Quantum secure wireless communication system

By using a quantum-secure wireless communication system and a quantum key distribution and cryptographic service system to generate dynamic session keys, the risk of quantum computing attacks faced by traditional encryption technologies in rail transit is resolved. This achieves end-to-end communication with high confidentiality and integrity, and improves the reliability and security of the system.

CN121013074BActive Publication Date: 2026-08-25CRRC TANGSHAN CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511282706.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2026-08-25
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

In rail transit, existing technologies face the risk of quantum computing attacks due to the limitations of traditional encryption techniques. Physical noise sources are susceptible to environmental factors, and chaotic systems may lose their randomness under external interference. It is difficult to stably generate high-quality keys resistant to quantum attacks in unattended mobile vehicle environments, which affects the reliability of communication systems.

Method used

A quantum-safe wireless communication system is adopted, including a quantum-safe core board, a quantum key distribution system, and a multi-mode gateway platform. The quantum key distribution system provides an initial quantum key for encryption processing, and combined with the authentication and quantum-resistant algorithm of the cryptographic service system, a dynamic session key is generated to build an end-to-end quantum-safe communication link. The principle of quantum mechanics is used to achieve unbreakability and real-time updates.

Benefits of technology

It effectively resists quantum computing attacks, enhances the anti-interception and anti-tampering capabilities of rail transit safety communications, and strengthens the reliability and security of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121013074B_ABST
    Figure CN121013074B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of quantum security wireless communication system, it is related to quantum security communication technical field.System includes: quantum security wireless communication device, for receiving service data, and through quantum security core board to service data is encrypted processing;Quantum key distribution system is connected with quantum security core board, for providing initial quantum key to quantum security core board;Multi-mode gateway platform is used to receive the encrypted data transmitted by quantum security wireless communication device and decrypt the encrypted data.Quantum security core board uses the initial quantum key provided by quantum key distribution system to encrypt service data, so that the key has unbreakable and real-time update capability, to effectively resist quantum computing attack.And, through multi-mode gateway platform is responsible for receiving and decrypting encrypted data, constructs the end-to-end quantum security communication link, guarantees the confidentiality and integrity of service data, enhances the reliability of rail transit safety communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum secure communication technology, and more specifically, to a quantum secure wireless communication system. Background Technology

[0002] Currently, traditional encryption technologies are widely used in the rail transit sector to ensure the security of vehicle-to-everything (V2X) communication. However, with the development of quantum computing capabilities, encryption algorithms based on mathematical complexity face the risk of being cracked. Especially in wireless data transmission scenarios between vehicles and infrastructure, traditional pseudo-random number generators rely on algorithm seeds to generate keys, and their randomness is vulnerable to reverse engineering.

[0003] Related technologies employ physical noise sources (such as thermal or electronic noise) to generate random numbers, and enhance key unpredictability through environmental entropy sources. Others build random number generators based on chaotic systems, leveraging the sensitivity of system parameters to enhance randomness.

[0004] In the process of implementing the embodiments of this application, at least the following problems were found in the related technology: Employing physical mechanisms instead of pure algorithms through related technologies has improved the ability of communication systems to resist quantum computing attacks to some extent. However, in practical applications, physical noise sources are susceptible to environmental factors such as temperature and electromagnetic interference, which can easily lead to deviations in random numbers. Chaotic systems, due to their strong dependence on parameter settings, may lose their randomness under external interference. Therefore, the above-mentioned schemes struggle to stably generate high-quality keys resistant to quantum attacks in unattended mobile vehicle environments, impacting the reliability of rail transit safety communication systems. Summary of the Invention

[0005] This application provides a quantum-safe wireless communication system and device.

[0006] A first aspect of this application provides a quantum-safe wireless communication system, comprising: A quantum-safe wireless communication device is used to receive service data and encrypt the service data through a quantum-safe core board; A quantum key distribution system, connected to a quantum-safe core board, is used to provide an initial quantum key to the quantum-safe core board. A multi-mode gateway platform is used to receive encrypted data transmitted by quantum-safe wireless communication devices and decrypt the encrypted data.

