Communication method and device, equipment, storage medium and program product

By having both communicating parties generate quantum security keys themselves and having the key management system issue session keys, the problems of poor user experience and complex key management in existing quantum security communications are solved, and quantum security communications with simplified operations and enhanced security are achieved.

CN120658388APending Publication Date: 2025-09-16CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510928621.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In existing quantum secure communications, users need to go to operator outlets to pre-charge their own keys, which leads to high operational complexity and poor user experience. Key management and distribution are also complex and costly, and the single key type is not completely secure.

Method used

The communicating parties generate quantum security keys on their own, and the key management system issues session keys based on the keys of both parties to achieve quantum secure communication, improve user experience, and utilize existing network facilities to provide comprehensive quantum security.

Benefits of technology

Quantum secure communication can be achieved without pre-charging dedicated keys, improving user experience, simplifying key management, reducing costs and enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658388A_ABST
    Figure CN120658388A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and device, equipment, a storage medium and a program product, relates to the technical field of communication, and is used for improving user experience during quantum secure communication. The method comprises the following steps: calling a first algorithm to generate a first quantum key pair; a first ciphertext from the key management system is received, the first ciphertext is obtained by encrypting the session key based on a first quantum key pair and a second quantum key pair, and the second quantum key pair is generated by calling a first algorithm by the called terminal; decrypting the first ciphertext based on the first quantum key pair to obtain a session key; and communicating with the called terminal based on the session key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method, apparatus, device, storage medium, and program product. Background Art

[0002] With the development of quantum secure communication technology, quantum keys are functionally divided into two types: one is the quantum key pre-loaded into the quantum secure Subscriber Identity Module (SIM) card for authentication; the other is the quantum key used for voice encryption, generated in real time by a quantum key distribution network. Users who wish to use quantum keys can first visit a nearby operator's service station to pre-load their own unique key, which is a truly random number generated by a quantum random number generator. During a call, the service stations corresponding to both parties share an application key, also known as a session key, through quantum key distribution. This application key is then encrypted with each party's unique key and sent to both parties, allowing them to conduct a secure call.

[0003] However, if the dedicated key is depleted, users need to go to the operator's service station to pre-fill the dedicated key, which increases the user's operation complexity and leads to a poor user experience. Therefore, how to improve the user experience during quantum secure communication has become an urgent problem to be solved. Summary of the Invention

[0004] The present application provides a communication method, apparatus, device, storage medium, and program product for improving user experience during quantum secure communication.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a communication method is provided, which is applied to a calling end, and the method includes: calling a first algorithm to generate a first quantum key pair; receiving a first ciphertext from a key management system, the first ciphertext being encrypted based on the first quantum key pair and a second quantum key pair to obtain a session key, the second quantum key pair being generated by the called end calling the first algorithm; decrypting the first ciphertext based on the first quantum key pair to obtain a session key; and communicating with the called end based on the session key.

[0007] In one possible implementation, decrypting a first ciphertext based on a first quantum key pair to obtain a session key includes: decrypting the first ciphertext based on the first quantum key to obtain a session key and a second ciphertext, where the second ciphertext is obtained by encrypting the session key and identity information of the calling party based on the second quantum key pair; after decrypting the first ciphertext based on the first quantum key pair to obtain the session key, the method further includes: sending the second ciphertext to the called party.

[0008] In one possible implementation, before receiving the first ciphertext from the key management system, the method further includes: encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key pair to obtain a third ciphertext; and sending the third ciphertext to the key management system.

[0009] In one possible implementation, before encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key, the method also includes: encrypting and signing the identity information of the calling end based on the first quantum key to obtain a fourth ciphertext; sending the fourth ciphertext to the quantum communication station; receiving the identity authentication result sent by the quantum communication station; encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain a third ciphertext, including: when the identity authentication result is authentication passed, encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain the third ciphertext.

[0010] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0011] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0012] In a second aspect, a communication method is provided, which is applied to a key management system, and the method includes: obtaining a first quantum key pair of a calling end and a second quantum key pair of a called end, the first quantum key pair being generated by calling a first algorithm, and the second quantum key pair being generated by calling the first algorithm; generating a session key based on the second algorithm; encrypting the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext; and sending the first ciphertext to the calling end, the first ciphertext being used by the calling end to obtain the session key so as to communicate with the called end based on the session key.

[0013] In one possible implementation, before generating a session key based on the second algorithm, the method further includes: receiving a third ciphertext from the calling end; decrypting the third ciphertext based on the first quantum key pair to obtain identity information of the calling end and identity information of the called end; generating a session key based on the second algorithm, including: generating a session key based on a quantum random number generator when confirming that communication between the calling end and the called end is allowed based on the identity information of the calling end and the identity information of the called end.

[0014] In one possible implementation, encrypting a session key based on a first quantum key pair and a second quantum key to obtain a first ciphertext includes: encrypting the identity information of the calling party and the session key based on the second quantum key to obtain a second ciphertext; and encrypting the session key and the second ciphertext based on the first quantum key pair to obtain a first ciphertext.

[0015] In one possible implementation, before receiving the third ciphertext from the calling end, the method also includes: receiving a fourth ciphertext from the quantum communication station; decrypting and verifying the fourth ciphertext based on the first quantum key pair to obtain the identity information and verification result of the calling end; and sending the identity information and verification result of the calling end to the quantum communication station.

[0016] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0017] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm, and the second algorithm is a quantum random number generator.

[0018] In a third aspect, a communication method is provided, which is applied to a quantum communication station, and the method includes: receiving a fourth ciphertext from a calling end, the fourth ciphertext being obtained by encrypting and signing the identity information of the calling end based on a first quantum key pair, the first quantum key pair being generated by the calling end calling a first algorithm; sending the fourth ciphertext to a key management system; receiving the identity information and signature verification result of the calling end sent by the key management system; determining an identity authentication result based on the identity information and signature verification result of the calling end; and sending the identity authentication result to the calling end.

[0019] In one possible implementation, when the identity information authentication of the calling party passes and the signature verification result is verification passed, the identity authentication result is authentication passed; when the identity information authentication of the calling party fails and / or the signature verification result is verification failed, the identity authentication result is authentication failed.

