Methods, systems, media, and quantum computers for protecting a quantum key distribution process
By encrypting the quantum key with a transmission protection key generated using classical cryptographic algorithms during the quantum key distribution process, and then securely distributing it after generation on the server side, the problems of high cost and limited transmission distance in quantum key distribution are solved, achieving low-cost and high-stability quantum key distribution.
Patent Information
- Application Number
- CN202511272796.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-09-08
AI Technical Summary
Existing quantum key distribution schemes require the construction of quantum private network channels, which are costly, cannot be widely promoted, have limited transmission distance, and have poor applicability and stability.
The quantum key is encrypted using a transmission protection key generated by a classical cryptographic algorithm, and then securely sent to the working terminal after the quantum key is generated on the server side, avoiding the need for a dedicated quantum communication channel.
It reduces the cost of quantum key distribution, improves applicability and stability, solves the problem of transmission distance limitation, and ensures the security and reliability of quantum keys.
Smart Images

Figure CN120768547B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum secure communication technology, specifically to a method, system, medium, and quantum computer for protecting the quantum key distribution process. Background Technology
[0002] Quantum secure communication is a secure communication technology based on quantum key distribution, which uses a quantum key of the same length as the data being encrypted to encrypt and decrypt business data. Currently, the main quantum key distribution method used in quantum secure communication is to directly distribute quantum keys by building a secure quantum communication channel.
[0003] However, the aforementioned quantum key distribution schemes require the construction of quantum private network channels, which are costly and cannot be widely adopted. Furthermore, it is impossible to build a complete quantum private network channel from the work terminal directly to the data center; some steps still rely on traditional networks, resulting in limitations in transmission distance and poor applicability and stability. Therefore, how to reduce the cost of quantum key distribution while ensuring its security, and improve its applicability and stability, is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, embodiments of this application provide a method, system, medium, and quantum computer for protecting the quantum key distribution process, thereby improving the applicability and stability of the quantum key distribution process while reducing costs.
[0005] In a first aspect, embodiments of this application provide a method for protecting the quantum key distribution process. The method is applied to a server and includes: obtaining a transmission protection key and generating at least one quantum key, wherein the transmission protection key is generated using a classical cryptographic algorithm; encrypting the at least one quantum key using the transmission protection key to obtain at least one quantum key ciphertext; and sending the at least one quantum key ciphertext to a working terminal.
[0006] In some embodiments of this application, encrypting at least one quantum key using a transmission protection key includes: encrypting at least one quantum key and a digital signature using a classical cryptographic algorithm based on the public key of the transmission protection key.
[0007] In some embodiments of this application, classical cryptographic algorithms include any one or more combinations of the following: RSA algorithm, SM2, SM3, SM4 and SM9 algorithms in domestic commercial cryptographic systems, Advanced Encryption Standard (AES), Elliptic Curve Cryptography (ECC), Data Encryption Standard (DES), Triple Encryption Algorithm (3DES), and International Data Encryption Algorithm (IDEA).
[0008] In some embodiments of this application, obtaining the transmission protection key includes: receiving a digital envelope containing the ciphertext of the transmission protection key from a work terminal; verifying the ciphertext of the transmission protection key through the digital envelope; and obtaining the transmission protection key after the verification is successful.
[0009] In some embodiments of this application, the working terminal includes at least one working terminal, the server is configured with a first cryptographic module, and the method further includes: calling the first cryptographic module to generate an authentication key, and generating an identity key and at least one preset quantum key for each working terminal.
[0010] In some embodiments of this application, the method further includes: presetting the authentication key, the identity key, and at least one preset quantum key to a secure storage space.
[0011] In some embodiments of this application, the first cryptographic module on the server side includes any one or more combinations of a quantum random number generator, a quantum encryption card, a quantum server cryptographic machine, or a software cryptographic module.
[0012] Secondly, embodiments of this application provide a method for protecting the quantum key distribution process. The method is applied to a work terminal and includes: generating a transmission protection key; encrypting the transmission protection key to obtain transmission protection key ciphertext; sending the transmission protection key ciphertext to a server and receiving quantum key ciphertext from the server; decrypting the quantum key ciphertext to obtain a quantum key, and using the quantum key as a working key.
