryption router uses a block-splitting algorithm to divide the quantum key into multiple key blocks; each second quantum-safe encryption router encrypts and saves each key block to generate a second shared key pool.

[0049] Sd: Each second quantum-secure encryption router sends a session key request to the first quantum-secure encryption router.

[0050] In this embodiment, the session key request carries a signature authentication to ensure the legitimacy and authenticity of the session key request.

[0051] Se: The first quantum secure encryption router responds to the session key request and negotiates the key block identifier and offset with each of the second quantum secure encryption routers through the quantum negotiation channel.

[0052] In this embodiment, after receiving the session key request, the first quantum secure encryption router selects an unused key block identifier, such as Block 1, from the first shared key pool and specifies an offset, such as offset=1, that is, it uses the key block in Block 1 starting from the first bit.

[0053] Sf: The first quantum-secure encryption router obtains the first session key from the first shared key pool based on the key block identifier and offset.

[0054] In this embodiment, the first quantum secure encryption router extracts the corresponding key block ciphertext from the first shared key pool based on the key block identifier and offset, and obtains the first session key by decrypting it with the hardware key of the security chip.

[0055] Sg: Each second quantum-secure encryption router obtains the second session key from the second shared key pool based on the key block identifier and offset.

[0056] In this embodiment, each second quantum-secure encryption router extracts the corresponding key block ciphertext from the second shared key pool based on the key block identifier and offset, and decrypts it using the hardware key of the security chip to obtain the second session key.

[0057] In this embodiment, the second quantum-secure encryption router and the first quantum-secure encryption router derive a one-time session key based on the key block identifier and offset each time they communicate. The use of the one-time session key increases the security of the communication.

[0058] S3: Each second quantum-secure encryption router encrypts the plaintext to be transmitted according to the session key, generates ciphertext, and sends the ciphertext to the first quantum-secure encryption router.

[0059] In this embodiment, the plaintext to be transmitted is sent by the service layer's bicycle server to each of the second quantum-secure encryption routers via a classical channel.

[0060] In this embodiment, each second quantum-secure encryption router uses a cryptographic algorithm combined with IPSec VPN technology to encrypt the plaintext to be transmitted based on the session key, generating ciphertext. Optionally, the cryptographic algorithm can be SM4.

[0061] S4: The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset; if the verification is successful, it decrypts the ciphertext based on the session key to obtain the plaintext, thus completing the communication.

[0062] In this embodiment, the ciphertext carries a message code; the message code is generated by each of the second quantum-secure encryption routers using a cryptographic algorithm based on the second session key and the ciphertext.

[0063] Specifically, the first quantum secure encryption router retrieves the first session key from the first shared key pool based on the key block identifier and offset; the first quantum secure encryption router uses the same cryptographic algorithm to generate a verification message code based on the first session key and ciphertext; the first quantum secure encryption router determines whether the verification message code and the message code are the same; if the first quantum secure encryption router verifies that the verification message code and the message code are the same, the verification is successful.

[0064] Alternatively, the cryptographic algorithm can be SM3.

[0065] In this embodiment, the first quantum-secure encryption router decrypts the ciphertext using the session key to obtain the plaintext, and then transmits the plaintext to be transmitted from the bicycle server to the central server, thus completing the communication.

[0066] Optionally, the first quantum-secure encryption router and each of the second quantum-secure encryption routers can obtain quantum keys through a key cache pool, so that data encryption will not be impossible due to quantum channel interruption.

[0067] In this embodiment, the quantum channel and the quantum negotiation channel are fiber optic channels.

[0068] In this embodiment, the communication process between the individual vehicle servers of each carriage service terminal, the communication process between the individual vehicle servers of each carriage service terminal and the central server of the locomotive service terminal, and the communication process between the central server of the locomotive service terminal and the individual vehicle servers of each carriage service terminal are the same, and will not be described again here.

[0069] In summary, the quantum key distribution (QKD) transmitter generates the quantum key and distributes it to the receivers of each QKD. When the individual vehicle servers at each carriage service end communicate with the central server at the head of the train, each second quantum-secure encryption router negotiates with the first quantum-secure encryption router based on the quantum key stored on the second router side to obtain a session key. The session key carries a key block identifier and an offset. Each second quantum-secure encryption router encrypts the plaintext to be transmitted according to the session key and sends the ciphertext to the first quantum-secure encryption router. The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset. Upon successful verification, it decrypts the ciphertext using the session key to obtain the plaintext, completing the communication. By building a point-to-many quantum key distribution network based on a star network structure, replacing Ethernet switches with quantum-secure encryption routers for encryption and decryption of transmitted data, the security of transmitted data is improved. Furthermore, during communication between the two parties, key negotiation is performed based on the quantum key. By negotiating the key block identifier and offset, a session key is obtained, ensuring that a different session key is used for each communication, further enhancing the security of transmitted data.

