Security authentication method and device, storage medium and electronic equipment
By using quantum technology to generate symmetric quantum keys and using single photons to transmit encrypted information, combined with classical encryption technology to transmit keys, the problem of low security of symmetric key identity authentication is solved, and high-reliability security authentication is achieved in a quantum computing environment.
Patent Information
- Application Number
- CN202510904676.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-09-30
AI Technical Summary
The existing technology for identity authentication based on symmetric keys has low security, especially under the quantum computing algorithm Grover algorithm, where the security is halved.
By introducing quantum technology, the first device is connected to the quantum key distribution sending device, and the second device is connected to the quantum key distribution receiving device, a symmetric quantum key is generated, and encrypted information is transmitted using single photons. Security authentication is performed through the non-replicability of the quantum state, and the second key is transmitted in combination with classical encryption technology to achieve secure authentication of the symmetric quantum key.
It improves the reliability of identity security authentication, prevents attacks in quantum computing environments, and ensures the security of information transmission and the non-eavesdropping nature of the authentication process.
Smart Images

Figure CN120729587A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum technology, and specifically to a security authentication method, device, storage medium, and electronic device. Background Art
[0002] In existing symmetric key authentication schemes, the initiator typically encrypts information using a shared key and then sends the encrypted information to the verifier. The verifier then decrypts the information using the same key to verify the integrity of the information and the identity of the sender. However, with the development of quantum technology, the use of the Grover algorithm (a quantum computing algorithm) can reduce the time required to crack symmetric keys from exponential to square root levels, thereby reducing the security of existing symmetric key-based identity authentication.
[0003] Currently, no effective solution has been proposed to the technical problem of low security in identity authentication based on symmetric keys in the existing technology. Summary of the Invention
[0004] The present application provides a security authentication method, device, storage medium and electronic device to at least solve the technical problem of low security of identity security authentication based on symmetric keys in the prior art.
[0005] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a security authentication method is provided, including: after a first device initiates a security authentication request to a second device, controlling the second device to send a random number to the first device, wherein the first device is connected to a quantum key distribution sending device, and the second device is connected to a quantum key distribution receiving device; controlling the first device to generate a single photon based on the random number, a first key and a second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, and the second key is a binary random key pre-generated by the first device, and the single photon carries at least encrypted random number information and timestamp information; transmitting the single photon and the second key to the second device; and performing security authentication on the first device based on the single photon and the second key.
[0006] Optionally, before controlling the second device to send a random number to the first device, the security authentication method also includes: controlling the quantum key distribution sending device and the quantum key distribution receiving device to jointly generate a first key; controlling the quantum key distribution sending device to send the first key to the first device, and controlling the quantum key distribution receiving device to send the first key to the second device; and controlling the first device and the second device to store the first key.
[0007] Optionally, controlling the first device to generate a single photon based on a random number, a first key, and a second key includes: generating a timestamp based on the current moment through the first device; encrypting the timestamp based on the first key to obtain a first encryption sequence; encrypting the random number based on the first key to obtain a second encryption sequence; splicing the first encryption sequence and the second encryption sequence to obtain a first target sequence, wherein the first target sequence is a binary sequence generated by the first device; and generating a single photon based on the first target sequence and the second key.
[0008] Optionally, generating a single photon based on the first target sequence and the second key includes: using the first target sequence as a target basis, wherein the target basis is the physical reference system used to prepare the single photon; using the second key as a target code, wherein the target code is the encoded information of the quantum state used to prepare the single photon; and generating the single photon based on the target basis and the target code.
[0009] Optionally, transmitting the single photon and the second key to the second device includes: transmitting the single photon to the second device through a first channel, wherein the first channel is a quantum optical fiber link between a quantum key distribution sending device and a quantum key distribution receiving device; transmitting the second key to the second device through a second channel, wherein the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device.
[0010] Optionally, security authentication of the first device is performed based on a single photon and a second key, including: controlling the second device to encrypt a random number and a timestamp based on the first key to obtain a second target sequence, wherein the second target sequence is a binary sequence generated by the second device; measuring the single photon according to the second target sequence to obtain a sequence to be detected, wherein the sequence to be detected is used to characterize the physical reference system of the quantum state corresponding to the single photon received by the second device; and security authentication of the first device is performed using the sequence to be detected and the second key.
[0011] Optionally, security authentication of the first device is performed using the sequence to be detected and the second key, including: obtaining the similarity between the sequence to be detected and the second key; when the similarity is less than a preset threshold, determining that the security authentication of the second device has failed; when the similarity is greater than or equal to the preset threshold, determining that the security authentication of the second device has succeeded.