[0007] In an optional embodiment of this application, the quantum-safe wireless communication system further includes: The cryptographic service system is connected to the quantum-safe core board, the quantum key distribution system, and the multi-mode gateway platform. It is used to authenticate the quantum-safe wireless communication device and the multi-mode gateway platform by calling the quantum authentication certificate pre-loaded into the quantum-safe core board. After successful authentication, it generates a third quantum key for encrypted communication between the quantum-safe wireless communication device and the multi-mode gateway platform based on the first quantum key and the second quantum key. The cryptographic service system, according to a first preset algorithm, negotiates with the quantum-safe wireless communication device and the multi-mode gateway platform to generate the first quantum key. The second quantum key is pre-loaded into the quantum-safe core board.

[0008] In an optional embodiment of this application, the cryptographic service system integrates a quantum-resistant algorithm and pre-charges a second quantum key into the quantum-secure core board through a quantum key distribution system. The cryptographic service system monitors the remaining amount of the second quantum key in the quantum-secure core board. When the remaining amount is lower than a preset security threshold, the cryptographic service system uses a random number generated by quantum random number generation technology to encrypt the initial quantum key, generate a second quantum key, and charge the second quantum key into the quantum-secure core board.

[0009] In one optional embodiment of this application, the quantum-safe wireless communication device and the multi-mode gateway platform transmit data through a quantum-safe channel established based on a multi-mode protocol; wherein, the multi-mode protocol includes a secure transmission protocol based on public key infrastructure and quantum random number generation technology, a key service protocol based on a quantum key distribution system, and / or a quantum-resistant key exchange protocol.

[0010] In an optional embodiment of this application, during cross-domain communication, the quantum-secure channel includes a zero-trust transmission channel; wherein, the zero-trust transmission channel includes a quantum-secure IPSec tunnel module, a quantum-resistant key update module, and an attack detection module. The quantum-secure IPSec tunnel module is used to encrypt the transmitted data based on a third quantum key; the key update module is used to periodically update the third quantum key through a quantum-resistant key exchange protocol; and the attack detection module is used to detect quantum computing attacks and trigger the key update module to switch to a quantum-resistant algorithm.

[0011] In an optional embodiment of this application, the quantum-safe wireless communication device includes: The business data receiving and processing module includes a business data communication board and an in-vehicle safety core board, which is used to receive and process business data to obtain the first business data; The encryption module is connected to the vehicle security core board through the quantum security core board. It is used to receive the first business data and call the third quantum key generated by the quantum security core board to perform encryption operation on the first business data to generate ciphertext data. The communication module, connected to the encryption module, is used to transmit encrypted data to the multi-mode gateway platform via a quantum-secure channel; in the event of a failure of the encryption module, the first service data is transmitted to the trackless vehicle project maintenance platform.

[0012] In an optional embodiment of this application, the quantum-safe wireless communication device further includes: The power supply module provides power to the business data receiving and processing module, the encryption module, and the communication module. The energy storage module is used to supply power to the business data receiving and processing module, encryption module and communication module when the power module is powered off.

[0013] In one optional embodiment of this application, the quantum-safe core board includes: The main control module includes a first interface, a second interface, and a third interface; The cryptographic module, connected to the main control module via the first interface, integrates a quantum random number chip; the cryptographic module generates quantum random numbers based on the quantum random number chip and performs data encryption / decryption and digital signature operations; The secure storage module, connected to the main control module via a second interface, is used to store the quantum authentication certificate, the second quantum key, and the third quantum key. The third interface of the main control module is used to connect to external devices, including the communication module of the quantum-safe wireless communication device, the gateway module of the multi-mode gateway platform, and the / live cryptographic service system.

