Quantum security communication method for satellite communication, electronic equipment and medium

By combining QUIC and DTLS protocols and introducing anti-quantum encryption algorithms, the problems of high latency and high packet loss rate in satellite communications are solved, efficient and secure communication in quantum computing environment is achieved, and flexible switching of encryption algorithms is supported.

CN120582784AActive Publication Date: 2025-09-02ZHEJIANG LAB
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511072546.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-09-02
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

The high latency and high packet loss rate in satellite communication environments lead to poor performance in security and reliability of traditional TLS protocols and QUIC protocols. Traditional encryption algorithms are easily cracked under the threat of quantum computing, and the encryption algorithm switching is inflexible.

Method used

Combining the QUIC and DTLS protocols, the quantum encryption algorithms MLKEM and MLDSA are introduced to implement the low latency and high throughput of the QUIC protocol and the security guarantee of DTLS, and the flexible switching of the encryption algorithm and anti-quantum security are achieved.

Benefits of technology

It improves the security and reliability of satellite communications, ensures the efficiency of data transmission and the security of quantum computing resistance in high packet loss and high latency environments, and reduces maintenance costs and complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582784A_ABST
    Figure CN120582784A_ABST
Patent Text Reader

Abstract

The invention discloses a satellite communication-oriented quantum security communication method, electronic equipment and a medium, and the method comprises the steps that a satellite client sends a handshake message to a ground server based on a QUIC protocol, and the ground server responds to the handshake message so as to complete handshake. And the satellite client sends a handshake message to the ground server based on the DTLS protocol, and the ground server responds to the handshake message, so that key exchange between the satellite client and the ground server is completed, and a shared key is generated. And the satellite client encrypts transmission data through the negotiated anti-quantum encryption algorithm and the shared key and then uploads the transmission data to the ground server. The ground server decrypts the received transmission data based on the DTLS protocol and verifies the data; and if the transmission data is not tampered and verification is passed, the ground server returns an integrity verification result to the satellite client based on the DTLS protocol. And after the satellite client and the ground server complete exchange of transmission data, connection is terminated through a QUIC protocol and a DTLS protocol, so that the integrity and security of communication are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security, and in particular relates to a quantum secure communication method, electronic equipment, and medium for satellite communication. Background Art

[0002] With the widespread adoption of satellite communications, especially low-orbit satellite communications and satellite-to-ground communications, the security and reliability of data transmission are facing increasing challenges. Existing satellite communications systems face high latency, high packet loss rates, and limited bandwidth resources, and traditional TLS protocols are no longer able to effectively meet these requirements.

[0003] Traditional secure communication protocols, such as the TCP-based TLS (Transport Layer Security) protocol, although they perform well in traditional networks, have some obvious limitations in satellite communications. First, the TLS protocol relies on the TCP protocol, which does not perform well in satellite communication environments. The main reason is that TCP's reliability mechanism is not suitable for handling the high packet loss, high latency, and unstable network conditions common in satellite communications. For this reason, the QUIC protocol came into being. QUIC is a UDP-based transport protocol that is designed to be more suitable for high-latency, packet loss, and unstable network environments. The QUIC protocol significantly reduces the delay in connection establishment and performance loss during transmission through multiplexing and non-blocking connection management. Therefore, it is considered an ideal transport protocol for satellite communications.

[0004] However, the security of the QUIC protocol relies on TLS 1.3. While TLS is relatively mature in today's environments, it's still not suitable for unstable environments with high latency and high packet loss. To address this issue, DTLS (Datagram Transport Layer Security), a security protocol designed specifically for UDP, is more adaptable to UDP than TLS and can better cope with high packet loss and high latency environments. Therefore, for satellite communications, the DTLS-based QUIC protocol is more suitable than the native TLS-based QUIC protocol. At the same time, the existing DTLS protocol relies on traditional encryption algorithms such as RSA and ECC. With the development of quantum computers, these algorithms will be easily cracked under the threat of quantum computing.

