Key distribution method, facility, device and medium for quantum secure infrastructure

By leveraging the collaborative work of the quantum communication layer and cryptographic service layer within a quantum-safe infrastructure, random numbers are generated and combined to address security issues in the quantum key distribution process, thereby achieving more secure key distribution and encrypted communication.

CN120934757BActive Publication Date: 2026-02-10中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511420735.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2026-02-10
Estimated Expiration
2045-09-30

AI Technical Summary

Technical Problem

Quantum key distribution has many attack surfaces, resulting in low security.

Method used

By utilizing a quantum-safe infrastructure, including a quantum communication layer and a cryptographic service layer, and leveraging communication between a quantum key manager and a key management system, random numbers can be generated and combined to generate target session keys, reducing the risk of key leakage during relay processes.

Benefits of technology

It improves the security of the quantum key distribution process, reduces the risk of key leakage during relay, and ensures secure encrypted communication between terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934757B_ABST
    Figure CN120934757B_ABST
Patent Text Reader

Abstract

The application provides a key distribution method, facility, equipment and medium of quantum security infrastructure, and relates to the technical field of quantum security communication, and the method comprises the following steps: in the process of encrypted communication of a terminal, based on a set of pre-shared keys between two key management systems, the risk of key leakage in the key relay process is reduced, and the security of quantum key distribution in the key relay process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure communication technology, and in particular to a key distribution method for a quantum secure infrastructure, a quantum secure infrastructure, an electronic device, and a computer-readable storage medium. Background Technology

[0002] With the rapid development of IP-based 4G and 5G mobile communication technologies, modern telecom operators face unprecedented information security challenges. Among these challenges, cryptographic methods, such as Public Key Infrastructure (PKI)-based encryption systems, while providing reliable security for data transmission, are threatened by the rapid advancements in quantum computing technology. The powerful computing capabilities of quantum computers may allow them to break existing asymmetric encryption algorithms in the future, such as RSA (Rivest–Shamir–Adleman) and ECC (Elliptic Curve Cryptography), posing a risk of failure to traditional PKI systems that rely on these algorithms. In response, Quantum Key Distribution (QKD), a novel key exchange technology based on quantum mechanics, offers a crucial solution to this problem due to its core advantage of "unconditional security." However, the short key generation distance in QKD necessitates trusted relays, causing the keys to circulate across multiple physical devices, creating numerous attack surfaces and reducing the security of key distribution. Summary of the Invention

[0003] The present invention provides a key distribution method, facility, electronic device, and computer-readable storage medium for quantum secure infrastructure, in order to solve or partially solve the problems of numerous attack exposure surfaces and low security in the quantum key distribution process.

[0004] This invention discloses a key distribution method for a quantum-safe infrastructure, wherein the quantum-safe infrastructure includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system, and the quantum key manager is communicatively connected to the key management system; wherein the method includes:

[0005] In response to a session request initiated by the calling terminal for the called terminal, the first key management system generates a first random number and sends the first random number to the first quantum key manager corresponding to the first key management system.

[0006] The first quantum key manager generates a second random number, and generates a base session key for the session request based on the first random number and the second random number;

[0007] The first key management system obtains a pre-shared first sub-key table, extracts a second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extracts the corresponding second pre-shared key from the second key set;

[0008] The first key management system combines the basic session key with the second pre-shared key to generate a target session key for the session request, and sends the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

[0009] This invention also discloses a quantum-safe infrastructure, which includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system, and the quantum key manager is communicatively connected to the key management system; wherein,

[0010] The first key management system is used to respond to a session request initiated by the calling terminal for the called terminal, generate a first random number, and send the first random number to the first quantum key manager corresponding to the first key management system.

[0011] The first quantum key manager is used to generate a second random number, and to generate a base session key for the session request based on the first random number and the second random number;

[0012] The first key management system is used to obtain a pre-shared first sub-key table, extract the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extract the corresponding second pre-shared key from the second key set;

[0013] The first key management system is used to combine the basic session key and the second pre-shared key to generate a target session key for the session request, and to send the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

[0014] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0015] The memory is used to store computer programs;

[0016] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.

[0017] This invention also discloses a computer-readable storage medium storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.

[0018] The embodiments of the present invention have the following advantages:

[0019] In this embodiment of the invention, the quantum security infrastructure includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system. The quantum key manager is communicatively connected to the key management system. During encrypted communication by the user terminal, the first key management system responds to a session request initiated by the calling terminal for the called terminal, generates a first random number, and sends the first random number to the first quantum key manager corresponding to the first key management system. Then, the first quantum key manager generates a second random number and generates a basic session key for the session request based on the first and second random numbers. The key management system obtains the pre-shared first sub-key table and extracts the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table. It then extracts the corresponding second pre-shared key from the second key set. The first key management system combines the basic session key and the second pre-shared key to generate a target session key for the session request. The target session key is then sent to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal. Thus, during the encrypted communication process between the terminals, based on the pairwise pre-shared key sets between the key management systems, the risk of key leakage during key relay is reduced, and the security of quantum key distribution during key relay is improved. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating the steps of a key distribution method for quantum-safe infrastructure provided in this embodiment of the invention;

[0021] Figure 2 This is a schematic diagram of the system architecture provided in an embodiment of the present invention. Detailed Implementation

[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0023] As an example, in the quantum key distribution process, due to the short coding distance, a trusted relay is required, which causes the quantum key distribution key to circulate on multiple physical devices, resulting in a large number of attack exposure surfaces and reducing the security of key distribution.

[0024] In this invention, during encrypted communication between user terminals, the first key management system responds to a session request initiated by the calling terminal for the called terminal by generating a first random number and sending it to the first quantum key manager corresponding to the first key management system. The first quantum key manager then generates a second random number and, based on the first and second random numbers, generates a basic session key for the session request. The first key management system then obtains a pre-shared first sub-key table and extracts a second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table. It extracts the corresponding second pre-shared key from the second key set. The first key management system combines the basic session key and the second pre-shared key to generate a target session key for the session request and sends the target session key to the calling terminal. The target session key is used for encrypted communication between the calling and called terminals. Thus, during encrypted communication between terminals, based on the pairwise pre-shared key sets between key management systems, the risk of key leakage during key relay is reduced, and the security of quantum key distribution during key relay is improved.

[0025] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, some technical features involved in the embodiments of the present invention are explained and described below:

[0026] QKD (Quantum Key Distribution): A process in which two communicating parties achieve secure key distribution of information by transmitting quantum states. Any eavesdropping will be detected in time due to the disturbance of the quantum states.