[0014] In an optional embodiment of this application, the cryptographic module further includes: The national cryptographic algorithm unit is equipped with SM2, SM3 and SM4 algorithms. The SM2 algorithm is used to perform key negotiation, the SM3 algorithm is used to generate data integrity verification values, and the SM4 algorithm is used to perform symmetric encryption. A quantum-resistant algorithm unit is used to replace the national cryptographic algorithm unit execution unit in performing key negotiation and encryption operations when a risk of quantum computing attack is detected. The key generation unit, connected to the quantum random number chip, is used to receive the initial quantum key transmitted by the quantum key distribution system, and generate the first quantum key, the second quantum key, and the third quantum key based on the initial quantum key and the random number generated by the quantum random number chip.

[0015] In one optional embodiment of this application, the quantum key distribution system includes: A quantum key generation device for generating an initial quantum key based on a preset quantum protocol; The key management device is connected to the quantum key generation device and the quantum security core board respectively. It is used to receive the initial quantum key output by the quantum key generation device, verify and store the initial quantum key, and fill the secure storage module of the quantum security core board with the verified initial quantum key as the second quantum key according to the instructions of the cryptographic service system. The quantum certificate generation device, connected to the key management device, is used to generate a quantum authentication certificate based on the initial quantum key generated by the quantum key generation device, and then transmits the quantum authentication certificate to the secure storage module of the quantum security core board through the key management device.

[0016] The quantum-safe wireless communication system provided in this application has the following advantages: The quantum-safe core board in this application utilizes an initial quantum key provided by a quantum key distribution system to encrypt business data. Based on quantum mechanics principles, this ensures the encryption key is unbreakable and capable of real-time updates, effectively resisting quantum computing attacks. Furthermore, a multi-mode gateway platform receives and decrypts the encrypted data, constructing an end-to-end quantum-safe communication link. This achieves high confidentiality and integrity of business data in wireless transmission scenarios, thereby enhancing the anti-interception and anti-tampering capabilities of rail transit safety communication and strengthening the reliability of the rail transit safety communication system. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a schematic diagram of the architecture of a quantum-safe wireless communication system provided in an embodiment of this application; Figure 2 This is a schematic diagram of the architecture of a quantum-safe wireless communication device provided in an embodiment of this application; Figure 3 This is a schematic diagram of the software architecture of a quantum-safe wireless communication device provided in an embodiment of this application; Figure 4 This is a schematic diagram of the overall architecture of a quantum key distribution system provided in an embodiment of this application; Figure 5 This is an application diagram of a quantum key distribution system provided in an embodiment of this application; Figure 6 This is an application diagram of another quantum key distribution system provided in the embodiments of this application; Figure 7 This is an application diagram of another quantum key distribution system provided in the embodiments of this application; Figure 8 This is an application diagram of a quantum-safe wireless communication device provided in an embodiment of this application. Detailed Implementation

[0018] To make the technical solutions and advantages of the embodiments of this application clearer, the exemplary embodiments of this application will be described in further detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not an exhaustive list of all embodiments. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.

[0019] This application provides a quantum-safe wireless communication system, including a quantum-safe wireless communication device, a quantum key distribution system, and a multi-mode gateway platform. The quantum-safe wireless communication device receives service data and encrypts the data via a quantum-safe core board. The quantum key distribution system is connected to the quantum-safe core board and provides an initial quantum key to it. The multi-mode gateway platform receives and decrypts the encrypted data transmitted by the quantum-safe wireless communication device.

