Cloud data security transmission system and method based on quantum encryption technology

By generating physical layer security keys through quantum encryption technology, and combining an adaptive basis matching algorithm and a time-event fusion-driven dynamic update mechanism, the problem that existing encryption technologies cannot resist quantum computing cracking and lack physical layer security is solved. This enables real-time monitoring of the transmission link and highly reliable key management, thereby enhancing the security and continuity of cloud data transmission.

CN120811603BActive Publication Date: 2026-03-27JIUYILI DIGITAL TECH (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing encryption technologies cannot resist the risk of being cracked by quantum computing, lack physical layer security mechanisms, cannot detect eavesdropping in the transmission link in real time, and the key generation and transmission process is not bound to physical layer security, which poses a risk of key leakage.

Method used

Quantum encryption technology is used to generate physical layer security keys. The principle of no cloning of quantum states is used to achieve true random key generation. An improved adaptive basis matching algorithm is combined to optimize key negotiation efficiency. A time-event fusion-driven dynamic update mechanism is used to complete the full life cycle management of keys. Quantum key-derived session keys are combined with national cryptographic symmetric encryption algorithms to encrypt data in segments. Photon polarization state parameters are monitored in real time to detect eavesdropping behavior. When the quantum channel is abnormal, it switches to the classical channel to ensure transmission continuity.

Benefits of technology

It achieves a breakthrough over traditional encryption algorithms, reduces the risk of quantum computing cracking, detects eavesdropping behavior in real time, reduces the risk of key leakage, enhances the encryption system's resistance to quantum attacks, and maintains the secure binding relationship between the key and the physical layer during channel switching, thus reducing security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811603B_ABST
    Figure CN120811603B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to a cloud data security transmission system and method based on quantum encryption technology. The system comprises a quantum key generation and management unit, a data transmission encryption unit, a physical layer security monitoring unit and a channel fusion switching unit. The quantum key generation and management unit is used for generating a physical layer security key, realizes true random generation of the key through the principle of quantum state non-cloning, and optimizes the key negotiation efficiency by using an improved adaptive base vector matching algorithm. The physical layer security monitoring unit is used for collecting photon polarization state parameters in real time, detecting eavesdropping behavior based on a preset bit error rate threshold, realizing real-time perception of eavesdropping behavior in a transmission link, and making up for the deficiency that a traditional scheme cannot perceive the physical layer security state in real time.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a cloud data security transmission system and method based on quantum encryption technology. BACKGROUND

[0002] With the popularization of cloud computing technology, the demand for cloud transmission and storage of core sensitive data such as finance and government has surged, and data security protection needs to meet both dynamic anti-attack capability and long-term security. Traditional encryption systems (such as RSA and ECC) rely on the computational complexity of mathematical problems to ensure security, but the breakthrough of quantum computing technology poses a fundamental threat to such systems - a quantum computer can crack a 2048-bit RSA key in polynomial time, leading to the risk of failure of existing encryption mechanisms under the "quantum threat". In contrast, quantum encryption technology is based on the principles of quantum state cloning and measurement collapse, and can provide physically secure key distribution for cloud data transmission, providing a bottom-layer security guarantee for cloud data transmission, and becoming the core solution for data security transmission in the post-quantum era.

[0003] For example, Chinese patent CN202010929198.7 discloses a time-based cloud data security transmission control method, including the following steps: two-way authentication; dynamic allocation of security algorithm; adding cloud service security time tolerance; cloud data security transmission control; the invention performs two-way authentication between cloud service providers and end users, and can perform algorithm negotiation and key negotiation, thereby realizing access security of cloud services; the invention proposes the concepts of cloud service security time tolerance and security algorithm pool, dynamically allocates security algorithms to both parties of data transmission, and realizes data transmission security of cloud services through cloud suspicious data packet discard mechanism and cloud data security transmission control mechanism. For example, Chinese patent CN202311614155.X discloses a data security system and method in a cloud computing environment based on a national encryption algorithm, which uses the domestic SM3 algorithm to protect the username and login password, uses the SSL / TLS protocol based on domestic cryptography to ensure data transmission security, uses the asymmetric domestic cryptography SM2 algorithm to generate data encryption keys, and uses the symmetric domestic cryptography SM4 algorithm for data encryption and decryption to ensure data storage and access security. The method ensures the safety of the whole process of data access, transmission and storage in the cloud computing environment. At the same time, under the background of Xinyuan security, the system and method proposed by the invention have strong practical significance.

[0004] Although the above technical solutions have corresponding design advantages, the above technical solutions still have the following technical defects: firstly, they all do not break through the mathematical dependence limitation of traditional encryption algorithms, cannot resist the cracking risk of quantum computing to the underlying encryption logic, the dynamic algorithm distribution of Chinese patent CN202010929198.7 only optimizes the timeliness of the key, and the national encryption algorithm of Chinese patent CN202311614155.X is compliant but still belongs to the classical encryption system; secondly, there is a lack of physical layer security mechanism, relying on protocol layer strategy (such as time tolerance, hash check), which cannot realize real-time sensing of eavesdropping behavior in the transmission link, and the key generation and transmission process is not bound to the physical layer security, which has the risk of key leakage. In view of this, we propose a cloud data security transmission system and method based on quantum encryption technology. SUMMARY

[0005] The purpose of the present application is to provide a cloud data security transmission system and method based on quantum encryption technology to solve the problems of not breaking through the mathematical dependence limitation of traditional encryption algorithms, being unable to resist the cracking risk of quantum computing to the underlying encryption logic, lacking a physical layer security mechanism, being unable to realize real-time sensing of eavesdropping behavior in the transmission link, and the key generation and transmission process not being bound to the physical layer security, which has the risk of key leakage.

[0006] To solve the above technical problems, one of the purposes of the present application is to provide a cloud data security transmission system based on quantum encryption technology, which comprises:

[0007] A quantum key generation and management unit is used to generate a physical layer security key, realize true random key generation through the principle of quantum state non-cloning, optimize key negotiation efficiency by using an improved adaptive base vector matching algorithm, and complete key life cycle management based on a time-event fusion driven dynamic update mechanism;

[0008] A data transmission encryption unit is used to realize cloud data encryption transmission, derive a session key from a quantum key, combine a national encryption symmetric encryption algorithm to encrypt data segments, and generate an integrity check code through a national encryption hash algorithm to bind the transmission;

[0009] A physical layer security monitoring unit is used to monitor quantum link security, detect eavesdropping behavior based on a preset bit error rate threshold by real-time acquisition of photon polarization state parameters, and trigger key emergency regeneration;

[0010] A channel fusion switching unit is used to ensure transmission continuity, automatically switch to a secure transmission layer protocol encrypted classical channel using a national encryption algorithm suite when the quantum channel is abnormal, and synchronize and update the session key through the quantum pre-stored key.

[0011] As a further improvement of the technical solution, the quantum key generation and management unit comprises a quantum state encoding module, an adaptive base vector matching module and a key verification module, wherein:

[0012] The quantum state encoding module generates a single-photon sequence containing horizontal, vertical, +45° and -45° polarization states based on the BB84 protocol;

[0013] The adaptive base vector matching module interacts with the measurement base vector information through a classical channel, and dynamically adjusts the base vector selection strategy based on the historical base vector matching success rate;

[0014] The key verification module is used to randomly extract part of the bits from the initially generated key for consistency comparison, and when the inconsistent bit rate exceeds the preset threshold, the key regeneration process is triggered.

[0015] As a further improvement of the technical solution, the quantum key generation and management unit adopts an improved adaptive base vector matching algorithm to optimize the key agreement efficiency, comprising the following steps:

[0016] S140.1, model establishment:

[0017] Establish a base vector matching success rate statistical model to calculate the historical matching success rate of each base vector combination (0 represents rectilinear base, 1 represents diagonal base) :

[0018] ;

[0019] Wherein, is the number of successful matching of base vector combination in the nth round of negotiation, is the total number of attempts of base vector combination in the nth round of negotiation;

[0020] S140.2, probability adjustment:

[0021] Based on the sliding window mechanism, the base vector selection probability is dynamically updated, and for the base vector combination that meets within the continuous rounds, its selection probability in the next round is adjusted according to the following formula :

[0022] ;

[0023] Wherein, is a preset success rate threshold ( ) for judging whether the base vector combination is inefficient;​​ The attenuation coefficient ( ), controlling the magnitude of probability adjustment; when The lower hour, The more significant the attenuation;

[0024] S140.3, Normalization process:

[0025] The basis vector selection probabilities are normalized using an exponential smoothing algorithm to ensure that the sum of the selection probabilities of all basis vector combinations is 1.

