Authentication method and device for quantum encryption communication
Through hierarchical key design and two-way timestamp authentication mechanism, the problems of key unification and key residue in quantum encryption communication are solved, the secure separation and trusted destruction of quantum encryption communication are realized, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202511119409.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-09-26
AI Technical Summary
Existing quantum encryption communication technology has the problem of key singularity, the attack surface is expanded and there is a lack of a trusted destruction mechanism. The residual key after the session is terminated may cause the risk of key reuse.
A hierarchical key design is adopted, including authentication layer keys, communication layer keys and verification layer keys. The separation and secure destruction of keys are achieved through two-way timestamp authentication, dynamic binding of session identifiers and verifiable key destruction protocols.
It significantly reduces the attack surface, prevents man-in-the-middle attacks and replay attacks, ensures that each session uses a unique key, eliminates the risk of key residue after the session is terminated, and provides end-to-end security.
Smart Images

Figure CN120710792A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an authentication method and device for quantum encryption communication. Background Art
[0002] With the rapid development of quantum computing technology, traditional encryption systems face severe challenges. Quantum cryptography, due to its theoretically unbreakable security, is becoming a crucial technology for ensuring information security. Quantum cryptography, based on the principle of quantum non-cloning, has achieved secure communication within metropolitan areas. However, existing quantum cryptography suffers from two authentication issues: First, key uniformity is a prominent issue; most solutions use the same key for both authentication and communication, expanding the attack surface. Second, the lack of a trusted destruction mechanism means that residual keys after session termination may pose a risk of key reuse. Summary of the Invention
[0003] This application provides a method and device for authenticating quantum cryptographic communications to address the problems raised in the above-mentioned background technology.
[0004] In a first aspect, the present application provides a method for authenticating quantum cryptographic communication, an authentication device for quantum cryptographic communication, the device comprising a quantum key server and an external device, the method comprising: The quantum key server responds to the authentication request of the external device, performs identity authentication on the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key; After the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key; After the session ends, the quantum key server and the external device perform key destruction based on the verification layer key.
[0005] In one possible implementation, the quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key, including: The quantum key server sends the authentication layer key to the external device, generates a first timestamp, encrypts the first timestamp based on the authentication layer key to obtain a first encrypted ciphertext, and sends the first encrypted ciphertext to the external device; After receiving the authentication layer key and the first encrypted ciphertext, the external device decrypts the first encrypted ciphertext based on the authentication layer key to obtain the first timestamp, determines whether a first time difference between the first timestamp and the current moment is greater than a preset time length, generates a second timestamp, encrypts the second timestamp based on the authentication layer key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the quantum key server; After receiving the second encrypted ciphertext, the quantum key server decrypts the second encrypted ciphertext based on the authentication layer key to obtain the second timestamp, and determines whether a second time difference between the second timestamp and the current moment is greater than a preset time length; When the first time difference is not greater than the preset duration and the second time difference is not greater than the preset duration, the two-way timestamp authentication succeeds.
[0006] In a possible implementation, the quantum key server and the external device conduct a conversation based on the communication layer key, including: The quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, and sends the session identifier to the external device; The external device generates a communication key based on the communication layer key and the session identifier, encrypts the session request based on the communication key to obtain a third ciphertext, and sends the third ciphertext to the quantum key server; The quantum key server generates a decryption password based on the communication layer key and the session identifier, and decrypts the third ciphertext based on the decryption password to obtain the session request.