[0020] In one embodiment, the quantum-safe wireless communication device can be deployed in the onboard system of a high-speed train. It receives real-time business data such as traction motor temperature and braking pressure collected by vehicle sensors via a business data communication board. The onboard safety core board performs data format standardization processing to generate first business data. The quantum-safe core board calls a pre-charged second quantum key combined with a dynamically negotiated key to generate a third quantum key, and uses the national cryptographic SM4 algorithm to encrypt the first business data into ciphertext data. The quantum key distribution system generates an initial quantum key based on the BB84 protocol through a quantum key generation device deployed at a ground station. After verification by the key management device, the initial quantum key is charged to the onboard quantum-safe core board. The ciphertext data is transmitted via a vehicle-to-ground wireless channel to a multi-mode gateway platform deployed in the control center computer room. This platform restores the plaintext data through a reverse decryption process and inputs it into the train safety monitoring system, achieving end-to-end quantum-level secure transmission of train operation status. In other embodiments, the quantum-safe wireless communication device can also be embedded in a subway vehicle maintenance terminal. The business data receiving and processing module obtains maintenance report data generated by the onboard fault diagnosis system through dual gigabit network ports. When the encryption module generates a third quantum key through the quantum-safe core board to perform encryption operations, the quantum key distribution system distributes the initial quantum key to the trackside key management device via a pre-embedded fiber optic link. After being bound to a digital identity by the quantum certificate generation device, it is then stored in the onboard secure storage module. In tunnel environments, the communication module automatically switches to an anti-interference frequency band to transmit the encrypted maintenance data through a quantum-safe channel. The multi-mode gateway platform, deployed in the depot's data center, receives the encrypted data, decrypts it using the locally stored quantum key, and synchronizes the plaintext data to the maintenance management platform, achieving tamper-proof and secure data transmission back to the maintenance management platform.

[0021] The quantum-safe wireless communication system provided in this application utilizes an initial quantum key provided by a quantum key distribution system to encrypt business data. Based on quantum mechanics principles, this ensures the initial quantum key is unbreakable and capable of real-time updates, effectively resisting quantum computing attacks. Furthermore, a multi-mode gateway platform receives and decrypts the encrypted data, constructing an end-to-end quantum-safe communication link. This achieves high confidentiality and integrity of business data in wireless transmission scenarios, thereby enhancing the anti-interception and anti-tampering capabilities of rail transit safety communication and improving the reliability of the rail transit safety communication system.

[0022] In an optional embodiment of this application, the quantum-safe wireless communication system further includes a cryptographic service system. The cryptographic service system is connected to the quantum-safe core board, the quantum key distribution system, and the multi-mode gateway platform, respectively. It is used to authenticate the quantum-safe wireless communication device and the multi-mode gateway platform by invoking a quantum authentication certificate pre-loaded into the quantum-safe core board. After successful authentication, it generates a third quantum key for encrypted communication between the quantum-safe wireless communication device and the multi-mode gateway platform based on a first quantum key and a second quantum key. Specifically, the cryptographic service system, according to a first preset algorithm, negotiates with the quantum-safe wireless communication device and the multi-mode gateway platform to generate the first quantum key; the second quantum key is pre-loaded into the quantum-safe core board.

[0023] In this embodiment, the cryptographic service system is deployed at the ground control center. When the train enters the communication area, it invokes the quantum authentication certificate pre-charged to the quantum-safe core board to perform two-way authentication on the onboard quantum-safe wireless communication device and the regional multi-mode gateway platform. After successful authentication, the cryptographic service system negotiates with both ends of the device in real time based on the national cryptographic SM2 algorithm to generate a first quantum key (dynamic key), and simultaneously extracts the second quantum key pre-charged in the secure storage module of the quantum-safe core board (pre-distributed by the quantum key distribution system). The system inputs the first and second quantum keys into a quantum-resistant key derivation function to generate a third quantum key bound to a unique session identifier, which is used by the onboard device and the gateway platform to encrypt business data using the SM4 algorithm in this communication session. This process achieves the fusion of dynamic and static quantum keys, and the session key has forward security. In other embodiments, the cryptographic service system can be deployed as a distributed node in a cross-regional communication architecture. When the vehicle enters region B from region A, it invokes the cross-domain quantum authentication certificate pre-charged to the onboard quantum-safe core board to perform zero-trust authentication on the vehicle device and the region B multi-mode gateway platform. After successful verification, the cryptographic service system negotiates with both ends of the device using the quantum-resistant key exchange protocol (ML-KEM-512) to generate a first quantum key, while simultaneously activating a pre-filled, region-specific second quantum key within the quantum-safe core board. The system then uses a key obfuscation mechanism to perform quantum random number obfuscation on the first and second quantum keys, generating a third quantum key that is only applicable to the B-region communication link. This third key is automatically destroyed after the session ends. This design achieves region-isolated session key management, resisting key reuse attacks.