[0005] In summary, the following problems exist in existing satellite communication technologies: 1. The unique characteristics of satellite communication network environments: Satellite communication environments are highly specialized, particularly characterized by high latency and high packet loss. Traditional TLS protocols rely on TCP, which performs poorly in these environments. Therefore, the QUIC protocol, with its modifications such as 0-RTT and session resumption, has become particularly advantageous in satellite communications. However, QUIC's underlying reliance on TLS is not designed for high packet loss, low bandwidth, and resource-constrained network environments. Therefore, the UDP-based DTLS protocol can be considered as an alternative to TLS to optimize its application in satellite communications.

[0006] 2. Insufficient quantum-resistance of encryption algorithms: The current DTLS protocol is based on traditional encryption algorithms such as RSA and ECC, which cannot provide sufficient security against attacks by quantum computers. With the development of quantum computing, traditional encryption algorithms will no longer be able to effectively protect data security in satellite communications. Therefore, the DTLS protocol needs to be modified to incorporate quantum-resistant cryptographic algorithms to ensure that satellite communications can withstand the threat of quantum computing.

[0007] 3. Lack of flexibility in switching encryption algorithms: The environments of satellite-to-ground and inter-satellite communications are complex and dynamically changing, making frequent downtime, restarts, and redeployments cumbersome. To adapt to varying security requirements and communication environments, we need the ability to flexibly and promptly switch encryption algorithms without interrupting communications. The existing DTLS protocol lacks this flexibility and dynamic switching capability. Summary of the Invention

[0008] In view of this, the present invention provides a quantum secure communication method, electronic device, and medium for satellite communications. By combining the advantages of QUIC and DTLS and performing quantum-resistant modifications, it simultaneously solves the security threats brought by quantum computing and the problems of high packet loss and high latency in satellite communications, thereby improving the security and reliability of satellite communications.

[0009] In a first aspect, an embodiment of the present invention provides a quantum secure communication method for satellite communication, which is applied to a satellite client. The method includes the following steps: Send a handshake message to the ground server based on the QUIC protocol to establish a connection with the ground server; Send a handshake message to the ground server based on the DTLS protocol, complete the configuration of quantum-resistant encryption algorithm, key exchange and generate a shared key with the ground server; The transmitted data is encrypted using the configured quantum-resistant encryption algorithm and shared key, and uploaded to the ground service end based on the QUIC protocol; Receive a confirmation message from the ground service end; the confirmation message is sent by the ground service end to the satellite client based on the QUIC protocol after receiving the encrypted transmission data; Receive a verification message sent by the ground service end; the verification message is generated by the ground service end decrypting the received transmission data based on the DTLS protocol and verifying the transmission data; After completing the exchange of transmission data with the ground service end, the connection is terminated through the QUIC protocol and DTLS protocol.

[0010] In a second aspect, an embodiment of the present invention provides a quantum secure communication method for satellite communication, which is applied to a ground service end. The method includes the following steps: In response to the handshake message sent by the satellite client based on the QUIC protocol, the ground service end establishes a connection with the satellite client; In response to the handshake message sent by the satellite client based on the DTLS protocol, the ground service and the satellite client complete the configuration of the quantum-resistant encryption algorithm, key exchange and generate a shared key; Receive the transmission data uploaded by the satellite client based on the QUIC protocol and encrypted using the configured quantum-resistant encryption algorithm and shared key, and send a confirmation message to the satellite client based on the QUIC protocol; Decrypt the received transmission data based on the DTLS protocol and verify the transmission data; if the transmission data has not been tampered with and the verification passes, return the integrity verification result to the satellite client based on the DTLS protocol, thereby confirming the security of the transmission data; After completing the exchange of transmission data with the satellite client, the connection is terminated through the QUIC protocol and DTLS protocol.

[0011] In a third aspect, an embodiment of the present invention provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor, and the one or more computer programs are executed by the at least one processor so that the at least one processor can execute the above-mentioned quantum secure communication method for satellite communication.