[0026] ;

[0027] in, This represents the normalized final selection probability, used to allocate the number of basis vector attempts in the next round; This represents the summation of the original probabilities of the four basis vector combinations, ensuring that the sum is 1 after normalization;

[0028] This step ensures the validity of the probability distribution, enabling the quantum state encoding module to generate single-photon sequences based on normalized probabilities;

[0029] S140.4, Frequency Application:

[0030] Based on the normalized selection probability The basis vector combination is dynamically adjusted during subsequent quantum key negotiation. The selection frequency is as follows:

[0031] ;

[0032] in, For the first The total number of measurements in rounds of negotiation This indicates a floor operation, ensuring the number of attempts is an integer. For the first In the cycle, the basis vector combination The actual number of attempts;

[0033] S140.5, Periodic Reset:

[0034] Each completed After round of negotiations ( (where is a positive integer), reset the historical statistical data of all basis vector combinations to avoid algorithm failure due to long-term changes in channel characteristics. The reset formula is:

[0035] ;

[0036] in, Indicates that the number of successful combinations of all basis vectors is cleared at the start of the algorithm or after periodic reset, avoiding historical data interference with the evaluation of the new period. Indicates that the number of attempts of all basis vector combinations is cleared after the algorithm is started or periodically reset, and is initialized synchronously with the number of successes. Indicates that the selection probability of the four basis vector combinations is evenly distributed after the algorithm is started or periodically reset, ensuring that the algorithm starts to evaluate the performance of the basis vector from an unbiased state.

[0037] As a further improvement of the technical solution, the quantum key generation and management unit, based on the dynamic updating mechanism driven by time-event fusion, completes the whole life cycle management of the key, including the following steps:

[0038] S150.1, Time window definition:

[0039] Assign a dynamic life cycle to each quantum key , the calculation formula is:

[0040] ;

[0041] Where, is the basic time threshold; is the current quantum channel capacity; is the security key length; is the actual generation rate of the key; indicates the conversion factor of natural logarithm and bit unit; is the reference photon transmission rate of the current quantum channel;

[0042] S150.2, event trigger condition:

[0043] When any of the following conditions is met, the key update is triggered immediately:

[0044] The quantum error rate detected by the physical layer security monitoring unit exceeds the dynamic threshold , wherein: , in the formula is the initial error rate threshold, is the current environmental noise intensity, is the calibrated noise reference value, is the noise influence coefficient (NIF) );

[0045] Data layer event: the data transmission encryption unit fails times of data integrity verification in succession, and the verification failure rate exceeds the threshold : ;

[0046] System layer event: system receives external security audit instruction, detects abnormal key usage frequency or reaches preset maximum usage number ;

[0047] S150.3, fusion decision algorithm:

[0048] When the time-driven condition ( ) and the event-driven condition are triggered at the same time, the following decision logic is adopted:

[0049] ;

[0050] If multiple event-driven conditions are triggered at the same time, the priority order is: physical layer event > data layer event > system layer event;

[0051] S150.4, key smooth transition:

[0052] In a preset time period before the end of the current key life cycle , the next cycle key generation process is started, and the new and old key switching adopts an overlapping verification mechanism.

[0053] Further, the overlapping verification mechanism specifically includes:

[0054] Pre-distribution stage ): use the new and old keys to encrypt data at the same time, and generate double verification codes;

[0055] Verification stage ( ): the receiver decrypts and compares the verification codes through the new and old keys respectively to ensure data continuity;

[0056] Invalidation stage ( ): completely discard the old key and only use the new key for data transmission;

[0057] This mechanism realizes adaptive, high-reliable and full-life cycle management of quantum keys through dynamic life cycle calculation, multi-dimensional event triggering and seamless key switching.

[0058] As a further improvement of the technical solution, the data transmission encryption unit includes a quantum-session key derivation module, a dynamic segmentation encryption module and an integrity verification module, wherein:

[0059] The quantum-session key derivation module receives the quantum master key output by the quantum key generation and management unit, generates a session key through the HKDF key derivation algorithm, and the life cycle of the session key is associated with the update event of the quantum master key (when the quantum master key is updated, the session key is invalidated synchronously);

[0060] The dynamic segmented encryption module adopts the national SM4 symmetric encryption algorithm to encrypt cloud data by type;

[0061] The integrity check module generates a data check code through the national SM3 hash algorithm, and the check code is bound to the session key hash value output by the quantum-session key derivation module, so that the transmission of the check code and the encrypted data is associated.

[0062] As a further improvement of the technical solution, the dynamic segmented encryption module encrypts cloud data by type, including the following steps:

[0063] S220.1, data type identification and marking:

[0064] The type is identified by analyzing the format identifier (such as file extension, data header field) of the cloud data:

[0065] If the data contains structured field identifiers (such as JSON key-value separators, table row and column indexes), mark it as structured data type;

[0066] If the data is a continuous byte stream (without explicit field division, such as video frames, log entries), mark it as stream data type;

[0067] S220.2, differential segmentation rule execution:

[0068] According to the marked type, perform the splitting operation:

[0069] For structured data: determine the field boundary based on the field parsing result, split according to the field semantic integrity (ensure that a single field does not cross the segment), and generate an index table containing the field ID and segment mapping relationship;

[0070] For stream data: split by fixed length (such as ≤1MB) sliding window, generate a segment management table containing segment number, starting offset, and segment length;

[0071] S220.3, GCM mode encryption configuration:

[0072] GCM authentication encryption mode using the national SM4 algorithm, the specific configuration is as follows:

[0073] Plain text input: the original content of each data segment;

[0074] Additional authentication data: bind the index information of the corresponding segment (structure data binds field index table segment, stream data binds segment management table segment);

[0075] Encrypted output: the ciphertext data of each segment and the synchronously generated encryption authentication tag (the tag length is consistent with the SM4 algorithm block length);

[0076] S220.4, encrypted authentication tag association storage:

[0077] The encrypted authentication tag of each segment is associated with the ciphertext data of the corresponding segment, specifically including:

[0078] Structured data: the tag is bound to the segment ID in the field index table;

[0079] Streaming data: the tag is bound to the segment sequence number in the segment management table;

[0080] The association relationship is transmitted to the integrity verification module together with the ciphertext data;

[0081] S220.5, session key usage monitoring:

[0082] The encryption load of the current session key is monitored in real time, and when one of the following conditions is met, a key update request is sent to the quantum-session key derivation module:

[0083] The total number of encrypted structured data fields reaches a preset threshold;

[0084] The total number of encrypted streaming data segments reaches a preset threshold;

[0085] The continuous use time length of the session key reaches the life cycle warning value preset by the quantum-session key derivation module.

[0086] As a further improvement of the technical solution, the physical layer security monitoring unit includes a photon parameter acquisition module, a statistical analysis module, a threshold comparison module, and an emergency response module, wherein:

[0087] The photon parameter acquisition module acquires photon polarization state core parameters in real time through a quantum detector array, including horizontal and vertical polarization angles, diagonal polarization angles, and photon arrival time intervals. The acquisition frequency is synchronized with the key generation period of the quantum key generation and management unit;

[0088] The statistical analysis module calculates the actual bit error rate based on the acquired photon parameters, and the statistical rule is the proportion of the number of inconsistent photons to the total number of measured photons. It also maintains the bit error rate fluctuation trend in the sliding time window, and the window length is related to the key generation period;

[0089] The threshold comparison module compares the real-time calculated bit error rate with the dynamic threshold, which is dynamically adjusted according to the following factors: quantum channel initial calibration parameters (such as fiber attenuation coefficient, detector dark count rate), current environmental noise level (real-time acquired by background light intensity monitoring module), key update frequency of the quantum key generation and management unit;

[0090] The emergency response module is used to perform emergency operations when the real-time bit error rate exceeds the dynamic threshold.

[0091] As a further improvement of the technical solution, the emergency response module includes the following steps when performing emergency operation:

[0092] S340.1, abnormal classification threshold definition:

[0093] Let the dynamic threshold output by the threshold comparison module be , the bit error rate be , and the classification rule be:

[0094] ;

[0095] S340.2, classification response execution:

[0096] For a first-level anomaly: trigger key emergency regeneration, and the length of the regenerated key satisfies: ; wherein is the regular key length, used to ensure that the emergency key has enhanced noise resistance;

[0097] For a second-level anomaly: simultaneously perform key emergency regeneration and backup channel switching, and the backup channel switching delay needs to satisfy: ; wherein is the data transmission timeout threshold, used to ensure that the switching does not affect the continuity of transmission;

[0098] S340.3, channel recovery verification formula:

[0099] After enabling the backup channel, send a verification data packet through the original channel, and the verification pass condition is that the bit error rate measured for consecutive times satisfies: , wherein is the bit error rate of the th verification, and when the condition is met, the original channel is automatically switched back;

[0100] S340.4, abnormal data association storage:

[0101] Record the key parameter association relationship during the anomaly, and define an anomaly risk value calculation model:

[0102] ;

[0103] wherein is the key generation period of the quantum key generation and management unit; is the standard deviation of the environmental noise, used for subsequent security audit.