[0007] In a possible implementation, the quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, including: Inputting the first time difference into a preset hash algorithm to obtain a first hash value, and inputting the second time difference into a preset hash algorithm to obtain a second hash value; Adding the digits in the first hash value to obtain a first target value, and adding the digits in the second hash value to obtain a second target value; Obtaining a preset coding algorithm matrix; wherein the coding algorithms at various positions in the coding algorithm matrix are different from each other; Determining a first target encoding algorithm and a second target encoding algorithm in the encoding algorithm matrix based on the first target value and the second target value; wherein the number of rows at the position where the first target encoding algorithm is located is consistent with the first target value, the number of columns at the position where the first target encoding algorithm is located is consistent with the second target value, the number of rows at the position where the second target encoding algorithm is located is consistent with the second target value, and the number of columns at the position where the second target encoding algorithm is located is consistent with the first target value; Encoding the device identifier based on the first target encoding algorithm to obtain a first encoding sequence, and encoding the authentication layer key based on the second target encoding algorithm to obtain a second encoding sequence; Counting the total number of characters in the first coding sequence and the second coding sequence, and generating a blank matrix based on the total number of characters; the blank matrix is a square matrix, and the number of blank positions in the blank matrix is a perfect square number that is greater than the total number of characters and has the smallest difference from the total number of characters; Inserting each character in the first coding sequence and the second coding sequence into the blank position of the blank matrix in sequence to obtain an intermediate matrix, and filling the blank positions of the intermediate matrix based on preset characters to obtain a target matrix; the target matrix is the session identifier.
[0008] In a possible implementation, the external device generates a communication key based on the communication layer key and the session identifier, including: Determining a third target value, a fourth target value, and a fifth target value based on the target matrix; wherein the third target value is the minimum value among the matrix elements of the target matrix, the fourth target value is the average value among the matrix elements of the target matrix, and the fifth target value is the maximum value among the matrix elements of the target matrix; generating a target Fibonacci sequence using the third target value as a first term of the Fibonacci sequence and the fourth target value as a second term of the Fibonacci sequence; wherein the number of terms in the target Fibonacci sequence is consistent with the number of characters in the communication layer key; performing a modulo operation on each value of the target Fibonacci sequence based on the fifth target value to obtain a target sequence; Insert each digit of the communication layer key into each digit gap of the target number sequence in sequence to obtain the communication key.
[0009] In one possible implementation, the quantum key server and the external device perform key destruction based on the verification layer key, including: The quantum key server performs a hash operation on the last communication data to obtain a first hash digest, and encrypts the first hash digest based on the verification layer key to obtain a first destruction certificate; The external device performs a hash operation on the last communication data to obtain a second hash digest, and encrypts the second hash digest based on the verification layer key to obtain a second destruction certificate; The quantum key server sends the first destruction certificate to the external device; The external device sends the second destruction certificate to the quantum key server; After receiving the first destruction certificate, the external device decrypts the first destruction certificate based on the verification layer key to obtain a first hash digest, and determines whether the first hash digest is consistent with the second hash digest. If they are consistent, the external device deletes the authentication layer key, the communication layer key, and the verification layer key. After receiving the second destruction certificate, the quantum key server decrypts the second destruction certificate based on the verification layer key to obtain a second hash digest, and determines whether the second hash digest is consistent with the first hash digest. If they are consistent, the authentication layer key, communication layer key and verification layer key are deleted.
[0010] In a second aspect, the present application provides an authentication device for quantum cryptographic communication, including a quantum key server and an external device, the purpose of the device is as follows: The quantum key server responds to the authentication request of the external device, performs identity authentication on the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key; After the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key; After the session ends, the quantum key server and the external device perform key destruction based on the verification layer key.
[0011] The present application provides a method and apparatus for authenticating quantum cryptographic communication, an authentication apparatus for quantum cryptographic communication, the apparatus comprising a quantum key server and an external device, the method comprising: the quantum key server responding to an authentication request from an external device, performing identity authentication on the external device, and generating an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; the quantum key server and the external device performing two-way timestamp authentication based on the authentication layer key; after the two-way timestamp authentication is passed, the quantum key server and the external device perform a conversation based on the communication layer key; after the conversation ends, the quantum key server and the external device perform key destruction based on the verification layer key. This method, first, solves the key singularity problem through layered key design, separates the authentication, communication, and destruction functions, and significantly reduces the attack surface of each link. Secondly, the two-way timestamp authentication mechanism based on the authentication layer key helps to resist man-in-the-middle attacks and replay attacks. Then, the dynamic binding mechanism of the communication layer key and the session identifier ensures that a unique key is used for each session, avoiding the security risks of key reuse in traditional schemes. Finally, through the verifiable destruction protocol of the verification layer key, a two-way hash digest comparison is used to achieve key clearing, fundamentally eliminating the risk of key residue after the session termination, and providing an end-to-end security guarantee closed loop for quantum encryption communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0013] Figure 1 A schematic diagram of a flow chart of a method for authenticating quantum cryptographic communication provided in an embodiment of the present application; Figure 2 A schematic block diagram of the structure of the authentication device for quantum cryptographic communication provided in an embodiment of the present application. DETAILED DESCRIPTION
[0014] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0015] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, combined, or partially merged, so the actual execution order may vary depending on the actual situation.