[0070] Based on the above embodiments, this embodiment describes the situation of unauthorized interception during communication, as detailed below:

[0071] During the process of each second quantum-secure encryption router sending the quantum key to the first quantum-secure encryption router, the following steps are performed:

[0072] Specifically, this includes steps Sh~Sk:

[0073] Sh: Each second quantum-secure encryption router and the first quantum-secure encryption router determines whether there is interference in the quantum state.

[0074] In this embodiment, the quantum key carries information based on quantum states. Quantum states are highly sensitive to even the smallest disturbances, especially when the quantum key is intercepted and the quantum state is measured, which inevitably alters the quantum state. Each of the second and first quantum-secure encryption routers utilizes the sensitivity of the quantum state to determine whether interference exists.

[0075] Alternatively, the presence of interference in the quantum state can be monitored through methods such as quantum bit error rate detection and entangled state Bell inequality detection.

[0076] Si: If each of the second quantum-secure encryption routers and the first quantum-secure encryption router determines that there is interference in the quantum state, then the quantum key distribution device transmitter is notified to suspend the distribution of quantum keys.

[0077] In this embodiment, when interference is detected, it indicates a potential unauthorized interception of quantum keys. The quantum key distribution equipment transmitter at the quantum security encryption management center is notified to suspend quantum key distribution to prevent further insecure distribution. Simultaneously, warnings are sent to the bicycle servers corresponding to each of the second quantum security encryption routers, as well as the central server corresponding to the first quantum security encryption router, alerting them to the security threat.

[0078] Sg: The first quantum-secure encrypted router reinitializes the quantum channel.

[0079] Sk: The transmitter of the quantum key distribution device regenerates the quantum key and distributes the regenerated quantum key to the receivers of each quantum key distribution device through the initialized quantum channel.

[0080] Optionally, if it is determined that the quantum state is not disturbed, the following steps are performed, specifically including Sl~Sn:

[0081] Sl: If it is determined that there is no interference in the quantum state, then determine whether the usage time of the quantum key exceeds the preset time threshold, or / and whether the amount of plaintext data to be transmitted exceeds the preset data amount threshold.

[0082] Optionally, the preset time threshold can be 15 minutes, and the preset data volume threshold can be 1GB.

[0083] Sm: If it is determined that the usage time of the quantum key exceeds the preset time threshold, or / and the amount of plaintext data to be transmitted exceeds the preset data amount threshold, then a quantum key replacement request is sent to the transmitter of the quantum key distribution device.

[0084] In this embodiment, if the quantum key is used for too long, attackers will have more time to crack and intercept it. Regularly changing the quantum key reduces the chances of attackers cracking and intercepting it within a limited time. When the amount of plaintext data to be transmitted reaches a certain level, changing the quantum key can reduce the risk of a large amount of data being illegally intercepted due to quantum key leakage.

[0085] Sn: The transmitter of the quantum key distribution device responds to the quantum key replacement request, regenerates the quantum key, and distributes the quantum key to the receivers of each quantum key distribution device through the quantum channel.

[0086] In this embodiment, after the quantum key is distributed to the receiving end of each quantum key distribution device, the two communicating parties communicate normally, which will not be described in detail here.

[0087] In summary, during the process of each second quantum-secure encryption router sending the quantum key to the first quantum-secure encryption router, the presence of interference in the quantum state can determine whether there has been unauthorized interception of the quantum key. When interference is detected, the quantum key distribution device transmitter is notified to suspend quantum key distribution to prevent more quantum keys from being distributed insecurely and to avoid greater security risks. The first quantum-secure encryption router reinitializes the quantum channel, the quantum key distribution device transmitter regenerates the quantum key, and distributes the regenerated quantum key to each quantum key distribution device receiver through the initialized quantum channel, ensuring the secure operation of subsequent communications. This further improves the security of transmitted data.

[0088] Based on the above embodiments, this embodiment describes the case where the communicating parties do not perform quantum key negotiation, as detailed below:

[0089] So: When the single-vehicle server at each carriage server communicates with the central server at the head of the train, each second quantum-secure encryption router checks whether a session key exists.