[0104] As a further improvement of the technical solution, the channel fusion switching unit comprises a channel state monitoring module, a switching decision module, a classical channel encryption module and a key synchronization updating module, wherein:

[0105] The channel state monitoring module is used for collecting error code rate data and quantum channel connectivity information output by the physical layer security monitoring unit in real time, and generating a channel switching trigger signal when the error code rate exceeds 1.5 times of a dynamic threshold or the channel is continuously interrupted for more than a preset time length;

[0106] The switching decision module is used for pre-storing a priority strategy of "quantum channel priority, classical channel backup", and after receiving the switching trigger signal, sending a verification data packet through the quantum channel, and if the verification fails for a plurality of times, performing a switching operation, wherein the switching delay needs to meet: ;

[0107] The classical channel encryption module uses the national SM4 symmetric encryption algorithm to encrypt data, and generates a data check code through the national SM3 hash algorithm, and the check code is bound with the encrypted data for transmission;

[0108] The key synchronization updating module obtains a quantum key from a pre-stored key pool of the quantum key generation and management unit, generates a classical channel session key through an HKDF key derivation algorithm, and triggers session key updating when the encrypted data volume of the classical channel reaches a preset proportion of the pre-stored key length or the continuous running time reaches a preset proportion of the session key life cycle.

[0109] The second object of the application is to provide a cloud data security transmission method based on quantum encryption technology, based on the cloud data security transmission system based on quantum encryption technology, comprising the following steps:

[0110] S100, quantum key generation and management: generating a physical layer security key, optimizing key negotiation efficiency by using an improved adaptive basis vector matching algorithm, and completing key full life cycle management through a time-event fusion driven dynamic updating mechanism, and performing key generation, negotiation, verification, updating and smooth transition;

[0111] S200, cloud data encryption transmission: deriving a session key based on a quantum key, encrypting cloud data by type, and realizing data encryption and integrity check by using a national symmetric encryption algorithm and a hash algorithm, and associating encrypted data and check information for transmission;

[0112] S300, physical layer security monitoring: collecting photon polarization state parameters in real time, calculating an error code rate and comparing it with a dynamic threshold, and performing key emergency regeneration, backup channel switching and abnormal data recording according to the error code rate grading result;

[0113] S400, channel fusion switching: monitoring quantum channel state, switching to classical channel when channel is abnormal, classical channel adopts national secret algorithm suite to build encrypted link, and synchronously updates session key to guarantee transmission continuity.

[0114] Compared with the prior art, the present application has the following beneficial effects:

[0115] 1. The present application generates physical layer security key based on the principle of quantum state non-cloning, breaks through the dependence of traditional encryption algorithm on mathematics, and helps to reduce the cracking risk of underlying encryption logic by quantum computing.

[0116] 2. The present application realizes real-time perception of eavesdropping behavior in the transmission link by real-time collection of photon polarization state parameters by the physical layer security monitoring unit, detection of eavesdropping behavior based on a preset error rate threshold, and makes up for the deficiency of traditional schemes that rely on protocol layer strategies and cannot realize real-time perception of physical layer security state.

[0117] 3. The present application combines quantum key generation, negotiation and full life cycle management with physical layer security monitoring, reduces the leakage risk of keys in the generation, transmission and use process through a dynamic update mechanism driven by time-event fusion and an emergency regeneration strategy.

[0118] 4. The data transmission encryption unit in the present application adopts quantum key derived session key combined with national secret symmetric encryption algorithm, enhances the anti-quantum attack ability of the encryption system through the physical layer security of quantum key while complying with the national secret algorithm, and takes into account the applicability of classical encryption system and the security of quantum encryption.

[0119] 5. The present application automatically switches to classical channel when quantum channel is abnormal through the channel fusion switching unit, and synchronously updates the session key based on the quantum pre-stored key, which maintains the binding relationship between the key and the physical layer security, reduces the security vulnerability in the channel switching process, and guarantees the transmission continuity. BRIEF DESCRIPTION OF DRAWINGS

[0120] Figure 1 The figure is a schematic diagram of the system framework of the present application.

[0121] The meanings of the various numbers in the figure are as follows:

[0122] 100, quantum key generation and management unit; 110, quantum state encoding module; 120, adaptive base vector matching module; 130, key verification module;

[0123] 200, data transmission encryption unit; 210, quantum-session key derivation module; 220, dynamic segmented encryption module; 230, integrity verification module.

[0124] 300, physical layer security monitoring unit; 310, photon parameter acquisition module; 320, statistical analysis module; 330, threshold comparison module; 340, emergency response module;

[0125] 400, channel fusion switching unit; 410, channel state monitoring module; 420, switching decision module; 430, classical channel encryption module; 440, key synchronization update module. DETAILED DESCRIPTION

[0126] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application. Embodiment 1

[0127] As shown in the figure, the present embodiment provides a cloud data security transmission system based on quantum encryption technology, which comprises: Figure 1 The quantum key generation and management unit 100 is used for generating a physical layer security key, realizing true random generation of the key through the principle of non-cloning of quantum state, optimizing the key agreement efficiency by using an improved adaptive basis vector matching algorithm, and completing the key full life cycle management based on a time-event fusion driven dynamic update mechanism;

[0128] In this step, the quantum key generation and management unit 100 comprises a quantum state encoding module 110, an adaptive basis vector matching module 120 and a key verification module 130, wherein:

[0129] The quantum state encoding module 110 generates a single photon sequence containing horizontal, vertical, +45° and -45° polarization states based on the BB84 protocol;

[0130] As a further description of the present embodiment, the quantum state encoding module 110 in the present embodiment comprises a single photon source, a polarization modulation component and a synchronization controller, wherein:

[0131] The single photon source is generated by pulse laser after attenuation processing, and the wavelength of the output photon is adapted to the quantum transmission channel (such as the commonly used 1550nm waveband of optical fiber channel), and the pulse interval is synchronized with the negotiation rhythm of the adaptive basis vector matching module 120 (such as a fixed number of pulse sequences corresponding to each round of negotiation);

[0132]

[0133] ​The polarization modulation component switches four polarization states (horizontal, vertical, +45°, -45°) through voltage control, each polarization state corresponding to a specific electrical signal instruction (such as 0V for horizontal polarization and 5V for vertical polarization, etc.), ensuring that the encoding state matches the base vector combination ;

[0134] The synchronization controller receives the final selection probability of the adaptive base vector matching module 120 , generates an encoding timing signal, controls the transmission frequency of the single-photon sequence to adapt to the transmission capacity of the quantum channel, and avoids signal congestion.

[0135] Furthermore, the quantum state encoding module 110 in the embodiment also has a built-in calibration mechanism, which periodically (such as every hour) sends photons with known polarization states to the local detection unit, compares the actual detection results with the preset values, and if the deviation exceeds a reasonable range (such as the polarization angle deviating from the preset value by more than 5°), adjusts the modulation component parameters to compensate for the deviation, ensuring encoding accuracy.

[0136] The adaptive base vector matching module 120 interacts with the base vector information through a classical channel, dynamically adjusts the base vector selection strategy based on the historical base vector matching success rate;

[0137] As a further description of the embodiment, at the level of classical channel interaction, the base vector information is transmitted through an encrypted TCP / IP link, using a standardized data frame format: the frame header identifies "base vector information", with additional round number, base vector selection sequence (distinguished by binary bits between rectilinear and diagonal bases), and check bits; the sender sends this frame after each round of negotiation, and the receiver synchronously feeds back the local base vector sequence and the matching success count. If the frame transmission fails, the sender automatically retransmits within a preset time (the number of retransmissions does not exceed 3 times), and if it still fails, it marks the current round as "invalid" and starts the next round of negotiation, ensuring the reliability of base vector information interaction through timeout retransmission and round tolerance mechanism.

[0138] The key verification module 130 is used to randomly extract part of the bits from the initially generated key for consistency comparison, and when the inconsistent bit rate exceeds the preset threshold, the key regeneration process is triggered.

[0139] As a further description of the embodiment, in the key verification module 130, part of the bits from the initially generated key are randomly extracted for consistency comparison, wherein:

[0140] The extraction method is to use a quantum random number generator to determine the index of the bits to be extracted, ensuring randomness and unpredictability, and the extraction ratio is 10%-20%;

[0141] The comparison process is that the sender and the receiver exchange the extracted index and the corresponding bit value through a classical channel, and calculate the inconsistent bit rate;

[0142] If ≤ preset threshold (such as 10%), the 80%-90% bits not extracted are reserved as valid keys;

[0143] If > threshold, the module generates a regeneration instruction, which is sent to the quantum state encoding module 110 through an internal signal channel, triggering a new round of key generation; if regeneration fails for 3 consecutive times, an alarm signal is sent to the system layer.

