Communication method and system based on MACsec channel and electronic equipment

By introducing quantum key distribution equipment into the MACsec communication system and generating hybrid keys, the key management and transmission security issues in MACsec communication are solved, and end-to-end secure communication against quantum computing attacks is achieved.

CN120768619APending Publication Date: 2025-10-10ANHUI GUOKE QUANTUM NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510974909.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing MACsec secure communications have problems with key management and transmission security, and traditional cryptographic algorithms cannot resist quantum computing attacks.

Method used

By introducing a quantum key distribution device into the communication system, generating the first MACsec key and the quantum key, and mixing them to generate the second MACsec key, the dual mechanism of quantum key and classical key is combined to ensure the confidentiality and integrity of link layer data and resist quantum computing attacks.

Benefits of technology

Improves the key security of encrypted session data, ensures end-to-end security of MACsec communications under the threat of quantum computing, and prevents keys from being cracked by quantum computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768619A_ABST
    Figure CN120768619A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of quantum security communication, and discloses a communication method and system based on an MACsec channel, and electronic equipment. The method comprises the steps that a first MACsec secret key is generated, a second MACsec secret key and a protocol message are generated according to the first MACsec secret key and a first quantum secret key, and the protocol message at least comprises a plurality of secret key information generated by the first MACsec secret key and the first quantum secret key; the protocol message is sent to the second device, so that the second device determines the second MACsec secret key according to the first MACsec secret key and the protocol message; and establishing an MACsec channel with a second device, encrypting the MACsec session data based on the second MACsec key, and sending the encrypted MACsec session data to the second device through the MACsec channel. Through the method, the security of the MACsec communication process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of quantum secure communication technology, and in particular to a communication method, system, and electronic device based on a MACsec channel. Background Art

[0002] MACsec (Media Access Control Security) is a protocol that provides secure communications at the data link layer (OSI layer 2). Its implementation process is as follows: Figure 1 As shown, it is used to protect the confidentiality, integrity and data source authenticity of Ethernet frames.

[0003] In current MACsec secure communications, although cryptographic algorithms are used for encryption protection, many challenges still exist, especially in key management, transmission security, and the inability of traditional cryptographic algorithms to resist quantum computing attacks. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a communication method, system and electronic device based on a MACsec channel, so as to improve the security of the MACsec communication process.

[0005] To solve the above technical problems, an embodiment of the present application provides a communication method based on a MACsec channel, which is applied to a first device, including: generating a first MACsec key, and generating a second MACsec key and a protocol message based on the first MACsec key and a first quantum key, wherein the protocol message includes at least a number of key information generated by the first MACsec key and the first quantum key; sending the protocol message to the second device, for the second device to determine the second MACsec key based on the first MACsec key and the protocol message; establishing a MACsec channel with the second device, encrypting MACsec session data based on the second MACsec key, and sending the encrypted MACsec session data to the second device through the MACsec channel.

[0006] An embodiment of the present application also provides a communication method based on a MACsec channel, which is applied to a second device, including: generating a first MACsec key; obtaining a protocol message from the first device, wherein the protocol message includes at least some key information; determining a second MACsec key based on the first MACsec key and the protocol message; establishing a MACsec channel with the first device, and decrypting encrypted MACsec session data sent by the first device through the MACsec channel based on the second MACsec key.

[0007] An embodiment of the present application further provides a communication system, the system comprising at least a first device, a second device, a first QKD device, and a second QKD device; wherein the first device is configured to generate a first MACsec key, and generate a second MACsec key and a protocol message based on the first MACsec key and the first quantum key, wherein the protocol message at least includes a plurality of key information generated by the first MACsec key and the first quantum key; send the protocol message to the second device, for the second device to determine the second MACsec key based on the first MACsec key and the protocol message; establish a MACsec channel with the second device, encrypt the MACsec session data based on the second MACsec key, and encrypt the MACsec session data through The MACsec channel sends the encrypted MACsec session data to a second device; the second device is configured to generate a first MACsec key; obtain a protocol message from the first device, wherein the protocol message includes at least some key information; determine a second MACsec key based on the first MACsec key and the protocol message; establish a MACsec channel with the first device, and decrypt the encrypted MACsec session data sent by the first device through the MACsec channel based on the second MACsec key; the first QKD device is configured to provide a first quantum key and a key identifier corresponding to the first quantum key to the first device; and the second QKD device is configured to provide a second quantum key to the second device based on the key identifier.