[0013] In some embodiments of this application, encrypting the transmission protection key includes encrypting the transmission protection key based on classical cryptographic algorithms.
[0014] In some embodiments of this application, the method further includes: the working terminal further includes a second cryptographic module, and an authentication key, an identity key, and at least one preset quantum key are injected into the second cryptographic module through a preset or offline method.
[0015] In some embodiments of this application, generating a transmission protection key includes: calling a second cryptographic module to generate a physical random number; encrypting and hashing the physical random number and at least one preset quantum key based on a classical cryptographic algorithm to obtain an enhanced random number; and using the enhanced random number as the private key of the transmission protection key.
[0016] Thirdly, embodiments of this application provide a system for protecting the quantum key distribution process. The system includes: a server, at least one work terminal, and a network. The server is configured with a key management system, which is used to execute the method for protecting the quantum key distribution process described in the first aspect; the work terminal executes the method for protecting the quantum key distribution process described in the second aspect.
[0017] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program for performing the method for protecting the quantum key distribution process described in the first aspect above, and / or for performing the method for protecting the quantum key distribution process described in the second aspect above.
[0018] Fifthly, embodiments of this application provide a quantum computer comprising: a control module and a quantum random number generation module, wherein the control module is configured to: in response to a key request from a server, invoke the quantum random number generation module to generate a true random number sequence as the quantum key in the method for protecting the quantum key distribution process described in the first aspect.
[0019] According to the embodiments of this application, the transmission protection key generated by the classical cryptographic algorithm is used to protect the distribution of quantum keys to the working terminal. This enables the generation of quantum keys by the server and their secure distribution to the working terminal without the need for a dedicated quantum communication channel, even when the working terminal cannot be equipped with a quantum key generation device. This saves the expensive cost of building a quantum communication channel, solves the problem of transmission distance limitation of quantum communication channels, and ensures the stability of quantum key transmission. Attached Figure Description
[0020] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the embodiments of the present disclosure to explain the disclosure and do not constitute a limitation thereof. The above and other features and advantages will become more apparent to those skilled in the art from the description of detailed exemplary embodiments with reference to the accompanying drawings.
[0021] Figure 1 This is an application scenario diagram of a quantum key distribution system provided in some embodiments of this application.
[0022] Figure 2 This is an exemplary flowchart of a server-side protection method for quantum key distribution provided in some embodiments of this application.
[0023] Figure 3 This is an exemplary flowchart of a method for protecting the quantum key distribution process on the working terminal side, provided in some embodiments of this application.
[0024] Figure 4 This is a flowchart illustrating a method for obtaining a transmission protection key provided in some embodiments of this application.
[0025] Figure 5 This is a flowchart illustrating a quantum key encryption method provided in some embodiments of this application.
[0026] Figure 6This is a block diagram of an electronic device provided in some embodiments of this application. Detailed Implementation
[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0028] Application Overview
[0029] Random numbers are crucial to the security of cryptographic algorithms, serving as a fundamental element in core aspects such as key generation, data encryption, digital signatures, and security protocols. The true randomness of random numbers is a decisive factor in key reliability. Quantum keys, as a type of truly random number (bit sequence) generated based on the principles of quantum mechanics, utilize the intrinsic randomness of quantum mechanics (such as quantum tunneling and spontaneous emission of photons) to ensure the unpredictability and true randomness of random numbers. Due to the high security brought about by its true randomness, it has gradually attracted widespread attention from researchers in the field of communication and information security in recent years.