[0144] In this step, the quantum key generation and management unit 100 uses an improved adaptive basis vector matching algorithm to optimize the efficiency of key agreement, including the following steps:

[0145] S140.1, model establishment:

[0146] A basis vector matching success rate statistical model is established to calculate the historical matching success rate of each basis vector combination (0 represents rectilinear basis, and 1 represents diagonal basis) :

[0147] ;

[0148] wherein, is the number of times of successful matching of the basis vector combination in the nth round of negotiation, is the total number of attempts of the basis vector combination in the nth round of negotiation;

[0149] S140.2, probability adjustment:

[0150] Based on the sliding window mechanism, the basis vector selection probability is dynamically updated. For the basis vector combination that meets the condition within the continuous rounds, its selection probability in the next round is adjusted according to the following formula: :

[0151] ;

[0152] wherein, is a preset success rate threshold (a) ) for judging whether the basis vector combination is inefficient; is a decay coefficient (a ), which controls the amplitude of probability adjustment; the lower is below , the more significant the decay is;

[0153] S140.3, normalization processing: ​​

[0154] The basis vector selection probabilities are normalized using an exponential smoothing algorithm to ensure that the sum of the selection probabilities of all basis vector combinations is 1.

[0155] ;

[0156] in, This represents the normalized final selection probability, used to allocate the number of basis vector attempts in the next round; This represents the summation of the original probabilities of the four basis vector combinations, ensuring that the sum is 1 after normalization;

[0157] This step ensures the validity of the probability distribution, enabling the quantum state encoding module 110 to generate single-photon sequences based on normalized probabilities;

[0158] S140.4, Frequency Application:

[0159] Based on the normalized selection probability The basis vector combination is dynamically adjusted during subsequent quantum key negotiation. The selection frequency is as follows:

[0160] ;

[0161] in, For the first The total number of measurements in rounds of negotiation This indicates a floor operation, ensuring the number of attempts is an integer. For the first In the cycle, the basis vector combination The actual number of attempts;

[0162] S140.5, Periodic Reset:

[0163] Each completed After round of negotiations ( (where is a positive integer), reset the historical statistical data of all basis vector combinations to avoid algorithm failure due to long-term changes in channel characteristics. The reset formula is:

[0164] ;

[0165] in, This means that when the algorithm starts or after a periodic reset, the success count of all basis vector combinations is reset to zero to avoid historical data interfering with the evaluation of the new cycle; This means that when the algorithm starts or after a periodic reset, the number of attempts for all basis vector combinations is reset to zero, and the count of successes is initialized synchronously. This means that the selection probability of the four basis vector combinations is evenly distributed when the algorithm starts or after periodic reset, ensuring that the algorithm evaluates the basis vector performance from an unbiased state.

[0166] As a further illustration of the present embodiment, for the improved adaptive basis matching algorithm, parameters need to be dynamically configured in combination with channel characteristics: preset success rate threshold Adjust according to channel stability (0.6 for stable channel, 0.5 for fluctuating channel), used to screen inefficient basis combination; attenuation coefficient Adjust sensitivity according to basis (0.4-0.5 for fast optimization, 0.2-0.3 for smooth adjustment); sliding window Based on channel characteristic change period determination (e.g. channel may fluctuate once every 10 rounds, Take 5-8 to balance historical reference and real-time); reset period Reference channel long-term drift characteristics (optical fiber channel Take 80-100 rounds, free space channel Take 30-50 rounds), through scenario parameter configuration, ensure that the algorithm adapts to different quantum transmission environment. In this step, the quantum key generation and management unit 100 completes the key full life cycle management based on the time-event fusion driven dynamic update mechanism, including the following steps:

[0167] S150.1, time window definition:

[0168] S150.2, event trigger condition:

[0169] Assign a dynamic life cycle to each quantum key , the calculation formula is:

[0170] ;

[0171] Wherein, is the basic time threshold; is the current quantum channel capacity; is the security key length; is the actual generation rate of the key; Indicates the conversion factor of natural logarithm and bit unit; is the reference photon transmission rate of the current quantum channel;

[0172] S150.2, event trigger condition:

[0173] When any of the following conditions is met, the key update is triggered immediately:

[0174] The quantum error rate detected by the physical layer security monitoring unit 300 Exceeds the dynamic threshold , wherein: , wherein ​is an initial bit error rate threshold value, is a current ambient noise intensity, is a calibration noise reference value, is a noise influence coefficient, ;

[0175] Data layer event: the data transmission encryption unit 200 continuously fails the data integrity check, and the check failure rate exceeds the threshold value : ;

[0176] System layer event: the system receives an external security audit instruction, detects abnormal key usage frequency, or reaches the preset maximum usage number ;

[0177] S150.3, fusion decision algorithm:

[0178] When the time-driven condition ) and the event-driven condition are triggered at the same time, the following decision logic is adopted:

[0179] ;

[0180] If multiple event-driven conditions are triggered at the same time, the priority order is: physical layer event > data layer event > system layer event;

[0181] S150.4, key smooth transition:

[0182] Within a preset time period before the end of the current key life cycle , the next cycle key generation process is started, and the new and old key switching adopts an overlapping verification mechanism.

[0183] Further, the overlapping verification mechanism specifically includes:

[0184] Pre-distribution stage ): simultaneously encrypt data using new and old keys to generate double check codes;

[0185] Verification stage ): the receiver decrypts and compares the check codes respectively through new and old keys to ensure data continuity;

[0186] Invalidation stage ): completely discard the old key and only use the new key for data transmission;

[0187] This mechanism realizes adaptive, high-reliability full-life cycle management of quantum keys through dynamic life cycle calculation, multi-dimensional event triggering, and seamless key switching.

[0188] As a further illustration of the present embodiment, the time-event fusion driven dynamic update mechanism in the present embodiment, the core is to build a "period bottom + abnormal trigger" dynamic update rule for quantum key, by balancing the universality of time period and the sensitivity of multi-dimensional events, to ensure the timeliness and security of the key. Dynamic life cycle Need to meet the basic security requirements and channel carrying capacity, wherein:

[0189] Basic time threshold Set according to the data sensitivity level (5-10 minutes for high sensitive data, 20-30 minutes for ordinary data), as the "bottom period" of key update;

[0190] Current quantum channel capacity Real-time acquisition by channel state monitoring module 410 (such as the number of photons transmitted per unit time), reflecting the real-time transmission capacity of the channel;

[0191] Security key length Determined according to the encryption algorithm requirements (such as 128bit for the national standard SM4 algorithm);

[0192] Key generation rate Statistical by quantum key generation and management unit 100 (such as the number of valid key bits generated per second);

[0193] In the calculation, Take And The larger value, both to ensure the compliance of the basic safety period, and to adapt to the longest key validity period supported by the actual carrying capacity of the channel, to avoid "short period waste resources" or "long period introduces risk".

[0194] Further, the time-event fusion driven dynamic update mechanism in the present embodiment, through three types of events of physical layer, data layer and system layer, real-time sensing key environment anomaly, wherein:

[0195] Physical layer error rate Real-time calculation by physical layer security monitoring unit 300 based on the error count of the latest preset number of photons, initial error rate threshold Configure according to channel type (such as 5%-8% for optical fiber channel), calibrate noise reference value To obtain through the no-eavesdropping state measurement in the system initialization stage, to ensure the rationality of the error rate monitoring reference;

[0196] The number of consecutive failures is counted by integrity checking module 230 (such as setting That is, 3 consecutive failures trigger the event), failure rate The ratio of "number of failures / total number of checks", threshold Take 5%-10% (flexible adjustment according to data integrity requirements, such as financial data with high integrity requirements, which can be set to 5%); system layer key usage anomaly is recorded by quantum key generation and management unit 100 in real time, and the maximum number of times is According to the "key length + single encryption data volume" setting (such as 128-bit key encryption of 1KB data, It can be set to 1000-2000 times), to avoid brute force cracking of the key due to high frequency use.

[0197] Further, when the time-driven condition ( ) and the event-driven condition are triggered at the same time, if the physical layer ( ) and the data layer ( ) indicators are normal, update according to time-driven (follow the preset period); if any indicator is abnormal, immediately trigger the update according to the event priority (physical layer > data layer > system layer), and respond to the bottom layer anomaly that is more likely to threaten the security of the key. At the same time, in order to avoid interrupting the business during key switching, the mechanism introduces the "pre-distribution + overlap verification" process: within the preset transition period , the sender encrypts the same data with the new and old keys at the same time, generating a double check code that binds the new and old key hash values; the receiver decrypts and compares the double check code, and if they are consistent, the switching is confirmed; if they are not consistent, automatically extend to 2 times the original value for re-verification (up to 3 times), and if it still fails, trigger manual intervention alarm - through "pre-distribution buffer + retry mechanism", ensure business continuity during key switching.