[0020] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0021] In a fourth aspect, a communication method is provided, which is applied to the called end, and the method includes: calling a first algorithm to generate a second quantum key pair; receiving a second ciphertext from the calling end; decrypting the second ciphertext based on the second quantum key pair to obtain a session key and the identity information of the calling end; and communicating with the calling end based on the session key.

[0022] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption; the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0023] In a fifth aspect, a communication device is provided, which is applied to a calling end, and the communication device includes: a processing unit and a transmission unit; the processing unit is used to call a user identity identification module of the calling end to generate a first quantum key pair; the transmission unit is used to receive a first ciphertext from a key management system, the first ciphertext is obtained by encrypting a session key based on the first quantum key pair and the second quantum key pair, and the second quantum key pair is generated by the called end calling the user identity identification module of the called end; the processing unit is also used to decrypt the first ciphertext based on the first quantum key pair to obtain a session key; the transmission unit is also used to communicate with the called end based on the session key.

[0024] In one possible implementation, the processing unit is further configured to decrypt the first ciphertext using the first quantum key to obtain a session key and a second ciphertext, where the second ciphertext is obtained by encrypting the session key and the identity information of the calling party using the second quantum key pair. The transmission unit is further configured to send the second ciphertext to the called party.

[0025] In one possible implementation, the processing unit is further configured to encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key pair to obtain a third ciphertext; and the transmission unit is further configured to send the third ciphertext to the key management system.

[0026] In one possible implementation, the processing unit is further used to encrypt and sign the identity information of the calling end based on the first quantum key to obtain a fourth ciphertext; the transmission unit is further used to send the fourth ciphertext to the quantum communication station; the transmission unit is further used to receive the identity authentication result sent by the quantum communication station; the processing unit is further used to encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain a third ciphertext when the identity authentication result is that the authentication is passed.

[0027] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0028] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0029] In a sixth aspect, a communication device is provided, which is applied to a key management system, and the communication device includes: a transmission unit and a processing unit; the transmission unit is used to obtain a first quantum key pair of a calling end and a second quantum key pair of a called end, the first quantum key pair is generated by calling a user identity identification module of the calling end, and the second quantum key pair is generated by calling a user identity identification module of the called end; the processing unit is used to generate a session key based on a second algorithm; the processing unit is also used to encrypt the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext; the transmission unit is also used to send the first ciphertext to the calling end, and the first ciphertext is used by the calling end to obtain the session key, so as to communicate with the called end based on the session key.

[0030] In one possible implementation, the transmission unit is further used to receive a third ciphertext from the calling end; decrypt the third ciphertext based on the first quantum key pair to obtain identity information of the calling end and identity information of the called end; and the processing unit is further used to generate a session key based on a quantum random number generator when it is confirmed that communication between the calling end and the called end is allowed based on the identity information of the calling end and the identity information of the called end.

[0031] In one possible implementation, the processing unit is further configured to encrypt the identity information and session key of the calling party based on the second quantum key to obtain a second ciphertext; and the processing unit is further configured to encrypt the session key and the second ciphertext based on the first quantum key pair to obtain a first ciphertext.

[0032] In one possible implementation, the transmission unit is further used to receive a fourth ciphertext from the quantum communication station; the processing unit is further used to decrypt and verify the fourth ciphertext based on the first quantum key pair to obtain the identity information and verification result of the calling party; the transmission unit is further used to send the identity information and verification result of the calling party to the quantum communication station.

[0033] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0034] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm, and the second algorithm is a quantum random number generator.

[0035] In the seventh aspect, a communication device is provided, which is applied to a quantum communication station, and the communication device includes: a transmission unit and a processing unit; the transmission unit is used to receive a fourth ciphertext from the calling end, and the fourth ciphertext is obtained by encrypting and signing the identity information of the calling end based on the first quantum key pair, and the first quantum key pair is generated by the calling end calling the user identity identification module of the calling end; the transmission unit is also used to send the fourth ciphertext to the key management system; the transmission unit is also used to receive the identity information and signature verification result of the calling end sent by the key management system; the processing unit is used to determine the identity authentication result based on the identity information and signature verification result of the calling end; the transmission unit is also used to send the identity authentication result to the calling end.

[0036] In one possible implementation, when the identity information authentication of the calling party passes and the signature verification result is verification passed, the identity authentication result is authentication passed; when the identity information authentication of the calling party fails and / or the signature verification result is verification failed, the identity authentication result is authentication failed.

[0037] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0038] In an eighth aspect, a communication device is provided, which is applied to a called end, and the communication device includes: a processing unit and a transmission unit; the processing unit is used to call a user identity identification module of the called end to generate a second quantum key pair; the transmission unit is used to receive a second ciphertext from the calling end; the processing unit is also used to decrypt the second ciphertext based on the second quantum key pair to obtain a session key and the identity information of the calling end; the transmission unit is also used to communicate with the calling end based on the session key.

[0039] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption; the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0040] In the ninth aspect, an electronic device comprises: a processor and a memory; wherein the memory is used to store one or more programs, and the one or more programs include computer execution instructions. When the electronic device is running, the processor executes the computer execution instructions stored in the memory to enable the electronic device to perform a communication method as in the first aspect.

[0041] In a tenth aspect, a computer-readable storage medium storing one or more programs is provided, wherein the one or more programs include instructions, and when the instructions are executed by a computer, the computer executes a communication method as described in any one of the first to fourth aspects.

[0042] In an eleventh aspect, a computer program product is provided. When the computer instructions are executed on an electronic device, the electronic device executes a communication method according to any one of the first to fourth aspects.