[0027] PQC (Post Quantum Cryptography): also known as quantum-resistant cryptography, is a new generation of cryptographic algorithms that can resist quantum computing attacks on public-key cryptographic algorithms. It aims to study the security of cryptographic algorithms in quantum environments and design cryptographic systems that are secure in both classical and quantum environments.

[0028] Cryptographic Infrastructure is a collection of hardware, software, personnel, policies, and procedures used to implement functions such as key and digital certificate generation, management, storage, distribution, and revocation throughout the entire process of quantum communication and its applications.

[0029] Reference Figure 1This diagram illustrates a flowchart of a key distribution method for a quantum-safe infrastructure provided in an embodiment of the present invention. The quantum-safe infrastructure includes at least a quantum communication layer and a cryptographic service layer. The quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system. The quantum key manager and the key management system are communicatively connected. Specifically, the method may include the following steps:

[0030] Step 101: In response to a session request initiated by the calling terminal for the called terminal, the first key management system generates a first random number and sends the first random number to the first quantum key manager corresponding to the first key management system.

[0031] In this embodiment of the invention, the quantum security infrastructure may include at least a quantum communication layer and a cryptographic service layer. The quantum communication layer can be used to implement quantum key distribution and may include at least a quantum key manager (QKM), a quantum key distributor (QKD), and a quantum key distribution network controller (QKDNC), etc. It generates QKD keys by executing the QKD protocol through a QKD link and combining it with key relay. The cryptographic service layer can obtain the corresponding QKD distributed session keys from the quantum communication layer and provide them to the service terminals. It may include at least a key management system (KMS) and a cryptography management service platform (CMSP), etc., all of which are equipped with corresponding cryptographic machines to achieve hardware cryptographic security.

[0032] Based on quantum-safe infrastructure, business terminals can obtain the corresponding session key from KMS in the cryptographic service layer through a secure channel, and use the session key to conduct encrypted communication with other business terminals. Thus, based on quantum encryption, the security of communication between business terminals can be effectively guaranteed.

[0033] In some feasible implementations, during the encrypted communication process of the business terminals, it is assumed that there are calling terminals and called terminals, and the calling terminal corresponds to the first key management system and the called terminal corresponds to the second key management system. Then, both the calling and called terminals can obtain the corresponding session key through their respective key management systems and conduct encrypted communication based on the session key.

[0034] For the calling terminal, its first key management system can respond to a session request initiated by the calling terminal for the called terminal, generate a first random number, and send the first random number to the first quantum key manager corresponding to the first key management system, so that the first quantum key manager can generate the corresponding key. It is understood that the called terminal can perform the same or similar processing as the calling terminal. In this invention, the quantum key distribution process of the calling terminal is used as an example for illustrative purposes; the quantum key distribution process of the called terminal can be referenced to that of the calling terminal.

[0035] Step 102: The first quantum key manager generates a second random number and generates a base session key for the session request based on the first random number and the second random number;

[0036] After receiving the first random number sent by the first key management system, the first quantum key manager can generate a corresponding second random number using a quantum random number generator. Then, by XORing the first and second random numbers, a basic session key for the session request is generated. Further, after generating the basic session key, the first quantum key manager can relay and securely distribute the basic session key through a quantum communication network, synchronizing the basic session key among all quantum key managers to ensure they all have a consistent basic session key. Each quantum key manager then transmits the basic session key to its respective key management system, further ensuring that all key management systems have a consistent basic session key. This allows both the calling and called terminals to obtain a consistent basic session key, enabling them to perform corresponding encryption processing based on the basic session key for encrypted communication.

[0037] Step 103: The first key management system obtains the pre-shared first sub-key table, extracts the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extracts the corresponding second pre-shared key from the second key set.

[0038] In this embodiment of the invention, a pairwise corresponding keybook (i.e., subkey table) between key management systems can be provided to the key service nodes (i.e. key management systems) of the quantum security infrastructure as a means of enhancing the security of quantum keys in the quantum key distribution process of the key relay process. This avoids the risk of relay nodes or relay platforms illegally obtaining quantum keys during the quantum key relay process and improves the security of key distribution.

[0039] In some feasible implementations, before constructing the corresponding sub-key tables between key management systems, corresponding digital identities can be established for core entities, trust roots can be built, and corresponding trusted relationships can be established between various core entities in the quantum security infrastructure.

[0040] The cryptographic service layer may also include a cryptographic management service platform that communicates with the key management system. During the establishment of a trusted relationship, the key management system and the cryptographic management service platform can generate and load corresponding key pairs respectively. Specifically, the key management system can obtain the corresponding signature algorithm and encryption algorithm, and use the signature algorithm to generate the corresponding first signature key pair and the encryption algorithm to generate the corresponding first encryption key pair. The first signature public key in the first signature key pair and the first encryption public key in the first encryption key pair are stored in the corresponding secure medium of the key management system. Then, the cryptographic management service platform loads the first signature public key in the first signature key pair and the first encryption public key in the first encryption key pair from the secure medium.

[0041] In some examples, the signature algorithm includes at least a commercial cryptographic signature algorithm and a quantum-resistant cryptographic signature algorithm, and the encryption algorithm includes at least a commercial cryptographic encryption algorithm and a quantum-resistant cryptographic encryption algorithm. In the key management system, during the generation and loading of key pairs, the key management system can generate a corresponding first signature subkey pair using the commercial cryptographic signature algorithm, generate a corresponding second signature subkey pair using the quantum-resistant cryptographic signature algorithm, generate a corresponding first encryption subkey pair using the commercial cryptographic encryption algorithm, and generate a corresponding second encryption subkey pair using the quantum-resistant cryptographic encryption algorithm. Then, the first signature public key, the second signature public key, the first encryption public key, and the second encryption public key in the first and second encryption subkey pairs are stored in the secure medium corresponding to the key management system. At the same time, the first signature private key, the second signature private key, the first encryption private key, and the second encryption private key in the first and second encryption subkey pairs are stored locally.

[0042] Once the key management system generates the corresponding key pair and stores the corresponding public key in the secure medium, the password management service platform can obtain and load the first signing public key, the second signing public key, the first encryption public key, and the second encryption public key from the secure medium, so as to encrypt or verify the key management system based on the loaded public key.

[0043] Accordingly, the cryptographic management service platform can use the same signature algorithm as the key management system to generate the corresponding second signature key pair, and use the same encryption algorithm as the key management system to generate the corresponding second encryption key pair, and store the second signature public key in the second signature key pair and the second encryption public key in the second encryption key pair in the corresponding secure medium of the key management system.