[0008] Compared with the related art, the implementation method of the present application generates a first MACsec key in the first device and the second device respectively. The first device also generates a second MACsec key and a protocol message based on the first MACsec key and the quantum key, and sends the protocol message to the second device, so that the second device can generate the second MACsec key based on the key information contained in the protocol message and the first MACsec key. In the subsequent data communication, the first device and the second device complete the authentication to establish a MACsec communication channel, and the first device and the second device encrypt and decrypt the data respectively using the second MACsec key to ensure the confidentiality and integrity of the link layer data. The present application generates a second MACsec key by mixing the first MACsec key and the quantum key, effectively improving the security of the key used to encrypt the session data, so that the key can resist quantum computing attacks, and ensure the end-to-end security of MACsec communication under the threat of quantum computing. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] One or more embodiments are exemplarily illustrated by pictures in the corresponding drawings. These exemplifications do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements. Unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0010] Figure 1 is a flowchart of the MACsec protocol in the related art;

[0011] Figure 2 Schematic diagram of the communication process of the communication system provided in an embodiment of the present application;

[0012] Figure 3 is a structural diagram of an electronic device provided by another embodiment of the present application;

[0013] Figure 4 is a flowchart of a MACsec channel-based communication method applied to a first device provided in another embodiment of the present application;

[0014] Figure 5 This is a flowchart of a two-way authentication protocol involved in a MACsec channel-based communication method provided in another embodiment of the present application;

[0015] Figure 6 This is a schematic diagram of a MACsec message protocol format involved in a MACsec channel-based communication method provided in another embodiment of the present application;

[0016] Figure 7 This is a flowchart of a MACsec channel-based communication method applied to a second device provided in another embodiment of the present application. DETAILED DESCRIPTION

[0017] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, each embodiment of the present application will be described in detail below with reference to the accompanying drawings. However, it will be understood by those skilled in the art that in each embodiment of the present application, many technical details are proposed in order to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can be implemented. The division of the following embodiments is for convenience of description and should not constitute any limitation on the specific implementation of the present application. The various embodiments can be combined with each other and referenced to each other under the premise of no contradiction.

[0018] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0019] In the current MACsec secure communication, although cryptographic algorithms are used for encryption protection, there are still many challenges, especially in key management, transmission security, and technical problems such as the inability of traditional cryptographic algorithms to resist quantum computing attacks. The embodiment of the present application provides a communication system, such as Figure 2 As shown, the system includes a first device, a second device, a first QKD device matching the first device, and a second QKD device matching the second device. The system implements the MACsec channel-based communication method provided in the embodiment of the present application through the above-mentioned devices (this article will elaborate on this later and will not be repeated here).

[0020] Among them, the first QKD device (such as Figure 2 The QKD-A or QKD-B (shown) and the second QKD device are quantum key distribution (QKD) devices, which leverage the properties of quantum mechanics to ensure communication security. They enable both communicating parties to generate and share a random, secure quantum key for encrypting and decrypting messages, and provide physically secure key material, guaranteeing the randomness of the key based on the principle of quantum non-cloning. Different QKD devices are interconnected via a quantum network, effectively supporting large-scale, distributed key distribution.

[0021] The first QKD device is used to provide a first quantum key and a key identifier (KID) corresponding to the first quantum key to the first device; the second QKD device is used to provide a second quantum key to the second device according to the key identifier (KID).

[0022] Among them, the two ends of the communication between the first device and the second device (both can serve as key servers or peer devices during the communication process) execute the MACsec protocol to establish a MACsec communication channel, and are responsible for key negotiation and data encryption and decryption processes.

[0023] The first device is configured to generate a first MACsec key (Master Session Key, MSK); and a first quantum key (such as Figure 2 The method comprises: using the first MACsec key (MSK) and the first quantum key (SAK2) to generate a second MACsec key (Secure Association Key, SAK) and a protocol message, wherein the protocol message includes at least a plurality of key information generated by the first MACsec key (MSK) and the first quantum key (SAK2); sending the protocol message to the second device through the MACsec channel, so that the second device determines the second MACsec key (SAK) according to the first MACsec key (MSK) and the protocol message; establishing a MACsec channel with the second device, encrypting MACsec session data based on the second MACsec key (SAK), and sending the encrypted MACsec session data to the second device through the MACsec channel.

[0024] The second device is used to generate a first MACsec key (MSK); obtain a protocol message from the first device, wherein the protocol message includes at least some key information; determine a second MACsec key (SAK) based on the first MACsec key (MSK) and the protocol message; establish a MACsec channel with the first device, and decrypt the encrypted MACsec session data sent by the first device through the MACsec channel based on the second MACsec key (SAK).

[0025] By using the above-mentioned quantum key-based security enhancement communication system for MACsec communication, QKD is used to provide a physical layer secure quantum key (SAK2). Combined with the classical key (MSK) of the MACsec protocol, both ends collaborate to generate a more secure session key, namely the second MACsec key (SAK), so that the link layer data encryption can resist quantum computing attacks and solve the problem that traditional MACsec keys are easily cracked by quantum.

[0026] In view of the problems of key management, transmission security, and the inability of traditional cryptographic algorithms to resist quantum computing attacks in current MACsec secure communications, the embodiment of the present application also provides an electronic device, such as Figure 3 As shown, it includes: at least one processor; and a memory communicatively connected to the at least one processor, wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the MACsec channel-based communication method provided in an embodiment of the present application (this article will explain in detail later and will not be repeated here).