[0198] Further, when the quantum key generation and management unit 100 in the embodiment outputs the key to the data transmission encryption unit 200, it needs to carry the key identifier, validity period and check code, and transmit through the internal encryption link; the physical layer security monitoring unit 300 sends the error rate data to the 100 unit every 50ms; before channel switching, the channel fusion switching unit 400 requests the pre-stored key from the 100 unit, and the 100 unit assigns and synchronizes the timestamp according to the index, to ensure that the key is synchronized with the channel switching.

[0199] The data transmission encryption unit 200 is used to realize cloud data encryption transmission, and adopts quantum key derivation session key combined with national symmetric encryption algorithm to encrypt data segmentation, and generates integrity check code through national hash algorithm to bind transmission;

[0200] In this step, the data transmission encryption unit 200 includes a quantum-session key derivation module 210, a dynamic segmentation encryption module 220 and an integrity verification module 230, wherein:

[0201] The quantum-session key derivation module 210 receives the quantum master key output by the quantum key generation and management unit 100, generates a session key through an HKDF key derivation algorithm, and the life cycle of the session key is associated with the update event of the quantum master key. When the quantum master key is updated, the session key is synchronized to be invalid;

[0202] As a further description of the present embodiment, the quantum-session key derivation module 210 in the present embodiment generates a session key based on an HKDF key derivation algorithm, specifically including:

[0203] Parameter design: The salt value defaults to an empty byte string (simplified deployment), the input is the quantum master key output by the quantum key generation and management unit 100, and the key use is distinguished through a fixed identification string “quantum derived session key”. Finally, a 128-bit session key (adapted to the national SM4 algorithm) is generated;

[0204] Generation logic: The pseudo-random base key is first extracted from the quantum master key, and then the session key is expanded in combination with the identification string to ensure the uniqueness and scene binding of the key.

[0205] Further, the life cycle of the session key in the present embodiment is strongly associated with the quantum master key: the effective period of the session key is set to 80% of the quantum master key period (20% of the time window is reserved for switching). When the quantum master key is updated:

[0206] Pre-generate new key: Pre-generate new key 10 seconds before the old session key is invalid to avoid business interruption;

[0207] Hash synchronization: First, send the SM3 hash value of the new key to the integrity verification module 230 to establish a verification association;

[0208] Seamless switching: At the moment when the old key is invalid, push the new key to the dynamic segmented encryption module 220 to ensure continuous encryption process.

[0209] The dynamic segmented encryption module 220 uses the national SM4 symmetric encryption algorithm to encrypt the cloud data by type;

[0210] The integrity verification module 230 generates a data verification code through the national SM3 hash algorithm, the verification code binds the corresponding encrypted segmented data and the session key hash value output by the quantum-session key derivation module 210, and realizes the associated transmission of the verification code and the encrypted data.

[0211] As a further description of the present embodiment, in the integrity verification module 230 of the present embodiment, the SM3 hash-based verification closed loop implementation includes the following steps:

[0212] First, receive the ciphertext data, encryption authentication tag and segment index association relationship transmitted by the dynamic segmented encryption module 220, and synchronize the session key output by the quantum-session key derivation module 210;

[0213] Subsequently, the SM3 hash algorithm is called, the encrypted segmented data, the session key hash value and the corresponding segment index information are spliced into a byte stream, and a check code is generated;

[0214] Then, the check code is bound with the ciphertext data, the session key hash value and the segment index information, and is packaged into an associated transmission data packet;

[0215] Next, the associated transmission data packet is sent to the integrity check module of the receiving end through an encryption channel;

[0216] Finally, the check result of the receiving end is received: if the check fails, a retransmission request for the corresponding segmented data is triggered; if the continuous retransmission fails, data exception information is fed back to the dynamic segmented encryption module 220, and the upper layer error processing is driven.

[0217] In this step, the dynamic segmented encryption module 220 segments and encrypts the cloud data according to the type, including the following steps:

[0218] S220.1, data type identification and marking:

[0219] The type is identified by analyzing the format identifier (such as file extension, data header field) of the cloud data:

[0220] If the data contains structured field identifier (such as JSON key value separator, table row and column index), it is marked as structured data type;

[0221] If the data is a continuous byte stream (without explicit field division, such as video frame, log entry), it is marked as stream data type;

[0222] S220.2, differential segmentation rule execution:

[0223] According to the marked type, the splitting operation is performed:

[0224] For structured data: determine the field boundary based on the field parsing result, split according to the field semantic integrity (ensure that a single field does not cross the segment), and generate an index table containing the field ID and segment mapping relationship;

[0225] For stream data: split according to a fixed length (such as ≤1MB) sliding window, and generate a segment management table containing segment number, starting offset and segment length;

[0226] S220.3, GCM mode encryption configuration:

[0227] The GCM authentication encryption mode of the national SM4 algorithm is adopted, and the specific configuration is as follows:

[0228] Plain text input: original content of each data segment;

[0229] Additional authentication data: index information (structured data binding field index table segment, streaming data binding segment management table segment) bound to the corresponding segment;

[0230] Encrypted output: encrypted data of each segment and synchronously generated encrypted authentication tag (the length of the tag is consistent with the block length of the SM4 algorithm);

[0231] S220.4, encrypted authentication tag association storage:

[0232] The encrypted authentication tag of each segment is associated with the encrypted data of the corresponding segment, specifically including:

[0233] Structured data: the tag is bound to the segment ID in the field index table;

[0234] Streaming data: the tag is bound to the segment number in the segment management table;

[0235] The association relationship is transmitted to the integrity verification module 230 together with the encrypted data;

[0236] S220.5, session key usage monitoring:

[0237] Real-time monitoring of the encryption load of the current session key, and sending a key update request to the quantum-session key derivation module 210 when one of the following conditions is met:

[0238] The total number of encrypted structured data fields reaches a preset threshold;

[0239] The total number of encrypted streaming data segments reaches a preset threshold;

[0240] The continuous use time length of the session key reaches the life cycle warning value preset by the quantum-session key derivation module 210.

[0241] As a further description of the present embodiment, the dynamic segmentation encryption module 220 in the present embodiment distinguishes data types through format analysis and structure recognition:

[0242] Structured data: contains explicit field identifiers such as JSON key-value separators;

[0243] Streaming data: video frames, continuous byte streams (only divided by line feed or timestamp) without field division, etc.

[0244] Meanwhile, the differentiated segmentation rule in the present embodiment specifically includes:

[0245] Structured data is split by field boundary (ensuring that a single field does not cross a segment), a "field ID-segment ID" index table is generated, and the semantic integrity of the field is ensured.

[0246] The streaming data is split by a fixed length of ≤1MB sliding (balance encryption efficiency and transmission overhead), and a "segment sequence number-start / end offset" management table is generated.

[0247] Further, the encryption in the embodiment adopts the GCM authentication mode of the national standard SM4 algorithm:

[0248] The plaintext is the content of the data segment, the additional authentication data (AAD) binds the segment index (structured data associated field index segment, streaming data associated segment management table segment), and a 128-bit authentication tag (check data integrity) is generated synchronously.

[0249] Exception handling: if the field parsing fails (such as JSON format error), it is automatically degraded to 1MB fixed segmentation; if the authentication tag generation fails, retry encryption (up to 3 times), and still fail to request a new key.

[0250] It should be noted that in the dynamic segmented encryption module 220 of the embodiment, the threshold triggered update of the session key includes the following steps:

[0251] First, the total number of encrypted structured data fields, the number of encrypted streaming data segments, and the continuous use time length of the session key are monitored in real time;

[0252] Then, it is judged whether the number of encrypted structured data fields reaches the preset threshold (which can be adjusted according to the business scenario, and in a typical scenario, it is 1000), and whether the number of encrypted streaming data segments reaches the preset threshold (derived according to the data splitting logic, such as 1000 in the 1GB data splitting scenario);

[0253] Then, it is judged whether the continuous use time length of the session key reaches 80% of its validity period (early warning time);

[0254] Next, if any of the above conditions is met, immediately send a key update request to the quantum-session key derivation module 210;

[0255] Finally, after sending the request, the generation and distribution status of the new key is continuously monitored to ensure the continuity of the key connection of the encryption process.