[0024] In this way, the cryptographic service system performs bidirectional authentication between the quantum-safe wireless communication device and the multi-mode gateway platform by calling the quantum authentication certificate pre-charged to the quantum-safe core board, ensuring the legitimacy and trustworthiness of both parties and preventing unauthorized devices from accessing the communication link. After successful authentication, the system generates a session key by combining two independent key sources. On the one hand, it dynamically negotiates with both ends of the device using a first preset algorithm (such as the national cryptographic standard SM2) to generate a first quantum key; on the other hand, it calls the second quantum key pre-charged to the quantum-safe core board. A third quantum key is derived from the first and second quantum keys as the session key, so that the key used for encrypting business data has both the real-time nature of dynamic negotiation and the physical unbreakability of the pre-charged key. Through the dual-source key fusion mechanism, since the second quantum key is generated based on quantum mechanics principles and dynamic factors are introduced through the negotiation key, it avoids the algorithm cracking risk that may be faced by single dynamic negotiation and overcomes the update lag defect of static pre-charged keys. This improves the unpredictability and anti-attack capability of the session key in the context of quantum computing threats, providing stronger key protection for the end-to-end quantum-safe communication link.

[0025] In an optional embodiment of this application, the cryptographic service system integrates a quantum-resistant algorithm and pre-charges a second quantum key into the quantum-secure core board via a quantum key distribution system. Specifically, the cryptographic service system monitors the remaining amount of the second quantum key within the quantum-secure core board. When the remaining amount falls below a preset security threshold, the cryptographic service system uses a random number generated by quantum random number generation technology to encrypt the initial quantum key, generating a second quantum key, and then charges the quantum-secure core board with the second quantum key.

[0026] In this embodiment, when a rail vehicle is undergoing maintenance in the depot, the cryptographic service system pre-charges a second quantum key into the onboard quantum-safe core board via a quantum key distribution system. The system continuously monitors the key balance within the core board. When it detects that the key balance for a vehicle is below a security threshold, it immediately activates the integrated ML-KEM-512 quantum-resistant algorithm module. The cryptographic service system calls a local quantum random number generator to generate a high-entropy random number. This random number is then combined with the initial quantum key provided by the quantum key distribution system to perform a quantum-resistant encapsulation operation, generating a new second quantum key with forward security characteristics. This new key is then charged into the vehicle's quantum-safe core board via a dedicated optical communication link within the depot. This process achieves closed-loop management of real-time key balance sensing and quantum-resistant cascade encryption charging. In other embodiments, during high-speed train operation, the cryptographic service system obtains the status of the second quantum key balance within the quantum-safe core board in real time via a wireless network. When the balance approaches a preset security threshold, the system activates the quantum-resistant algorithm engine to generate a dynamic charging command. By using truly random numbers generated through quantum random number generation technology as encryption factors, layered obfuscation encryption is applied to the initial quantum key transmitted by the quantum key distribution system, forming a new second quantum key with spatiotemporal uniqueness. This key is then continuously supplied to the mobile vehicle core board via a vehicle-to-ground quantum secure channel, with a session binding mechanism ensuring transmission integrity during the supply process. This achieves seamless key resource replenishment and quantum-level anti-theft protection in mobile scenarios.