[0012] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a security authentication device is also provided, including: a first sending unit, used to control the second device to send a random number to the first device after the first device initiates a security authentication request to the second device, wherein the first device is connected to the quantum key distribution sending end device, and the second device is connected to the quantum key distribution receiving end device; a first generating unit, used to control the first device to generate a single photon based on the random number, the first key and the second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, and the second key is a binary random key pre-generated by the first device, and the single photon carries at least encrypted random number information and timestamp information; a transmission unit, used to transmit the single photon and the second key to the second device; and an authentication unit, used to perform security authentication on the first device based on the single photon and the second key.
[0013] Optionally, the security authentication device also includes: a second generation unit, used to control the quantum key distribution sending device and the quantum key distribution receiving device to jointly generate a first key; a second sending unit, used to control the quantum key distribution sending device to send the first key to the first device, and control the quantum key distribution receiving device to send the first key to the second device; a storage unit, used to control the first device and the second device to store the first key.
[0014] Optionally, the first generation unit includes: a first generation subunit, used to generate a timestamp based on the current moment through the first device; a first encryption subunit, used to encrypt the timestamp based on the first key to obtain a first encryption sequence; a second encryption subunit, used to encrypt the random number based on the first key to obtain a second encryption sequence; a splicing subunit, used to splice the first encryption sequence and the second encryption sequence to obtain a first target sequence, wherein the first target sequence is a binary sequence generated by the first device; and a second generation subunit, used to generate a single photon based on the first target sequence and the second key.
[0015] Optionally, the second generation subunit includes: a first determination module, used to use the first target sequence as a target basis, wherein the target basis is the physical reference system used to prepare single photons; a second determination module, used to use the second key as a target code, wherein the target code is the coding information of the quantum state used to prepare single photons; and a generation module, used to generate single photons based on the target basis and the target code.
[0016] Optionally, the transmission unit includes: a first transmission subunit, used to transmit the single photon to the second device through a first channel, wherein the first channel is a quantum optical fiber link between the quantum key distribution sending device and the quantum key distribution receiving device; a second transmission subunit, used to transmit the second key to the second device through a second channel, wherein the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device.
[0017] Optionally, the authentication unit includes: a third encryption subunit, used to control the second device to encrypt a random number and a timestamp based on the first key to obtain a second target sequence, wherein the second target sequence is a binary sequence generated by the second device; a measurement subunit, used to measure single photons according to the second target sequence to obtain a sequence to be detected, wherein the sequence to be detected is used to characterize the physical reference system of the quantum state corresponding to the single photon received by the second device; and an authentication subunit, used to securely authenticate the first device using the sequence to be detected and the second key.
[0018] Optionally, the authentication subunit includes: an acquisition module for acquiring the similarity between the sequence to be detected and the second key; a third determination module for determining that the security authentication of the second device has failed when the similarity is less than a preset threshold; and a fourth determination module for determining that the security authentication of the second device has succeeded when the similarity is greater than or equal to the preset threshold.
[0019] In this application, after the first device initiates a security authentication request to the second device, the second device is controlled to send a random number to the first device, wherein the first device is connected to the quantum key distribution sending device, and the second device is connected to the quantum key distribution receiving device. Afterwards, this application controls the first device to generate a single photon based on the random number, the first key and the second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, and the second key is a binary random key pre-generated by the first device. The single photon carries at least encrypted random number information and timestamp information. Then, this application transmits the single photon and the second key to the second device. Finally, this application performs security authentication on the first device based on the single photon and the second key.
[0020] From the above content, it can be seen that this application introduces quantum technology to connect the first device (i.e., the initiator of security authentication) with the quantum key distribution sending end device, and connect the second device (i.e., the receiving end of security authentication) with the quantum key distribution receiving end device, and control the first device to prepare single photons based on random numbers, quantum keys and random keys, and transmit encrypted information to the second device through single photons in quantum states. Since single photons in quantum states are non-replicable, during the single photon transmission process, once a single photon is intercepted, the second device can immediately discover it. Finally, this application controls the second device to perform security authentication based on single photons and the second key, thereby achieving the technical effect of improving the reliability of identity security authentication, and thus solving the technical problem of low security of identity security authentication based on symmetric keys in the existing technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0022] Figure 1 This is an optional framework diagram for a security authentication process based on symmetric quantum keys;
[0023] Figure 2 is a flowchart of an optional security authentication method according to an embodiment of the present application;
[0024] Figure 3 is a flowchart of another optional security authentication method according to an embodiment of the present application;
[0025] Figure 4 is a schematic diagram of an optional security authentication device according to an embodiment of the present application;
[0026] Figure 5 This is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] It should also be noted that the relevant information (including but not limited to information for display and information for analysis) and data (including but not limited to data for display and data for analysis) involved in this application are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and the relevant users or institutions. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned users or institutions through the interface, and obtain the relevant information after receiving the consent information fed back by the aforementioned users or institutions.