[0012] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-mentioned quantum secure communication method for satellite communication.

[0013] In a fifth aspect, an embodiment of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the above-mentioned quantum secure communication method for satellite communication.

[0014] Compared with the prior art, the present invention has the following beneficial effects: The present invention provides a quantum secure communication method for satellite communications. By combining the DTLS protocol with the QUIC protocol, the performance of satellite communications in high packet loss and high latency environments is improved, ensuring data security and efficiency. At the same time, quantum-resistant cryptography is introduced to ensure that satellite communications remain highly secure under the threat of quantum computing. This provides long-term security for satellite communications in the future era of quantum computing and ensures that the system can cope with future security challenges. Furthermore, when the quantum-resistant encryption algorithm is switched and updated, a pluggable encryption algorithm mechanism is adopted, and satellite communication nodes are hot-swapped to the updated quantum-resistant encryption algorithm without the need for redeployment, reducing maintenance costs and complexity. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0016] Figure 1 This is a diagram of the overall protocol architecture for the combination of QUIC and DTLS provided in an embodiment of the present invention; Figure 2 A flowchart of a quantum secure communication method for satellite communications provided by an embodiment of the present invention; Figure 3 A schematic diagram of the DTLS quantum-resistant handshake process provided by an embodiment of the present invention; Figure 4 A schematic diagram of the process of updating and switching encryption algorithms provided in an embodiment of the present invention; Figure 5 A schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0018] It should be noted that, unless there is any conflict, the features in the following embodiments and implementations may be combined with each other.

[0019] The quantum secure communication method for satellite communications provided by the present invention combines the efficient transmission performance of QUIC with the security assurance capabilities of DTLS, and performs quantum-resistant encryption transformation on DTLS, thereby providing a more secure, stable and flexible communication solution in satellite communications and satellite-to-ground communication environments.

[0020] Specifically, this invention combines the QUIC protocol and the DTLS protocol, leveraging the strengths of each. As a UDP-based transport layer protocol, QUIC offers low latency and high throughput, while DTLS, as a UDP-based security protocol, provides robustness against packet loss, out-of-order traffic, and security. By using DTLS as the security layer for QUIC, the efficient transmission and security of the QUIC protocol can be ensured in specialized environments such as satellite communications.

[0021] like Figure 1 This example shows the overall protocol architecture of QUIC combined with DTLS, including, from top to bottom, the QUIC protocol layer, the DTLS protocol layer, and the UDP protocol layer. The QUIC protocol layer primarily handles flow control, multiplexing, congestion control, and packet loss mitigation for data transmission. The QUIC protocol effectively reduces data transmission latency in satellite communications through multiplexing and low-latency connection establishment, providing improved robustness against packet loss. This ensures fast and efficient data transmission, especially in high-packet-loss environments. The DTLS protocol layer, which replaces QUIC's native TLS layer, handles encryption, authentication, and data integrity verification, ensuring reliable security in unstable network environments. The DTLS protocol uses message numbering and timeout retransmission mechanisms to ensure complete and secure data transmission, even in networks with high packet loss rates. After quantum-resistant modifications, the DTLS protocol uses quantum-resistant cryptographic algorithms such as MLKEM and MLDSA for key negotiation, authentication, and data encryption. QUIC uses the UDP protocol for data transmission, while DTLS provides encryption protection on top of UDP to ensure the security and integrity of data transmission.

[0022] like Figure 2 As shown, the present invention provides a quantum secure communication method for satellite communication, the method comprising the following steps: In step S1, the satellite client sends a handshake message to the ground server based on the QUIC protocol, and the ground server responds to the handshake message, thereby completing the handshake process of the QUIC protocol and confirming that the satellite client has established a connection with the ground server.

[0023] In step S2, the satellite client sends a handshake message to the ground server based on the DTLS protocol, and the ground server responds to the handshake message, so that the satellite client and the ground server complete the configuration of the quantum-resistant encryption algorithm, key exchange and generation of a shared key.