[0027] In this way, the cryptographic service system integrates quantum-resistant algorithms (such as ML-KEM-512 and Kyber-512) to make the key filling process resistant to quantum computing attacks, avoiding the risk of traditional encryption algorithms being cracked in a quantum computing environment. The system pre-fills the quantum security core board with a second quantum key through a quantum key distribution system, using quantum mechanics principles to ensure the physical unbreakability of the initial key. Simultaneously, the cryptographic service system continuously monitors the remaining amount of the second quantum key within the quantum security core board. When the remaining amount falls below a preset security threshold, a high-randomness protection factor is generated using quantum random number generation technology. This random number is then used to encrypt the initial quantum key provided by the quantum key distribution system, dynamically generating a new second quantum key. This dynamic filling mechanism ensures a continuous supply of key resources, avoiding communication interruptions due to key depletion. Quantum random number generation technology, based on the physical irreversibility of quantum state collapse, generates random numbers with theoretical unpredictability and resistance to reverse engineering, further enhancing the randomness and security of the second quantum key and reducing the risk of key cracking or forgery. By combining pre-filling and dynamic generation, the system can quickly respond to communication needs and continuously maintain a secure key reserve, achieving quantum-resistant protection throughout the key's lifecycle and providing stable and reliable key support for encrypted communication between quantum-secure wireless communication devices and multi-mode gateway platforms.

[0028] In one optional embodiment of this application, the quantum-secure wireless communication device and the multi-mode gateway platform transmit data through a quantum-secure channel established based on a multi-mode protocol. The multi-mode protocol includes a secure transmission protocol based on public key infrastructure and quantum random number generation technology, a key service protocol based on a quantum key distribution system, and / or a quantum-resistant key exchange protocol.

[0029] In this embodiment, the quantum-secure wireless communication device can transmit real-time video monitoring data to the multi-mode gateway platform via a quantum-secure channel during train operation. When the train enters a public network coverage area, a secure transmission protocol based on public key infrastructure and quantum random number generation technology is automatically activated. The device uses a pre-set digital certificate for authentication and utilizes a quantum random number generated by the quantum-secure core board as a session seed key, combined with the SM2 algorithm for key encapsulation, forming an anti-eavesdropping transmission channel. If the train enters a signal blind zone causing quantum key distribution to be interrupted, the system immediately switches to a quantum-resistant key exchange protocol, generating a temporary session key through the integrated ML-KEM-512 algorithm to maintain encrypted transmission. This dual-mode adaptive switching process is achieved through a protocol fingerprint dynamic matching mechanism, ensuring continuous data transmission security under different network environments. In other embodiments, after collecting vehicle bogie vibration data, the quantum-secure wireless communication device can send an encrypted diagnostic report to the multi-mode gateway platform via a quantum-secure channel. In densely populated base station areas, a key service protocol based on a quantum key distribution system is preferentially activated. The device directly calls the quantum key pre-charged by the quantum-secure core board and encrypts the data packet using a one-time pad method to generate ciphertext with information theory security. When an external network attack is detected, the channel automatically switches to a quantum-resistant key exchange protocol, performs key renegotiation using the FrodoKEM-1344 algorithm, updates the transmission key, and discards historical session data. The entire process is driven by a protocol behavior feature analysis engine, which identifies channel threats in real time and triggers the optimal protocol switch.

[0030] In this way, quantum-secure wireless communication devices and multi-mode gateway platforms transmit data through a quantum-secure channel established based on a multi-mode protocol, enhancing the adaptability of the communication link by integrating multiple security mechanisms. The secure transmission protocol based on public key infrastructure and quantum random number generation technology utilizes the high entropy of quantum random numbers to generate keys, improving the unpredictability of keys in traditional public key systems. The key service protocol based on a quantum key distribution system directly calls the physically unbreakable key provided by the quantum key distribution system, providing underlying quantum mechanical security for data transmission. The quantum-resistant key exchange protocol integrates quantum-resistant algorithms (such as ML-KEM-512) to ensure that the key negotiation process is resistant to quantum computing attacks. Through a multi-mode protocol collaboration mechanism, dynamic adaptation capabilities are provided for the complex wireless environment of rail transit. Protocol types can be flexibly switched under different security requirements or channel conditions, ensuring compatibility with existing public key infrastructure deployments while integrating the physical security of quantum key distribution and the forward-looking protection of quantum-resistant algorithms. This allows for the construction of a highly reliable and scalable end-to-end secure transmission channel in mobile vehicle scenarios.