[0043] This application provides a communication method, apparatus, device, storage medium, and program product for use in quantum communication scenarios. When a calling party needs to conduct quantum secure communication with a called party, the calling party can invoke its user identity module to generate a first quantum key pair and receive a first ciphertext from a key management system, obtained by encrypting a session key using the first and second quantum key pairs. The second quantum key pair is generated by the called party invoking its user identity module. Furthermore, the first ciphertext is decrypted using the first quantum key pair to obtain a session key, which is then used to communicate with the called party. In other words, both communicating parties can independently generate quantum secure keys, and the key management system issues a session key based on their respective quantum secure keys for quantum secure communication. This eliminates the need for pre-filling dedicated keys between the two communicating parties, improving the user experience during quantum secure communication. This avoids the technical issue of users having to visit a service station at an operator's network to pre-fill dedicated keys if dedicated keys are depleted, resulting in a poor user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 A schematic diagram of the structure of a communication system provided in an embodiment of the present application;

[0045] Figure 2 A schematic diagram of a communication method provided in an embodiment of the present application Figure 1 ;

[0046] Figure 3 A schematic diagram of a communication method provided in an embodiment of the present application Figure 2 ;

[0047] Figure 4 A schematic diagram of a communication method provided in an embodiment of the present application Figure 3 ;

[0048] Figure 5 A schematic diagram of a communication method provided in an embodiment of the present application Figure 4 ;

[0049] Figure 6 A schematic diagram of a communication method provided in an embodiment of the present application Figure 5 ;

[0050] Figure 7 A schematic diagram of a communication method provided in an embodiment of the present application Figure 6 ;

[0051] Figure 8 A schematic diagram of a communication method provided in an embodiment of the present application Figure 7 ;

[0052] Figure 9 A schematic diagram of a communication method provided in an embodiment of the present application Figure 8 ;

[0053] Figure 10 A schematic diagram of a communication method provided in an embodiment of the present application Figure 9 ;

[0054] Figure 11 A schematic diagram of a communication method provided in an embodiment of the present application Figure 10 ;

[0055] Figure 12 A schematic diagram of components of a system architecture diagram of a communication method provided in an embodiment of the present application;

[0056] Figure 13 A schematic diagram of a quantum secure communication process of a communication method provided in an embodiment of the present application;

[0057] Figure 14 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 1 ;

[0058] Figure 15 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 2 ;

[0059] Figure 16 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 3 ;

[0060] Figure 17 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 4 ;

[0061] Figure 18 A schematic structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0063] In the description of this application, "and / or" is used to describe the association relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, "at least one" and "plurality" refer to two or more. Words such as "first" and "second" do not limit the quantity or order of execution, and words such as "first" and "second" do not necessarily mean different.

[0064] With the development of quantum secure communication technology, quantum keys are functionally divided into two types: one is the quantum key pre-loaded into the quantum secure SIM card for authentication; the other is the quantum key used for voice encryption, generated in real time by the quantum key distribution network. Users who wish to use quantum keys can first visit a nearby operator's service station to pre-load their own unique key, which is a truly random number generated by a quantum random number generator. During a call, the service stations corresponding to both parties share an application key through quantum key distribution. This application key is then encrypted with each party's unique key and sent to both parties, allowing them to conduct a secure call.

[0065] However, the above method has the following problems:

[0066] (1) Complex key management and poor user experience: Users need to go to the operator's service station to pre-fill their dedicated key, which increases the complexity of the user's operation. When the dedicated key is exhausted, the user needs to go to the service station again to refill it, which reduces the user experience and convenience.

[0067] (2) Key distribution is complex and costly: Key service stations share session keys through quantum key distribution (QKD), which requires the establishment and maintenance of a complex QKD network and requires significant changes to existing network facilities.

[0068] (3) Single key type and incomplete security: The above method mainly relies on the random numbers generated by the quantum random number generator (QRNG) as pre-charge keys for encrypting session keys, but lacks other types of keys such as signature keys, which limits the security of key use.

[0069] To address the aforementioned issues, this application provides a communication method in which both communicating parties can independently generate quantum-secure keys. A key management system then issues session keys based on the quantum-secure keys of both communicating parties, enabling quantum-secure communication between the two parties. This eliminates the need for pre-priming dedicated keys between the two communicating parties, enabling quantum-secure communication between the two parties and improving the user experience. Furthermore, this method leverages existing network infrastructure to provide comprehensive quantum security.

[0070] A communication method provided in an embodiment of the present application can be applied to a communication system. Figure 1 FIG. 1 shows a schematic diagram of the structure of a communication system. Figure 1 As shown, the communication system includes: a calling terminal 11, a key management system 12, a quantum communication station 13, and a called terminal 14. The calling terminal 11, the key management system 12, the quantum communication station 13, and the called terminal 14 can be connected by wired or wireless means, which is not limited in this embodiment of the present invention.

[0071] The calling end 11 is used to call the first algorithm, generate a first quantum key pair, and receive a first ciphertext obtained by encrypting a session key based on the first quantum key pair and the second quantum key pair from the key management system 12. The second quantum key pair is generated by the called end 14 by calling the first algorithm, decrypting the first ciphertext based on the first quantum key pair to obtain the session key, and communicating with the called end 14 based on the session key.

[0072] The key management system 12 is used to obtain a first quantum key pair generated by calling a first algorithm from the calling end 11 and a second quantum key pair generated by calling the first algorithm from the called end 14, generate a session key based on the second algorithm, encrypt the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext, and send the first ciphertext to the calling end 11. The first ciphertext is used by the calling end 11 to obtain the session key so as to communicate with the called end 14 based on the session key.

[0073] The quantum communication station 13 is used to receive a fourth ciphertext obtained by encrypting and signing the identity information of the calling terminal 11 based on the first quantum key from the calling terminal 11, send the fourth ciphertext to the key management system 12, receive the identity information and signature verification result of the calling terminal 11 sent by the key management system 12, determine the identity authentication result based on the identity information and signature verification result of the calling terminal 11, and send the identity authentication result to the calling terminal 11.

[0074] The calling end 11 and the called end 14 can be terminal devices with wireless transceiver functions, such as mobile phones, tablet computers, computers with wireless transceiver functions, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. The embodiments of the present application do not limit the application scenarios. Terminal devices may sometimes also be referred to as users, A-IoT devices, access terminals, user equipment (UE), UE units, UE stations, mobile stations, mobile stations, remote stations, transmitters, remote terminals, mobile devices, UE terminals, wireless communication devices, UE agents or UE devices, etc., which are not limited in the embodiments of the present application.

[0075] The key management system 12 can be a device that supports key generation, key management, encryption and decryption, signature verification, and other functions of the server (i.e., the key management system). It can also be called an encryption key management system, a cryptographic key management system (CKMS), a key service system, a key vault, etc., and the embodiments of the present application are not limited to this.

[0076] The quantum communication station 13 can be a device that deploys quantum communication technology and supports users in quantum secure communication. It can also be called a quantum secure communication service station, a quantum secure communication service system, a business application system, a quantum secure communication station, etc., which is not limited in this embodiment of the application.