[0044] In its implementation, the cryptographic management service platform can generate a corresponding third signature subkey pair using a commercial cryptographic signature algorithm, a corresponding fourth signature subkey pair using a quantum-resistant cryptographic signature algorithm, a corresponding third encryption subkey pair using a commercial cryptographic encryption algorithm, and a corresponding fourth encryption subkey pair using a quantum-resistant cryptographic encryption algorithm. Then, the third signature public key, the fourth signature public key, the third encryption public key, and the fourth encryption subkey public key from the third signature subkey pair are stored in the secure medium corresponding to the key management system. Simultaneously, the third signature private key, the fourth signature private key, the third encryption private key, and the fourth encryption private key from the third and fourth encryption subkey pairs are stored locally.

[0045] Based on the above initialization process, each key management system can store the corresponding first signature private key, second signature private key, first encryption private key, and second encryption private key. At the same time, the secure storage medium corresponding to the key management system can store the first signature public key, second signature public key, first encryption public key, and second encryption public key corresponding to the key management system, as well as the third signature public key, fourth signature public key, third encryption public key, and fourth encryption public key corresponding to the cryptographic management service platform. Based on this process, a corresponding trusted network can be effectively established, thus constructing a network-wide trust relationship in the quantum-based security infrastructure.

[0046] Optionally, in the above process, the cryptographic management service platform can read and load the signature public keys corresponding to the commercial cryptographic signature algorithms, the quantum-resistant cryptographic signature algorithms, and the encryption public keys corresponding to the commercial cryptographic encryption algorithms and the quantum-resistant cryptographic encryption algorithms from the secure media corresponding to each key management system offline. Correspondingly, the key management system can also obtain the signature public key and encryption public key corresponding to the cryptographic management service platform offline. This offline acquisition effectively avoids the risk of attack or key leakage during key acquisition, thus improving security.

[0047] After establishing a trusted network relationship, the cryptographic management service platform obtains the number of nodes corresponding to the key management system, the storage capacity of the security media used by each key management system, and the key length of each key. Then, it integrates these factors to obtain a shared key table corresponding to each key management system. This shared key table can be a three-dimensional array Ks[N][N][K], where N is the total number of KMS nodes in the system, and the value of K depends on the storage capacity of the security media used by the system (assuming the security media storage capacity is C bytes and the key length is L bytes, then K = 0.8 * C / N / L). Optionally, each array element Ks[x][y] (1 <= x <= M, 1 <= y <= N) represents a shared seed key between KMS-x and KMS-y, with a quantity of K keys.

[0048] Based on the shared key table, the cryptographic management service platform extracts the sub-key table corresponding to the key management system. The sub-key table contains shared keys between the key management system and other key management systems. Then, it randomly generates a third and a fourth random number, and performs an XOR operation on the third and fourth random numbers to generate a temporary symmetric session key. The sub-key table is then encrypted using the temporary symmetric session key to obtain the corresponding encrypted key table. Furthermore, the third random number is encrypted using the first encryption public key to obtain the corresponding first encrypted random number, and the fourth random number is encrypted using the second encryption public key to obtain the corresponding second encrypted random number. The system first generates a number of random numbers, then assembles the encrypted key table, the first encrypted random number, and the second encrypted random number into a corresponding envelope. The envelope is then signed using the third signature private key from the third signature sub-key pair and the fourth signature private key from the fourth signature sub-key pair to obtain the corresponding target envelope. This target envelope is then stored in the secure medium corresponding to the key management system. This approach effectively reduces the risk of key leakage during key relay by constructing pairwise corresponding sub-key tables between key management systems, thus improving the security of quantum key distribution during key relay. Furthermore, the security of key table transmission is enhanced by encrypting and encapsulating the corresponding sub-key tables with hybrid cryptographic envelopes.

[0049] Accordingly, after the cryptographic management service platform distributes the target envelope to the key management system, the key management system can obtain and load the third and fourth signature public keys from the secure medium. Then, it uses the third and fourth signature public keys to verify the signature of the target envelope. If the verification is successful, it obtains the encryption key table, the first encrypted random number, and the second encrypted random number. Next, the key management system can use the first encryption private key in the first encryption subkey pair to decrypt the first encrypted random number to obtain the third random number, and use the second encryption private key in the second encryption subkey pair to decrypt the second encrypted random number to obtain the fourth random number. Then, it calculates the third and fourth random numbers to obtain the temporary symmetric session key. Finally, it uses the temporary symmetric session key to decrypt the encryption key table to obtain the subkey table and loads the subkey table. At this point, each key management system can pre-share the shared key with other key management systems to achieve encrypted communication based on the shared key.

[0050] Based on the above process, for the calling terminal, its first key management system can obtain the pre-shared first sub-key table, extract the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, extract the corresponding second pre-shared key from the second key set, so as to combine the second pre-shared key and the basic session key to achieve key obfuscation, and realize encrypted communication with the called terminal based on the obfuscated key.

[0051] In some feasible implementations, the session request includes at least a session identifier. The first key management system can first obtain the number of first valid keys corresponding to the second key set, then use the session identifier and the number of first valid keys to calculate the corresponding first index number, and then extract the corresponding second pre-shared key from the second key set according to the first index number, so as to combine the second pre-shared key and the basic session key to achieve key obfuscation, and realize encrypted communication with the called terminal based on the obfuscated key.

[0052] The session identifier is used to indicate the session corresponding to this encrypted communication. It is unique. For the key set, a corresponding key count Kn can be maintained (the initial value can be K, which is the total number of keys in the key set). Whenever a key in the key set is cancelled, the key count is decremented by one. During the encrypted communication process of the business terminal, the extracted key sequence number Sep = Session ID mod Kn, where Session ID is the session identifier. The corresponding pre-shared key can be extracted based on this key sequence number. In this process, based on the number of remaining available keys in the key set and the unique session identifier, a "unique" key can be extracted, which effectively improves the complexity of key distribution and ensures the security of subsequent encrypted communication.

[0053] Step 104: The first key management system combines the basic session key with the second pre-shared key to generate a target session key for the session request, and sends the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

[0054] For the first key management system, after obtaining the corresponding basic session key and the second pre-shared key, it can confuse the two to generate a more complex key, thereby increasing the complexity of the session key. Then, the confused target session key is sent to the calling terminal, enabling the calling terminal to conduct encrypted communication with the called terminal based on the target session key. In this way, during the encrypted communication process between the terminals, the risk of key leakage during key relay is reduced based on the pairwise pre-shared key sets between the key management systems, thus improving the security of quantum key distribution during key relay.