[0256] Further, the collaborative process of the quantum-session key derivation module 210, the dynamic segmented encryption module 220 and the integrity verification module 230 in the embodiment includes the following steps:

[0257] Firstly, after the quantum-session key derivation module 210 generates the session key, the SM3 hash value of the session key is sent to the integrity verification module 230 first, and then the session key is transmitted to the dynamic segmented encryption module 220, to ensure the consistency of the encryption and verification keys;

[0258] Subsequently, the dynamic segmented encryption module 220 monitors the total number of encrypted structured data fields, the total number of streaming data segments, and the continuous use time length of the session key in real time, and sends a key update request to the quantum-session key derivation module 210 when any indicator reaches a preset threshold;

[0259] Then, the quantum-session key derivation module 210 pre-generates a new session key, and repeats the "hash value synchronization-session key distribution" process;

[0260] Next, in the transition window period before the old session key is invalidated, the dynamic segmented encryption module 220 uses the new and old session keys to encrypt data in parallel, realizing the uninterrupted transition of the service;

[0261] Finally, the integrity verification module 230 synchronously verifies the verification codes corresponding to the new and old session keys, completes the key switching closed loop, and marks the old session key as invalid.

[0262] The physical layer security monitoring unit 300 is configured to monitor the security of the quantum link, detect eavesdropping behavior based on a preset bit error rate threshold, and trigger key emergency regeneration by collecting photon polarization state parameters in real time;

[0263] In this step, the physical layer security monitoring unit 300 includes a photon parameter collection module 310, a statistical analysis module 320, a threshold comparison module 330, and an emergency response module 340, wherein:

[0264] The photon parameter collection module 310 collects photon polarization state core parameters in real time through a quantum detector array, including horizontal and vertical polarization angles, diagonal polarization angles, and photon arrival time intervals. The collection frequency is synchronized with the key generation period of the quantum key generation and management unit 100;

[0265] As a further description of this embodiment, the quantum detector array in this embodiment uses a single-photon avalanche diode array, which includes horizontal and vertical polarization channels, ±45° diagonal polarization channels, and each channel corresponds to an independent detector.

[0266] The collected parameters include horizontal polarization angle, vertical polarization angle, +45° polarization angle, -45° polarization angle, and photon arrival time interval (time difference between adjacent photons arriving at the detector);

[0267] At the same time, the collection frequency is strictly synchronized with the key generation period of the quantum key generation and management unit 100: assuming that the key generation period is T, then the collection frequency is 1 / T. (like ), that is, each A full parameter acquisition is completed in time, and timing consistency is ensured by a TTL clock signal;

[0268] Meanwhile, the original parameters are filtered by moving average to remove noise, and the photon arrival time interval is converted into a system reference timestamp for subsequent photon sequence matching.

[0269] The statistical analysis module 320 calculates the actual bit error rate based on the collected photon parameters. The statistical rule is the proportion of photons with inconsistent measurement results to the total number of measured photons. It also maintains the bit error rate fluctuation trend within the sliding time window, and the window length is related to the key generation cycle.

[0270] As a further explanation of this embodiment, the statistical analysis module 320 of this embodiment calculates the bit error rate and analyzes the trend, including the following steps:

[0271] First, the polarization state parameters and timestamps sent by the photon parameter acquisition module 310 are received;

[0272] Subsequently, the number of photons with inconsistent measurement results within a single period was counted. Total effective number of photons measured And calculate the bit error rate (BER). (This is the bit error rate), the formula is: ;

[0273] Then, set the sliding time window (length is...). ), will the window Data caching;

[0274] Next, calculate the window. The variance is calculated using the following formula:

[0275] ;

[0276] in For window length, For the first Periodic , For window average Analyze fluctuation trends;

[0277] Finally, the current The variance data is sent to the threshold comparison module 330.

[0278] The threshold comparison module 330 compares the real-time calculated error rate with a dynamic threshold, which is dynamically adjusted according to the following factors: quantum channel initial calibration parameters (such as fiber attenuation coefficient, detector dark count rate), current environmental noise level (real-time obtained by background light intensity monitoring module), key update frequency of the quantum key generation and management unit 100;

[0279] As a further illustration of the present embodiment, the threshold comparison module 330 of the present embodiment in the present embodiment adjusts the dynamic threshold and comparison includes the following steps:

[0280] First, obtain the initial calibration threshold of the quantum channel , fiber attenuation coefficient (normalized as ), detector dark count rate (normalized as ), environmental noise (normalized as ), and key update frequency (normalized as );

[0281] Subsequently, calculate the dynamic threshold , the calculation formula is:

[0282] ;

[0283] Wherein, is the weight, satisfying ;

[0284] Then, compare the sent by the statistical analysis module 320 with the dynamic threshold ;

[0285] Next, determine the result as normal ( ), first abnormality ( ) or second abnormality ( );

[0286] Finally, send the determination result to the emergency response module 340.

[0287] The emergency response module 340 is used to perform emergency operation when the real-time error rate exceeds the dynamic threshold.

[0288] As a further illustration of the present embodiment, the

[0289] In this step, the emergency response module 340 performs emergency operation includes the following steps:

[0290] S340.1, abnormality grading threshold definition:

[0291] Let the dynamic threshold output by the threshold comparison module 330 be , and the error rate be The grading rule is:

[0292] ;

[0293] S340.2, Grading response execution:

[0294] For first-level anomalies: trigger key emergency regeneration, and the length of the regenerated key satisfies: ; wherein is the regular key length, used to ensure that the emergency key has enhanced noise resistance;

[0295] For second-level anomalies: simultaneously perform key emergency regeneration and backup channel switching, and the backup channel switching delay needs to satisfy: ; wherein is the data transmission timeout threshold, used to ensure that switching does not affect transmission continuity;

[0296] S340.3, Channel recovery verification formula:

[0297] After enabling the backup channel, send a verification data packet through the original channel, and the verification pass condition is that the error rate measured continuously times satisfies: , wherein is the error rate of the th verification, and when the condition is met, automatically switch back to the original channel;

[0298] S340.4, Abnormal data association storage:

[0299] Record the key parameter association relationship during the anomaly, and define an anomaly risk value calculation model:

[0300] ;

[0301] wherein, is the key generation period of the quantum key generation and management unit 100; is the standard deviation of environmental noise, used for subsequent security audits.

[0302] The channel fusion switching unit 400 is used to ensure transmission continuity, and automatically switches to a classical channel encrypted by a secure transmission layer protocol using a national cryptographic algorithm suite when the quantum channel is abnormal, and synchronously updates the session key through the quantum pre-stored key.

[0303] In this step, the channel fusion switching unit 400 includes a channel state monitoring module 410, a switching decision module 420, a classical channel encryption module 430, and a key synchronization update module 440, wherein:

[0304] The channel state monitoring module 410 is configured to collect the error code rate data and quantum channel connectivity information output by the physical layer security monitoring unit in real time, and generate a channel switching trigger signal when the error code rate exceeds 1.5 times of the dynamic threshold or the channel is continuously interrupted for more than a preset time length.

[0305] As a further description of the embodiment, the channel state monitoring module 410 in the embodiment continuously monitors the running state of the quantum channel to determine whether it is necessary to switch to the classical channel. It receives the error code rate data output by the physical layer security monitoring unit 300 in real time, and collects the connectivity information of the quantum channel, including the link heartbeat response, the data packet loss condition, etc. The module presets a time length threshold of continuous interruption of the channel (the threshold is set according to the demand of the business on the continuity of transmission, for example, the high real-time business can be set to a shorter time length, and the ordinary business can be appropriately extended). When any of the following conditions is monitored, the module generates a channel switching trigger signal: the error code rate of the quantum channel exceeds 1.5 times of the dynamic threshold of the physical layer security monitoring unit 300; or the time length of continuous interruption of the quantum channel reaches the preset threshold. The trigger signal contains key information such as the current error code rate and the interruption duration, which is used to support the subsequent switching decision.

[0306] The switching decision module 420 is configured to prestore the priority policy of “quantum channel priority, classical channel backup”, and after receiving the switching trigger signal, send a verification data packet through the quantum channel, and if the verification fails continuously for multiple times, perform a switching operation, and the switching delay needs to meet: ;

[0307] As a further description of the embodiment, the switching decision module 420 in the embodiment is configured to prestore the priority policy of “quantum channel priority, classical channel backup”, and clearly the classical channel is only used as a supplement to the quantum channel. After receiving the switching trigger signal of the channel state monitoring module 410, the switching decision module 420 first sends a verification data packet (the data packet contains a fixed identifier and random check information) to the opposite end through the quantum channel, and continuously verifies for multiple times (the number of verification times is not less than 3 to avoid misjudgment of the channel state due to instantaneous fluctuation). If the effective feedback from the opposite end is not received for multiple times, it is determined that the quantum channel is temporarily unavailable, and then a switching operation is performed. When switching, the switching decision module 420 controls the switching delay to adapt to the transmission timeout requirement of the business, to ensure that the continuity of data transmission is not affected during the switching process. After the decision is made, the switching decision module 420 sends an enabling instruction to the classical channel encryption module 430, and notifies the key synchronization update module 440 to prepare the session key.