[0030] In addition, the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant information and data involved in this application comply with the relevant laws, regulations and standards of the relevant regions, and necessary confidentiality measures have been taken, and do not violate public order and good morals. In addition, this application provides corresponding operation entrances for users to choose to agree to authorization or refuse authorization. If the user chooses to refuse authorization, he / she will enter the corresponding expert decision-making process.
[0031] In an optional embodiment, Figure 1 It is an optional framework diagram for the security authentication process based on symmetric quantum keys, such as Figure 1 As shown in the figure, the QKD-A (Quantum Key Distribution Sender) device is the quantum key distribution sending device, and the QKD-B (Quantum Key Distribution Receiver) device is the quantum key distribution receiving device. Figure 1 The steps of the security authentication method based on symmetric quantum key are as follows:
[0032] 1. QKD-A and QKD-B devices generate symmetric quantum keys;
[0033] 2. QKD-A and QKD-B send the symmetric quantum key to the authentication initiator (i.e. Figure 1The initiator) and the verifier in the above code securely store the shared key;
[0034] 3. The authentication initiator initiates a round of authentication to the verifier;
[0035] 4. The verifier sends a random number to the authentication initiator;
[0036] 5. Signature process: The authentication initiator uses the symmetric quantum key to encrypt the random number and timestamp to obtain the ciphertext, and then sends the timestamp and ciphertext M to the verifier;
[0037] 6. Signature verification process: The verifier uses a symmetric quantum key to encrypt the random number and timestamp to obtain the ciphertext M'. It compares M and M'. If the two are consistent, the verification is successful. Otherwise, if they are inconsistent, the verification fails.
[0038] However, the above-mentioned security authentication scheme based on symmetric quantum keys requires the use of symmetric encryption algorithms to implement the signing and verification processes during the authentication process. The existing symmetric encryption algorithms have the risk of halving their security under the Grover algorithm.
[0039] According to an embodiment of the present application, an embodiment of a security authentication method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0040] This application provides a security authentication system for executing the security authentication method in this application. Figure 2 This is a flow chart of an optional security authentication method according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:
[0041] Step S201: After the first device initiates a security authentication request to the second device, the second device is controlled to send a random number to the first device, wherein the first device is connected to the quantum key distribution sending device and the second device is connected to the quantum key distribution receiving device.
[0042] Optionally, the first device refers to the entity that initiates the security authentication request, such as a server or mobile terminal of a financial institution; the second device is the entity responsible for verifying the security authentication request of the first device, usually the back-end system corresponding to the service provider.
[0043] Optionally, the quantum key distribution sending device, i.e., the QKD-A device, is responsible for preparing and sending the quantum state; the quantum key distribution receiving device, i.e., the QKD-B device, is responsible for receiving the quantum state, and the QKD-A device and the QKD-B device jointly generate the first key.
[0044] Optionally, after the first device initiates a security authentication request to the second device, the second device generates a random number and sends the random number to the first device. Since the random number generated for each authentication is different, the random number can prevent attackers from impersonating legitimate users by replaying previous communication records. Even if the attacker intercepts and obtains authentication information once within a historical time period, due to the change in the random number, the intercepted authentication information will be invalid in subsequent authentication requests, thereby improving the security of subsequent identity security authentication.
[0045] Step S202: Control the first device to generate a single photon based on a random number, a first key, and a second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, and the second key is a binary random key pre-generated by the first device. The single photon carries at least encrypted random number information and timestamp information.
[0046] Optionally, the preset quantum encryption algorithm can be set to BB84 (Bennett-Brassard 1984 protocol, a quantum key distribution protocol) technology.
[0047] Optionally, the first key is a symmetric quantum key securely generated by the QKD-A device and the QKD-B device through a quantum optical fiber link. The QKD-A device distributes the symmetric quantum key to the first device for storage, and the QKD-B device distributes the symmetric quantum key to the second device for storage.
[0048] Optionally, the security authentication system controls the first device to encrypt the random number and timestamp based on the first key, and prepares a single photon through the encrypted random number and timestamp information, wherein the single photon is the most basic unit of light particle in quantum mechanics and has the characteristics of being indivisible and non-cloneable. Therefore, any attempt to eavesdrop or copy a single photon during the transmission process will change the quantum state of the single photon, which can be detected by the recipient of the single photon, thereby ensuring the security of the encrypted information transmission.