[0027] The memory and the processor are connected in a bus manner, the bus can include any number of interconnected buses and bridges, the bus connects various circuits of one or more processors and memories together. The bus can also connect various other circuits such as peripheral devices, voltage stabilizers and power management circuits together, which are well known in the art, therefore, further description will not be made herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements such as multiple receivers and transmitters, which provide units for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted on the wireless medium through the antenna, further, the antenna also receives data and transmits the data to the processor. The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management and other control functions. While the memory can be used to store data used by the processor in performing operations.

[0028] Through the above manner of the present application, a communication system and an electronic device for implementing a communication method based on a MACsec channel are built, so that the communication method can be carried out based on the system or device, the security of the key for encrypting session data is effectively improved, the key can resist quantum computing attacks, and the end-to-end security of MACsec communication under quantum computing threats is ensured.

[0029] Under the above-mentioned software and hardware running environment, in view of the problems of key management, transmission security, and the inability of traditional cryptographic algorithms to resist quantum computing attacks in current MACsec secure communication, the present application embodiment provides a communication method based on a MACsec channel. In the method, the first device and the second device each generate a first MACsec key (MSK), and the first device further generates a second MACsec key (SAK) and a protocol message according to the first MACsec key and a quantum key, and sends the protocol message to the second device, so that the second device can generate the second MACsec key (SAK) according to the first MACsec key and the key information contained in the protocol message. In subsequent data communication, the first device and the second device complete authentication to establish a MACsec communication channel, and the first device and the second device respectively encrypt and decrypt data through the second MACsec key (SAK), to ensure the confidentiality and integrity of the link layer data. The present application generates the second MACsec key (SAK) by mixing the first MACsec key and the quantum key, effectively improves the security of the key for encrypting session data, so that the key can resist quantum computing attacks, and ensures the end-to-end security of MACsec communication under quantum computing threats. In order to facilitate understanding of the communication method based on the MACsec channel provided by the present application, the different implementation processes thereof will be described below.

[0030] In some embodiments, a flow chart of a communication method based on a MACsec channel applied to a first device is as follows: Figure 4 As shown, the following steps are included:

[0031] In step 401, a first device generates a first MACsec key; and generates a second MACsec key and a protocol message based on the first MACsec key and the first quantum key, wherein the protocol message includes at least some key information generated by the first MACsec key and the first quantum key.

[0032] In step 402, the first device sends a protocol message to the second device, so that the second device can determine a second MACsec key based on the first MACsec key and the protocol message.

[0033] In step 403 , the first device establishes a MACsec channel with the second device, encrypts the MACsec session data based on the second MACsec key, and sends the encrypted MACsec session data to the second device through the MACsec channel.

[0034] In this way, the first device and the second device each generate a first MACsec key (Master Session Key, MSK), and the first device also generates a second MACsec key (SAK) and a protocol message based on the first MACsec key and the quantum key, and sends the protocol message to the second device, so that the second device can generate a second MACsec key (SAK) based on the key information contained in the protocol message and the first MACsec key. In subsequent data communications, the first device and the second device complete the authentication to establish a MACsec communication channel, and the first device and the second device respectively encrypt and decrypt the data through the second MACsec key (SAK) to ensure the confidentiality and integrity of the link layer data. This application generates a second MACsec key (SAK) by mixing the first MACsec key and the quantum key, effectively improving the security of the key used to encrypt session data, so that the key can resist quantum computing attacks, and ensure the end-to-end security of MACsec communications under the threat of quantum computing.

[0035] To facilitate better understanding of those skilled in the art Figure 4 The communication method based on the MACsec channel shown is further described below.

[0036] Prior to step 401, in practical applications, the first and second devices must complete mutual authentication to confirm each other's identities. This authentication process requires combining post-quantum certificates (such as SPHINCS+ signature certificates) and a quantum random number generator (QRNG) to ensure that identity authentication is resistant to quantum computing attacks. After the authentication process is successful, both parties derive the first MACsec key (Master Session Key, MSK), or master key, based on the random number and algorithm parameters used in the authentication process.

[0037] The embodiment of the present application also provides a two-way authentication protocol (Extensible Authentication Protocol-Transport Layer Security, EAP-TLS). Different from the classic EAP-TLS standard process, the algorithm, certificate, and key derivation in this embodiment are replaced with a post-quantum solution. At the same time, a quantum random number generator is incorporated to generate quantum random numbers, allowing the identity authentication process that originally relied on RSA and ECC to resist quantum computer attacks. The MSK finally generated is no longer a product of traditional cryptography, but a security key that integrates post-quantum algorithms and quantum random numbers, providing a quantum-resistant foundation for the subsequent MACsec session key (SAK). It should be noted that some steps in the embodiment of the present application (such as step 401) correspond to some steps in the "Certificate-based Two-Way Authentication Protocol (EAP-TLS)".