[0308] The classical channel encryption module 430 uses the national standard SM4 symmetric encryption algorithm to encrypt the data, and generates a data check code through the national standard SM3 hash algorithm, and the check code is transmitted together with the encrypted data.

[0309] As a further illustration of the present embodiment, the classical channel encryption module 430 in the present embodiment implements data encryption transmission based on the national cryptographic algorithm suite after receiving the enable instruction of the switching decision module 420. It obtains the session key of the classical channel from the key synchronization update module 440, and uses the national SM4 symmetric encryption algorithm to encrypt the transmission data, ensuring the confidentiality of the data on the classical channel.

[0310] Further, the classical channel encryption module 430 in the present embodiment generates a data check code through the national SM3 hash algorithm, and the check code is bound to the hash value of the corresponding encrypted data and session key, forming an association. This binding ensures that the check code can not only verify the data integrity, but also be associated with the session key used for encryption, avoiding check failure caused by mismatched keys. The encrypted data, check code and session key hash value are transmitted together through the secure transmission layer protocol based on the national cryptographic algorithm suite, ensuring the security of the transmission process.

[0311] The key synchronization update module 440 obtains quantum keys from the pre-stored key pool of the quantum key generation and management unit 100, generates a classical channel session key through the HKDF key derivation algorithm, and triggers session key update when the amount of encrypted data on the classical channel reaches a preset proportion of the pre-stored key length or the continuous running time reaches a preset proportion of the session key life cycle.

[0312] As a further illustration of the present embodiment, the key synchronization update module 440 in the present embodiment is used for the generation and dynamic update of the classical channel session key, ensuring the encryption security of the classical channel. It obtains quantum keys from the pre-stored key pool of the quantum key generation and management unit 100, and generates a session key suitable for the classical channel through the HKDF key derivation algorithm (the identification information of the "classical channel session key" is added in the derivation process to distinguish the key usage in different scenarios).

[0313] Further, the key synchronization update module 440 in the present embodiment sets the update condition of the session key: when the total amount of encrypted data on the classical channel reaches a preset proportion of the pre-stored quantum key length (the proportion is set according to the balance between key security and utilization rate), or the continuous running time of the classical channel reaches a preset proportion of the session key life cycle (the proportion is set based on the risk assessment of key use), the session key update is triggered. When updating, the module obtains quantum keys from the pre-stored key pool, derives a new session key, and synchronizes it to the classical channel encryption module 430, while marking the old session key as invalid, realizing seamless connection of the keys. Embodiment 2

[0314] The present embodiment also provides a cloud data security transmission method based on quantum encryption technology, based on the above-mentioned cloud data security transmission system based on quantum encryption technology, comprising the following steps:

[0315] S100, quantum key generation and management: generate physical layer security key, adopt improved adaptive basis vector matching algorithm to optimize key negotiation efficiency, at the same time, complete key full life cycle management through time-event fusion driven dynamic update mechanism, execute key generation, negotiation, verification, update and smooth transition;

[0316] S200, cloud data encryption transmission: based on quantum key derivation session key, encrypt cloud data according to type, adopt national encryption symmetric encryption algorithm and hash algorithm to realize data encryption and integrity check, associate transmission encryption data and check information;

[0317] S300, physical layer security monitoring: real-time acquisition of photon polarization state parameters, calculation of bit error rate and comparison with dynamic threshold, key emergency regeneration, standby channel switching and abnormal data recording according to bit error rate grading results;

[0318] S400, channel fusion switching: monitor quantum channel state, switch to classical channel when channel is abnormal, adopt national encryption algorithm suite to build encryption link, and update session key synchronously to ensure transmission continuity.

[0319] Those skilled in the art can understand that the process of implementing all or part of the steps of the above embodiments can be completed by hardware, or by program to instruct related hardware.

[0320] The basic principles, main features and advantages of the present application are shown and described above. Those skilled in the art should understand that the present application is not limited by the above embodiments, the above embodiments and the description in the specification are only preferred examples of the present application, and are not intended to limit the present application, various changes and improvements can be made without departing from the spirit and scope of the present application, and these changes and improvements all fall within the scope of the present application. The scope of protection of the present application is defined by the appended claims and their equivalents.

Claims

1. A cloud data secure transmission system based on quantum encryption technology, characterized in that, include: The quantum key generation and management unit (100) is used to generate physical layer security keys. It achieves true random key generation through the quantum state no-cloning principle, optimizes key negotiation efficiency by adopting an improved adaptive basis matching algorithm, and completes key lifecycle management based on a time-event fusion-driven dynamic update mechanism. The quantum key generation and management unit (100) employs an improved adaptive basis matching algorithm to optimize key negotiation efficiency, including the following steps: S140.1 Model Establishment: Establish a statistical model for the success rate of basis vector matching, and calculate the success rate of each basis vector combination. Historical matching success rate ; S140.2, Probability Adjustment: The basis vector selection probability is dynamically updated based on the sliding window mechanism, for continuous... In-wheel satisfaction basis combination Adjust its selection probability in the next round according to the following formula. : ; in, A preset success rate threshold is used to determine whether the basis vector combination is inefficient; The attenuation coefficient controls the magnitude of probability adjustment; when The lower hour, The more significant the attenuation; S140.3, Normalization process: The basis vector selection probabilities are normalized using an exponential smoothing algorithm to ensure that the sum of the selection probabilities of all basis vector combinations is 1. ; in, This represents the normalized final selection probability, used to allocate the number of basis vector attempts in the next round; This represents the summation of the original probabilities of the four basis vector combinations, ensuring that the sum is 1 after normalization; S140.4, Frequency Application: Based on the normalized selection probability The basis vector combination is dynamically adjusted during subsequent quantum key negotiation. The selection frequency is as follows: ; in, For the first The total number of measurements in rounds of negotiation This indicates a floor operation, ensuring the number of attempts is an integer. For the first In the cycle, the basis combination The actual number of attempts; S140.5, Periodic Reset: Each completed After rounds of negotiation, reset the historical statistical data of all basis vector combinations to avoid algorithm failure due to long-term changes in channel characteristics. The reset formula is: ; in, This means that when the algorithm starts or after a periodic reset, the success count of all basis vector combinations is reset to zero to avoid historical data interfering with the evaluation of the new cycle; This means that when the algorithm starts or after a periodic reset, the number of attempts for all basis vector combinations is reset to zero, and the count of successes is initialized synchronously. This means that the selection probability of the four basis vector combinations is evenly distributed when the algorithm starts or after periodic reset, ensuring that the algorithm evaluates the basis vector performance from an unbiased state. The quantum key generation and management unit (100) completes the full lifecycle management of the key based on a time-event fusion-driven dynamic update mechanism, including the following steps: S150.1 Time window definition: Assign a dynamic lifetime to each quantum key The calculation formula is as follows: ; in, Based on the time threshold; This represents the current quantum channel capacity; The length of the security key; For the first The actual generation rate of each key; A conversion factor representing the natural logarithm to the bit unit; This is the current benchmark photon transmission rate for quantum channels; S150.2 Event triggering conditions: A key update is triggered immediately when any of the following conditions are met: Quantum bit error rate detected by the physical layer security monitoring unit (300) Exceeding the dynamic threshold ,in: In the formula This is the initial bit error rate threshold. Given the current ambient noise intensity, To calibrate the noise reference value, Noise impact factor; Data layer event: Data transmission encryption unit (200) continuous This data integrity check failed, with a failure rate of [missing information]. Exceeding the threshold : ; System-level events: The system receives an external security audit command, detects abnormal key usage frequency, or reaches the preset maximum usage count. ; S150.3, Fusion Decision Algorithm: When both time-driven and event-driven conditions are triggered simultaneously, the following decision logic is adopted: ; If multiple event-driven conditions are triggered simultaneously, the priority order is: physical layer events > data layer events > system layer events; S150.4, Smooth Key Transition: A preset time period before the current key's lifecycle ends. Within this period, the next cycle of key generation process is initiated, and the switching between the old and new keys adopts an overlapping verification mechanism; The data transmission encryption unit (200) is used to realize encrypted transmission of cloud data. It uses quantum key-derived session keys combined with national cryptographic symmetric encryption algorithms to encrypt data segments, and generates integrity verification codes through national cryptographic hash algorithms to bind the transmission. The physical layer security monitoring unit (300) is used to monitor the security of the quantum link. It detects eavesdropping behavior and triggers emergency key regeneration by collecting photon polarization state parameters in real time and based on a preset bit error rate threshold. The channel fusion switching unit (400) is used to ensure transmission continuity. When the quantum channel is abnormal, it automatically switches to the secure transport layer protocol encrypted classical channel using the national cryptographic algorithm suite, and synchronously updates the session key through the quantum pre-stored key.