[0024] It's important to note that this example implements quantum-resistant DTLS. Traditional DTLS uses encryption algorithms such as RSA and ECC, which are vulnerable to attacks from quantum computers. To improve DTLS's security in a quantum computing environment, this example implements a quantum-resistant digital signature algorithm (MLKEM) and replaces the original RSA and ECC algorithms with the lattice-based cryptographic algorithm MLKEM and quantum-resistant digital signature algorithms (such as MLDSA).

[0025] Specifically, if Figure 3 As shown, step S2 includes the following sub-steps: In step S201, the satellite client sends a client hello message (i.e., ClientHello message) to the ground server. The client hello message includes a list of quantum-resistant cryptographic algorithms supported by the satellite client, a random number, and a session ID.

[0026] In step S202 , in response to the client hello message, the ground server sends a server hello message (i.e., a ServerHello message) to the satellite client. The server hello message includes a quantum-resistant cryptographic algorithm selected from a list of quantum-resistant cryptographic algorithms supported by the satellite client and a random number.

[0027] In step S203, the ground service generates a first quantum-resistant key pair based on a quantum-resistant signature algorithm. The first quantum-resistant key pair includes a first public key pk1 and a first private key sk1. Furthermore, the ground service sends a server digital certificate to the satellite client. The server digital certificate includes the first public key pk1, a first quantum-resistant digital signature sig1 signed with the first private key sk1, holder information, and issuer information.

[0028] Furthermore, in this example, the quantum-resistant signature algorithm uses the MLDSA algorithm.

[0029] In step S204, the satellite client verifies the first quantum-resistant digital signature sig1 using the quantum-resistant signature algorithm and the first public key pk1, thereby confirming the legitimacy of the server digital certificate and the server.

[0030] In step S205, the ground server generates a second quantum-resistant key pair based on a quantum-resistant key agreement algorithm. The second quantum-resistant key pair includes a second public key pk2 and a second private key sk2. Furthermore, the ground server sends a server key exchange message (i.e., a ServerKeyExchange message) to the satellite client. The server key exchange message includes the second public key pk2 and a second quantum-resistant digital signature sig2 signed with the first private key sk1.

[0031] Furthermore, in this example, the quantum-resistant key agreement algorithm uses the MLKEM algorithm.

[0032] In step S206 , the satellite client verifies the second quantum-resistant digital signature sig2 using the quantum-resistant signature algorithm and the first public key pk1 , thereby confirming the legitimacy of the second public key pk2 .

[0033] In step S207, the satellite client performs key encapsulation using a quantum-resistant key agreement algorithm to generate a first shared key K1 and a ciphertext ct; and sends the ciphertext ct to the ground service end.

[0034] In step S208, the ground service end receives the ciphertext ct and uses a quantum-resistant key agreement algorithm to decapsulate the key and generate a second shared key K2.

[0035] In step S209, the ground server sends a server hello completion message (ie, ServerHelloDone message) to the satellite client, indicating that the initial stage of the handshake has been completed.

[0036] In step S2010, the satellite client sends a ChangeCipherSpec message to the ground server to confirm the quantum-resistant encryption algorithm (such as AES-256) used. The satellite client then sends a Finished message to the ground server to indicate that the satellite client is ready for communication.

[0037] In step S2011, the ground service sends a ChangeCipherSpec message to the satellite client to confirm the quantum-resistant encryption algorithm used; the ground service then sends a Finished message to the satellite client to indicate that the ground service is ready for communication.

[0038] Furthermore, in subsequent communications, the satellite client can use the previous session ID to resume the session, thereby quickly establishing a connection without having to go through the full handshake process again. However, if a configuration update is found, the connection needs to be reestablished to use the new encryption algorithm.

[0039] In step S3, the satellite client encrypts the transmitted data using the negotiated quantum-resistant encryption algorithm and shared key, and then uploads it to the ground server based on the QUIC protocol.