[0038] See also Figure 5 , Figure 5 The flowchart of the certificate-based mutual authentication protocol (EAP-TLS) includes the following steps:

[0039] 1. The second device (client) initiates authentication (steps A-1 to A-2).

[0040] A-1: The second device (client) sends a ClientHello message to the first device (server). The message contains the second device's protocol version number, a quantum random number generated by a QRNG, a second device session identifier, and a list of cipher suites containing post-quantum cryptographic algorithms.

[0041] B-2: The first device sends a ServerHello message to the second device. The message contains the protocol version of the first device, the quantum random number of the first device generated by QRNG, the session identifier of the first device, and the post-quantum cipher suite selected by the first device.

[0042] 2. The first device (server) sends a certificate and exchanges keys (steps B-3 to B-6).

[0043] B-3. ​​The first device sends a post-quantum signature certificate and a post-quantum encryption certificate to the second device.

[0044] B-4. The first device sends a key exchange message to the second device. The message content includes key exchange parameters, a first quantum random number, and a first device signature. The first quantum random number is generated by a first QONG device that matches the first device. The first device signature uses the signature public key corresponding to the first device's post-quantum signature certificate using the SPHINCS+ algorithm to obtain a signature value, which is used by the second device to verify its identity based on the signature value.

[0045] B-5. The first device sends a certificate request message to the second device, where the certificate request message requires the second device to provide a post-quantum certificate list.

[0046] B-6. The first device sends a Hello completion message to the second device, notifying the second device that the Hello message processing is complete.

[0047] 3. The second device (client) responds with authentication and key exchange (steps A-7 to A-10).

[0048] A-7. The second device sends the second device post-quantum signature certificate and post-quantum encryption certificate to the service.

[0049] A-8. The second device sends a key exchange message to the first device. The key exchange message includes a quantum random number generated by the second device using a QRNG and a signature of the second device. The signature of the second device uses the signature public key corresponding to the second device's post-quantum signature certificate and the SPHINCS+ algorithm to obtain a signature value, which is used by the first device to verify its identity based on the signature value.

[0050] A-9. The second device sends a certificate verification message to the first device to verify whether the second device is the correct holder of the certificate.

[0051] A-10. The second device sends a handshake completion message to the first device.

[0052] 4. First device (server) confirms and prepares encryption (steps B-11 to B-12).

[0053] B-11, the server sends a password change message to the client, informing the client that after this message, data will be sent encrypted with the previously negotiated key.

[0054] B-12, the server sends a message completion message to the client.

[0055] The first device and the second device of the embodiment implement bidirectional authentication based on certificates (hereinafter referred to as "certificate-based EAP-TLS"), in which both devices sign using SPHINCS+, encrypt using ML-KEM, and derive keys using a post-quantum KDF, completely replacing traditional RSA / ECC algorithms to resist quantum computing attacks; all random parameters are generated by QRNG to eliminate the predictability vulnerability of pseudo-random numbers; the first device and the second device verify the post-quantum certificates of each other to ensure that the identity cannot be forged; and random numbers are encrypted during the key exchange process to avoid plaintext leakage. Through the above process, the dual mechanism of "post-quantum cryptography and quantum random numbers" is realized, and quantum-resistant secure authentication and key agreement are achieved at the link layer, providing a secure foundation for subsequent MACsec session encryption.

[0056] In some embodiments, for step 401, generating the first MACsec key can be implemented by: generating a first key exchange message, and obtaining a second key exchange message sent by the second device; completing identity authentication with the second device using the first key exchange message and the second key exchange message, and generating the first MACsec key using the second key exchange message.

[0057] In some embodiments, generating the first MACsec key using the second key exchange message can be implemented by: parsing the second key exchange message to obtain a second quantum random number; and generating the first MACsec key according to the first quantum random number and the second quantum random number, wherein the first quantum random number is obtained from a first quantum random number generator matched with the first device, and the second quantum random number is obtained from a second quantum random number generator matched with the second device.

[0058] Specifically, the first MACsec key (MSK) can be generated according to a pre-master key, a fixed string, and a first device random number and a second device random number; wherein the pre-master key is the version information of the current EAP-TLS protocol, and the fixed string is a pre-stored string. Alternatively, the first MACsec key (MSK) can also be pre-stored between the first device and the second device.

[0059] Because classic EAP-TLS uses a pseudo-random number generator to generate random numbers (such as ClientHello.random), there is a risk of predictability. Therefore, this application uses a quantum random number generator to generate true random numbers based on quantum physics phenomena (such as photon polarization states) to ensure that random numbers are unpredictable and resist statistical attacks from quantum computing. Quantum random numbers are integrated into the first MACsec key generation process, and the post-quantum public key in the certificate is further used to verify identity, and the certificate is used as one of the entropy sources for key derivation. Compared with the universal MasterSecret derived from classic EAP-TLS, this application solution integrates quantum random numbers to ensure that even if a quantum computer cracks the traditional password, the first MACsec key remains secure.