[0077] The following describes a communication method provided by an embodiment of the present application in conjunction with the accompanying drawings. Figure 2 As shown, a communication method provided in an embodiment of the present application is applied to a calling end, and the method includes S201-S204:

[0078] S201. Call a first algorithm to generate a first quantum key pair.

[0079] Optionally, the first algorithm can be integrated into the SIM card of the calling party so that the SIM card of the calling party supports key generation, key management, encryption and decryption, signature verification and other functions of the mobile terminal (i.e., the user terminal, which can include the calling terminal and the called terminal). The SIM card can also be called a quantum SIM card.

[0080] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0081] In other words, a QRNG chip and a post-quantum cryptography (PQC) chip can be integrated into the calling party's SIM card. Post-quantum cryptography is also called quantum-resistant. In this way, the calling party can call the quantum SIM card and use the QRNG and PQC algorithms to generate public and private keys for encryption and signing, namely the first quantum key pair.

[0082] Optionally, the calling party may generate a key in the following manner: the calling party generates a signature key, the server / Certificate Authority (CA) generates an encryption key, which is then encrypted using the calling party's signature key and returned to the calling party for writing.

[0083] The core of the PQC algorithm is to ensure resistance to quantum attacks. The PQC algorithm can also be called a PQC hybrid traditional algorithm, which also has the ability to resist quantum attacks.

[0084] S202: Receive a first ciphertext from a key management system, where the first ciphertext is obtained by encrypting a session key based on a first quantum key pair and a second quantum key pair, where the second quantum key pair is generated by the called party calling a first algorithm.

[0085] Alternatively, similar to the calling party, the called party can also integrate a QRNG chip and a PQC chip into its SIM card. This allows the called party to call the quantum SIM card and use the QRNG and PQC algorithms to generate public and private keys for encryption and signing, i.e., the second quantum key pair.

[0086] Optionally, the called party may generate a key in the following manner: the called party generates a signature key, the server / CA generates an encryption key, which is then encrypted using the called party's signature key and returned to the called party for writing.

[0087] When the calling end needs to communicate with the called end, the key management system can generate a session key based on the second algorithm. The second algorithm can be QRNG. The calling end and the called end need to generate a session key every time they communicate to ensure the security of the session.

[0088] Furthermore, the key management system may encrypt the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext, and send the first ciphertext to the calling end.

[0089] It should be noted that the first algorithm may also be integrated into the SIM card and the server without using a hardware module, and may be run in the form of software on the mobile terminal and the server.

[0090] S203. Decrypt the first ciphertext based on the first quantum key pair to obtain a session key.

[0091] S204: Communicate with the called party based on the session key.

[0092] Optionally, the calling end may decrypt the first ciphertext based on the first quantum key pair to obtain a session key, so that the calling end can communicate with the called end based on the session key.

[0093] This application enables quantum-secure communication between two communicating parties by enabling them to generate their own quantum-secure keys. A key management system then issues session keys based on these keys, enabling quantum-secure communication between the two communicating parties. This eliminates the need for pre-filling dedicated keys between the two communicating parties, enhancing the user experience during quantum-secure communication. Furthermore, existing network infrastructure (i.e., the key management system) can be fully utilized without requiring significant modifications to existing network infrastructure.

[0094] In one design, Figure 3 As shown, a communication method provided in an embodiment of the present application, the method in the above step S203 specifically includes S301, and after the above step S203, the method further includes S302:

[0095] S301. Decrypt the first ciphertext based on the first quantum key to obtain a session key and a second ciphertext.

[0096] The second ciphertext is obtained by encrypting the session key and the identity information of the calling party based on the second quantum key pair.

[0097] S302: Send a second ciphertext to the called party.

[0098] Optionally, the key management system can encrypt the identity information of the calling party and the session key based on the second quantum key to obtain a second ciphertext, namely Kb(A, Ks), where Kb represents the second quantum key pair, A represents the identity information of the calling party, and Ks represents the session key.

[0099] Furthermore, the key management system can encrypt the session key and the second ciphertext based on the first quantum key pair, generating the first ciphertext, Ka(Ks, Kb(A, Ks)), where Ka represents the first quantum key pair. This allows encryption of the session key using the first and second quantum key pairs, facilitating subsequent quantum secure communication.

[0100] Furthermore, the key management system can send a first ciphertext to the calling party. The calling party can decrypt the first ciphertext using the first quantum key to obtain a session key and a second ciphertext. Furthermore, the calling party can send a second ciphertext to the called party. The called party can decrypt the second ciphertext using the second quantum key to obtain the session key and the calling party's identity information. In other words, the calling party can obtain the session key, and the called party can also obtain the session key and the identity of the calling party with whom they are communicating based on the second ciphertext. In this way, the calling and called parties can encrypt session information using the session key, achieving secure communication between the two parties.

[0101] Optionally, the identity information of the calling party may be information that can prove the identity of the calling party, such as the calling party's telephone number.

[0102] In one design, Figure 4 As shown, a communication method provided in an embodiment of the present application, before the above step S202, the method further includes: S401-S402:

[0103] S401. Encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key pair to obtain a third ciphertext.

[0104] S402: Send the third ciphertext to the key management system.

[0105] Optionally, when the calling party needs to communicate with the called party, the calling party can encrypt and sign the calling party's and called party's identities using the first quantum key pair, generating a third ciphertext, Ka(A, B), where B represents the called party's identity. This ciphertext is then sent to the key management system. By encrypting and signing the calling party's and called party's identities, the security issue of key usage, which is limited by the lack of other key types such as signature keys, can be addressed in related technologies, thereby improving key security.

[0106] Furthermore, the key management system can receive a third ciphertext from the calling party and decrypt it based on the first quantum key pair to obtain the identity information of the calling party and the called party. Based on the identity information of the calling party and the called party, the key management system can determine whether to allow communication between the two parties. If communication is allowed, the key management system can generate a session key for subsequent communication between the two parties. If communication is not allowed, no session key is generated. This improves the security of communication between the two parties.

[0107] Optionally, the identity information of the called party may be information that can prove the identity of the calling party, such as the called party's phone number.

[0108] Before the calling party initiates communication with the called party, the calling party needs to be authenticated. The following describes how to authenticate the calling party.

[0109] In one design, Figure 5 As shown, a communication method provided in an embodiment of the present application, before the above step S401, the method further includes S501-S503, and the above step S401 specifically includes S504:

[0110] S501. Encrypt and sign the identity information of the calling party based on the first quantum key to obtain a fourth ciphertext.