[0090] Sp: If each of the second quantum-secure encryption routers checks for the existence of a session key, it will not perform key negotiation, but will encrypt the plaintext to be transmitted according to the session key, generate ciphertext, and send the ciphertext to the first quantum-secure encryption router.

[0091] In this embodiment, if each second quantum secure encryption router detects the existence of a session key, it means that each second quantum secure encryption router and the first quantum secure encryption router have performed key negotiation and generated a session key, which can be used directly without further key negotiation.

[0092] Sq: The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset; if the verification is successful, it decrypts the ciphertext based on the session key to obtain the plaintext, thus completing the communication.

[0093] Step Sq is the same as the implementation process in the above embodiment, and will not be repeated here.

[0094] In summary, the key negotiation process involves a complex interaction process. Using existing session keys directly can significantly improve communication efficiency and save computing resources.

[0095] Figure 3 This is a flowchart illustrating a quantum-secure encryption method based on rail vehicles, provided in an embodiment of this application. The system, applied to a quantum-secure encryption system based on rail vehicles, includes: a head server and multiple carriage servers; the head server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server. Figure 3 As shown, the method includes:

[0096] S301: The quantum key distribution device transmitter generates a quantum key and distributes the quantum key to the receiving end of each quantum key distribution device through a quantum channel;

[0097] S302: When the individual vehicle server of each carriage communicates with the central server of the locomotive server, the following steps are performed:

[0098] S3021: Each second quantum-secure encryption router obtains the quantum key from the receiving end of each quantum key distribution device and sends the quantum key to the first quantum-secure encryption router.

[0099] S3022: Each of the second quantum-secure encryption routers and the first quantum-secure encryption routers negotiates a key based on the quantum key through a quantum negotiation channel to obtain a session key; wherein the session key includes a key block identifier and an offset.

[0100] In this embodiment, the session key includes a first session key and a second session key, wherein the first session key and the second session key are the same.

[0101] Specifically, step S3022 includes S30221 to S30227:

[0102] S30221: Each of the second quantum-secure encryption routers and the first quantum-secure encryption routers negotiates the block division algorithm in the quantum negotiation channel.

[0103] S30222: The first quantum-secure encryption router uses a block algorithm to generate the first shared key pool based on the quantum key.

[0104] Specifically, the first quantum-secure encryption router uses a block-splitting algorithm to divide the quantum key into multiple key blocks; the first quantum-secure encryption router encrypts and saves each key block to generate a first shared key pool.

[0105] S30223: Each second quantum-secure encryption router uses a block-based algorithm to generate a second shared key pool based on the quantum key; the second shared key pool is the same as the first shared key pool.

[0106] S30224: Each second quantum-secure encryption router sends a session key request to the first quantum-secure encryption router.

[0107] S30225: The first quantum secure encryption router responds to the session key request and negotiates the key block identifier and offset with each of the second quantum secure encryption routers through the quantum negotiation channel.

[0108] S30226: The first quantum-secure encryption router obtains the first session key from the first shared key pool based on the key block identifier and offset.

[0109] S30227: Each second quantum-secure encryption router obtains the second session key from the second shared key pool based on the key block identifier and offset.

[0110] S3023: Each second quantum secure encryption router encrypts the plaintext to be transmitted according to the session key, generates ciphertext, and sends the ciphertext to the first quantum secure encryption router;

[0111] S3024: The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset; if the verification is successful, it decrypts the ciphertext based on the session key to obtain the plaintext, thereby completing the communication.

[0112] In this embodiment, the ciphertext carries a message code; the message code is generated by each of the second quantum-secure encryption routers using a cryptographic algorithm based on the second session key and the ciphertext.

[0113] Specifically, the first quantum secure encryption router retrieves the first session key from the first shared key pool based on the key block identifier and offset; the first quantum secure encryption router uses the same cryptographic algorithm to generate a verification message code based on the first session key and ciphertext; the first quantum secure encryption router determines whether the verification message code and the message code are the same; if the first quantum secure encryption router verifies that the verification message code and the message code are the same, the verification is successful.