[0030] In related technologies, quantum keys are primarily generated using devices such as quantum random number generators, quantum encryption cards, and quantum server cryptographic machines. However, due to limitations in size, power requirements, system requirements, and product performance, these devices cannot be directly applied to mobile devices such as smartphones, computers, and IoT devices. When work terminals cannot be directly equipped with the aforementioned quantum key generation devices, a server-side mechanism is needed to generate quantum keys and then securely distribute them to each work terminal. Currently, the mainstream method for protecting the quantum key distribution process is to establish a secure quantum communication channel to achieve direct quantum key distribution. However, this method has the following problems:
[0031] First, the construction cost is high. Dedicated quantum communication channels are needed to distribute quantum keys. Standardized mass production has not been established, making large-scale commercial deployment difficult and resulting in high construction costs.
[0032] Second, poor applicability and stability. The transmission of quantum states relies on single photons as the carriers of quantum information. At the same time, due to the decoherence effect of quantum state transmission and the inherent attenuation and scattering effects in optical fiber transmission, the transmission distance is limited, and relay nodes are needed for segmented transmission. Therefore, the applicability and stability are low, and it is impossible to build a full-range quantum communication channel network from the working terminal to the data center.
[0033] To address the aforementioned problems, this application creatively proposes a method for protecting the quantum key distribution process. This method encrypts the quantum key generated on the server side using a transmission guard key generated based on classical cryptographic algorithms, thus protecting the quantum key distribution process. This enables the generation and secure distribution of quantum keys from the server to the workstation even when the workstation cannot be equipped with a quantum key generation device, without the need for a dedicated quantum communication channel. This achieves low cost while improving the applicability and stability of the quantum key distribution process. Various non-limiting embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0034] Exemplary application scenarios
[0035] Figure 1 This is an application scenario diagram of a quantum key distribution system provided in some embodiments of this application. For example... Figure 1 As shown, the quantum key distribution system 100 may include at least one working terminal 110, a server 120, and a network 130. Each working terminal 110 may be configured with a cryptographic module, namely a second cryptographic module 111, and the server 120 may be configured with a cryptographic module, namely a first cryptographic module 121.
[0036] Specifically, work terminal 110 can refer to a user terminal. For example, work terminal 110 can be a mobile device such as a mobile phone, laptop, IoT device, or law enforcement terminal device; it can also be a desktop device such as a desktop computer or all-in-one computer. No specific limitation is made here.
[0037] In some embodiments, the work terminal 110 may include any one or more of the following: energy and power terminal, industrial control terminal, government and financial terminal, and public service terminal.
[0038] The second cryptographic module 111 of the work terminal 110 can be used to encrypt / decrypt communication data or generate keys based on classical cryptographic algorithms, and can also be used as a secure carrier of keys. Specifically, the second cryptographic module 111 can be a software cryptographic module or a hardware cryptographic module. For example, the second cryptographic module 111 can be an encryption carrier or an encryption UKey, such as a national cryptographic encryption chip / cryptographic card or a software cryptographic module, without specific limitations.
[0039] The first cryptographic module 121 of the server 120 can be used to encrypt / decrypt communication data or generate quantum keys, i.e., a quantum key generation unit or device. Specifically, the first cryptographic module 121 can be a software cryptographic module or a hardware cryptographic module. For example, the first cryptographic module 121 can be a quantum encryption board, a quantum server cryptographic machine, or a software cryptographic module, without specific limitations here.
[0040] In some embodiments, network 130 can connect each work terminal 110 and server 120 as a data transmission channel, enabling communication between each work terminal 110 and server 120, facilitating the transmission and exchange of data and / or information. In some embodiments, network 130 can be any one or more of wired or wireless networks. For example, network 130 can be a private network, such as an enterprise intranet, government intranet, industrial network, etc.; or it can be a public network, specifically, a cable network, fiber optic network, telecommunications network, Internet, local area network (LAN), wide area network (WAN), wireless local area network (WLAN), metropolitan area network (MAN), etc., or any combination thereof. The network connection between each work terminal and server can adopt one or more of the above methods.
[0041] In some embodiments, the server 120 may include a key management system, which can call the first cryptographic module of the server to perform corresponding operations according to the instructions of the server, and perform the quantum key distribution method described below.