[0016] It should also be understood that the terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit the present application. As used in this specification and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0017] It should be further understood that the term "and / or" used in this specification and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0018] The following describes some embodiments of the present application in detail with reference to the accompanying drawings. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.
[0019] See also Figure 1 , Figure 1 A flow chart of a method for authenticating quantum cryptographic communication provided in an embodiment of the present application, wherein the method is used in an authentication device 100 for quantum cryptographic communication, such as Figure 2 As shown, the authentication device 100 for quantum cryptographic communication includes a quantum key server 110 and an external device 120, as shown in FIG. Figure 1 As shown, the authentication method for quantum encryption communication provided in an embodiment of the present application includes steps S1 to S4.
[0020] Step S1: The quantum key server responds to the authentication request of the external device, performs identity authentication on the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed.
[0021] Step S2: The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key.
[0022] Step S3: After the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key.
[0023] Step S4: After the session ends, the quantum key server and the external device perform key destruction based on the verification layer key.
[0024] In this embodiment, it specifically includes: As described in step S1 above, the quantum key server responds to the authentication request from the external device, authenticates the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is successful. Specifically, the external device sends a session request to the quantum key server. After receiving the session request, the quantum key server traverses a preset authorized device information table. If the device identifier of the external device is found in the authorized device information table, it determines that the identity authentication is successful and generates an authentication layer key, a communication layer key, and a verification layer key through a quantum key generator.
[0025] As described in step S2 above, the quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key. Specifically, step S2 includes: the quantum key server sends the authentication layer key to the external device, and at the same time generates a first timestamp, and encrypts the first timestamp based on the authentication layer key to obtain a first encrypted ciphertext, and sends the first encrypted ciphertext to the external device; after the external device receives the authentication layer key and the first encrypted ciphertext, it decrypts the first encrypted ciphertext based on the authentication layer key to obtain the first timestamp, and determines whether a first time difference between the first timestamp and the current moment is greater than a preset time length, and at the same time generates a second timestamp, and encrypts the second timestamp based on the authentication layer key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the quantum key server; after the quantum key server receives the second encrypted ciphertext, it decrypts the second encrypted ciphertext based on the authentication layer key to obtain a second timestamp, and determines whether a second time difference between the second timestamp and the current moment is greater than a preset time length; when the first time difference is not greater than the preset time length and the second time difference is not greater than the preset time length, the two-way timestamp authentication is passed.
[0026] As described in step S3 above, after the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key. Specifically, step S3 includes: the quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, and sends the session identifier to the external device; the external device generates a communication key based on the communication layer key and the session identifier, encrypts the session request based on the communication key to obtain a third ciphertext, and sends the third ciphertext to the quantum key server; the quantum key server generates a decryption password based on the communication layer key and the session identifier, and decrypts the third ciphertext based on the decryption password to obtain the session request.
[0027] As described in step S4 above, after the session ends, the quantum key server and the external device perform key destruction based on the verification layer key. Specifically, step S4 includes: the quantum key server performs a hash operation on the last communication data to obtain a first hash digest, and encrypts the first hash digest based on the verification layer key to obtain a first destruction certificate; the external device performs a hash operation on the last communication data to obtain a second hash digest, and encrypts the second hash digest based on the verification layer key to obtain a second destruction certificate; the quantum key server sends the first destruction certificate to the external device; the external device sends the first destruction certificate to the external device; The second destruction certificate is sent to the quantum key server; after the external device receives the first destruction certificate, it decrypts the first destruction certificate based on the verification layer key to obtain a first hash digest, and determines whether the first hash digest is consistent with the second hash digest. If they are consistent, the authentication layer key, the communication layer key, and the verification layer key are deleted; after the quantum key server receives the second destruction certificate, it decrypts the second destruction certificate based on the verification layer key to obtain a second hash digest, and determines whether the second hash digest is consistent with the first hash digest. If they are consistent, the authentication layer key, the communication layer key, and the verification layer key are deleted.