[0040] Furthermore, the QUIC protocol ensures low latency and high throughput, and guarantees transmission data integrity and reliable transmission.

[0041] In step S4, the ground service end receives the transmitted data and sends a confirmation message (i.e., an ACK confirmation message) to the satellite client based on the QUIC protocol.

[0042] It should be noted that if the transmitted data is lost or arrives out of sequence, the satellite client will resend the lost data frames through the retransmission mechanism of the QUIC protocol.

[0043] In step S5, the ground service end decrypts the received transmission data based on the DTLS protocol and verifies the transmission data; if the transmission data has not been tampered with and the verification passes, the ground service end returns the integrity verification result to the satellite client based on the DTLS protocol, thereby confirming the security of the transmission data.

[0044] In step S6, after the satellite client and the ground server complete the exchange of transmission data, the connection is terminated through the QUIC protocol and the DTLS protocol to ensure the integrity and security of the communication.

[0045] Furthermore, in this example, the satellite client and the ground server are used as satellite communication nodes. New quantum-resistant encryption algorithm configurations are dynamically pushed through WebSocket, and hot-switch is performed in the satellite communication nodes. This allows the satellite communication nodes to flexibly update and switch encryption algorithms without interrupting existing communications, thereby adapting to the security needs of the quantum computing era. Specifically, Figure 4 As shown in Figure 2, the process of switching quantum-resistant encryption algorithms includes: In step S100 , the satellite communication node establishes a WebSocket connection with the configuration server and subscribes to configuration updates of the encryption algorithm.

[0046] At this point, the satellite node is ready to receive configuration changes to the encryption algorithm, ensuring that the algorithm can be switched without restarting communication.

[0047] In step S200 , the configuration server pushes the updated encryption algorithm configuration to the satellite communication node.

[0048] For example, the updated encryption algorithm configuration may include a key exchange algorithm (e.g., switching from MLKEM to NTRU), an encryption algorithm (e.g., switching from AES to Saber), etc. The updated encryption algorithm configuration is based on actual security requirements or the need to respond to quantum computing threats.

[0049] In step S300, the satellite communication node receives the updated encryption algorithm configuration and updates the encryption algorithm configuration stored in the local cache; thereby ensuring that the satellite communication node always maintains the latest encryption scheme and is ready for the next data transmission.

[0050] In step S400 , the satellite communication node replaces the encryption algorithm locally according to the updated encryption algorithm configuration, and hot switches to the updated encryption algorithm, for example, switching from MLKEM to NTRU, to cope with the threat of quantum computing.

[0051] It should be noted that hot switching means that the satellite communication node replaces the encryption algorithm without interrupting existing communications, and there is no need to restart the connection or interrupt data transmission.

[0052] Step S500: Activate the updated encryption algorithm. The satellite communication node will send a confirmation message to the configuration server, notifying the configuration server that the satellite communication node has successfully applied the new encryption algorithm configuration and continues to perform the data transmission task.

[0053] Accordingly, the present application also provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned quantum secure communication method for satellite communication. Figure 5 As shown in FIG, a hardware structure diagram of any device with data processing capability in which the quantum secure communication method for satellite communication provided by the embodiment of the present invention is located, except Figure 5 In addition to the processor, memory, and network interface shown, any device with data processing capabilities in which the apparatus in the embodiment is located may also include other hardware, generally based on the actual functions of the device with data processing capabilities, which will not be described in detail.

[0054] Accordingly, the present application also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the aforementioned quantum secure communication method for satellite communications. The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or memory. The computer-readable storage medium may also be an external storage device, such as a plug-in hard disk, smart media card (SMC), SD card, flash card, etc., equipped on the device. Furthermore, the computer-readable storage medium may include both an internal storage unit and an external storage device of any device with data processing capabilities. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or is to be output.