[0042] Exemplary method for protecting the quantum key distribution process
[0043] To further explain Figure 1 The present application also provides an exemplary flowchart of a server-side protection method for quantum key distribution, illustrating the data encryption and transmission process in the quantum key distribution system. Figure 2 This quantum key distribution method is applied to a quantum key distribution system 100. During the key distribution process:
[0044] like Figure 2 As shown, the key management system on server 120 can perform the following steps:
[0045] S210. Obtain the transmission protection key and generate at least one quantum key.
[0046] The transmission protection key can be a protection key used to encrypt the quantum key and protect the distribution process of the quantum key.
[0047] A quantum key can be a sequence of random qubits that possesses true randomness, generated based on the principles of quantum mechanics.
[0048] In some embodiments, the server can generate an authentication key by calling its configured first cryptographic module, and generate an identity key and at least one preset quantum key for each working terminal.
[0049] In some embodiments, the server stores all the authentication keys, identity keys and at least one preset quantum key generated above through a key management platform.
[0050] In some embodiments, the transmission protection key can be an asymmetric key generated by the work terminal by calling its equipped second cryptographic module and fusing a preset quantum key with a built-in random number generator.
[0051] In some embodiments, a transmission protection key can be generated based on a classical cryptographic algorithm.
[0052] In some embodiments, the server can receive a digital envelope containing the ciphertext of the transmission protection key from the work terminal through its built-in key management system. Based on the digital envelope, the server verifies the identity, integrity, and confidentiality of the ciphertext of the transmission protection key. After successful verification, the server obtains the plaintext of the transmission protection key (i.e., the transmission protection key).
[0053] In some embodiments, the received transmission protection key ciphertext can be decrypted using the authentication key to obtain the transmission protection key, signature data, and the serial number of the second cryptographic module of the corresponding work terminal.
[0054] In some embodiments, the server verifies the received transmission protection key ciphertext from the work terminal by using the identity key corresponding to the first cryptographic module, thereby ensuring the legitimacy of the cryptographic module of the work terminal that transmitted the transmission protection key.
[0055] S220. Encrypt at least one quantum key using the transmission protection key to obtain at least one quantum key ciphertext.
[0056] In some embodiments, the server can use the key management system to call its own configured first cryptographic module to generate at least one quantum key, and then encrypt the at least one quantum key using a transmission protection key to obtain at least one quantum key ciphertext. For details on quantum key encryption, please refer to [reference needed]. Figure 5 And related descriptions.
[0057] S230, Send at least one quantum key ciphertext to the work terminal.
[0058] In some embodiments, the at least one quantum key ciphertext can be sent to the corresponding work terminal via a network. For details regarding networks, please refer to [link to relevant documentation]. Figure 1 And related descriptions.
[0059] Correspondingly, this application also provides an exemplary flowchart of a method for protecting quantum key distribution on a work terminal ( Figure 3 This quantum key distribution method is applied to a quantum key distribution system 100. During the key distribution process:
[0060] like Figure 3As shown, the work terminal 110 can perform the following steps:
[0061] S310, Generate transmission protection key.
[0062] In some embodiments, to ensure key security and prevent key leakage, the authentication key public key, the identity key, and at least one preset quantum key can be injected into the second cryptographic module of the work terminal via a preset or offline method.
[0063] In some embodiments, the work terminal can use classical cryptographic algorithms to encrypt the transmission protection key to obtain the transmission protection key ciphertext. For example, the encryption process of the transmission protection key can be implemented based on a digital envelope. The digital envelope containing the transmission protection key ciphertext is sent to the server. Specifically, the data to be transmitted (transmission protection key) is first encrypted using a symmetric encryption algorithm to obtain the transmission protection key ciphertext. Symmetric encryption algorithms are fast and efficient, but their security level is relatively low, while asymmetric algorithms have a relatively high security level. Therefore, an asymmetric encryption algorithm is used again for encryption (wrapping the ciphertext, which is equivalent to putting the contents of the letter into an envelope) to obtain a digital envelope containing the transmission protection key ciphertext. This combines the efficiency of symmetric encryption with the secure key distribution of asymmetric encryption to balance the security and efficiency of encryption.