[0049] Step S203: Transmit the single photon and the second key to the second device.
[0050] Optionally, the security authentication system controls the first device to transmit a single photon to the second device through a quantum optical fiber link, and transmits the second key to the second device through a second channel, wherein the first channel is a quantum optical fiber link between a quantum key distribution sending device and a quantum key distribution receiving device, and the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device. Transmitting single photons through the quantum optical fiber link ensures that the encrypted information cannot be eavesdropped, and transmitting the second key through the classical link achieves the purpose of providing the second device with a basis for measuring and verifying single photons.
[0051] Step S204: Perform security authentication on the first device based on the single photon and the second key.
[0052] Optionally, after the second device receives the single photon and the second key, the second device regenerates the encryption sequence (i.e., the encrypted random number and timestamp information) based on the locally stored first key, and uses the regenerated encryption sequence as the measurement basis of the single photon to measure the single photon sent by the first device to obtain the measurement result. Afterwards, the security authentication result is determined based on the comparison result between the measurement result and the second key.
[0053] Optionally, if the measurement result is consistent with the second key, it indicates that the quantum key shared by the first device and the second device is valid, and the transmission channel between the first device and the second device passes the security authentication; otherwise, it indicates that there is a security threat in the transmission channel between the first device and the second device, and the authentication fails.
[0054] Optionally, the security authentication system achieves quantum-level secure identity authentication by combining quantum communication and classical encryption technology, thereby effectively counteracting the security threats posed by the Grover algorithm and providing security protection for communication systems in financial institutions.
[0055] From the above content, it can be seen that this application introduces quantum technology to connect the first device (i.e., the initiator of security authentication) with the quantum key distribution sending end device, and connect the second device (i.e., the receiving end of security authentication) with the quantum key distribution receiving end device, and control the first device to prepare single photons based on random numbers, quantum keys and random keys, and transmit encrypted information to the second device through single photons in quantum states. Since single photons in quantum states are non-replicable, during the single photon transmission process, once a single photon is intercepted, the second device can immediately discover it. Finally, this application controls the second device to perform security authentication based on single photons and the second key, thereby achieving the technical effect of improving the reliability of identity security authentication, and thus solving the technical problem of low security of identity security authentication based on symmetric keys in the existing technology.
[0056] In an optional embodiment, the security authentication system first controls the quantum key distribution sending device and the quantum key distribution receiving device to jointly generate a first key. Then, the security authentication system controls the quantum key distribution sending device to send the first key to the first device, and controls the quantum key distribution receiving device to send the first key to the second device. Then, the security authentication system controls the first device and the second device to store the first key.
[0057] Optionally, the security authentication system first controls the quantum key distribution sending device and the quantum key distribution receiving device to enter a communication state, and controls the quantum key distribution sending device and the quantum key distribution receiving device to jointly generate a first key through a quantum optical fiber link. The key generation process is based on the principles of quantum physics, ensuring that even in the face of attacks in a quantum computing environment, the security authentication system can ensure the security of the first key generation process.
[0058] Optionally, the process of generating the first key includes: a quantum key distribution transmitting device emits randomly coded single photons, a quantum key distribution receiving device receives and measures these photons, and then the two parties exchange the information carried by the photons and eliminate the eavesdropped part of the information carried by the photons, thereby obtaining a sufficiently secure first key that is only known by the two devices.
[0059] Optionally, after the first device and the second device each receive the first key, they store the first key in their respective corresponding storage media to ensure that the first key will not be leaked without authorization. For example, the storage method here can be set to hardware encryption storage, software encryption storage, or a combination of hardware and software to ensure that the integrity of the first key is not violated. The security authentication system utilizes the unique characteristics of quantum communication to ensure security from the generation, distribution, and storage of the first key.
[0060] In an optional embodiment, the security authentication system first generates a timestamp based on the current moment through the first device. Then, the security authentication system encrypts the timestamp based on the first key to obtain a first encryption sequence. Then, the security authentication system encrypts the random number based on the first key to obtain a second encryption sequence. In addition, the security authentication system splices the first encryption sequence and the second encryption sequence to obtain a first target sequence, wherein the first target sequence is a binary sequence generated by the first device. Finally, the security authentication system generates a single photon based on the first target sequence and the second key.
[0061] Optionally, when the first device initiates an authentication request, the security authentication system controls the first device to generate a timestamp based on the current system time to mark the moment when the authentication request is initiated, thereby achieving the purpose of preventing subsequent replay attacks and ensuring the timeliness of authentication.