[0060] In step 401, a second MACsec key (SAK) and a protocol message are generated based on the first MACsec key (MSK) and the first quantum key (SAK2). This can be achieved by determining a session key component (SAK1) based on the first MACsec key (MSK); and generating the second MACsec key (SAK) based on the session key component (SAK1) and the first quantum key (SAK2).

[0061] See also Figure 2 , Figure 2 In addition to showing the interaction relationship between each device, a process of the MKA protocol is also given. MKA (MACsec Key Agreement) is the core key management protocol of MACsec, which is used to dynamically negotiate the session key (SAK). The MKA process in this application integrates QKD and PQC technologies to solve the problems of key derivation relying on non-quantum-resistant algorithms and insecure key transmission in traditional protocols, and realizes quantum-safe link layer key management. Some steps in the embodiments of this application (such as step 401 and step 402) are implemented based on the "MKA protocol".

[0062] The flowchart of the MKA protocol process includes the following steps:

[0063] 1) After the MACsec function is enabled on the interfaces of the two devices, a key server (KeyServer) is elected based on priority.

[0064] 2) The key server uses the CAK (Secure Connectivity Association Key) and CKN to derive the session key component 1 (SAK1), key encryption key (KEK) and integrity check key (ICK).

[0065] 3) The key server obtains the quantum key from QKD-A as the session key component 2 (SAK2) and the quantum key identifier (Key ID, KID) corresponding to the quantum key.

[0066] 4) The key server calculates the hash value of SAK2 to obtain HSAK2.

[0067] 5) The key server uses KEK to encrypt SAK1 to obtain encrypted (ENC-SAK1), and uses ICK to generate an integrity check value (ICV).

[0068] 6) The key server encapsulates the KID, HASK2, and ENC-SAK1 in an MKA protocol message and sends it to the peer device.

[0069] 7) The peer device uses the CAK and CKN to derive a key encryption key (KEK) and an integrity check key (ICK), and uses the ICK to generate an integrity check value (ICV).

[0070] 8) The peer device receives the MKA protocol message, uses ICK verification, and verifies the integrity of the message. If the verification is successful, the subsequent process continues. If the verification fails, an error message is returned.

[0071] 9) After parsing the MKA protocol message, the peer device obtains KID, HASK2, and ENC-SAK1.

[0072] 10) The peer device obtains SAK2 from QKD-B using KID. If the key cannot be obtained, an error message is returned and the MKA key negotiation process is restarted.

[0073] 11) The peer device calculates the hash value of SAK2 and compares it with HASK2 to see if they are consistent. If they are consistent, the subsequent process continues.

[0074] 12) The peer device uses its own KEK to decrypt ENC-SAK1 and obtain SAK1.

[0075] 13) The key server and the peer device use SAK1 and SAK2 to synthesize the session key SAK. The synthesis formula is: SAK = KDF(SAK1||SAK2,"PQC-SAK",256).

[0076] Specifically, after the MACsec function is enabled on the interfaces of both devices, the primary device is determined as the key server (i.e., the first device) and the other is the client (i.e., the second device) based on the device priority (e.g., MAC address, configuration weight, etc.). Figure 2The "key server" in the first MACsec key (MSK) uses the first MACsec key (MSK) to derive a pre-shared key (CAK) and a key identifier (CKN), wherein the pre-shared key is derived from the MSK and the key identifier is derived synchronously with the CAK. After obtaining the pre-shared key (CAK) and the key identifier (CKN), the first device further derives a session key component (such as Figure 2 "SAK1" in ), the key encryption key (such as Figure 2 "KEK" in the ) and the integrity check key ( Figure 2 The "ICK" in the figure is used to encrypt the data. SAK1 is derived from the post-quantum KDF (such as HMAC-SHA3) and is used for quantum-resistant encryption. KEK is used to encrypt SAK1 to avoid plaintext transmission. ICK is used for integrity verification of MKA messages. At the same time, the derivation of SAK1 in this process is based on the post-quantum algorithm to ensure resistance to quantum attacks. The first quantum key (SAK2) is the first device (such as Figure 2 The "key server" in the Figure 2 "QKD-A" in the Figure 2 The quantum key SAK2 is obtained by the peer device, and the key identifier (KID) corresponding to the quantum key SAK2 is obtained to help the peer device index the key.

[0077] The first device can generate the second MACsec key (such as Figure 2 For ease of understanding, a synthesis method is given here:

[0078] SAK=KDF(SAK1||SAK2,"PQC-SAK",256);

[0079] Here, KDF stands for post-quantum key derivation function, "PQC-SAK" is a tag that ensures the uniqueness of the synthesis logic, and 256 represents the generation of a 256-bit key. Thus, the SAK is composed of "SAK1 derived from a quantum-resistant algorithm" and "SAK2 generated by quantum physics." An attacker must crack both the algorithmic and physical layers to obtain the SAK, achieving dual protection.