[0055] In some feasible implementations, for the key obfuscation process, the first key management system can obtain the key derivation function and the first fixed tag string, and then use the key derivation function to calculate the basic session key, the second pre-shared key, the session identifier, the first index number and the first fixed tag string to generate the target session key corresponding to the session identifier, thereby generating a more complex key and increasing the complexity of the session key.

[0056] In addition, the key management system can maintain a counter for each key in the key set that monotonically increases from 1. When the counter exceeds the threshold, the key is cancelled, and the key numbers from Sep+1 to Kn are incremented one step forward. When the key set counter Kn decreases to 0, a partial update of the shared key table is performed, that is, the key set that has been cleared to 0 is updated.

[0057] For example, taking the first key management system as an example, the first key management system can obtain the number of times the second pre-shared key is used. If the number of times it is used reaches a preset threshold, the first key management system will cancel the second pre-shared key from the second key set and adjust the sequence number of each pre-shared key in the second key set. Furthermore, if all the pre-shared keys in the second key set are canceled, the first key management system will send a key request to the cryptographic management service platform. The key request is used to instruct the cryptographic management service platform to supplement the second key set with keys, thereby ensuring that the key set always has valid and usable keys.

[0058] In the above process, taking the calling terminal as an example, for the called terminal, its second key management system can also obtain the pre-shared second sub-key table, extract the first key set corresponding to the first key management system from the second sub-key table, extract the corresponding first pre-shared key from the first key set, and then combine the basic session key with the first pre-shared key to generate the target session key for the session request, and send the target session key to the called terminal.

[0059] In some feasible implementations, the session request includes at least a session identifier. Then, the second key management system can obtain the number of second valid keys corresponding to the first key set, and then use the session identifier and the number of second valid keys to calculate the corresponding second index number. Finally, the system can extract the corresponding first pre-shared key from the first key set according to the second index number.

[0060] In some feasible implementations, for the key obfuscation process, the second key management system can obtain the key derivation function and the second fixed tag string; use the key derivation function to calculate the basic session key, the first pre-shared key, the session identifier, the second index number, and the second fixed tag string to generate the target session key corresponding to the session identifier.

[0061] In some feasible implementations, the second key management system obtains the number of times the first pre-shared key is used; if the number of uses reaches a preset threshold, the second key management system cancels the first pre-shared key from the first key set and adjusts the sequence number of each pre-shared key in the first key set; if all pre-shared keys in the first key set are canceled, the second key management system initiates a key request to the cryptographic management service platform, which instructs the cryptographic management service platform to supplement the first key set with keys.

[0062] It should be noted that the embodiments of the present invention include, but are not limited to, the examples described above. Those skilled in the art can make settings according to actual needs under the guidance of the ideas in the embodiments of the present invention, and the present invention does not limit such settings.

[0063] In this embodiment of the invention, the quantum security infrastructure includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system. The quantum key manager is communicatively connected to the key management system. During encrypted communication by the user terminal, the first key management system responds to a session request initiated by the calling terminal for the called terminal, generates a first random number, and sends the first random number to the first quantum key manager corresponding to the first key management system. Then, the first quantum key manager generates a second random number and generates a basic session key for the session request based on the first and second random numbers. The key management system obtains the pre-shared first sub-key table and extracts the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table. It then extracts the corresponding second pre-shared key from the second key set. The first key management system combines the basic session key and the second pre-shared key to generate a target session key for the session request. The target session key is then sent to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal. Thus, during the encrypted communication process between the terminals, based on the pairwise pre-shared key sets between the key management systems, the risk of key leakage during key relay is reduced, and the security of quantum key distribution during key relay is improved.

[0064] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the following examples are provided for illustrative purposes:

[0065] As an example, refer to Figure 2 The diagram illustrates a system architecture provided in an embodiment of the present invention. Based on this quantum-based security facility, XXX_CALL represents caller-related information, and XXX_CALLED represents callee-related information. The corresponding quantum key distribution process may include:

[0066] (1) KMS key pair generation and loading

[0067] KMS calls the directly connected cryptographic machine to generate and load the signature key pairs corresponding to the commercial cryptographic signature algorithm and the PQC signature algorithm, as well as the encryption key pairs corresponding to the commercial cryptographic encryption algorithm and the PQC encryption algorithm. It then stores the public keys of these four key pairs in secure media such as smart cryptographic keys. Correspondingly, CMSP reads and loads the signature public keys corresponding to the commercial cryptographic signature algorithm, the PQC signature algorithm, the encryption public keys corresponding to the commercial cryptographic encryption algorithm, and the PQC encryption algorithm from the secure media of each KMS offline.

[0068] (2) CMSP key pair generation

[0069] CMSP calls the directly connected cryptographic machine to generate and load the signature key pair corresponding to the commercial cryptographic signature algorithm and the signature key pair corresponding to the PQC signature algorithm, as well as the encryption key pair corresponding to the commercial cryptographic encryption algorithm and the encryption key pair corresponding to the PQC encryption algorithm, and stores the public keys of these four key pairs in the secure medium of each KMS.

[0070] (3) Generation of a shared key table

[0071] The CMSP (the cryptographic machine connected via the CMSP) generates a shared key table for all KMS nodes in the network. This table can be a three-dimensional array Ks[N][N][K], where N is the total number of KMS nodes in the system, and the value of K depends on the storage capacity of the security medium used by the system (assuming the storage capacity of the security medium is C bytes and the length of each key is L bytes, then K = 0.8 * C / N / L). Each array element Ks[x][y] (1 <= x <= M, 1 <= y <= N) represents the shared seed key between KMS-x and KMS-y, and the number of seed keys is K.

[0072] CMSP extracts a sub-table Ks[k] (with N*K seed keys) from the shared key table for each KMS (assuming KMS node number is k). It then uses a hybrid cryptographic envelope for encryption and encapsulation (generating two temporary random numbers, XORing them, and using the XORed result as the symmetric key to encrypt the sub-table in the shared key table; the temporary random numbers are then encrypted and protected using the public key corresponding to the KMS's PQC encryption algorithm (loaded by CMSP in step 1) and the public key corresponding to the commercial cryptographic encryption algorithm (loaded by CMSP in step 1), respectively. After assembling the envelopes, CMSP signs them using the private key of its own commercial cryptographic signature algorithm and the private key of its PQC signature algorithm to ensure reliability. Finally, the signed envelopes can be stored in the secure medium of each KMS.