[0111] Optionally, the calling end may encrypt and sign the identity information of the calling end based on the first quantum key to obtain a fourth ciphertext.

[0112] The identity information of the calling party may also be referred to as basic information of the calling party, and may be information such as the calling party's telephone number.

[0113] S502. Send a fourth ciphertext to the quantum communication station.

[0114] Optionally, the calling party may send an authentication request message carrying a fourth ciphertext to the quantum communication station. Furthermore, the quantum communication station may receive the authentication request message carrying the fourth ciphertext and forward it to the key management system. Furthermore, the key management system may decrypt and verify the fourth ciphertext based on the first quantum key pair, obtain the calling party's identity information and the verification result, and return the calling party's identity information and the verification result to the quantum communication station. The verification result may indicate either a successful or failed verification.

[0115] Furthermore, the quantum communication station can authenticate the identity information of the calling party. For example, the calling party determines whether the calling party's identity information is legal. If the calling party's identity information is legal, the calling party's identity information authentication is successful. If the calling party's identity information is illegal, the calling party's identity information authentication is unsuccessful. If the calling party's identity information authentication is successful and the signature verification result is "verified successful," the identity authentication result is "authenticated successful." If the calling party's identity information authentication is unsuccessful and / or the signature verification result is "verified unsuccessful," the identity authentication result is "authenticated unsuccessful." The quantum communication station then returns the identity authentication result to the calling party. Authentication of identity information by the quantum communication station can improve the security of subsequent quantum communications.

[0116] S503. Receive the identity authentication result sent by the quantum communication station.

[0117] S504: If the identity authentication result is authentication passed, encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain a third ciphertext.

[0118] In other words, the calling party receives the identity authentication result from the quantum communication station. If the authentication result is "passed," the calling party can communicate with the called party and can proceed with the subsequent encrypted communication process. If the authentication result is "failed," the calling party cannot communicate with the called party and cannot proceed with the subsequent encrypted communication process. This improves the security of subsequent quantum communication.

[0119] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0120] That is, the first quantum key pair may include two quantum key pairs, one for encryption and decryption and the other for signing and verifying. The key pair for encryption and decryption may include a public key for encryption and a private key for decryption. The quantum key pair for signing and verifying may include a public key for verification and a private key for signing.

[0121] In one design, Figure 6 As shown, an embodiment of the present application provides a communication method, which is applied to a key management system. The method includes S601-S604:

[0122] S601. Obtain a first quantum key pair of the calling end and a second quantum key pair of the called end, where the first quantum key pair is generated by calling a first algorithm, and the second quantum key pair is generated by calling the first algorithm.

[0123] Optionally, the key management system can integrate a QRNG chip and a PQC chip. In this way, the key management system can call the quantum QRNG chip and the PQC chip to generate a first quantum key pair for the calling end and a second quantum key pair for the called end.

[0124] S602: Generate a session key based on a second algorithm.

[0125] S603: Encrypt the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext.

[0126] S604: Send a first ciphertext to the calling end. The first ciphertext is used by the calling end to obtain a session key so as to communicate with the called end based on the session key.

[0127] For the introduction of the session key and the first ciphertext, please refer to the above embodiment and will not be repeated here.

[0128] In one design, Figure 7 As shown, a communication method provided in an embodiment of the present application, before the above step S601, the method further includes S701-S702, and the above step S601 specifically includes S703:

[0129] S701: Receive a third ciphertext from the calling terminal.

[0130] S702: Decrypt the third ciphertext based on the first quantum key pair to obtain the identity information of the calling end and the identity information of the called end.

[0131] S703: When it is confirmed based on the identity information of the calling end and the identity information of the called end that the calling end and the called end are allowed to communicate, generate a session key based on a quantum random number generator.

[0132] For the introduction of the third ciphertext, please refer to the above embodiment and will not be described in detail here.

[0133] In one design, Figure 8 As shown, in a communication method provided in an embodiment of the present application, the above step S603 specifically includes S801-S802:

[0134] S801. Encrypt the identity information and session key of the calling party based on the second quantum key to obtain a second ciphertext.

[0135] S802. Encrypt the session key and the second ciphertext based on the first quantum key pair to obtain a first ciphertext.

[0136] For an introduction on how the key management system obtains the first ciphertext and the second ciphertext, please refer to the above embodiment and will not be described in detail here.

[0137] In one design, Figure 9 As shown, a communication method provided in an embodiment of the present application, before the above step S701, the method further includes S901-S903:

[0138] S901. Receive the fourth ciphertext from the quantum communication station.

[0139] S902. Decrypt and verify the signature of the fourth ciphertext based on the first quantum key pair to obtain the identity information of the calling party and the signature verification result.

[0140] S903: Send the identity information of the calling party and the signature verification result to the quantum communication station.

[0141] For the introduction of the fourth ciphertext, please refer to the above embodiment and will not be described in detail here.

[0142] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0143] In one possible implementation, the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm, and the second algorithm is a quantum random number generator.

[0144] For the introduction of the first quantum key pair, the first algorithm, and the second algorithm, please refer to the above embodiments and will not be repeated here.

[0145] In one design, Figure 10 As shown, an embodiment of the present application provides a communication method, which is applied to a quantum communication station. The method includes S1001-S1005:

[0146] S1001. Receive a fourth ciphertext from a calling terminal. The fourth ciphertext is obtained by encrypting and signing the identity information of the calling terminal based on a first quantum key pair. The first quantum key pair is generated by the calling terminal by calling a first algorithm.

[0147] S1002. Send the fourth ciphertext to the key management system.

[0148] S1003: Receive the identity information of the calling party and the signature verification result sent by the key management system.

[0149] S1004: Determine the identity authentication result based on the identity information of the calling party and the signature verification result.

[0150] S1005. Send the identity authentication result to the calling party.

[0151] For the introduction of the fourth ciphertext, signature verification result and identity authentication result, please refer to the above embodiment and will not be repeated here.

[0152] In one possible implementation, if the identity information authentication of the calling party passes and the signature verification result is verification passed, the identity authentication result is authentication passed. If the identity information authentication of the calling party fails and / or the signature verification result is verification failed, the identity authentication result is authentication failed.