[0114] In summary, the quantum key distribution (QKD) transmitter generates the quantum key and distributes it to the receivers of each QKD. When the individual vehicle servers at each carriage service end communicate with the central server at the head of the train, each second quantum-secure encryption router negotiates with the first quantum-secure encryption router based on the quantum key stored on the second router side to obtain a session key. The session key carries a key block identifier and an offset. Each second quantum-secure encryption router encrypts the plaintext to be transmitted according to the session key and sends the ciphertext to the first quantum-secure encryption router. The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset. Upon successful verification, it decrypts the ciphertext using the session key to obtain the plaintext, completing the communication. By building a point-to-many quantum key distribution network based on a star network structure, replacing Ethernet switches with quantum-secure encryption routers for encryption and decryption of transmitted data, the security of transmitted data is improved. Furthermore, during communication between the two parties, key negotiation is performed based on the quantum key. By negotiating the key block identifier and offset, a session key is obtained, ensuring that a different session key is used for each communication, further enhancing the security of transmitted data.

[0115] Based on the above embodiments, this embodiment describes the situation of unauthorized interception during communication, as detailed below:

[0116] During the process of each second quantum-secure encryption router sending the quantum key to the first quantum-secure encryption router, the following steps are performed:

[0117] Specifically, steps S401 to S404 are included:

[0118] S401: Each second quantum-secure encryption router and the first quantum-secure encryption router determines whether there is interference in the quantum state.

[0119] In this embodiment, the quantum key carries information based on quantum states. Quantum states are highly sensitive to even the smallest disturbances, especially when the quantum key is intercepted and the quantum state is measured, which inevitably alters the quantum state. Each of the second and first quantum-secure encryption routers utilizes the sensitivity of the quantum state to determine whether interference exists.

[0120] Alternatively, the presence of interference in the quantum state can be monitored through methods such as quantum bit error rate detection and entangled state Bell inequality detection.

[0121] S402: If each of the second quantum-secure encryption routers and the first quantum-secure encryption router determines that there is interference in the quantum state, then notify the quantum key distribution device transmitter to suspend the distribution of quantum keys.

[0122] In this embodiment, when interference is detected, it indicates a potential unauthorized interception of quantum keys. The quantum key distribution equipment transmitter at the quantum security encryption management center is notified to suspend quantum key distribution to prevent further insecure distribution. Simultaneously, warnings are sent to the bicycle servers corresponding to each of the second quantum security encryption routers, as well as the central server corresponding to the first quantum security encryption router, alerting them to the security threat.

[0123] S403: The first quantum-secure encrypted router reinitializes the quantum channel.

[0124] S404: The transmitter of the quantum key distribution device regenerates the quantum key and distributes the regenerated quantum key to the receivers of each quantum key distribution device through the initialized quantum channel.

[0125] Optionally, if it is determined that there is no interference in the quantum state, the following steps are performed, specifically including S501~S503:

[0126] S501: If it is determined that there is no interference in the quantum state, then determine whether the usage time of the quantum key exceeds the preset time threshold, or / and whether the amount of plaintext data to be transmitted exceeds the preset data amount threshold.

[0127] Optionally, the preset time threshold can be 15 minutes, and the preset data volume threshold can be 1GB.

[0128] S502: If it is determined that the usage time of the quantum key exceeds the preset time threshold, or / and the amount of plaintext data to be transmitted exceeds the preset data amount threshold, then a quantum key replacement request is sent to the transmitter of the quantum key distribution device.

[0129] In this embodiment, if the quantum key is used for too long, attackers will have more time to crack and intercept it. Regularly changing the quantum key reduces the chances of attackers cracking and intercepting it within a limited time. When the amount of plaintext data to be transmitted reaches a certain level, changing the quantum key can reduce the risk of a large amount of data being illegally intercepted due to quantum key leakage.

[0130] S503: The transmitter of the quantum key distribution device responds to the quantum key replacement request, regenerates the quantum key, and distributes the quantum key to the receivers of each quantum key distribution device through the quantum channel.

[0131] In this embodiment, after the quantum key is distributed to the receiving end of each quantum key distribution device, the two communicating parties communicate normally, which will not be described in detail here.

[0132] In summary, during the process of each second quantum-secure encryption router sending the quantum key to the first quantum-secure encryption router, the presence of interference in the quantum state can determine whether there has been unauthorized interception of the quantum key. When interference is detected, the quantum key distribution device transmitter is notified to suspend quantum key distribution to prevent more quantum keys from being distributed insecurely and to avoid greater security risks. The first quantum-secure encryption router reinitializes the quantum channel, the quantum key distribution device transmitter regenerates the quantum key, and distributes the regenerated quantum key to each quantum key distribution device receiver through the initialized quantum channel, ensuring the secure operation of subsequent communications. This further improves the security of transmitted data.