[0080] Furthermore, the first device also needs to generate a protocol message. In some embodiments, the protocol message includes at least some key information, and the key information includes: a quantum key hash value (HSAK2), an encrypted session key component (ENC-SAK1), and a key identifier (KID); wherein the quantum key hash value (HSAK2) is obtained by calculating a hash operation on the first quantum key (SAK2); the encrypted session key component (ENC-SAK1) is obtained by encrypting the session key component (SAK1); and the key identifier (KID) is used to identify the first quantum key (SAK2).

[0081] The first device performs a hash operation (such as SHA-256) on SAK2 to obtain HSAK2. HSAK2 is sent along with the message to the peer device to verify the consistency of SAK2 on both sides and prevent key tampering or man-in-the-middle attacks. The first device then encrypts SAK1 (Key Encryption Key) using the KEK to obtain ENC-SAK1. After generating the message, it is transmitted to the second device (i.e., the peer device).

[0082] The present application also provides a MACsec message protocol format (see Attached Figure 6 ), containing at least the destination address, source address, and SECTAG fields. The MKA protocol message is the core carrier of MACsec link layer key negotiation. It adheres to the IEEE802.1AE standard format and implements quantum-resistance enhancements through the addition of new fields (KID, HSAK2, and ENC-SAK1). Its core function is to securely transmit key components between the key server and the peer device, ensuring that the session key (SAK) negotiation process is resistant to interception and tampering.

[0083] Specifically, if Figure 6 As shown, the protocol message in this embodiment includes at least the following: destination address (such as Figure 6 "1" in ), source address (such as Figure 6 "2" in ), safety tags (SECTAG, such as Figure 6 "3" in ), encrypted data (core anti-quantum fields, such as Figure 6 "4" in the ), Integrity Check Value (ICV, such as Figure 6 5) and the frame check sequence (FCS).

[0084] The destination address identifies the MAC address of the message recipient, ensuring accurate delivery of the message to the peer device. The source address identifies the MAC address of the key server and is used to trace the message's origin. Combined with subsequent security fields (such as SECTAG and ICV), this ensures the address has not been tampered with, preventing man-in-the-middle attacks from replacing the target address.

[0085] SECTAG includes at least an encryption identifier and a key index, which are used to quickly identify the security status of a message, prevent unencrypted messages from being forged, and provide context for subsequent key processing. The encryption identifier is used to mark whether the message is encrypted (such as the SCrypt identifier in MACsec), and the key index is used to implicitly indicate the key version used. It works with the KID to locate SAK2.

[0086] The encrypted data at least includes the data block after the original data is encrypted: VLAN ( Figure 6 "4-1" in), Ethernet type ( Figure 6 "4-2" in the ), KID (Quantum Key Identifier, Figure 6 "4-3" in ), HSAK2( Figure 6 "4-4" in) and ENC-SAK1 ( Figure 6 VLAN is the virtual local area network identifier used for network isolation; Ethernet type defines the upper-layer protocol type, such as IPv4 (0x0800); KID is used to identify the currently used SAK2 (the quantum key generated by QKD); HSAK2 is the hash value of SAK2 (such as SHA-256), used to verify the consistency of SAK2; ENC-SAK1 is the encrypted SAK1, which is derived from the MSK and encrypted by the KEK.

[0087] ICV is generated by applying a post-quantum hash algorithm (such as SHA3) to encrypted data using an integrity check key (ICK) to verify that the data has not been tampered with during transmission.

[0088] FCS and ICV form a double check. ICV is for encrypted data, and FCS is for the entire message, preventing attackers from tampering with non-encrypted fields (such as addresses) and enhancing security.

[0089] This protocol message does not directly transmit SAK2 plaintext; instead, it only indexes the key in the QKD device through the KID, achieving "zero key transmission" and preventing quantum computers from intercepting the key. The second device calculates the SAK2 hash and compares it with the HSAK2 to ensure that both parties use the same key, preventing key replacement. Furthermore, the first device encrypts SAK1 using a post-quantum symmetric algorithm (PQC-SM4), making it difficult for a quantum computer to crack even if the transmission is intercepted. If the MKA message is periodically updated, the SAK can also be dynamically refreshed. Combined with QKD's real-time key generation, this provides resistance to sustained quantum attacks.

[0090] In step 403, the first device uses the SAK to encrypt the transmitted data using the PQC-SM4 algorithm in the session encryption stage, and transmits the encrypted data to the second device. Those skilled in the art can understand that since the first device and the second device have the same SAK and share the PQC-SM4 algorithm, both parties can encrypt and decrypt data.

[0091] In this way, the second MACsec key (SAK) is generated by mixing the first MACsec key and the quantum key, effectively improving the security of the key used to encrypt session data, so that the key can resist quantum computing attacks and ensure the end-to-end security of MACsec communication under the threat of quantum computing.