[0028] The method provided in this embodiment, first, solves the key singularity problem through a layered key design, separates the authentication, communication, and destruction functions, and significantly reduces the attack surface of each link. Secondly, the two-way timestamp authentication mechanism based on the authentication layer key helps to resist man-in-the-middle attacks and replay attacks. Then, the dynamic binding mechanism of the communication layer key and the session identifier ensures that a unique key is used for each session, avoiding the security risks of key reuse in traditional schemes. Finally, through the verifiable destruction protocol of the verification layer key, a two-way hash digest comparison is used to achieve key clearing, fundamentally eliminating the risk of key residue after the session termination, and providing an end-to-end security guarantee closed loop for quantum encryption communication.
[0029] In some embodiments, the quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key, including the following steps: The quantum key server sends the authentication layer key to the external device, generates a first timestamp, encrypts the first timestamp based on the authentication layer key to obtain a first encrypted ciphertext, and sends the first encrypted ciphertext to the external device; After receiving the authentication layer key and the first encrypted ciphertext, the external device decrypts the first encrypted ciphertext based on the authentication layer key to obtain the first timestamp, determines whether a first time difference between the first timestamp and the current moment is greater than a preset time length, generates a second timestamp, encrypts the second timestamp based on the authentication layer key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the quantum key server; After receiving the second encrypted ciphertext, the quantum key server decrypts the second encrypted ciphertext based on the authentication layer key to obtain the second timestamp, and determines whether a second time difference between the second timestamp and the current moment is greater than a preset time length; When the first time difference is not greater than the preset duration and the second time difference is not greater than the preset duration, the two-way timestamp authentication succeeds.
[0030] The method provided in this embodiment, first, realizes two-way identity authentication by exchanging encrypted timestamps between a quantum key server and an external device, effectively solving the security risk that the server may be counterfeited in traditional one-way authentication. Secondly, the timestamp is encrypted and transmitted using the authentication layer key, which not only ensures the security of time synchronization information, but also prevents man-in-the-middle attacks by utilizing the non-replicability of the quantum key. Then, through timestamp comparison and preset time threshold verification, any abnormal requests caused by replay attacks or network delays can be accurately identified and intercepted. Finally, the two-way time difference verification mechanism forms a closed-loop verification. The authentication is considered successful only when the timestamps at both ends pass the timeliness verification, thereby building a multi-level, high-precision security protection system and improving the overall security of the quantum encryption communication system.
[0031] In some embodiments, the quantum key server and the external device conduct a conversation based on the communication layer key, comprising the following steps: The quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, and sends the session identifier to the external device; The external device generates a communication key based on the communication layer key and the session identifier, encrypts the session request based on the communication key to obtain a third ciphertext, and sends the third ciphertext to the quantum key server; The quantum key server generates a decryption password based on the communication layer key and the session identifier, and decrypts the third ciphertext based on the decryption password to obtain the session request.
[0032] The method provided in this embodiment, first, generates a session identifier by dynamically binding multiple factors such as device identification, authentication layer key, and two-way time difference, thereby ensuring the uniqueness and unpredictability of each session identifier. Secondly, it uses quantum encryption technology to provide end-to-end protection for session requests, which not only ensures the confidentiality of communication content but also resists the risk of data tampering through an integrity verification mechanism.