[0073] (4) Key table loading

[0074] KMS obtains and loads the signature public key corresponding to the CMSP commercial cryptographic signature algorithm, the signature public key corresponding to the PQC signature algorithm, and the encryption private key of its own corresponding commercial cryptographic encryption algorithm and PQC encryption algorithm from the secure medium. It then verifies the signature based on the signature public key and decrypts the hybrid cryptographic envelope using the encryption private key to obtain and load its own public key table sub-table.

[0075] (5) Session key application

[0076] User terminals request session keys from the quantum security infrastructure for encrypted communication.

[0077] The calling and called user terminals each request a session key from their respective KMS, carrying the SessionID of the encrypted communication session.

[0078] (6) Quantum key distribution and relay

[0079] The KMS belonging to the calling user terminal generates a random number through the physical noise source built into the cryptographic machine and sends it to the corresponding QKM. The QKM generates a random number through a quantum random number generator and XORs it with the received random number to form the basic session key. The basic session key is relayed and securely distributed through a quantum communication network. Finally, the QKMs obtain a consistent basic session key Kb and transmit it to their respective associated KMS.

[0080] (7) Session key obfuscation

[0081] The KMS belonging to the calling and called user terminals retrieves a key from the key set corresponding to the other party's KMS (key sets are Ks[KMS-CALL][KMS-CALLED] and Ks[KMS-CALLED][KMS-CALL], respectively) in its own shared key table sub-table. Each key set maintains a key count Kn, which is initially set to K and decremented by one each time a key is canceled. The retrieved key sequence number Seq = SessionID mod Kn, that is, the keys are Ks[KMS-CALL][KMS-CALLED][Seq] (calling party) and Ks[KMS-CALLED][KMS-CALL][Seq] (called party).

[0082] Caller's session key Ke = HMAC (Kb ⊕ Ks[KMS-CALL][KMS-CALLED][Seq], Kb||SessionID||Seq||“session secret mix”).

[0083] The called party's session key Ke = HMAC (Kb ⊕ Ks[KMS-CALLED][KMS-CALL][Seq], Kb||SessionID||Seq||“session secret mix”).

[0084] (8) Encrypted communication

[0085] The calling and called parties' KMS send the session key Ke generated in step (7) to the calling and called parties' terminals through a secure channel (which may be an SSL secure channel).

[0086] (9) Public key table update

[0087] KMS maintains a monotonically increasing counter for each key, starting from 1. When the counter exceeds a threshold (a uniform setting across the entire network), the key is cancelled. The key numbers from Seq+1 to Kn are incremented sequentially to Seq and Kn-1. When the key set counter Kn decreases to 0, a partial update of the shared key table is performed, i.e., the key set that has been cleared to 0 is updated.

[0088] Suppose that the key set that KMS-CALL clears at a certain moment is Ks[KMS-CALL][KMS-CALLED], then KMS-CALL sends an update request message to CMSP:

[0089] LABEL||KMS_IP-CALL|| KMS_IP-CALLED||Timestamp||PQC_Sign(LABEL||Timestamp ||KMS_IP-CALL|| KMS_IP-CALLED,PRIV_PQC_KMS-CALL)|| KMS_IP-CALLED,PRIV_SM_KMS-CALL).

[0090] In this context, LABEL represents the key table update tag as a fixed string, Timestamp is the timestamp generated by KMS-CALL, KMS_IP-CALL and KMS_IP-CALLED are the IP addresses of the calling and called KMS (KMS-CALL and KMS-CALLED) respectively, PQC_Sign indicates that the private key PRIV_PQC_KMS-CALL is signed using the PQC signature algorithm of KMS-CALL, and SM_Sign indicates that the private key PRIV_SM_KMS-CALL is signed using the commercial cryptographic signature algorithm of KMS-CALL.

[0091] CMSP generates K new key seeds for the key sub-tables Ks[KMS-CALL][KMS-CALLED] and Ks[KMS-CALLED][KMS-CALL] (the corresponding keys in the two key sets are the same), and responds to KMS-CALL with a key set update message:

[0092] LABEL||KMS_IP-CALL||KMS_IP-CALLED||Timestamp||PQC_Sign(LABEL||Timestamp ||KMS_IP-CALL|| KMS_IP-CALLED,PRIV_SM_CMSP)||PQC_Encap(Kt1,PUB_PQC_KMS-CALL)|| SM_Encap(Kt2,PUB_SM_KMS-CALL).

[0093] Push key set update message to KMS-CALLED:

[0094] LABEL | | KMS_IP-CALLED | | KMS_IP-CALL,PRIV_SM_CMSP) ||PQC_Encap(Kt1,PUB_PQC_KMS-CALLED) || SM_Encap(Kt2,PUB_SM_KMS-CALLED).

[0095] Wherein, PQC_Sign and SM_Sign represent the digital signatures of the CMSP PQC signature algorithm signature private key PRIV_PQC_CMSP and the commercial cryptographic signature algorithm signature private key PRIV_SM_CMSP, respectively; Kt1 and Kt2 are random numbers generated by CMSP; PQC_Encap represents the encryption of Kt1 using the public key of the PQC encryption algorithm (PUB_PQC_KMS-CALL or PUB_PQC_KMS-CALLED) with KMS-CALL or KMS-CALLED; and SM_Encap represents the encryption of Kt2 using the public key of the commercial cryptographic encryption algorithm (SM_PQC_KMS-CALL or SM_PQC_KMS-CALLED) with KMS-CALL or KMS-CALLED.

[0096] CMSP uses Kt1⊕Kt2 as a temporary symmetric encryption key. After symmetric encryption of the updated key set Ks[KMS-CALL][KMS-CALLED] and Ks[KMS-CALLED][KMS-CALL], it is pushed to KMS-CALL and KMS-CALLED via secure file transfer protocols such as HTTPS, SSH or SFTP.

[0097] KMS-CALL and KMS-CALLED verify the signature respectively, decrypt to obtain Kt1 and Kt2, use Kt1⊕Kt2 as a temporary symmetric encryption key to decrypt to obtain the updated key set, insert it into the corresponding position in the key sub-table (Ks[KMS-CALL][KMS-CALLED] or Ks[KMS-CALLED][KMS-CALL]).

[0098] Through the above process, in the encrypted communication process of the terminal, based on the key sets pre-shared between the key management systems, the risk of key leakage during key relay is reduced, and the security of quantum key distribution during key relay is improved.

[0099] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0100] This invention also discloses a quantum-safe infrastructure, which includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system, and the quantum key manager is communicatively connected to the key management system; wherein,

[0101] The first key management system is used to respond to a session request initiated by the calling terminal for the called terminal, generate a first random number, and send the first random number to the first quantum key manager corresponding to the first key management system.