[0064] S320. Encrypt the transmission protection key to obtain the transmission protection key ciphertext.
[0065] In some embodiments, the transmission protection key can be encrypted using classical cryptographic algorithms to obtain the transmission protection key, thereby ensuring the security of transmitting the transmission protection key to the work terminal. For details regarding transmission protection key encryption, please refer to [link to relevant documentation]. Figure 4 And related descriptions.
[0066] In some embodiments, after the authentication key, identity key, and at least one preset quantum key data are injected into the second cryptographic module of the work terminal, the authentication key, identity key, and at least one preset quantum key data are preset in a secure storage space. The work terminal can only use the aforementioned keys through the encryption and signature interface and does not provide a key export function to prevent key leakage and the occurrence of cryptographic module forgery and man-in-the-middle attacks.
[0067] In some embodiments, to ensure the security and reliability of the transmission key, a transmission protection key can be injected into the first cryptographic module on the server side either pre-configured or offline. For example, a pre-configured or offline injected identity key can be used as the transmission protection key.
[0068] S330: Send the transmission protection key ciphertext to the server and receive the quantum key ciphertext from the server.
[0069] In some embodiments, the work terminal can transmit the transmission protection key to the key management system on the server via a network. Correspondingly, the server can obtain the transmission protection key from the work terminal via the network and transmit the quantum key back to the work terminal via the network. For example, network 130 can be a private network, such as an enterprise intranet, government intranet, or industrial network; or it can be a public network. Using a private or public network as a secure communication channel for quantum keys saves the high cost of building quantum communication network channels, while solving the problems of poor stability and versatility of quantum communication network channels. This achieves increased quantum key deployment at low cost, improving the applicability and compatibility of quantum keys.
[0070] In some embodiments, network 130 can be any one or more of wired or wireless networks. Specifically, it can be a cable network, fiber optic network, telecommunications network, Internet, local area network (LAN), wide area network (WAN), wireless local area network (WLAN), metropolitan area network (MAN), or any combination thereof. The network connection between each work terminal and the server can adopt one or more of the above methods.
[0071] It should be noted that, in order to ensure the security of the quantum key distribution process, the transmission protection key is only used for a single quantum key transmission process (i.e., this transmission protection). After the completion of this quantum key transmission process, it is destroyed immediately and will not be used for the next protection process.
[0072] S340. Decrypt the quantum key ciphertext to obtain the quantum key, and use the quantum key as the working key.
[0073] In some embodiments, the working terminal decrypts the quantum key ciphertext received from the server using the private key of the transmission protection key, performs signature verification on the data using the public key of the authentication key injected into the second cryptographic module, and obtains the quantum key after the signature verification is successful, ensuring that the quantum key is securely distributed to the working terminal.
[0074] In some embodiments, the working terminal stores the quantum key obtained from the server within the trusted execution environment of its built-in second cryptographic module, providing a trusted execution environment for the quantum key, which cannot leave the trusted execution environment.
[0075] In some embodiments, the work terminal uses the quantum key obtained from the server as the working key. For example, the quantum key can be used as a random number entropy source for SM4 encryption keys and SM2 keys to ensure the randomness of the keys and the use of random numbers in the work terminal.
[0076] In some embodiments, the second cryptographic module of the work terminal can use quantum keys within its trusted execution environment to support the cryptographic services of the work terminal, such as key generation, data encryption, digital signature, etc., thereby enhancing the security of the cryptographic module and meeting the security encryption requirements of the business system.
[0077] It should be understood that the method for protecting the quantum key distribution process on the server side corresponds to the method for protecting the quantum key distribution process on the worker side. Therefore, the above-mentioned... Figure 3 The specific implementation process of the steps in the described embodiments can be found in the following references. Figure 2 The relevant descriptions in the embodiments are omitted here to avoid repetition.