[0062] Optionally, during the preparation of single photons, the security authentication system combines symmetric encryption technology and quantum communication technology, and enhances the security of timestamp and random number transmission by doubly encrypting the timestamp and random number based on the first key (i.e., the symmetric quantum key). In addition, the non-cloning and non-eavesdropping properties of the single-photon quantum state further enhance the security of encrypted information during transmission.
[0063] In an optional embodiment, the security authentication system first uses the first target sequence as a target basis, wherein the target basis is the physical reference system used to prepare single photons. Then, the security authentication system uses the second key as a target code, wherein the target code is the encoded information of the quantum state used to prepare single photons. Then, the security authentication system generates single photons based on the target basis and the target code.
[0064] Optionally, in the BB84 protocol, the target basis can set two orthogonal quantum state bases, for example, |0> and |1> represent the polarization bases in the horizontal and vertical directions, or |+> and |-> represent the polarization bases in the diagonal direction. By selecting the target basis, the first device can determine the preparation method of the single photon, thereby providing a standard for subsequent single-photon quantum state measurements.
[0065] Optionally, the security authentication system will use the generated second key as the quantum state encoding information for preparing a single photon (i.e., target code). For example, when the security authentication system uses |0> and |1> as target bases, if a bit in the binary sequence corresponding to the second key is 0, the corresponding quantum state of the single photon is prepared into a |0> state; if a bit in the binary sequence corresponding to the second key is 1, the corresponding quantum state of the single photon is prepared into a |1> state. The use of target code ensures the randomness of the single photon preparation process, thereby increasing the security and complexity of the authentication process.
[0066] Alternatively, by combining traditional key information with quantum state preparation, the security authentication system not only overcomes the halving of the security of traditional symmetric keys under quantum computing attacks, but also ensures the uniqueness of the generated single photons during each authentication process through dynamically generated target bases and target encoding, thereby improving the authentication process's resistance to quantum attacks. Furthermore, due to the natural physical properties of single photons, eavesdropping can be immediately detected when a quantum fiber link is monitored, allowing the security authentication system to take timely measures to protect communication security.
[0067] In an optional embodiment, the security authentication system first transmits a single photon to a second device through a first channel, wherein the first channel is a quantum optical fiber link between a quantum key distribution sending device and a quantum key distribution receiving device. Then, the security authentication system transmits a second key to the second device through a second channel, wherein the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device.
[0068] Optionally, a quantum fiber link is a special communication medium that can transmit encrypted sub-information carried by single photons. When using a quantum fiber link to transmit single photons, any interference with the transmission process can cause a change in the quantum state, which can then be detected by the receiver of the single photon, thereby preventing potential eavesdropping.
[0069] Optionally, the second channel is a classical communication link in the traditional sense, such as a wireless communication link and a network cable link. Although the classical communication link is at risk of being eavesdropped, since the second key itself does not contain sensitive information and the second key can only play a security authentication role in combination with a single photon, even if the second key is transmitted through the second channel, the security of the authentication process will not be reduced.
[0070] Optionally, compared to transmitting single photons and the second key entirely through a quantum optical fiber link, the security authentication system transmits the second key through classical communication, which reduces the consumption of quantum resources and lowers the implementation difficulty and transmission resource cost of the solution.
[0071] In an optional embodiment, the security authentication system first controls the second device to encrypt a random number and a timestamp based on the first key to obtain a second target sequence, wherein the second target sequence is a binary sequence generated by the second device. Afterwards, the security authentication system measures the single photon according to the second target sequence to obtain a sequence to be detected, wherein the sequence to be detected is used to characterize the physical reference system of the quantum state corresponding to the single photon received by the second device. Then, the security authentication system performs security authentication on the first device through the sequence to be detected and the second key.
[0072] Here, the second target sequence is essentially a binary ciphertext, which is composed of an encrypted sequence obtained by encrypting a random number by the second device based on the first key, and an encrypted sequence obtained by encrypting a timestamp based on the first key. The security authentication system uses the second target sequence as the physical reference system used by the second device to measure a single photon, and measures the single photon to obtain a quantum state measurement result (i.e., the sequence to be detected). The sequence to be detected here can verify whether the quantum state of the single photon is consistent with the expected preparation substrate (i.e., the second key), thereby indirectly verifying the validity of the first key.
[0073] Optionally, the addition of a timestamp in the above-mentioned signature verification process makes the authentication process time-sensitive, thereby ensuring the immediacy and effectiveness of the authentication operation, and further preventing the reuse of authentication information intercepted by an attacker.
[0074] In an optional embodiment, the security authentication system first obtains the similarity between the sequence to be detected and the second key. Then, if the similarity is less than a preset threshold, the security authentication system determines that the security authentication of the second device has failed. Then, if the similarity is greater than or equal to the preset threshold, the security authentication system determines that the security authentication of the second device has succeeded.