[0092] Another embodiment of the present application relates to a flowchart of a MACsec channel-based communication method applied to the second device as shown in Figure 7 The method comprises the following steps:

[0093] In step 701, the second device generates a first MACsec key and obtains a protocol message from the first device through a MACsec channel, wherein the protocol message comprises at least a plurality of key information.

[0094] In step 702, the second device determines a second MACsec key according to the first MACsec key and the protocol message.

[0095] In step 703, the second device establishes a MACsec channel with the first device and decrypts encrypted MACsec session data sent by the first device through the MACsec channel based on the second MACsec key.

[0096] In this way, the first device and the second device each generate a first MACsec key (i.e., a master session key, MSK), the first device further generates a second MACsec key (SAK) and a protocol message according to the first MACsec key and a quantum key, and sends the protocol message to the second device, and the second device can generate the second MACsec key (SAK) according to the plurality of key information contained in the protocol message and the first MACsec key. In subsequent data communication, the first device and the second device complete authentication to establish a MACsec communication channel, and the first device and the second device respectively encrypt and decrypt data through the second MACsec key (SAK), thereby ensuring the confidentiality and integrity of the link layer data. The second MACsec key (SAK) is generated by mixing the first MACsec key and the quantum key, effectively improving the security of the key used to encrypt session data, so that the key can resist quantum computing attacks and ensure the end-to-end security of MACsec communication under the threat of quantum computing.

[0097] To facilitate better understanding of those skilled in the art Figure 7 The communication method based on the MACsec channel shown is further described below.

[0098] Prior to step 701, two-way authentication (similar to a "network handshake") must be implemented between the first and second devices to confirm the correctness of each other's identities. During the authentication process, a combination of post-quantum certificates (such as SPHINCS+ signature certificates) and quantum random numbers (generated by a QRNG) is required to ensure that identity authentication is resistant to quantum computing attacks. After the authentication process, if the authentication is successful, both parties derive the first MACsec key (Master Session Key, MSK), or the master key MSK, based on the random number and algorithm parameters used in the authentication process.

[0099] For step 702, determining the second MACsec key (SAK) based on the first MACsec key (MSK) and the protocol message can be implemented as follows: the second device uses the key identifier (KID) to obtain the second quantum key (SAK2), and determines the correctness of the second quantum key (SAK2) based on the quantum key hash value (HSAK2); if correct, decrypting the encrypted session key component (ENC-SAK1) to obtain the session key component (SAK1); and generating the second MACsec key (SAK) based on the session key component (SAK1) and the second quantum key (SAK2).

[0100] Specifically, the second device (such as Figure 2 The "non-key server" in the original text also derives the CAK and CKN consistent with the first device based on the first MACsec key (MSK). It also locally generates a KEK and ICK based on the CAK and CKN, which are consistent with the results derived by the key server and used for subsequent decryption and verification. The ICK is further used to calculate the integrity check value (ICV) of the received MKA message and compare it with the ICV in the message. If they are consistent, the process continues; otherwise, an error is returned and negotiation is renegotiated to prevent message tampering.

[0101] In some embodiments, obtaining a second quantum key using the key identifier and determining the correctness of the second quantum key based on the quantum key hash value can be achieved in the following manner: providing the key identifier to a second QKD device that matches the second device, so that the second QKD device obtains the second quantum key based on the key identifier; obtaining the second quantum key from the second QKD device; performing a hash operation on the second quantum key, comparing the operation result with the quantum key hash value, and determining that the second quantum key is correct if they are consistent.

[0102] Specifically, the second device extracts KID, HSAK2 and ENC-SAK1 from the message to prepare for subsequent key synthesis. The local QKD device (such as Figure 2 The "QKD-B" in the message uses the key identifier (KID) in the message to obtain the corresponding second quantum key (such as Figure 2 If SAK2 is not obtained (such as the key expires or the QKD link is interrupted), an error is returned and the MKA process is restarted. After obtaining the local SAK2 (i.e., the second quantum key), the hash value of the local SAK2 is calculated and compared with the HSAK2 in the message to verify the correctness of the local SAK2 (the second quantum key). In this way, the above verification process ensures that the SAK2 obtained by the other end is consistent with the one sent by the key server to prevent the key from being replaced. The second device further uses the locally derived KEK to decrypt ENC-SAK1 to obtain SAK1, where the locally derived KEK is consistent with the KEK derived by the first device, so that the decryption is successful.

[0103] Through the above process, the second device now possesses local SAK2 and the decrypted SAK1. It then synthesizes the second MACsec key (SAK) using SAK2 and SAK1. During this synthesis process, the first and second devices use the same synthesis method: SAK = KDF(SAK1||SAK2,"PQC-SAK",256). This process has been explained above and will not be repeated here.