[0078] Therefore, the method for protecting the quantum key distribution process provided in this application protects the distribution of quantum keys to the working terminal by using a transmission protection key generated by a classical cryptographic algorithm. This enables the generation and secure distribution of quantum keys to the working terminal via a server, even when the working terminal cannot be equipped with a quantum key generation device, without the need for a dedicated quantum communication channel. This saves the expensive cost of building a quantum communication channel, solves the problem of transmission distance limitations imposed by quantum communication channels, and ensures the stability and applicability of quantum key transmission. Furthermore, the working terminal uses the quantum key as its working key, ensuring the randomness of the key and the security of the algorithm within the working terminal. This eliminates the periodic vulnerabilities present in the use of pseudo-random number generators in the working terminal, thus achieving security for the working terminal's cryptographic services.
[0079] Exemplary encryption method for transmitting protection keys
[0080] To more clearly illustrate the detailed process of the work terminal generating and encrypting the transmission protection key, some embodiments of this application provide a flowchart of a transmission protection key encryption method. Figure 4 ).
[0081] In some embodiments, Figure 4 The process shown can be executed by a work terminal.
[0082] like Figure 4 As shown, the method may include the following steps:
[0083] S410, The working terminal obtains the private key of the transmission protection key.
[0084] Considering that the transmission protection key is transmitted from the work terminal to the server via a network, the security (i.e., randomness) of the generated transmission protection key needs to be improved due to the network transmission. Therefore, in some embodiments, the transmission protection key can be generated jointly by the work terminal's random number generation unit and at least one preset quantum key. Specifically, the transmission protection key is generated using classical cryptographic algorithms based on physical random numbers and preset quantum keys. For example, the work terminal can call the physical random number generator inside its second cryptographic module to generate physical random numbers, and then encrypt and hash the physical random numbers and the preset quantum key stored in a secure space using classical cryptographic algorithms to obtain enhanced random numbers. This enhances the security of the random numbers generated by the work terminal and avoids the insufficient randomness problem that exists when directly using a physical random number generator.
[0085] Specifically, after obtaining the initial enhanced random number through the above steps, it is necessary to further filter the enhanced random number. If the enhanced random number meets the standard of classical cryptography algorithm, it is used as the private key for transmitting the protection key; if the enhanced random number does not meet the standard of classical cryptography algorithm, the above steps are repeated until an enhanced random number that meets the standard of classical cryptography algorithm is obtained.
[0086] For example, the physical random number and a pre-set quantum key stored in a secure space can be encrypted and hashed using the domestically developed commercial cryptographic algorithm SM4 to obtain an enhanced random number. This enhanced random number is then selected based on the domestically developed commercial cryptographic algorithm SM2 standard and used as the private key for transmission protection. For details on classical cryptographic algorithms, please refer to [link to relevant documentation]. Figure 1 The relevant descriptions in the text will not be repeated here.
[0087] S420. Derive the public key of the transmission protection key from the private key of the transmission protection key.
[0088] S430. Using the private key of the identity key injected by the second cryptographic module, digitally sign the public key of the transmission protection key using a classic cryptographic algorithm to generate digital signature data, and assemble the digital signature data, the public key of the transmission protection key, and the unique serial number of the second cryptographic module.
[0089] S440. Using the authentication key public key, the assembled data is encrypted using a classic cryptographic algorithm to obtain the transmission protection key ciphertext.
[0090] Therefore, the encryption method of the transmission protection key encrypts the transmission protection key with an authentication key to ensure the confidentiality of the transmission protection key, and ensures the non-repudiation of the cryptographic module by signing with an identity key.
[0091] Exemplary quantum key encryption method
[0092] To more clearly illustrate the encryption process of quantum keys based on transmission protection keys, some embodiments of this application provide a flowchart of a quantum key encryption method. Figure 5 ).
[0093] In some embodiments, Figure 5 The process shown can be executed by the server-side key management system.
[0094] like Figure 5 As shown, the method may include the following steps:
[0095] S510, The server calls the first cryptographic module to generate at least one quantum key.
[0096] S520 uses the authentication key private key generated on the server to digitally sign the quantum key using classical cryptographic algorithms, generating digital signature data.
[0097] For example, in the aforementioned S520, the quantum key can be digitally signed using the domestically developed commercial cryptographic algorithm SM2.