[0153] For an introduction on how to authenticate the identity information of the calling party, please refer to the above embodiment and will not be described in detail here.

[0154] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verification.

[0155] For the introduction of the first quantum key pair, please refer to the above embodiment and will not be repeated here.

[0156] In one design, Figure 11 As shown, a communication method provided in an embodiment of the present application is applied to a called party, and the method includes S1101-S1104:

[0157] S1101. Call the first algorithm to generate a second quantum key pair.

[0158] S1102: Receive a second ciphertext from the calling end.

[0159] S1103. Decrypt the second ciphertext based on the second quantum key pair to obtain the session key and the identity information of the calling party.

[0160] S1104: Communicate with the calling party based on the session key.

[0161] For the introduction of the second ciphertext and the session key, please refer to the above embodiment and will not be repeated here.

[0162] In a possible implementation, the first quantum key pair includes a first quantum key pair for encryption and decryption; the first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

[0163] For an introduction to the first algorithm and the first quantum key pair, please refer to the above embodiments and will not be repeated here.

[0164] In order to make the purpose, technical solutions and advantages of this application clearer, the following introduces the components of the system architecture diagram for executing the communication method provided by this application and the quantum secure communication process of the communication method provided by this application in combination with specific embodiments.

[0165] like Figure 12As shown in the figure, the system architecture diagram includes a quantum SIM card, a key management system, and a quantum secure communication service. The quantum SIM card supports key generation, key management, encryption and decryption, and signature verification functions on the mobile end (i.e., the user end, which can include both the calling and called ends). The quantum SIM card integrates terminal cryptographic chips such as QRNG and PQC. The key management system supports key generation, key management, encryption and decryption, and signature verification functions on the server end. The key management system integrates server-side cryptographic cards such as QRNG and PQC. The quantum secure communication service supports users in quantum secure communication. The calling and called ends can communicate with the quantum secure communication service via the mobile communication network.

[0166] like Figure 13 As shown, the specific steps of the quantum secure communication process are as follows:

[0167] S1. Key generation: Terminal A (i.e., the calling end in this application) calls the quantum SIM card and uses the QRNG and PQC algorithms to generate public and private keys for encryption and signing (i.e., the first quantum key pair in this application).

[0168] S2. Identity authentication: Terminal A calls the quantum SIM card, uses the QRNG and PQC algorithms to encrypt the basic information used for identity authentication, and uses the QRNG and PQC algorithms to sign to obtain a ciphertext (i.e., the fourth ciphertext in this application). Terminal A sends an authentication request message including the ciphertext to the business application system, requesting the business application system to perform authentication. The business application system calls the key management system, uses the QRNG and PQC algorithms to decrypt the basic information, and uses the QRNG and PQC algorithms to verify the signature, that is, the business application system forwards the authentication request message including the ciphertext to the key management system. The key management system returns the basic information and the signature verification result to the business application system. The business application system returns the authentication result to terminal A.

[0169] S3. Encrypted communication: Terminal A calls the quantum SIM card, uses the QRNG and PQC algorithms to encrypt the information of both communicating parties, and uses the QRNG and PQC algorithms to sign, obtaining the ciphertext Ka(A, B) (i.e., the third ciphertext in this application), i.e., PQC-encrypted Ka(A, B). The key management system uses the QRNG card to generate the session key Ks, a one-time key. The key management system uses the PQC-encrypted public keys of both communicating parties to encrypt the session key, obtaining the ciphertext Ka(Ks, Kb(A, Ks)) (i.e., the first ciphertext in this application), i.e., PQC-encrypted Ka(Ks, Kb(A, Ks)). Terminal A uses the PQC-encrypted private key to decrypt and obtain the session key and ciphertext Kb(A, Ks) (i.e., the second ciphertext in this application). Terminal A sends the ciphertext Kb(A, Ks) to terminal B (i.e., the called party in this application), i.e., PQC-encrypted Kb(A, Ks). Terminal A and terminal B use Ks for encrypted communication to achieve quantum secure communication.

[0170] This application integrates the QRNG and PQC algorithm modules in the SIM card to avoid pre-filling keys, generate keys in real time, simplify user operations and improve convenience.

[0171] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of method. In order to realize the above functions, it includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily appreciate that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0172] In an embodiment of the present application, a communication method can be divided into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. Optionally, the division of modules in the embodiment of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods.

[0173] Figure 14 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Figure 14 As shown, a communication device 160 is used to improve the user experience during quantum secure communication, for example, for performing Figure 2 The communication device 160 includes a processing unit 1601 and a transmission unit 1602 .

[0174] The processing unit 1601 is configured to call a user identity recognition module of the calling end to generate a first quantum key pair.

[0175] The transmission unit 1602 is used to receive a first ciphertext from the key management system, where the first ciphertext is obtained by encrypting a session key based on a first quantum key pair and a second quantum key pair, where the second quantum key pair is generated by the called party calling the user identity module of the called party.

[0176] The processing unit 1601 is further configured to decrypt the first ciphertext based on the first quantum key pair to obtain a session key.

[0177] The transmission unit 1602 is further configured to communicate with the called party based on the session key.

[0178] In one possible implementation, processing unit 1601 is further configured to decrypt the first ciphertext using the first quantum key to obtain a session key and a second ciphertext, where the second ciphertext is obtained by encrypting the session key and the identity information of the calling party using the second quantum key pair. Transmission unit 1602 is further configured to send the second ciphertext to the called party.

[0179] In one possible implementation, the processing unit 1601 is further configured to encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key pair to obtain a third ciphertext; and the transmission unit 1602 is further configured to send the third ciphertext to the key management system.

[0180] In one possible implementation, the processing unit 1601 is further used to encrypt and sign the identity information of the calling end based on the first quantum key to obtain a fourth ciphertext; the transmission unit 1602 is further used to send the fourth ciphertext to the quantum communication station; the transmission unit 1602 is further used to receive the identity authentication result sent by the quantum communication station; the processing unit 1601 is further used to encrypt and sign the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain a third ciphertext when the identity authentication result is authentication passed.

[0181] Figure 15 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Figure 15 As shown, a communication device 170 is used to improve the user experience during quantum secure communication, for example, to perform Figure 6 The communication device 170 includes a transmission unit 1701 and a processing unit 1702 .