[0102] The first quantum key manager is used to generate a second random number, and to generate a base session key for the session request based on the first random number and the second random number;

[0103] The first key management system is used to obtain a pre-shared first sub-key table, extract the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extract the corresponding second pre-shared key from the second key set;

[0104] The first key management system is used to combine the basic session key and the second pre-shared key to generate a target session key for the session request, and to send the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

[0105] In some feasible implementations, the first quantum key manager is used to relay the basic session key in a trusted and secure manner through a quantum communication network, and to synchronize the basic session key among the various quantum key managers;

[0106] Each of the quantum key managers is used to transmit the basic session key to its respective key management system.

[0107] In some feasible implementations, the session request includes at least a session identifier; wherein, the first key management system is specifically used for:

[0108] Obtain the first valid key number corresponding to the second key set;

[0109] The first index number is calculated using the session identifier and the first number of valid keys;

[0110] The corresponding second pre-shared key is extracted from the second key set according to the first index number.

[0111] In some feasible implementations, the first key management system is specifically used for:

[0112] Obtain the key derivation function and the first fixed tag string;

[0113] The key derivation function is used to calculate the base session key, the second pre-shared key, the session identifier, the first index number, and the first fixed tag string to generate a target session key corresponding to the session identifier.

[0114] In some feasible implementations, the first key management system is used to obtain the number of times the second pre-shared key is used;

[0115] The first key management system is used to cancel the second pre-shared key from the second key set and adjust the sequence number corresponding to each pre-shared key in the second key set if the number of uses reaches a preset threshold.

[0116] The first key management system is used to initiate a key request to the cryptographic management service platform if all the pre-shared keys in the second key set are cancelled. The key request is used to instruct the cryptographic management service platform to supplement the second key set with keys.

[0117] In some feasible implementations, the second key management system to which the called terminal belongs is used to obtain a pre-shared second sub-key table, extract the first key set corresponding to the first key management system from the second sub-key table, and extract the corresponding first pre-shared key from the first key set;

[0118] The second key management system is used to combine the basic session key with the first pre-shared key to generate a target session key for the session request, and to send the target session key to the called terminal.

[0119] In some feasible implementations, the session request includes at least a session identifier; wherein, the second key management system is specifically used for:

[0120] Obtain the number of second valid keys corresponding to the first key set;

[0121] The corresponding second index number is calculated using the session identifier and the second valid key number;

[0122] The first pre-shared key is extracted from the first key set according to the second index number.

[0123] In some feasible implementations, the second key management system is specifically used for:

[0124] Obtain the key derivation function and the second fixed tag string;

[0125] The key derivation function is used to calculate the base session key, the first pre-shared key, the session identifier, the second index number, and the second fixed tag string to generate a target session key corresponding to the session identifier.

[0126] In some feasible implementations, the second key management system is used to obtain the number of times the first pre-shared key is used;

[0127] The second key management system is used to cancel the first pre-shared key from the first key set and adjust the sequence number corresponding to each pre-shared key in the first key set if the number of uses reaches a preset threshold.

[0128] The second key management system is used to initiate a key request to the cryptographic management service platform if all the pre-shared keys in the first key set are cancelled. The key request is used to instruct the cryptographic management service platform to supplement the first key set with keys.

[0129] In some feasible implementations, the cryptographic service layer further includes a cryptographic management service platform that is communicatively connected to the key management system; wherein,

[0130] The key management system is used to acquire a signature algorithm and an encryption algorithm, generate a corresponding first signature key pair using the signature algorithm, generate a corresponding first encryption key pair using the encryption algorithm, and store the first signature public key in the first signature key pair and the first encryption public key in the first encryption key pair into the security medium corresponding to the key management system.

[0131] The cryptographic management service platform is used to load the first signing public key from the first signing key pair and the first encryption public key from the first encryption key pair from the secure medium.

[0132] In some feasible implementations, the signature algorithm includes at least a commercial cryptographic signature algorithm and a quantum-resistant cryptographic signature algorithm, and the encryption algorithm includes at least a commercial cryptographic encryption algorithm and a quantum-resistant cryptographic encryption algorithm; wherein, the key management system is used for

[0133] The commercial cryptographic signature algorithm is used to generate the corresponding first signature subkey pair;

[0134] The quantum-resistant cryptographic signature algorithm is used to generate the corresponding second signature subkey pair;

[0135] The commercial cryptographic encryption algorithm is used to generate the corresponding first encryption subkey pair;

[0136] The quantum-resistant cryptographic algorithm is used to generate the corresponding second cryptographic subkey pair;

[0137] The first signature public key in the first signature sub-key pair, the second signature public key in the second signature sub-key pair, the first encryption public key in the first encryption sub-key pair, and the second encryption public key in the second encryption sub-key pair are stored in the security medium corresponding to the key management system.

[0138] In some feasible implementations, the password management service platform is specifically used for:

[0139] Obtain and load the first signing public key, the second signing public key, the first encryption public key, and the second encryption public key from the secure medium.

[0140] In some feasible implementations, the cryptographic management service platform is used to generate a corresponding second signature key pair using the signature algorithm and a corresponding second encryption key pair using the encryption algorithm, and to store the second signature public key in the second signature key pair and the second encryption public key in the second encryption key pair into the security medium corresponding to the key management system.

[0141] In some feasible implementations, the signature algorithm includes at least a commercial cryptographic signature algorithm and a quantum-resistant cryptographic signature algorithm, and the encryption algorithm includes at least a commercial cryptographic encryption algorithm and a quantum-resistant cryptographic encryption algorithm; wherein, the cryptographic management service platform is specifically used for:

[0142] The commercial cryptographic signature algorithm is used to generate the corresponding third signature subkey pair;

[0143] The quantum-resistant cryptographic signature algorithm is used to generate the corresponding fourth signature subkey pair;

[0144] The commercial cryptographic encryption algorithm is used to generate the corresponding third encryption subkey pair;

[0145] The quantum-resistant cryptographic algorithm is used to generate the corresponding fourth encryption subkey pair;

[0146] The third signature public key in the third signature sub-key pair, the fourth signature public key in the fourth signature sub-key pair, the third encryption public key in the third encryption sub-key pair, and the fourth encryption sub-key in the fourth encryption sub-key pair are stored in the security medium corresponding to the key management system.