[0098] S530 uses the public key of the transmission protection key to encrypt the quantum key and digital signature data using classical cryptographic algorithms to obtain the quantum key ciphertext, and then sends the quantum key ciphertext to the work terminal.
[0099] For example, in S530, the quantum key and digital signature data can be encrypted using the domestically developed commercial cryptographic algorithm SM2 to obtain quantum key ciphertext data. By using lightweight and low-power classical cryptographic algorithms in S520 and S530 to encrypt the quantum key, the quantum key distribution process is facilitated, thereby increasing the applicability and compatibility of the quantum key. This application does not specifically limit the type of classical cryptographic algorithm; for details on classical cryptographic algorithms, please refer to [link to relevant documentation]. Figure 1 The relevant descriptions in the text will not be repeated here.
[0100] In some embodiments, the identity key injected into the cryptographic module offline can be directly used as the transmission protection key. The quantum key generated by the aforementioned S510 is encrypted using a classical cryptographic algorithm using the identity key public key to obtain the quantum key ciphertext, and the quantum key ciphertext is sent to the work terminal.
[0101] Exemplary computer-readable storage media and quantum computers
[0102] This application also provides a quantum computer as a tool and method for providing quantum keys, applied to the aforementioned method for protecting the quantum key distribution process. Specifically, the quantum computer includes a control module and a quantum random number generation module, wherein the control module is configured to: in response to a key request from the aforementioned server, invoke the quantum random number generation module to generate a sequence of truly random numbers, which serves as the quantum key in the aforementioned method for protecting the quantum key distribution process.
[0103] In some embodiments, the quantum computer may be any one or a combination of photonic quantum computers, ion trap quantum computers, quantum dot quantum computers, and neutral atom quantum computers, without specific limitations herein. For details on the specific process of generating quantum keys using a quantum computer, please refer to the specific descriptions of related technologies, which will not be elaborated upon here.
[0104] This application also provides an electronic device, such as Figure 6 As shown. The electronic device 600 provided in this application includes a memory 610, a processor 620, and an input / output interface 630. The memory 610, processor 620, and input / output interface 630 are connected via internal connection paths. The memory 610 stores instructions, and the processor 620 executes the instructions stored in the memory 610 to control the input / output interface 630 to receive input data and information, and output operation results and other data.
[0105] It should be understood that in the embodiments of this application, the processor 620 may be a general-purpose central processing unit (CPU), GPU, FPGA, microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits to execute related programs in order to implement the technical solutions provided in the embodiments of this application.
[0106] The memory 610 may include read-only memory and random access memory, and provides instructions and data to the processor 620. A portion of the processor 620 may also include non-volatile random access memory. For example, the processor 620 may also store device type information.
[0107] In implementation, each step of the above method can be completed by the integrated logic circuits in the hardware of the processor 620 or by instructions in software form. The method for protecting the quantum key distribution process disclosed in the embodiments of this application can be directly implemented by the hardware processor, or by a combination of hardware and software modules in the processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory 610, and the processor 620 reads the information in memory 610 and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here. This application also provides a computer program product, including a computer program / instructions. When the computer program / instruction processor in the computer program product provided in this application is executed, the method for protecting the quantum key distribution process provided in this application can be implemented.
[0108] All of the above-mentioned optional technical solutions can be combined in any way to form the optional embodiments of this application, and will not be described in detail here.
[0109] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0110] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0111] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0112] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0113] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0114] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program verification codes, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0115] It should be noted that in the description of this application, the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0116] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications or equivalent substitutions made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for protecting a quantum key distribution process, the method being applied to a server, comprising: Obtain a transmission protection key and generate at least one quantum key, wherein the transmission protection key is an asymmetric key generated by the working terminal using a classical cryptographic algorithm based on a physical random number and a preset quantum key, wherein the private key of the transmission protection key is an enhanced random number obtained by the working terminal by calling a second cryptographic module to generate a physical random number, and encrypting and hashing the physical random number and the at least one preset quantum key based on a classical cryptographic algorithm; The at least one quantum key is encrypted using the transmission protection key to obtain the at least one quantum key ciphertext; The at least one quantum key ciphertext is sent to the working terminal. The step of encrypting the at least one quantum key using a transmission protection key includes: The at least one quantum key is encrypted using the public key of the transmission protection key, based on the classical cryptographic algorithm.