[0133] Based on the above embodiments, this embodiment describes the case where the communicating parties do not perform quantum key negotiation, as detailed below:

[0134] S601: When the single-vehicle server of each carriage server communicates with the central server of the locomotive server, each second quantum-secure encryption router checks whether a session key exists.

[0135] S602: If each of the second quantum-secure encryption routers checks that a session key exists, key negotiation is not performed. Instead, the plaintext to be transmitted is encrypted according to the session key to generate ciphertext, and the ciphertext is sent to the first quantum-secure encryption router.

[0136] In this embodiment, if each second quantum secure encryption router detects the existence of a session key, it means that each second quantum secure encryption router and the first quantum secure encryption router have performed key negotiation and generated a session key, which can be used directly without further key negotiation.

[0137] S603: The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and offset; if the verification is successful, it decrypts the ciphertext based on the session key to obtain the plaintext, thereby completing the communication.

[0138] In summary, the key negotiation process involves a complex interaction process. Using existing session keys directly can significantly improve communication efficiency and save computing resources.

[0139] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A quantum-secure encryption system based on rail vehicles, characterized in that, include: The system includes a locomotive server and multiple carriage servers; wherein the locomotive server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum secure encryption router, and a single-vehicle server. The quantum key distribution device's transmitter generates a quantum key and distributes the quantum key to each quantum key distribution device's receiver via a quantum channel; When the individual vehicle server of each carriage service terminal communicates with the central server of the locomotive service terminal, the following steps are performed: Each second quantum-secure encryption router obtains the quantum key from the receiving end of each quantum key distribution device and sends the quantum key to the first quantum-secure encryption router; The second quantum-secure encryption router and the first quantum-secure encryption router negotiate a key through a quantum negotiation channel based on the quantum key to obtain a session key; The session key includes a key block identifier and an offset; Each of the second quantum-secure encryption routers encrypts the plaintext to be transmitted according to the session key, generates ciphertext, and sends the ciphertext to the first quantum-secure encryption router; The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and the offset; If the verification is successful, the ciphertext is decrypted using the session key to obtain the plaintext, thus completing the communication. The session key includes a first session key and a second session key, wherein the first session key and the second session key are the same; Accordingly, each of the second quantum-secure encryption routers and the first quantum-secure encryption routers, through a quantum negotiation channel, performs key negotiation based on the quantum key to obtain a session key, including: The second quantum-secure encryption router and the first quantum-secure encryption router negotiate the block division algorithm in the quantum negotiation channel; The first quantum-secure encryption router uses the block-sharing algorithm to generate a first shared key pool based on the quantum key; Each of the second quantum-secure encryption routers uses the block-sharing algorithm to generate a second shared key pool based on the quantum key; wherein the second shared key pool is the same as the first shared key pool. Each of the second quantum-secure encryption routers sends a session key request to the first quantum-secure encryption router; The first quantum-secure encryption router responds to the session key request by negotiating the key block identifier and offset with each of the second quantum-secure encryption routers through a quantum negotiation channel; The first quantum-secure encryption router obtains the first session key from the first shared key pool based on the key block identifier and the offset; Each of the second quantum-secure encryption routers obtains a second session key from the second shared key pool based on the key block identifier and the offset.

2. The system according to claim 1, characterized in that, The first quantum-secure encryption router uses the block-sharing algorithm to generate a first shared key pool based on the quantum key, including: The first quantum-secure encryption router uses the block-splitting algorithm to divide the quantum key into multiple key blocks; The first quantum-secure encryption router encrypts and saves each key block to generate a first shared key pool.

3. The system according to claim 1 or 2, characterized in that, The ciphertext carries a message code; the message code is generated by each of the second quantum-secure encryption routers using a cryptographic algorithm, based on the second session key and the ciphertext. Accordingly, the first quantum-secure encryption router verifies the ciphertext based on the key block identifier and the offset, including: The first quantum-secure encryption router retrieves the first session key from the first shared key pool based on the key block identifier and the offset; The first quantum-secure encryption router uses the same cryptographic algorithm to generate a verification message code based on the first session key and the ciphertext; The first quantum-secure encryption router determines whether the verification message code and the message code are the same; If the verification message code and the message code of the first quantum-secure encryption router are the same, then the verification is successful.