[0147] In some feasible implementations, the cryptographic management service platform is used to obtain the number of nodes corresponding to the key management system, the storage capacity of the security medium used by each key management system, and the key length of each key;

[0148] The cryptographic management service platform is used to integrate the number of nodes, the storage capacity, and the key length to obtain a common key table corresponding to each of the key management systems.

[0149] In some feasible implementations, the cryptographic management service platform is used to extract a sub-key table corresponding to the key management system from the public key table, and the sub-key table contains the shared key between the key management system and other key management systems;

[0150] The cryptographic management service platform is used to randomly generate a third random number and a fourth random number, and to perform an XOR operation on the third random number and the fourth random number to generate a temporary symmetric session key;

[0151] The cryptographic management service platform is used to encrypt the subkey table using the temporary symmetric session key to obtain the corresponding encryption key table;

[0152] The password management service platform is used to encrypt the third random number using the first encryption public key to obtain the corresponding first encrypted random number, and to encrypt the fourth random number using the second encryption public key to obtain the corresponding second encrypted random number.

[0153] The cryptographic management service platform is used to assemble the encryption key table, the first encrypted random number, and the second encrypted random number into a corresponding envelope, and to sign the envelope using the third signature private key in the third signature sub-key pair and the fourth signature private key in the fourth signature sub-key pair to obtain the corresponding target envelope, and to store the target envelope in the security medium corresponding to the key management system.

[0154] In some feasible implementations, the key management system is used to obtain and load the third signature public key and the fourth signature public key from the secure medium;

[0155] The key management system is used to verify the signature of the target envelope using the third signature public key and the fourth signature public key. If the verification is successful, the encryption key table, the first encryption random number, and the second encryption random number are obtained.

[0156] The key management system is used to decrypt the first encrypted random number using the first encryption private key in the first encryption sub-key pair to obtain the third random number, and to decrypt the second encrypted random number using the second encryption private key in the second encryption sub-key pair to obtain the fourth random number.

[0157] The key management system is used to calculate the temporary symmetric session key by combining the third random number and the fourth random number.

[0158] The key management system is used to decrypt the encryption key table using the temporary symmetric session key to obtain the subkey table and load the subkey table.

[0159] As the facility implementation is basically similar to the method implementation, it is described in a relatively simple way. For relevant details, please refer to the description of the method implementation.

[0160] In addition, this invention also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described key distribution method embodiment for quantum secure infrastructure and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0161] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the various processes of the key distribution method embodiment for the quantum secure infrastructure described above, achieving the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0162] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0163] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, EEPROM, Flash, and eMMC, etc.) containing computer-usable program code.

[0164] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0165] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0166] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0167] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0168] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0169] The key distribution method and quantum secure infrastructure provided by this invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this invention. Therefore, the content of this specification should not be construed as a limitation of this invention.

Claims

1. A key distribution method for quantum-safe infrastructure, characterized in that, The quantum-safe infrastructure includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, the cryptographic service layer includes at least a key management system, and the quantum key manager is communicatively connected to the key management system; wherein the method includes: In response to a session request initiated by the calling terminal for the called terminal, the first key management system generates a first random number and sends the first random number to the first quantum key manager corresponding to the first key management system. The first quantum key manager generates a second random number, and generates a base session key for the session request based on the first random number and the second random number; The first key management system obtains a pre-shared first sub-key table, extracts a second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extracts the corresponding second pre-shared key from the second key set; The first key management system combines the basic session key with the second pre-shared key to generate a target session key for the session request, and sends the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

2. The method according to claim 1, characterized in that, After generating the base session key for the session request based on the first random number and the second random number, the method further includes: The first quantum key manager relays the basic session key in a trusted and secure manner through a quantum communication network, and synchronizes the basic session key among the various quantum key managers; Each of the quantum key managers transmits the basic session key to its respective key management system.

3. The method according to claim 1 or 2, characterized in that, The session request includes at least a session identifier, and the step of extracting the corresponding second pre-shared key from the second key set includes: Obtain the first valid key number corresponding to the second key set; The first index number is calculated using the session identifier and the first number of valid keys; The corresponding second pre-shared key is extracted from the second key set according to the first index number.

4. The method according to claim 3, characterized in that, The step of combining the base session key with the second pre-shared key to generate a target session key for the session request includes: Obtain the key derivation function and the first fixed tag string; The key derivation function is used to calculate the base session key, the second pre-shared key, the session identifier, the first index number, and the first fixed tag string to generate a target session key corresponding to the session identifier.

5. The method according to claim 3, characterized in that, Also includes: The first key management system obtains the number of times the second pre-shared key is used; If the number of uses reaches a preset threshold, the first key management system will cancel the second pre-shared key from the second key set and adjust the sequence number corresponding to each pre-shared key in the second key set. If all the pre-shared keys in the second key set are cancelled, the first key management system initiates a key request to the cryptographic management service platform, which instructs the cryptographic management service platform to supplement the second key set with keys.

6. The method according to claim 1, characterized in that, Also includes: The second key management system to which the called terminal belongs obtains the pre-shared second sub-key table, extracts the first key set corresponding to the first key management system from the second sub-key table, and extracts the corresponding first pre-shared key from the first key set; The second key management system combines the basic session key with the first pre-shared key to generate a target session key for the session request, and sends the target session key to the called terminal.

7. The method according to claim 6, characterized in that, The session request includes at least a session identifier, and the step of extracting the corresponding first pre-shared key from the first key set includes: Obtain the number of second valid keys corresponding to the first key set; The corresponding second index number is calculated using the session identifier and the second valid key number; The first pre-shared key is extracted from the first key set according to the second index number.

8. The method according to claim 7, characterized in that, The step of combining the basic session key with the first pre-shared key to generate a target session key for the session request includes: Obtain the key derivation function and the second fixed tag string; The key derivation function is used to calculate the base session key, the first pre-shared key, the session identifier, the second index number, and the second fixed tag string to generate a target session key corresponding to the session identifier.

9. The method according to claim 7, characterized in that, Also includes: The second key management system obtains the number of times the first pre-shared key has been used; If the number of uses reaches a preset threshold, the second key management system will cancel the first pre-shared key from the first key set and adjust the sequence number corresponding to each pre-shared key in the first key set. If all the pre-shared keys in the first key set are cancelled, the second key management system initiates a key request to the cryptographic management service platform, which instructs the cryptographic management service platform to supplement the first key set with keys.