[0055] The above embodiments are intended only to illustrate the design concepts and features of the present invention. Their purpose is to enable those skilled in the art to understand the contents of the present invention and implement them accordingly. The scope of protection of the present invention is not limited to the above embodiments. Therefore, any equivalent changes or modifications made based on the principles and design concepts disclosed in the present invention are within the scope of protection of the present invention.

Claims

1. A quantum secure communication method for satellite communication, characterized in that: Applied to a satellite client, the method comprises the following steps: Send a handshake message to the ground server based on the QUIC protocol to establish a connection with the ground server; Send a handshake message to the ground server based on the DTLS protocol, complete the configuration of quantum-resistant encryption algorithm, key exchange and generate a shared key with the ground server; The transmitted data is encrypted using the configured quantum-resistant encryption algorithm and shared key, and uploaded to the ground service end based on the QUIC protocol; Receive a confirmation message from the ground service end; the confirmation message is sent by the ground service end to the satellite client based on the QUIC protocol after receiving the encrypted transmission data; Receive a verification message sent by the ground service end; the verification message is generated by the ground service end decrypting the received transmission data based on the DTLS protocol and verifying the transmission data; After completing the exchange of transmission data with the ground service end, the connection is terminated through the QUIC protocol and DTLS protocol.

2. A quantum secure communication method for satellite communication according to claim 1, characterized in that: The satellite client sends a handshake message to the ground server based on the DTLS protocol. The process of configuring the quantum-resistant encryption algorithm, exchanging keys, and generating a shared key with the ground server includes: Sending a client hello message to the ground service end, wherein the client hello message includes a list of quantum-resistant cryptographic algorithms supported by the satellite client; receiving a server hello message sent by a ground server, where the server hello message is generated by the ground server in response to the client hello message, and the server hello message includes a quantum-resistant cryptographic algorithm selected from a list of quantum-resistant cryptographic algorithms supported by the satellite client; Receive a server digital certificate issued by a ground service end, where the server digital certificate includes a first public key and a first quantum-resistant digital signature signed with a first private key; wherein the first public key and the first private key are generated by the ground service end based on a quantum-resistant signature algorithm; Verifying the first quantum-resistant digital signature using the quantum-resistant signature algorithm and the first public key; Receive a server key exchange message sent by the ground service end, the server key exchange message including the second public key and a second quantum-resistant digital signature signed with the first private key; wherein the second public key is generated by the ground service end based on a quantum-resistant key agreement algorithm; verifying the second quantum-resistant digital signature using the first quantum-resistant cryptographic algorithm and the first public key; Use quantum-resistant key agreement algorithm to perform key encapsulation, generate the first shared key and ciphertext, and send the ciphertext to the ground service terminal; Receive the server greeting completion message sent by the ground service end; Send a completion message to the ground service end and receive a completion message from the ground service end to confirm the configured quantum-resistant encryption algorithm.

3. The quantum secure communication method for satellite communication according to claim 2, characterized in that: The quantum-resistant signature algorithm uses the MLDSA algorithm, and the quantum-resistant key agreement algorithm uses the MLKEM algorithm.

4. The quantum secure communication method for satellite communication according to claim 1, characterized in that: When the quantum-resistant encryption algorithm is switched and updated, the satellite client and the ground server are used as satellite communication nodes. The process of switching and updating the quantum-resistant encryption algorithm for the satellite communication node includes: Establish a WebSocket connection with the configuration server and subscribe to configuration updates of quantum-resistant encryption algorithms; Receive updated quantum-resistant encryption algorithm configuration, update the quantum-resistant encryption algorithm configuration stored in the local cache, replace the quantum-resistant encryption algorithm locally, and hot-switch to the updated quantum-resistant encryption algorithm; Enable the updated quantum-resistant encryption algorithm and send a confirmation message to the configuration server to notify the configuration server that the satellite communication node has successfully applied the updated quantum-resistant encryption algorithm configuration and continues to perform data transmission tasks.