[0182] Transmission unit 1701 is used to obtain a first quantum key pair of the calling end and a second quantum key pair of the called end, where the first quantum key pair is generated by calling the user identity identification module of the calling end, and the second quantum key pair is generated by calling the user identity identification module of the called end.

[0183] The processing unit 1702 is configured to generate a session key based on a second algorithm.

[0184] The processing unit 1702 is further configured to encrypt the session key based on the first quantum key pair and the second quantum key pair to obtain a first ciphertext.

[0185] The transmission unit 1701 is further configured to send a first ciphertext to the calling end, where the first ciphertext is used by the calling end to obtain a session key so as to communicate with the called end based on the session key.

[0186] In one possible implementation, the transmission unit 1701 is further used to receive a third ciphertext from the calling end; decrypt the third ciphertext based on the first quantum key pair to obtain the identity information of the calling end and the identity information of the called end; and the processing unit 1702 is further used to generate a session key based on the quantum random number generator when it is confirmed that the calling end and the called end are allowed to communicate based on the identity information of the calling end and the identity information of the called end.

[0187] In one possible implementation, the processing unit 1702 is further used to encrypt the identity information and session key of the calling party based on the second quantum key to obtain a second ciphertext; the processing unit 1702 is further used to encrypt the session key and the second ciphertext based on the first quantum key pair to obtain a first ciphertext.

[0188] In one possible implementation, the transmission unit 1701 is further used to receive a fourth ciphertext from the quantum communication station; the processing unit 1702 is further used to decrypt and verify the fourth ciphertext based on the first quantum key pair to obtain the identity information and verification result of the calling party; the transmission unit 1701 is further used to send the identity information and verification result of the calling party to the quantum communication station.

[0189] Figure 16 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Figure 16 As shown, a communication device 180 is used to improve the user experience during quantum secure communication, for example, to perform Figure 10 The communication device 180 includes a transmission unit 1801 and a processing unit 1802.

[0190] Transmission unit 1801 is used to receive a fourth ciphertext from the calling end, where the fourth ciphertext is obtained by encrypting and signing the identity information of the calling end based on the first quantum key pair, where the first quantum key pair is generated by the calling end calling the user identity identification module of the calling end.

[0191] The transmission unit 1801 is further configured to send the fourth ciphertext to the key management system.

[0192] The transmission unit 1801 is further configured to receive the identity information of the calling party and the signature verification result sent by the key management system.

[0193] The processing unit 1802 is configured to determine an identity authentication result based on the identity information of the calling party and the signature verification result.

[0194] The transmission unit 1801 is further configured to send the identity authentication result to the calling party.

[0195] Figure 17 This is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Figure 17As shown, a communication device 190 is used to improve the user experience during quantum secure communication, for example, for performing Figure 11 The communication device 190 includes a processing unit 1901 and a transmission unit 1902.

[0196] The processing unit 1901 is configured to call the user identity recognition module of the called party to generate a second quantum key pair.

[0197] The transmission unit 1902 is configured to receive a second ciphertext from the calling end.

[0198] The processing unit 1901 is further configured to decrypt the second ciphertext based on the second quantum key pair to obtain the session key and the identity information of the calling party.

[0199] The transmission unit 1902 is further configured to communicate with the calling party based on the session key.

[0200] In the case of implementing the functions of the above-mentioned integrated modules in the form of hardware, the embodiment of the present application provides a possible structural diagram of the electronic device involved in the above-mentioned embodiment. Figure 18 As shown, an electronic device 200 is used to improve the user experience during quantum secure communication, for example, Figure 2 The electronic device 200 includes a processor 2001, a memory 2002, and a bus 2003. The processor 2001 and the memory 2002 may be connected via the bus 2003.

[0201] Processor 2001 is the control center of the communication device and can be a single processor or a collective term for multiple processing elements. For example, processor 2001 can be a general-purpose central processing unit (CPU) or other general-purpose processor. The general-purpose processor can be a microprocessor or any conventional processor.

[0202] As an embodiment, the processor 2001 may include one or more CPUs, such as Figure 18 CPU 0 and CPU 1 are shown in Figure 1.

[0203] The memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0204] As a possible implementation, memory 2002 can exist independently of processor 2001. Memory 2002 can be connected to processor 2001 via bus 2003 to store instructions or program codes. When processor 2001 calls and executes the instructions or program codes stored in memory 2002, a communication method provided in an embodiment of the present application can be implemented.

[0205] In another possible implementation, the memory 2002 may also be integrated with the processor 2001 .

[0206] Bus 2003 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. This bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 18 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0207] It should be pointed out that Figure 18 The structure shown does not constitute a limitation on the electronic device 200. Figure 18 In addition to the components shown, the electronic device 200 may include more or fewer components than shown, or combine certain components, or arrange the components differently.

[0208] As an example, combining Figure 14 The functions implemented by the processing unit 1601 and the transmission unit 1602 in the communication device 160 are the same as those implemented by the Figure 18 The functions of processor 2001 are the same as those of processor 2001 in FIG.

[0209] Optional, such as Figure 18 As shown, the electronic device 200 provided in the embodiment of the present application may further include a communication interface 2004 .

[0210] The communication interface 2004 is used to connect to other devices via a communication network. The communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc. The communication interface 2004 can include a receiving unit for receiving data and a sending unit for sending data.

[0211] In one design, in the electronic device provided in the embodiment of the present application, the communication interface can also be integrated into the processor.

[0212] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above-mentioned functional units is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units as needed, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. The specific working processes of the above-mentioned systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0213] An embodiment of the present application further provides a computer-readable storage medium, in which instructions are stored. When a computer executes the instructions, the computer executes each step in the method flow shown in the above method embodiment.

[0214] An embodiment of the present application provides a computer program product. When a computer instruction is executed on an electronic device, the electronic device executes a communication method in the above method embodiment.

[0215] Among them, the computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable computer disk, a hard disk. Random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any other form of computer-readable storage media in a suitable combination of the above, or values ​​in this field.

[0216] An exemplary storage medium is coupled to a processor so that the processor can read information from and write information to the storage medium. Alternatively, the storage medium may be an integral part of the processor. The processor and storage medium may be located in an application-specific integrated circuit (ASIC).

[0217] In the embodiments of the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0218] Since the electronic device, computer-readable storage medium, and computer program product in the embodiments of the present application can be applied to the above method, the technical effects that can be obtained can also refer to the above method embodiments, and the embodiments of the present application will not be repeated here.