[0075] Optionally, the similarity can be achieved by calculating the Euclidean distance or comparing the bit strings bit by bit. Ideally, if the sequence to be detected is completely consistent with the second key, it means that the information transmission and measurement process is not interfered with or eavesdropped.
[0076] Optionally, the above-mentioned preset threshold is a pre-set value used to distinguish whether the difference between the sequence to be detected and the second key is within an acceptable range. The setting of the preset threshold needs to take into account the characteristics of quantum communication, such as the randomness of quantum state measurement and channel noise factors, so as to ensure that under normal communication conditions, the similarity can reach or exceed the preset threshold.
[0077] Optionally, the setting of the preset threshold takes into account noise and uncertainty in the actual communication environment, so that the security authentication system can automatically adjust the security policy under different communication conditions, thereby improving the overall robustness and stability.
[0078] From the above content, it can be seen that this application introduces quantum technology to connect the first device (i.e., the initiator of security authentication) with the quantum key distribution sending end device, and connect the second device (i.e., the receiving end of security authentication) with the quantum key distribution receiving end device, and control the first device to prepare single photons based on random numbers, quantum keys and random keys, and transmit encrypted information to the second device through single photons in quantum states. Since single photons in quantum states are non-replicable, during the single photon transmission process, once a single photon is intercepted, the second device can immediately discover it. Finally, this application controls the second device to perform security authentication based on single photons and the second key, thereby achieving the technical effect of improving the reliability of identity security authentication, and thus solving the technical problem of low security of identity security authentication based on symmetric keys in the existing technology.
[0079] In an optional embodiment, Figure 3 is a flowchart of another optional security authentication method according to an embodiment of the present application, such as Figure 3 As shown, the security authentication method includes the following steps:
[0080] 1. QKD-A and QKD-B devices generate a symmetric quantum key k;
[0081] 2. QKD-A and QKD-B send the symmetric quantum key k to the authentication initiator and verifier respectively, and the two parties securely store the shared k;
[0082] 3. The symmetric quantum key k is stored in the key storage medium corresponding to the authentication initiator and the verifier;
[0083] 4. The authentication initiator initiates a round of authentication to the verifier;
[0084] 5. The verifier sends a random number R to the authentication initiator;
[0085] 6. The authentication initiator's QKD-A locally uses k to encrypt the timestamp t and the random number R, obtaining the encryption result E = Ek(t|R). It then uses E as the basis to prepare a single photon, and QKD-A generates a random key sequence x.
[0086] 7. The authentication initiator sends a single photon to the verifier via the quantum fiber link between QKD-A and QKD-B, and sends x via the classical link between QKD-A and QKD-B.
[0087] 8. The verifier uses the locally stored k to encrypt the timestamp t and the random number R, obtaining the encryption result E' = Ek(t|R). Then, the verifier uses E' as the measurement basis to measure the single photon received in the quantum fiber link and obtain the measurement result x';
[0088] 9. The verifier compares x and x'. If the comparison results are consistent, the verification is successful; if they are inconsistent, the verification fails.
[0089] As can be seen from the above content, the beneficial effects brought about by the solution of the above embodiment include:
[0090] 1. The symmetric quantum key k used in the authentication process is generated through quantum key distribution, ensuring the quantum security of the key generation and distribution process.
[0091] 2. The information encrypted using the symmetric quantum key k does not need to be transmitted through the classical channel. The attacker cannot obtain the plaintext t and R, as well as the encrypted information E corresponding to t and R, through the classical channel at the same time, and the attacker cannot crack k.
[0092] 3. Single photons are transmitted through quantum links. Due to the non-replicability and non-cloning properties of quantum, once a single photon is intercepted, it will be discovered by the verifier, and the system can immediately terminate subsequent authentication processes and services.
[0093] 4. Even if an attacker intercepts a single photon from the quantum link and obtains x from the classical link, since the attacker cannot obtain the key k, he can only randomly use the measurement basis to measure the single photon, and obtain a result that is unrelated to the authentication information. The attacker cannot use x to reversely infer all the measurement bases used in this authentication, thus ensuring the security of the authentication communication process.
[0094] 5. During each authentication process, the verifier sends a different random number R to the authentication initiator. The measurement basis used by QKD-A is different each time, thereby ensuring that the attacker cannot intercept single photons and x multiple times and decrypt them to obtain a fixed measurement basis.