[0033] In some embodiments, the quantum key server generates a session identifier based on the device identification of the external device, the authentication layer key, the first time difference, and the second time difference, comprising the following steps: Inputting the first time difference into a preset hash algorithm to obtain a first hash value, and inputting the second time difference into a preset hash algorithm to obtain a second hash value; Adding the digits in the first hash value to obtain a first target value, and adding the digits in the second hash value to obtain a second target value; Obtaining a preset coding algorithm matrix; wherein the coding algorithms at various positions in the coding algorithm matrix are different from each other; Determining a first target encoding algorithm and a second target encoding algorithm in the encoding algorithm matrix based on the first target value and the second target value; wherein the number of rows at the position where the first target encoding algorithm is located is consistent with the first target value, the number of columns at the position where the first target encoding algorithm is located is consistent with the second target value, the number of rows at the position where the second target encoding algorithm is located is consistent with the second target value, and the number of columns at the position where the second target encoding algorithm is located is consistent with the first target value; Encoding the device identifier based on the first target encoding algorithm to obtain a first encoding sequence, and encoding the authentication layer key based on the second target encoding algorithm to obtain a second encoding sequence; Counting the total number of characters in the first coding sequence and the second coding sequence, and generating a blank matrix based on the total number of characters; the blank matrix is a square matrix, and the number of blank positions in the blank matrix is a perfect square number that is greater than the total number of characters and has the smallest difference from the total number of characters; Sequentially inserting each character in the first and second coding sequences into the blank positions of the blank matrix to obtain an intermediate matrix, and then filling the blank positions of the intermediate matrix with preset characters to obtain a target matrix; the target matrix is the session identifier. Specifically, first, each character in the first coding sequence is sequentially inserted into the blank matrix, and then each character in the second coding sequence is sequentially inserted into the blank matrix to obtain an intermediate matrix.
[0034] The method provided in this embodiment, first, by combining the time difference hash value with digital feature extraction, constructs a dynamically variable encoding algorithm selection mechanism, so that the session identifier generation process has the characteristics of resistance to analysis and cracking. Secondly, by utilizing the bidirectional coordinate positioning function of the encoding algorithm matrix, asymmetric encoding processing of device identification and quantum key is realized, effectively preventing the security risks brought by fixed encoding mode. Then, the design of dynamically generating and intelligently filling blank matrices based on the total number of characters ensures the adaptability of the information capacity of the session identifier while increasing the complexity of the data structure through matrix transformation. Finally, through the hybrid operation of ordered insertion and preset character filling, a highly random and unique session identifier is finally generated, providing a verifiable and difficult-to-forge session credential for quantum encryption communication, significantly improving the overall security of the system.
[0035] In some embodiments, the external device generates a communication key based on the communication layer key and the session identifier, comprising the following steps: Determining a third target value, a fourth target value, and a fifth target value based on the target matrix; wherein the third target value is the minimum value among the matrix elements of the target matrix, the fourth target value is the average value among the matrix elements of the target matrix, and the fifth target value is the maximum value among the matrix elements of the target matrix; generating a target Fibonacci sequence using the third target value as the first term of the Fibonacci sequence and the fourth target value as the second term of the Fibonacci sequence; wherein the number of terms in the target Fibonacci sequence is consistent with the number of characters in the communication-layer key; illustratively, if the third target value is 3, the fourth target value is 10, and the number of characters in the communication-layer key is 5, then the target Fibonacci sequence is 3, 10, 13, 23, and 36; performing a modulo operation on each value of the target Fibonacci sequence based on the fifth target value to obtain a target sequence; specifically, for each value of the target Fibonacci sequence, using the remainder obtained after dividing the value by the fifth target value as the modulus of the value; Insert each digit of the communication layer key into each digit gap of the target number sequence in sequence to obtain the communication key.
[0036] The method provided in this embodiment, first, constructs a multi-dimensional dynamic parameter system by extracting the minimum, average and maximum three key values from the target matrix, providing a rich source of randomness for communication key generation. Secondly, the Fibonacci sequence generation mechanism is adopted to convert static values into dynamically growing sequences, and the key's anti-cracking ability is enhanced by the irreversible nature of the sequence. Then, a modulo operation based on the maximum value is introduced to ensure a reasonable range of the final sequence value and increase the unpredictability of the key transformation. Finally, by cross-integrating the communication layer key with the dynamic sequence, the generated communication key retains the original security of the quantum key and incorporates the dynamic characteristics unique to the session, effectively resisting replay attacks and key derivation risks.