10. The method according to claim 1, characterized in that, The cryptographic service layer further includes a cryptographic management service platform that is communicatively connected to the key management system, and the method further includes: The key management system acquires the signature algorithm and the encryption algorithm, and uses the signature algorithm to generate a corresponding first signature key pair and uses the encryption algorithm to generate a corresponding first encryption key pair, and stores the first signature public key in the first signature key pair and the first encryption public key in the first encryption key pair into the security medium corresponding to the key management system. The cryptographic management service platform loads the first signing public key from the first signing key pair and the first encryption public key from the first encryption key pair from the secure medium.

11. The method according to claim 10, characterized in that, The signature algorithm includes at least a commercial cryptographic signature algorithm and a quantum-resistant cryptographic signature algorithm, and the encryption algorithm includes at least a commercial cryptographic encryption algorithm and a quantum-resistant cryptographic encryption algorithm. The step of generating a corresponding first signature key pair using the signature algorithm and a corresponding first encryption key pair using the encryption algorithm, and storing the first signature public key in the first signature key pair and the first encryption public key in the first encryption key pair in the secure medium corresponding to the key management system, includes: The commercial cryptographic signature algorithm is used to generate the corresponding first signature subkey pair; The quantum-resistant cryptographic signature algorithm is used to generate the corresponding second signature subkey pair; The commercial cryptographic encryption algorithm is used to generate the corresponding first encryption subkey pair; The quantum-resistant cryptographic algorithm is used to generate the corresponding second cryptographic subkey pair; The first signature public key in the first signature sub-key pair, the second signature public key in the second signature sub-key pair, the first encryption public key in the first encryption sub-key pair, and the second encryption public key in the second encryption sub-key pair are stored in the security medium corresponding to the key management system.

12. The method according to claim 11, characterized in that, Loading the first signing public key from the first signing key pair and the first encryption public key from the first encryption key pair from the secure medium includes: Obtain and load the first signing public key, the second signing public key, the first encryption public key, and the second encryption public key from the secure medium.

13. The method according to claim 11, characterized in that, Also includes: The cryptographic management service platform uses the signature algorithm to generate a corresponding second signature key pair and uses the encryption algorithm to generate a corresponding second encryption key pair, and stores the second signature public key in the second signature key pair and the second encryption public key in the second encryption key pair in the security medium corresponding to the key management system.

14. The method according to claim 13, characterized in that, The signature algorithm includes at least a commercial cryptographic signature algorithm and a quantum-resistant cryptographic signature algorithm, and the encryption algorithm includes at least a commercial cryptographic encryption algorithm and a quantum-resistant cryptographic encryption algorithm. The step of generating a corresponding second signature key pair using the signature algorithm and a corresponding second encryption key pair using the encryption algorithm, and storing the second signature public key from the second signature key pair and the second encryption public key from the second encryption key pair in the secure medium corresponding to the key management system, includes: The commercial cryptographic signature algorithm is used to generate the corresponding third signature subkey pair; The quantum-resistant cryptographic signature algorithm is used to generate the corresponding fourth signature subkey pair; The commercial cryptographic encryption algorithm is used to generate the corresponding third encryption subkey pair; The quantum-resistant cryptographic algorithm is used to generate the corresponding fourth encryption subkey pair; The third signature public key in the third signature sub-key pair, the fourth signature public key in the fourth signature sub-key pair, the third encryption public key in the third encryption sub-key pair, and the fourth encryption sub-key in the fourth encryption sub-key pair are stored in the security medium corresponding to the key management system.

15. The method according to claim 14, characterized in that, Also includes: The cryptographic management service platform obtains the number of nodes corresponding to the key management system, the storage capacity of the security medium used by each key management system, and the key length of each key; The cryptographic management service platform integrates the number of nodes, the storage capacity, and the key length to obtain a shared key table corresponding to each of the key management systems.

16. The method according to claim 15, characterized in that, Also includes: The cryptographic management service platform extracts the sub-key table corresponding to the key management system from the public key table. The sub-key table contains the shared key between the key management system and other key management systems. The cryptographic management service platform randomly generates a third random number and a fourth random number, and performs an XOR operation on the third random number and the fourth random number to generate a temporary symmetric session key; The cryptographic management service platform encrypts the subkey table using the temporary symmetric session key to obtain the corresponding encrypted key table; The password management service platform uses the first encryption public key to encrypt the third random number to obtain the corresponding first encrypted random number, and uses the second encryption public key to encrypt the fourth random number to obtain the corresponding second encrypted random number. The cryptographic management service platform assembles the encryption key table, the first encrypted random number, and the second encrypted random number into a corresponding envelope, and signs the envelope using the third signature private key in the third signature sub-key pair and the fourth signature private key in the fourth signature sub-key pair to obtain the corresponding target envelope, and stores the target envelope in the security medium corresponding to the key management system.

17. The method according to claim 16, characterized in that, Also includes: The key management system obtains and loads the third signature public key and the fourth signature public key from the secure medium; The key management system uses the third and fourth signature public keys to verify the signature of the target envelope. If the verification is successful, the encryption key table, the first encrypted random number, and the second encrypted random number are obtained. The key management system uses the first encryption private key in the first encryption sub-key pair to decrypt the first encrypted random number to obtain the third random number, and uses the second encryption private key in the second encryption sub-key pair to decrypt the second encrypted random number to obtain the fourth random number; The key management system calculates the third random number and the fourth random number to obtain the temporary symmetric session key; The key management system uses the temporary symmetric session key to decrypt the encryption key table, obtain the subkey table, and load the subkey table.

18. A quantum-safe infrastructure, characterized in that, The quantum-safe infrastructure includes at least a quantum communication layer and a cryptographic service layer; wherein the quantum communication layer includes at least a quantum key manager, and the cryptographic service layer includes at least a key management system, and the quantum key manager is communicatively connected to the key management system; wherein... The first key management system is used to respond to a session request initiated by the calling terminal for the called terminal, generate a first random number, and send the first random number to the first quantum key manager corresponding to the first key management system. The first quantum key manager is used to generate a second random number, and to generate a base session key for the session request based on the first random number and the second random number; The first key management system is used to obtain a pre-shared first sub-key table, extract the second key set corresponding to the second key management system to which the called terminal belongs from the first sub-key table, and extract the corresponding second pre-shared key from the second key set; The first key management system is used to combine the basic session key and the second pre-shared key to generate a target session key for the session request, and to send the target session key to the calling terminal. The target session key is used for encrypted communication between the calling terminal and the called terminal.

19. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in any one of claims 1-17.

20. A computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method as described in any one of claims 1-17.

Citation Information

Patent Citations

  • Authentication method and system based on Ksession shared session key MAC

    CN119583064A

  • Encrypted data transmission method based on dynamic key and server

    CN119788361A