[0104] In this way, SAK1 is derived through a quantum-resistant algorithm, and SAK2 is obtained using QKD, forming a dual-component key synthesis mechanism. SAK1 is transmitted encrypted, and SAK2 is obtained through the KID index. No plaintext key exists on the network, reducing the risk of interception. Furthermore, this application achieves quantum-resistant security throughout the entire process, from key derivation and transmission to synthesis, providing a solid key foundation for MACsec's link-layer encryption.

[0105] Those skilled in the art will appreciate that the above-mentioned embodiments are specific examples for implementing the present application, and that in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present application.

Claims

1. A communication method based on a MACsec channel, applied to a first device, characterized in that: include: Generating a first MACsec key, and generating a second MACsec key and a protocol message based on the first MACsec key and the first quantum key, wherein the protocol message includes at least key information generated by the first MACsec key and the first quantum key; Sending the protocol message to a second device, for the second device to determine the second MACsec key based on the first MACsec key and the protocol message; A MACsec channel is established with the second device, MACsec session data is encrypted based on the second MACsec key, and the encrypted MACsec session data is sent to the second device through the MACsec channel.

2. The communication method based on the MACsec channel according to claim 1, characterized in that: The first quantum key is obtained by the first device from a first QKD device; Generating a second MACsec key according to the first MACsec key and the first quantum key includes: determining a session key component based on the first MACsec key; The second MACsec key is generated based on the session key component and the first quantum key.

3. The communication method based on the MACsec channel according to claim 2, characterized in that: The key information includes: quantum key hash value, encrypted session key component and key identifier; wherein, The quantum key hash value is obtained by calculating a hash operation on the first quantum key. The encrypted session key component is obtained by encrypting the session key component; The key identifier is used to identify the first quantum key.

4. The communication method based on the MACsec channel according to claim 1, characterized in that: Generating a first MACsec key includes: Generate a first key exchange message, and obtain a second key exchange message sent by the second device; The first key exchange message and the second key exchange message are used to complete identity authentication with the second device, and the second key exchange message is used to generate a first MACsec key.

5. The communication method based on the MACsec channel according to claim 4, characterized in that: The generating a first MACsec key by using the second key exchange message includes: Parsing the second key exchange message to obtain a second quantum random number; The first MACsec key is generated according to a first quantum random number and a second quantum random number, wherein the first quantum random number is obtained from a first quantum random number generator matched with the first device, and the second quantum random number is obtained from a second quantum random number generator matched with the second device.

6. A communication method based on a MACsec channel, applied to a second device, characterized in that: include: generating a first MACsec key; Obtaining a protocol message from the first device, wherein the protocol message includes at least some key information; Determine a second MACsec key based on the first MACsec key and the protocol message; A MACsec channel is established with the first device, and encrypted MACsec session data sent by the first device through the MACsec channel is decrypted based on the second MACsec key.

7. The communication method based on the MACsec channel according to claim 6, characterized in that: The key information includes: quantum key hash value, encrypted session key component and key identifier; The determining the second MACsec key according to the first MACsec key and the protocol message includes: Obtaining a second quantum key using the key identifier, and determining the correctness of the second quantum key according to the quantum key hash value; If correct, decrypt the encrypted session key component to obtain the session key component; and generate the second MACsec key according to the session key component and the second quantum key.

8. The communication method based on the MACsec channel according to claim 7, characterized in that: The obtaining of a second quantum key by using the key identifier and determining the correctness of the second quantum key according to the quantum key hash value includes: Providing the key identifier to a second QKD device that matches the second device, so that the second QKD device obtains the second quantum key according to the key identifier; Obtain the second quantum key from the second QKD device; Perform a hash operation on the second quantum key, and compare the operation result with the quantum key hash value. If they are consistent, it is determined that the second quantum key is correct.

9. A communication system, characterized in that: The system comprises at least a first device, a second device, a first QKD device and a second QKD device; wherein, The first device is configured to generate a first MACsec key, generate a second MACsec key and a protocol message based on the first MACsec key and the first quantum key, wherein the protocol message includes at least a plurality of key information generated by the first MACsec key and the first quantum key; send the protocol message to the second device, for the second device to determine the second MACsec key based on the first MACsec key and the protocol message; establish a MACsec channel with the second device, encrypt MACsec session data based on the second MACsec key, and send the encrypted MACsec session data to the second device via the MACsec channel; The second device is configured to generate a first MACsec key; obtain a protocol message from the first device, wherein the protocol message includes at least key information; determine a second MACsec key based on the first MACsec key and the protocol message; establish a MACsec channel with the first device, and decrypt encrypted MACsec session data sent by the first device through the MACsec channel based on the second MACsec key; The first QKD device is configured to provide a first quantum key and a key identifier corresponding to the first quantum key to the first device; The second QKD device is configured to provide a second quantum key to the second device according to the key identifier.

10. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the communication method based on the MACsec channel as described in any one of claims 1 to 5, and\or the communication method based on the MACsec channel as described in any one of claims 6 to 8.