[0037] In some embodiments, the quantum key server and the external device perform key destruction based on the verification layer key, including the following steps: The quantum key server performs a hash operation on the last communication data to obtain a first hash digest, and encrypts the first hash digest based on the verification layer key to obtain a first destruction certificate; The external device performs a hash operation on the last communication data to obtain a second hash digest, and encrypts the second hash digest based on the verification layer key to obtain a second destruction certificate; The quantum key server sends the first destruction certificate to the external device; The external device sends the second destruction certificate to the quantum key server; After receiving the first destruction certificate, the external device decrypts the first destruction certificate based on the verification layer key to obtain a first hash digest, and determines whether the first hash digest is consistent with the second hash digest. If they are consistent, the external device deletes the authentication layer key, the communication layer key, and the verification layer key. After receiving the second destruction certificate, the quantum key server decrypts the second destruction certificate based on the verification layer key to obtain a second hash digest, and determines whether the second hash digest is consistent with the first hash digest. If they are consistent, the authentication layer key, communication layer key and verification layer key are deleted.
[0038] The method provided in this embodiment first constructs a mutually verified key destruction mechanism by bidirectionally generating and exchanging encrypted hash digests between a quantum key server and an external device, thereby ensuring the credibility and non-repudiation of the key destruction process. Then, the communication digest is end-to-end encrypted using a verification layer key, thereby ensuring the confidentiality of the destruction credential and preventing the credential from being forged or tampered with through the characteristics of quantum encryption. Finally, a bidirectional hash digest comparison and verification mechanism is used to strictly confirm the integrity and consistency of the communication data before key destruction, effectively preventing the risk of accidental destruction under abnormal conditions.
[0039] See also Figure 2 , Figure 2 The schematic block diagram of the structure of the authentication device 100 for quantum cryptographic communication provided in the embodiment of the present application is as follows: Figure 2 As shown, the authentication device 100 for quantum cryptography communication provided in an embodiment of the present application includes a quantum key server 110 and an external device 120. The functions of the authentication device 100 for quantum cryptography communication are as follows: The quantum key server 110 responds to the authentication request of the external device, authenticates the identity of the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; The quantum key server 110 and the external device 120 perform bidirectional timestamp authentication based on the authentication layer key; After the two-way timestamp authentication is passed, the quantum key server 110 and the external device 120 conduct a conversation based on the communication layer key; After the session ends, the quantum key server 110 and the external device 120 perform key destruction based on the verification layer key.
[0040] It should be noted that those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the processes in the aforementioned authentication method embodiment of quantum encryption communication and will not be repeated here.
[0041] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for authenticating quantum cryptographic communication, characterized in that: The method is used for an authentication device for quantum cryptographic communication, the device including a quantum key server and an external device, and the method includes: The quantum key server responds to the authentication request of the external device, performs identity authentication on the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key; After the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key; After the session ends, the quantum key server and the external device perform key destruction based on the verification layer key.
2. The authentication method for quantum encryption communication according to claim 1, characterized in that: The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key, including: The quantum key server sends the authentication layer key to the external device, generates a first timestamp, encrypts the first timestamp based on the authentication layer key to obtain a first encrypted ciphertext, and sends the first encrypted ciphertext to the external device; After receiving the authentication layer key and the first encrypted ciphertext, the external device decrypts the first encrypted ciphertext based on the authentication layer key to obtain the first timestamp, determines whether a first time difference between the first timestamp and the current moment is greater than a preset time length, generates a second timestamp, encrypts the second timestamp based on the authentication layer key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the quantum key server; After receiving the second encrypted ciphertext, the quantum key server decrypts the second encrypted ciphertext based on the authentication layer key to obtain the second timestamp, and determines whether a second time difference between the second timestamp and the current moment is greater than a preset time length; When the first time difference is not greater than the preset duration and the second time difference is not greater than the preset duration, the two-way timestamp authentication succeeds.
3. The authentication method for quantum encryption communication according to claim 2, characterized in that: The quantum key server and the external device conduct a conversation based on the communication layer key, including: The quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, and sends the session identifier to the external device; The external device generates a communication key based on the communication layer key and the session identifier, encrypts the session request based on the communication key to obtain a third ciphertext, and sends the third ciphertext to the quantum key server; The quantum key server generates a decryption password based on the communication layer key and the session identifier, and decrypts the third ciphertext based on the decryption password to obtain the session request.