[0031] In an optional embodiment of this application, during cross-domain communication, the quantum-secure channel includes a zero-trust transmission channel. The zero-trust transmission channel includes a quantum-secure IPSec tunnel module, a quantum-resistant key update module, and an attack detection module. The quantum-secure IPSec tunnel module is used to encrypt transmitted data based on a third quantum key. The key update module is used to periodically update the third quantum key using a quantum-resistant key exchange protocol. The attack detection module is used to detect quantum computing attacks and trigger the key update module to switch to a quantum-resistant algorithm.

[0032] In this embodiment, when the train enters dispatch area B from dispatch area A, the quantum-secure channel initiates a zero-trust transmission channel. The quantum-secure IPSec tunnel module uses a third quantum key to encrypt train control commands end-to-end, forming a quantum-level encrypted tunnel. The quantum-resistant key update module automatically triggers key updates based on a preset time threshold, renegotiating a new third quantum key with the multi-mode gateway platform in area B using the NTRU quantum-resistant algorithm. The attack detection module monitors the channel's quantum bit error rate in real time. When quantum entanglement eavesdropping characteristics are detected, the key update module is immediately forced to switch to the CRYSTALS-Kyber algorithm and discard the historical key. This process ensures the spatiotemporal consistency of key updates and area switching through a cross-domain key anchoring mechanism, preventing unauthorized command injection. In other embodiments, when the train is running across operator network boundaries, the quantum-secure IPSec tunnel module of the zero-trust transmission channel uses a third quantum key to encrypt onboard video stream data, attaching an integrity check value generated by a quantum random number to each data packet. The quantum-resistant key update module dynamically calculates the key lifecycle based on the data transmission volume, and seamlessly rotates the key with the multi-mode gateway platform through the SIKE quantum-resistant protocol when a threshold is reached. The attack detection module simultaneously analyzes network traffic patterns and quantum channel characteristics. When it identifies Shor's algorithm attack characteristics, it immediately triggers the key update module to activate a multi-dimensional algorithm nesting mode. This mechanism, through a forward-secure key chain design, cryptographically isolates the new key from the historical key, completely blocking any backtracking or cracking paths.

[0033] In this way, the quantum-secure IPSec tunnel module encrypts transmitted data based on a third quantum key (i.e., the session key), inheriting the dual-source fusion characteristic of this key to ensure end-to-end confidentiality of cross-domain data. The quantum-resistant key update module periodically updates the third quantum key through a quantum-resistant key exchange protocol, breaking the time-limited limitations of traditional static keys and reducing the risk of long-term keys being brute-forced. The attack detection module monitors the channel status in real time and immediately triggers the key update module to switch to a quantum-resistant algorithm (such as ML-KEM-512) when quantum computing attack characteristics are identified, achieving proactive defense switching under attack conditions. Through the coordinated work of these three modules, system stagnation caused by key exhaustion is avoided through periodic key updates, and the quantum-resistant algorithm can be quickly activated to strengthen the key negotiation process when a quantum attack first appears, thereby maintaining a high-strength secure transmission state in complex network environments.

[0034] In an optional embodiment of this application, the quantum-safe wireless communication device includes: a service data receiving and processing module, an encryption module, and a communication module. The service data receiving and processing module includes a service data communication board and an on-board safety core board, used to receive and process service data to obtain first service data. The encryption module is connected to the on-board safety core board via the quantum-safe core board, used to receive the first service data and use a third quantum key generated by the quantum-safe core board to perform an encryption operation on the first service data, generating ciphertext data. The communication module is connected to the encryption module, used to transmit the ciphertext data to a multi-mode gateway platform via a quantum-safe channel. When the encryption module fails, the first service data is transmitted to the trackless vehicle project maintenance platform.