[0219] The above are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application should be included in the protection scope of the present application.

Claims

1. A communication method, characterized in that: Applied to the calling end, the method includes: Calling a first algorithm to generate a first quantum key pair; receiving a first ciphertext from a key management system, where the first ciphertext is obtained by encrypting a session key based on the first quantum key pair and a second quantum key pair, where the second quantum key pair is generated by the called party by calling the first algorithm; decrypting the first ciphertext based on the first quantum key pair to obtain the session key; Communicate with the called party based on the session key.

2. The method according to claim 1, characterized in that Decrypting the first ciphertext based on the first quantum key pair to obtain the session key includes: decrypting the first ciphertext based on the first quantum key to obtain the session key and a second ciphertext, where the second ciphertext is obtained by encrypting the session key and the identity information of the calling party based on the second quantum key pair; After decrypting the first ciphertext based on the first quantum key pair to obtain the session key, the method further includes: The second ciphertext is sent to the called party.

3. The method according to claim 1, characterized in that Before receiving the first ciphertext from the key management system, the method further includes: Encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key pair to obtain a third ciphertext; The third ciphertext is sent to the key management system.

4. The method according to claim 3, characterized in that Before encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key pair, the method further includes: Encrypting and signing the identity information of the calling end based on the first quantum key to obtain a fourth ciphertext; Sending the fourth ciphertext to the quantum communication station; Receiving an identity authentication result sent by the quantum communication station; The encrypting and signing the identity information of the calling end and the identity information of the called end based on the first quantum key to obtain a third ciphertext includes: When the identity authentication result is authentication passed, the identity information of the calling end and the identity information of the called end are encrypted and signed based on the first quantum key to obtain the third ciphertext.

5. The method according to claim 3 or 4, characterized in that The first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verifying signatures.

6. The method according to claim 1, characterized in that The first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

7. A communication method, characterized in that: Applied to a key management system, the method includes: Obtaining a first quantum key pair of the calling end and a second quantum key pair of the called end, where the first quantum key pair is generated by calling a first algorithm, and the second quantum key pair is generated by calling the first algorithm; generating a session key based on a second algorithm; Encrypting the session key based on the first quantum key pair and the second quantum key to obtain a first ciphertext; The first ciphertext is sent to the calling end, where the first ciphertext is used by the calling end to obtain the session key so as to communicate with the called end based on the session key.

8. The method according to claim 7, characterized in that Before generating the session key based on the second algorithm, the method further includes: receiving a third ciphertext from the calling terminal; decrypting the third ciphertext based on the first quantum key pair to obtain the identity information of the calling end and the identity information of the called end; Generating a session key based on a second algorithm includes: In a case where it is confirmed based on the identity information of the calling end and the identity information of the called end that the calling end is allowed to communicate with the called end, the session key is generated based on a quantum random number generator.

9. The method according to claim 8, characterized in that The encrypting the session key based on the first quantum key pair and the second quantum key to obtain a first ciphertext includes: Encrypting the identity information of the calling party and the session key based on the second quantum key to obtain a second ciphertext; The session key and the second ciphertext are encrypted based on the first quantum key pair to obtain the first ciphertext.

10. The method according to claim 8, characterized in that Before receiving the third ciphertext from the calling terminal, the method further includes: receiving a fourth ciphertext from the quantum communication station; Decrypting and verifying the signature of the fourth ciphertext based on the first quantum key pair to obtain the identity information of the calling end and a signature verification result; The identity information and signature verification result of the calling party are sent to the quantum communication station.

11. The method according to claim 8 or 10, characterized in that The first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verifying signatures.

12. The method according to claim 7, characterized in that The first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm, and the second algorithm is a quantum random number generator.

13. A communication method, characterized in that: Applied to a quantum communication station, the method comprises: receiving a fourth ciphertext from the calling end, where the fourth ciphertext is obtained by encrypting and signing the identity information of the calling end based on a first quantum key pair, where the first quantum key pair is generated by the calling end by calling a first algorithm; Sending the fourth ciphertext to the key management system; Receiving the identity information and signature verification result of the calling party sent by the key management system; Determining an identity authentication result based on the identity information of the calling party and the signature verification result; Sending the identity authentication result to the calling party.

14. The method according to claim 13, characterized in that If the identity information of the calling party is authenticated successfully and the signature verification result is verified successfully, the identity authentication result is authenticated successfully; If the identity information authentication of the calling party fails, and / or the signature verification result is verification failure, the identity authentication result is authentication failure.

15. The method according to claim 13, characterized in that The first quantum key pair includes a first quantum key pair for encryption and decryption and a first quantum key pair for signing and verifying signatures.

16. A communication method, characterized in that: Applied to the called party, the method includes: Calling the first algorithm to generate a second quantum key pair; receiving a second ciphertext from the calling end; decrypting the second ciphertext based on the second quantum key pair to obtain the session key and the identity information of the calling end; Communicate with the calling party based on the session key.

17. The method according to claim 16, characterized in that The first quantum key pair includes a first quantum key pair for encryption and decryption; The first algorithm includes a quantum random number generator and a post-quantum cryptographic algorithm.

18. A communication device, characterized in that: The communication device includes: a processing unit and a transmission unit; The processing unit is configured to call the user identity recognition module of the calling terminal to generate a first quantum key pair; The transmission unit is configured to receive a first ciphertext from a key management system, where the first ciphertext is obtained by encrypting a session key based on the first quantum key pair and the second quantum key pair, where the second quantum key pair is generated by the called party calling a user identity module of the called party; The processing unit is further configured to decrypt the first ciphertext based on the first quantum key pair to obtain the session key; The transmission unit is further configured to communicate with the called party based on the session key.

19. An electronic device, characterized in that: include: processor and memory; The memory is used to store one or more programs, and the one or more programs include computer-executable instructions. When the electronic device is running, the processor executes the computer-executable instructions stored in the memory to enable the electronic device to perform the method described in any one of claims 1 to 17.

20. A computer-readable storage medium storing one or more programs, characterized in that: The one or more programs include instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1-17.

21. A computer program product, characterized in that The computer program product comprises computer instructions. When the computer instructions are executed on an electronic device, the electronic device performs the method according to any one of claims 1 to 17.