4. The authentication method for quantum encryption communication according to claim 3, characterized in that: The quantum key server generates a session identifier based on the device identifier of the external device, the authentication layer key, the first time difference, and the second time difference, including: Inputting the first time difference into a preset hash algorithm to obtain a first hash value, and inputting the second time difference into a preset hash algorithm to obtain a second hash value; Adding the digits in the first hash value to obtain a first target value, and adding the digits in the second hash value to obtain a second target value; Obtaining a preset coding algorithm matrix; wherein the coding algorithms at various positions in the coding algorithm matrix are different from each other; Determining a first target encoding algorithm and a second target encoding algorithm in the encoding algorithm matrix based on the first target value and the second target value; wherein the number of rows at the position where the first target encoding algorithm is located is consistent with the first target value, the number of columns at the position where the first target encoding algorithm is located is consistent with the second target value, the number of rows at the position where the second target encoding algorithm is located is consistent with the second target value, and the number of columns at the position where the second target encoding algorithm is located is consistent with the first target value; Encoding the device identifier based on the first target encoding algorithm to obtain a first encoding sequence, and encoding the authentication layer key based on the second target encoding algorithm to obtain a second encoding sequence; Counting the total number of characters in the first coding sequence and the second coding sequence, and generating a blank matrix based on the total number of characters; the blank matrix is a square matrix, and the number of blank positions in the blank matrix is a perfect square number that is greater than the total number of characters and has the smallest difference from the total number of characters; Inserting each character in the first coding sequence and the second coding sequence into the blank position of the blank matrix in sequence to obtain an intermediate matrix, and filling the blank positions of the intermediate matrix based on preset characters to obtain a target matrix; the target matrix is the session identifier.
5. The authentication method for quantum encryption communication according to claim 4, characterized in that: The external device generates a communication key based on the communication layer key and the session identifier, including: Determining a third target value, a fourth target value, and a fifth target value based on the target matrix; wherein the third target value is the minimum value among the matrix elements of the target matrix, the fourth target value is the average value among the matrix elements of the target matrix, and the fifth target value is the maximum value among the matrix elements of the target matrix; generating a target Fibonacci sequence using the third target value as a first term of the Fibonacci sequence and the fourth target value as a second term of the Fibonacci sequence; wherein the number of terms in the target Fibonacci sequence is consistent with the number of characters in the communication layer key; performing a modulo operation on each value of the target Fibonacci sequence based on the fifth target value to obtain a target sequence; Insert each digit of the communication layer key into each digit gap of the target number sequence in sequence to obtain the communication key.
6. The authentication method for quantum encryption communication according to claim 1, characterized in that: The quantum key server and the external device perform key destruction based on the verification layer key, including: The quantum key server performs a hash operation on the last communication data to obtain a first hash digest, and encrypts the first hash digest based on the verification layer key to obtain a first destruction certificate; The external device performs a hash operation on the last communication data to obtain a second hash digest, and encrypts the second hash digest based on the verification layer key to obtain a second destruction certificate; The quantum key server sends the first destruction certificate to the external device; The external device sends the second destruction certificate to the quantum key server; After receiving the first destruction certificate, the external device decrypts the first destruction certificate based on the verification layer key to obtain a first hash digest, and determines whether the first hash digest is consistent with the second hash digest. If they are consistent, the external device deletes the authentication layer key, the communication layer key, and the verification layer key. After receiving the second destruction certificate, the quantum key server decrypts the second destruction certificate based on the verification layer key to obtain a second hash digest, and determines whether the second hash digest is consistent with the first hash digest. If they are consistent, the authentication layer key, communication layer key and verification layer key are deleted.
7. A quantum cryptographic communication authentication device, comprising a quantum key server and an external device, characterized in that: The quantum key server responds to the authentication request of the external device, performs identity authentication on the external device, and generates an authentication layer key, a communication layer key, and a verification layer key after the identity authentication is passed; The quantum key server and the external device perform bidirectional timestamp authentication based on the authentication layer key; After the two-way timestamp authentication is passed, the quantum key server and the external device conduct a conversation based on the communication layer key; After the session ends, the quantum key server and the external device perform key destruction based on the verification layer key.