5. The quantum secure communication method for satellite communication according to claim 1, characterized in that: When the quantum-resistant encryption algorithm is switched and updated, the satellite client and the ground server are used as satellite communication nodes and applied to the configuration server. The process of switching and updating the quantum-resistant encryption algorithm includes: Establish a WebSocket connection with the satellite communication node; Push updated quantum-resistant encryption algorithm configurations to satellite communication nodes; Receive a confirmation message sent by a satellite communication node; the confirmation message is generated by the satellite communication node receiving an updated quantum-resistant encryption algorithm configuration, updating the quantum-resistant encryption algorithm configuration stored in a local cache, replacing the quantum-resistant encryption algorithm locally, hot-switching to the updated quantum-resistant encryption algorithm, and after enabling the updated quantum-resistant encryption algorithm, notifying the configuration server that the satellite communication node has successfully applied the updated quantum-resistant encryption algorithm configuration and continuing to perform the data transmission task.

6. A quantum secure communication method for satellite communication, characterized in that: Applied to the ground service end, the method includes the following steps: In response to the handshake message sent by the satellite client based on the QUIC protocol, the ground service end establishes a connection with the satellite client; In response to the handshake message sent by the satellite client based on the DTLS protocol, the ground service and the satellite client complete the configuration of the quantum-resistant encryption algorithm, key exchange and generate a shared key; Receive the transmission data uploaded by the satellite client based on the QUIC protocol and encrypted using the configured quantum-resistant encryption algorithm and shared key, and send a confirmation message to the satellite client based on the QUIC protocol; Decrypt the received transmission data based on the DTLS protocol and verify the transmission data; if the transmission data has not been tampered with and the verification passes, return the integrity verification result to the satellite client based on the DTLS protocol, thereby confirming the security of the transmission data; After completing the exchange of transmission data with the satellite client, the connection is terminated through the QUIC protocol and DTLS protocol.

7. A quantum secure communication method for satellite communication according to claim 6, characterized in that: In response to the handshake message sent by the satellite client based on the DTLS protocol, the ground server and the satellite client complete the key exchange, configure the quantum-resistant encryption algorithm, and generate a shared key. The process includes: In response to the client hello message, the ground server sends a server hello message to the satellite client, wherein the server hello message includes a quantum-resistant cryptographic algorithm selected from a list of quantum-resistant cryptographic algorithms supported by the satellite client; wherein the client hello message includes the list of quantum-resistant cryptographic algorithms supported by the satellite client; generating a first public key and a first private key based on a quantum-resistant signature algorithm, and sending a server digital certificate to the satellite client, the server digital certificate including the first public key and a first quantum-resistant digital signature signed with the first private key; Generate a second public key and a second private key based on a quantum-resistant key agreement algorithm, and the ground service end sends a server key exchange message to the satellite client, wherein the server key exchange message includes the second public key and a second quantum-resistant digital signature signed with the first private key; receiving a ciphertext sent by a satellite client, and decapsulating the key using a quantum-resistant key agreement algorithm to generate a second shared key; wherein the ciphertext is generated by the satellite client performing key encapsulation using the quantum-resistant key agreement algorithm; Send server hello completion message to satellite client; Receive the change cipher specification message and completion message sent by the satellite client, and send the change cipher specification message and completion message to the satellite client to confirm the configured quantum-resistant encryption algorithm.

8. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs that can be executed by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to execute the quantum secure communication method for satellite communication according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the computer program implements the quantum secure communication method for satellite communication according to any one of claims 1 to 7.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the quantum secure communication method for satellite communication described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Connection establishment method based on QUIC protocol

    CN116405576A

  • QUIC connection establishment method, system and device, electronic equipment and storage medium

    CN116566612A

  • Anti-quantum cryptography migration method based on FIDO2 protocol, electronic equipment and medium

    CN119276642A

  • Quantum key distribution method and system after satellite communication based on QUIC

    CN120281477A

  • Network securing device data using two post-quantum cryptography key encapsulation mechanisms

    US11153080B1