2. The cloud data security transmission system based on quantum encryption technology according to claim 1, characterized in that, The quantum key generation and management unit (100) includes a quantum state encoding module (110), an adaptive basis matching module (120), and a key verification module (130), wherein: The quantum state encoding module (110) generates a single-photon sequence containing four polarization states: horizontal, vertical, +45°, and -45°, based on the BB84 protocol. The adaptive basis matching module (120) measures basis information through classical channel interaction and dynamically adjusts the basis selection strategy based on the historical basis matching success rate. The key verification module (130) is used to randomly extract a portion of bits from the initially generated key for consistency comparison. When the inconsistency bit rate exceeds a preset threshold, the key regeneration process is triggered.

3. The cloud data security transmission system based on quantum encryption technology according to claim 2, characterized in that, The data transmission encryption unit (200) includes a quantum-session key derivation module (210), a dynamic segmentation encryption module (220), and an integrity verification module (230), wherein: The quantum-session key derivation module (210) receives the quantum master key output by the quantum key generation and management unit (100) and generates a session key through the HKDF key derivation algorithm; The dynamic segmented encryption module (220) uses the national standard SM4 symmetric encryption algorithm to encrypt cloud data in segments according to type; The integrity verification module (230) generates a data verification code using the national cryptographic SM3 hash algorithm. The verification code is bound to the corresponding encrypted segment data and the session key hash value output by the quantum-session key derivation module (210), thereby realizing the associated transmission of the verification code and the encrypted data.

4. The cloud data security transmission system based on quantum encryption technology according to claim 3, characterized in that, The dynamic segmented encryption module (220) encrypts cloud data by type by segment, including the following steps: S220.1 Data Type Identification and Tagging: Identify the data type by parsing the format identifier of the cloud data: If the data contains structured field identifiers, mark it as a structured data type; If the data is a continuous stream of bytes, it is marked as a stream data type; S220.2, Execution of Differentiated Segmentation Rules: Perform the split operation based on the type of the tag: For structured data: determine field boundaries based on field parsing results, split according to field semantic integrity, and generate an index table containing field IDs and segment mapping relationships; Convection data: Split into fixed-length sliding windows to generate a segment management table containing segment number, starting offset, and segment length; S220.3, GCM mode encryption configuration: The GCM authentication encryption mode, which uses the national cryptographic algorithm SM4, is configured as follows: Plaintext input: The original content of each data segment; Additional authentication data: Binds the index information of the corresponding segment; Encrypted output: Ciphertext data for each segment and synchronously generated encrypted authentication tags; S220.4, Encrypted authentication tag associated storage: Associating the encrypted authentication tags of each segment with the ciphertext data of the corresponding segment, specifically including: Structured data: Tags are bound to segment IDs in the field index table; Streaming data: Tags are bound to segment numbers in the segment management table; The association relationship is transmitted to the integrity verification module (230) along with the encrypted data. S220.5 Session Key Usage Monitoring: The encryption payload of the current session key is monitored in real time, and a key update request is sent to the quantum-session key derivation module (210) when one of the following conditions is met: The total number of encrypted structured data fields has reached a preset threshold; The total number of encrypted streaming data segments has reached a preset threshold; The session key is used continuously for a period of time that reaches the lifecycle warning value preset by the quantum-session key derivation module (210).

5. The cloud data security transmission system based on quantum encryption technology according to claim 4, characterized in that, The physical layer security monitoring unit (300) includes a photon parameter acquisition module (310), a statistical analysis module (320), a threshold comparison module (330), and an emergency response module (340), wherein: The photon parameter acquisition module (310) acquires the core parameters of photon polarization state in real time through a quantum detector array, including horizontal and vertical polarization angles, diagonal polarization angles and photon arrival time intervals. The acquisition frequency is synchronized with the key generation cycle of the quantum key generation and management unit (100). The statistical analysis module (320) calculates the actual bit error rate based on the collected photon parameters. The statistical rule is the proportion of photons with inconsistent measurement results to the total number of measured photons. It also maintains the bit error rate fluctuation trend within the sliding time window, and the window length is related to the key generation cycle. The threshold comparison module (330) compares the real-time calculated bit error rate with a dynamic threshold, which is dynamically adjusted according to the following factors: the initial calibration parameters of the quantum channel, the current environmental noise level, and the key update frequency of the quantum key generation and management unit (100). The emergency response module (340) is used to perform emergency operations when the real-time bit error rate exceeds the dynamic threshold.

6. The cloud data secure transmission system based on quantum encryption technology according to claim 5, characterized in that, The emergency response module (340) performs the following steps when executing emergency operations: S340.1, Definition of anomaly classification threshold: Let the dynamic threshold output by the threshold comparison module (330) be... The bit error rate is The grading rules are as follows: ; S340.2, Hierarchical response execution: For Level 1 anomalies: trigger emergency key regeneration, regeneration key length... satisfy: ;in This is the standard key length, used to ensure enhanced noise immunity of emergency keys; For Level 2 anomalies: Simultaneously perform emergency key regeneration and backup channel switching, with backup channel switching delay. Must meet: ;in This is the data transmission timeout threshold, used to ensure that switching does not affect transmission continuity; S340.3, Channel Recovery Verification Formula: After activating the backup channel, verification data packets are sent through the original channel. The verification pass condition is continuous transmission. The bit error rate of this measurement satisfies: ,in For the first The error rate of the second verification is automatically switched back to the original channel when the condition is met. S340.4, Abnormal Data Association Storage: Record the correlations of key parameters during the anomaly period and define the anomaly risk value calculation model: ; in, The key generation cycle for the quantum key generation and management unit (100); This represents the standard deviation of environmental noise, used for subsequent safety audits.

7. The cloud data security transmission system based on quantum encryption technology according to claim 6, characterized in that, The channel fusion switching unit (400) includes a channel state monitoring module (410), a switching decision module (420), a classic channel encryption module (430), and a key synchronization update module (440), wherein: The channel state monitoring module (410) is used to collect bit error rate data and quantum channel connectivity information output by the physical layer security monitoring unit in real time. When the bit error rate exceeds 1.5 times the dynamic threshold or the channel is continuously interrupted for more than a preset time, a channel switching trigger signal is generated. The switching decision module (420) is used to pre-store the priority strategy of "quantum channel first, classical channel as backup". After receiving the switching trigger signal, it sends a verification data packet through the quantum channel. If the verification fails multiple times in a row, the switching operation is performed. The classic channel encryption module (430) uses the national standard SM4 symmetric encryption algorithm to encrypt the data and generates a data verification code through the national standard SM3 hash algorithm. The verification code is bound to the encrypted data for transmission. The key synchronization update module (440) obtains the quantum key from the pre-stored key pool of the quantum key generation and management unit (100), generates the classical channel session key through the HKDF key derivation algorithm, and triggers the session key update when the amount of classical channel encrypted data reaches the preset proportion of the pre-stored key length or the continuous running time reaches the preset proportion of the session key life cycle.

8. A cloud data secure transmission method based on quantum encryption technology, based on the cloud data secure transmission system based on quantum encryption technology as described in any one of claims 1-7, characterized in that, Includes the following steps: S100, Quantum Key Generation and Management: Generates physical layer secure keys, adopts an improved adaptive basis matching algorithm to optimize key negotiation efficiency, and completes key lifecycle management through a time-event fusion-driven dynamic update mechanism, performing key generation, negotiation, verification, update and smooth transition; S200, Cloud Data Encrypted Transmission: Based on quantum key derivation of session keys, cloud data is encrypted in segments according to type. The national cryptographic symmetric encryption algorithm and hash algorithm are used to realize data encryption and integrity verification, and the encrypted data and verification information are transmitted together. S300, Physical Layer Security Monitoring: Real-time acquisition of photon polarization state parameters, calculation of bit error rate and comparison with dynamic threshold, and execution of key emergency regeneration, backup channel switching and abnormal data recording based on bit error rate classification results; S400, Channel Fusion Switching: Monitors the quantum channel status and switches to the classical channel when the channel is abnormal. The classical channel uses a suite of national cryptographic algorithms to build an encrypted link and synchronously updates the session key to ensure transmission continuity.

Citation Information

Patent Citations

  • A time-based cloud data security transmission control method

    CN112073410B

  • Data security system and method under cloud computing environment based on national cryptographic algorithm

    CN117938387A

  • Internet of Things data acquisition and processing method based on quantum encryption security communication and host

    CN119051856A