2. The method for protecting the quantum key distribution process according to claim 1, characterized in that, The classical cryptographic algorithms include any one or more combinations of the following: RSA, SM2, SM3, SM4, SM9, Advanced Encryption Standard (AES), Elliptic Curve Cryptography (ECC), Data Encryption Standard (DES), Triple Encryption Algorithm (3DES), and International Data Encryption Algorithm (IDEA).
3. The method for protecting the quantum key distribution process according to claim 1, characterized in that, The process of obtaining the transmission protection key includes: Receive a digital envelope containing the ciphertext of the transmission protection key from the work terminal; The transmission protection key ciphertext is verified using the digital envelope, and the transmission protection key is obtained after the verification is successful.
4. The method for protecting the quantum key distribution process according to claim 1, characterized in that, The working terminal includes at least one working terminal, the server is configured with a first cryptographic module, and the method further includes: The first cryptographic module is invoked to generate an authentication key, and an identity key and at least one preset quantum key are generated for each work terminal.
5. The method for protecting the quantum key distribution process according to claim 4, characterized in that, The method further includes: The authentication key, identity key, and at least one preset quantum key are stored in a secure storage space.
6. The method for protecting the quantum key distribution process according to claim 5, characterized in that, The first cryptographic module on the server side includes any one or more combinations of a quantum random number generator, a quantum encryption card, a quantum server cryptographic machine, or a software cryptographic module.
7. A method for protecting a quantum key distribution process, the method being applied to a work terminal, the work terminal including a second cryptographic module, the method comprising: Generate a transmission protection key, wherein the transmission protection key is an asymmetric key generated by the working terminal using a classical cryptographic algorithm based on a physical random number and a preset quantum key; The transmission protection key is encrypted to obtain the ciphertext of the transmission protection key. The transmission protection key ciphertext is sent to the server, and the quantum key ciphertext is received from the server, wherein the quantum key ciphertext is obtained by encrypting at least one quantum key using the public key of the transmission protection key based on the classical cryptographic algorithm; The quantum key ciphertext is decrypted to obtain the quantum key, which is then used as the working key. The generation of the transmission protection key includes: The second cryptographic module is invoked to generate a physical random number; The physical random number and the at least one preset quantum key are encrypted and hashed using classical cryptographic algorithms to obtain an enhanced random number, which is then used as the private key for transmitting the protection key.
8. The method for protecting the quantum key distribution process according to claim 7, characterized in that, The encryption of the transmission protection key includes: The transmission protection key is encrypted using a classic cryptographic algorithm.
9. The method for protecting the quantum key distribution process according to claim 7, the method further comprising: The authentication key, identity key, and at least one pre-set quantum key are injected into the second cryptographic module either pre-set or offline.
10. A system for protecting the quantum key distribution process, characterized in that, include: On the server side, there is at least one work terminal and a network, wherein the server side is configured with a key management system. The key management system is used to perform the method for protecting the quantum key distribution process as described in any one of claims 1 to 6; The working terminal performs the method for protecting the quantum key distribution process as described in any one of claims 7 to 9.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for performing the method for protecting the quantum key distribution process according to any one of claims 1 to 6, and / or for performing the method for protecting the quantum key distribution process according to any one of claims 7 to 9.
12. A quantum computer for protecting the quantum key distribution process, characterized in that, The quantum computer includes a control module and a quantum random number generation module. The control module is configured to: in response to a key request from the server, invoke the quantum random number generation module to generate a true random number sequence as the quantum key in the method for protecting the quantum key distribution process according to any one of claims 1 to 6.
Citation Information
Patent Citations
Quantum key distribution method and system for power terminal
CN115333729A