4. The system according to claim 1, characterized in that, Also includes: During the process of each second quantum-secure encryption router sending the quantum key to the first quantum-secure encryption router, the following steps are performed: Each of the second quantum-secure encryption routers and the first quantum-secure encryption router determines whether there is interference in the quantum state; If each of the second quantum-secure encryption routers and the first quantum-secure encryption router determines that there is interference in the quantum state, they notify the transmitter of the quantum key distribution device to suspend the distribution of quantum keys. The first quantum-secure encryption router reinitializes the quantum channel; The quantum key distribution device transmitter regenerates the quantum key and distributes the regenerated quantum key to the receiving end of each quantum key distribution device through the initialized quantum channel.

5. The system according to claim 4, characterized in that, After determining whether interference exists in the quantum state, the method further includes: If it is determined that there is no interference in the quantum state, then it is determined whether the usage time of the quantum key exceeds a preset time threshold, or / and whether the amount of plaintext data to be transmitted exceeds a preset data amount threshold. If it is determined that the usage time of the quantum key exceeds the preset time threshold, or / and the amount of plaintext data to be transmitted exceeds the preset data amount threshold, then a quantum key replacement request is sent to the transmitter of the quantum key distribution device. The transmitter of the quantum key distribution device responds to the quantum key replacement request, regenerates the quantum key, and distributes the quantum key to the receiver of each quantum key distribution device through the quantum channel.

6. The system according to claim 1, characterized in that, Also includes: When the single-vehicle server of each carriage service terminal communicates with the central server of the locomotive service terminal, each second quantum-secure encryption router checks whether a session key exists; If each of the second quantum-secure encryption routers checks that a session key exists, it will not perform key negotiation, but will encrypt the plaintext to be transmitted according to the session key to generate ciphertext, and send the ciphertext to the first quantum-secure encryption router. The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and the offset; If the verification is successful, the ciphertext is decrypted using the session key to obtain the plaintext, thus completing the communication.

7. A quantum-secure encryption method based on rail vehicles, characterized in that, The quantum-secure encryption system based on rail vehicles as described in any one of claims 1-6 includes: a head server and multiple carriage servers; wherein the head server is equipped with a central server, which includes a quantum key distribution device transmitter and a first quantum-secure encryption router; each carriage server is equipped with a quantum key distribution device receiver, a second quantum-secure encryption router, and a single-vehicle server; The method includes: The quantum key distribution device's transmitter generates a quantum key and distributes the quantum key to each quantum key distribution device's receiver via a quantum channel; When the individual vehicle server of each carriage service terminal communicates with the central server of the locomotive service terminal, the following steps are performed: Each second quantum-secure encryption router obtains the quantum key from the receiving end of each quantum key distribution device and sends the quantum key to the first quantum-secure encryption router; Each of the second quantum-secure encryption routers and the first quantum-secure encryption routers performs key negotiation based on the quantum key through a quantum negotiation channel to obtain a session key; wherein the session key includes a key block identifier and an offset; Each of the second quantum-secure encryption routers encrypts the plaintext to be transmitted according to the session key, generates ciphertext, and sends the ciphertext to the first quantum-secure encryption router; The first quantum-secure encryption router verifies the ciphertext based on the key block identifier and the offset; if the verification is successful, it decrypts the ciphertext based on the session key to obtain the plaintext, thereby completing the communication. The session key includes a first session key and a second session key, wherein the first session key and the second session key are the same; Accordingly, each of the second quantum-secure encryption routers and the first quantum-secure encryption routers, through a quantum negotiation channel, performs key negotiation based on the quantum key to obtain a session key, including: The second quantum-secure encryption router and the first quantum-secure encryption router negotiate the block division algorithm in the quantum negotiation channel; The first quantum-secure encryption router uses the block-sharing algorithm to generate a first shared key pool based on the quantum key; Each of the second quantum-secure encryption routers uses the block-sharing algorithm to generate a second shared key pool based on the quantum key; wherein the second shared key pool is the same as the first shared key pool. Each of the second quantum-secure encryption routers sends a session key request to the first quantum-secure encryption router; The first quantum-secure encryption router responds to the session key request by negotiating the key block identifier and offset with each of the second quantum-secure encryption routers through a quantum negotiation channel; The first quantum-secure encryption router obtains the first session key from the first shared key pool based on the key block identifier and the offset; Each of the second quantum-secure encryption routers obtains a second session key from the second shared key pool based on the key block identifier and the offset.

8. The method according to claim 7, characterized in that, The first quantum-secure encryption router uses the block-sharing algorithm to generate a first shared key pool based on the quantum key, including: The first quantum-secure encryption router uses the block-splitting algorithm to divide the quantum key into multiple key blocks; The first quantum-secure encryption router encrypts and saves each key block to generate a first shared key pool.