[0095] According to another aspect of the embodiment of the present application, a security authentication device is also provided. Figure 4 is a schematic diagram of an optional security authentication device according to an embodiment of the present application, such as Figure 4 As shown, the security authentication device includes: a first sending unit, a first generating unit, a transmission unit and an authentication unit.
[0096] Optionally, the first sending unit is used to control the second device to send a random number to the first device after the first device initiates a security authentication request to the second device, wherein the first device is connected to the quantum key distribution sending device, and the second device is connected to the quantum key distribution receiving device; the first generating unit is used to control the first device to generate a single photon based on the random number, the first key and the second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, and the second key is a binary random key pre-generated by the first device, and the single photon carries at least encrypted random number information and timestamp information; the transmission unit is used to transmit the single photon and the second key to the second device; the authentication unit is used to perform security authentication on the first device based on the single photon and the second key.
[0097] In an optional embodiment, the security authentication device further includes: a second generating unit, a second sending unit, and a storage unit.
[0098] Optionally, the second generation unit is used to control the quantum key distribution sending device and the quantum key distribution receiving device to jointly generate the first key; the second sending unit is used to control the quantum key distribution sending device to send the first key to the first device, and control the quantum key distribution receiving device to send the first key to the second device; the storage unit is used to control the first device and the second device to store the first key.
[0099] In an optional embodiment, the first generation unit includes: a first generation subunit, a first encryption subunit, a second encryption subunit, a splicing subunit and a second generation subunit.
[0100] Optionally, the first generation subunit is used to generate a timestamp based on the current moment through the first device; the first encryption subunit is used to encrypt the timestamp based on the first key to obtain a first encryption sequence; the second encryption subunit is used to encrypt the random number based on the first key to obtain a second encryption sequence; the splicing subunit is used to splice the first encryption sequence and the second encryption sequence to obtain a first target sequence, wherein the first target sequence is a binary sequence generated by the first device; the second generation subunit is used to generate a single photon based on the first target sequence and the second key.
[0101] In an optional embodiment, the second generating subunit further includes: a first determining module, a second determining module and a generating module.
[0102] Optionally, the first determination module is used to use the first target sequence as the target basis, wherein the target basis is the physical reference system used to prepare the single photon; the second determination module is used to use the second key as the target code, wherein the target code is the encoding information of the quantum state used to prepare the single photon; and the generation module is used to generate the single photon based on the target basis and the target code.
[0103] In an optional embodiment, the transmission unit includes: a first transmission subunit and a second transmission subunit.
[0104] Optionally, the first transmission subunit is used to transmit a single photon to a second device through a first channel, wherein the first channel is a quantum optical fiber link between a quantum key distribution sending device and a quantum key distribution receiving device; the second transmission subunit is used to transmit a second key to a second device through a second channel, wherein the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device.
[0105] In an optional embodiment, the authentication unit includes: a third encryption subunit, a measurement subunit, and an authentication subunit.
[0106] Optionally, the third encryption subunit is used to control the second device to encrypt the random number and the timestamp based on the first key to obtain a second target sequence, wherein the second target sequence is a binary sequence generated by the second device; the measurement subunit is used to measure the single photon according to the second target sequence to obtain a sequence to be detected, wherein the sequence to be detected is used to characterize the physical reference system of the quantum state corresponding to the single photon received by the second device; the authentication subunit is used to securely authenticate the first device using the sequence to be detected and the second key.
[0107] In an optional embodiment, the authentication subunit further includes: an acquisition module, a third determination module, and a fourth determination module.
[0108] Optionally, the acquisition module is used to obtain the similarity between the sequence to be detected and the second key; the third determination module is used to determine that the security authentication of the second device has failed when the similarity is less than a preset threshold; and the fourth determination module is used to determine that the security authentication of the second device has succeeded when the similarity is greater than or equal to the preset threshold.
[0109] According to another aspect of an embodiment of the present application, a computer program product is further provided, which includes a stored computer program, wherein when the computer program is running, the computer program product is controlled to execute any one of the above-mentioned security authentication methods.
[0110] According to another aspect of an embodiment of the present application, an electronic device is also provided, including: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned security authentication methods by executing the executable instructions.
[0111] Optionally, Figure 5 This is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 5 As shown, the electronic device includes: one or more ( Figure 5 Only one is shown) processor 501, memory 502, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.
[0112] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implementing the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.
[0113] It can be understood by those skilled in the art that Figure 5 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (MID), a PAD, or other terminal devices. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device may also include Figure 5 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 5 Different configurations shown.
[0114] The above-mentioned embodiments or examples disclosed in this application are not exhaustive, but are only illustrations of some embodiments or examples, and are not intended to be specific limitations on the scope of protection disclosed in this application. In the absence of contradiction, each step in a certain embodiment or example in this application can be implemented as an independent example, and the steps can be arbitrarily combined. For example, the solution after removing some steps in a certain embodiment or example can also be implemented as an independent example, and the order of the steps in a certain embodiment or example can be arbitrarily exchanged. In addition, the optional methods or optional examples in a certain embodiment or example can be arbitrarily combined; in addition, the various embodiments or examples can be arbitrarily combined. For example, some or all of the steps in different embodiments or examples can be arbitrarily combined, and a certain embodiment or example can be arbitrarily combined with the optional methods or optional examples of other embodiments or examples.
[0115] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0116] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0117] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0119] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-permanent storage in a computer-readable medium, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0120] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0121] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0122] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0123] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A security authentication method, characterized in that: include: After the first device initiates a security authentication request to the second device, controlling the second device to send a random number to the first device, wherein the first device is connected to a quantum key distribution transmitting device and the second device is connected to a quantum key distribution receiving device; Controlling the first device to generate a single photon based on the random number, a first key, and a second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, the second key is a binary random key pre-generated by the first device, and the single photon carries at least encrypted random number information and timestamp information; transmitting the single photon and the second key to the second device; The first device is securely authenticated based on the single photon and the second key.
2. The security authentication method according to claim 1, wherein: Before controlling the second device to send a random number to the first device, the security authentication method further includes: Controlling the quantum key distribution sending end device and the quantum key distribution receiving end device to jointly generate the first key; Controlling the quantum key distribution sending end device to send the first key to the first device, and controlling the quantum key distribution receiving end device to send the first key to the second device; Control the first device and the second device to store the first key.
3. The security authentication method according to claim 1, wherein: Controlling the first device to generate a single photon based on the random number, the first key, and the second key includes: generating a timestamp based on the current moment by the first device; Encrypting the timestamp based on the first key to obtain a first encrypted sequence; Encrypting the random number based on the first key to obtain a second encrypted sequence; concatenating the first encryption sequence and the second encryption sequence to obtain a first target sequence, wherein the first target sequence is a binary sequence generated by the first device; The single photon is generated according to the first target sequence and the second key.
4. The security authentication method according to claim 3, wherein: Generating the single photon according to the first target sequence and the second key includes: Using the first target sequence as a target substrate, wherein the target substrate is a physical reference system used to prepare single photons; Using the second key as a target code, wherein the target code is encoded information of a quantum state used to prepare a single photon; The single photon is generated according to the target basis and the target code.
5. The security authentication method according to claim 1, wherein: Transmitting the single photon and the second key to the second device includes: Transmitting the single photon to the second device through a first channel, wherein the first channel is a quantum optical fiber link between the quantum key distribution transmitting device and the quantum key distribution receiving device; The second key is transmitted to the second device through a second channel, wherein the second channel is a wireless communication link or a network cable link between the quantum key distribution sending device and the quantum key distribution receiving device.
6. The security authentication method according to claim 1, wherein: Performing security authentication on the first device based on the single photon and the second key includes: controlling the second device to encrypt the random number and the timestamp based on the first key to obtain a second target sequence, wherein the second target sequence is a binary sequence generated by the second device; Measuring the single photons according to the second target sequence to obtain a sequence to be detected, wherein the sequence to be detected is used to characterize a physical reference system of a quantum state corresponding to the single photons received by the second device; The first device is securely authenticated using the sequence to be detected and the second key.
7. The security authentication method according to claim 6, characterized in that: Performing security authentication on the first device using the sequence to be detected and the second key includes: Obtaining a similarity between the sequence to be detected and the second key; If the similarity is less than a preset threshold, determining that the second device security authentication fails; If the similarity is greater than or equal to the preset threshold, it is determined that the security authentication of the second device is successful.
8. A security authentication device, characterized in that: include: a first sending unit, configured to control the second device to send a random number to the first device after the first device initiates a security authentication request to the second device, wherein the first device is connected to a quantum key distribution transmitting device, and the second device is connected to a quantum key distribution receiving device; a first generating unit, configured to control the first device to generate a single photon based on the random number, a first key, and a second key, wherein the first key is a symmetric quantum key pre-generated based on a preset quantum encryption algorithm, the second key is a binary random key pre-generated by the first device, and the single photon carries at least encrypted random number information and timestamp information; a transmitting unit, configured to transmit the single photon and the second key to the second device; An authentication unit, configured to perform security authentication on the first device based on the single photon and the second key.
9. A computer program product, characterized in that The computer program product includes a computer program, wherein when the computer program is run, the computer program product is controlled to execute the security authentication method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the security authentication method described in any one of claims 1 to 7.