[0035] In this embodiment, the business data receiving and processing module acquires raw business data such as traction motor temperature and current via the vehicle-mounted CAN bus. The business data communication board performs data cleaning and timestamp alignment, and the vehicle-mounted safety core board performs data normalization to generate standard-format first business data. The encryption module receives the first business data via a high-speed data interface, calls the third quantum key generated in real-time by the quantum safety core board, and uses a segmented dynamic encryption mechanism to encrypt the data packet in segments, generating ciphertext data with a quantum random number check factor. The communication module transmits the ciphertext data to the multi-mode gateway platform via a dual-band redundant link. When a hardware failure of the encryption module is detected, the secure channel switching unit immediately activates to directly transmit the unencrypted first business data to the trackless vehicle project maintenance platform, and adds a fault status identifier to the data packet header. In other embodiments, the business data receiving and processing module receives hydraulic pressure sensor signals from the brake control unit. After the business data communication board filters outliers, the vehicle-mounted safety core board fuses multi-sensor data to generate first business data with an integrity signature. The encryption module acquires data via a dedicated encryption bus and uses a parallel quantum encryption channel to call a third quantum key for real-time encryption. Simultaneously, it generates a quantum key and binds the ciphertext data using audit logs. The communication module transmits the ciphertext via an anti-interference frequency-hopping link. When the encryption module fails due to electromagnetic interference, the priority routing unit automatically classifies and marks the first service data as an emergency flow, directly transmitting it to the maintenance platform via an independent physical channel and triggering an audible and visual alarm.

[0036] Thus, the service data receiving and processing module in the quantum-safe wireless communication device includes a service data communication board and an on-board safety core board. It receives and processes service data to obtain the first service data, providing processed foundational data for subsequent encryption operations and ensuring the data's compliance before entering the encryption stage. The encryption module connects to the on-board safety core board via the quantum-safe core board. After receiving the first service data, it uses the third quantum key generated by the quantum-safe core board to encrypt and generate ciphertext data. Because the third quantum key has high security, it enhances the confidentiality of the encrypted data and reduces the risk of data decryption. The communication module connects to the encryption module and transmits the ciphertext data to the multi-mode gateway platform through a quantum-safe channel. The security characteristics of the quantum-safe channel further ensure the security of the ciphertext data during transmission. Furthermore, in the event of a failure in the encryption module, the first service data is transmitted to the trackless vehicle project maintenance platform, preventing data transmission interruption due to encryption module failure, ensuring data transmission continuity, facilitating timely fault detection and handling by maintenance personnel, and improving the system's reliability and fault tolerance.

[0037] In an optional embodiment of this application, the quantum-safe wireless communication device further includes a power module and an energy storage module. The power module supplies power to the service data receiving and processing module, the encryption module, and the communication module. The energy storage module supplies power to the service data receiving and processing module, the encryption module, and the communication module when the power module is powered off.

[0038] In this embodiment, the power module KE1 adopts a wide-voltage input design to adapt to fluctuations in the locomotive power grid and eliminates electromagnetic interference from the traction system through a multi-stage filtering unit. The energy storage module has a built-in supercapacitor array and intelligent switching circuit. When the train passes through a power-deprived area, causing a power outage in the power module, the voltage disturbance sensing algorithm is automatically activated to seamlessly take over the power supply. This algorithm monitors the power ripple characteristics in real time and pre-starts the energy storage module before the voltage drops, enabling the business data receiving and processing module to continuously collect track status data, the encryption module to maintain its quantum key generation capability, and the communication module to complete the final encrypted packet transmission. After power is restored, the energy storage module is intelligently charged using bidirectional pulse repair technology to eliminate deep discharge damage. In other embodiments, the power module can integrate a low-temperature heating unit to prevent electrolyte freezing, and the energy storage module uses a lithium iron battery pack wrapped with phase change material. When the external power supply to the carriage is interrupted in high-altitude and cold regions, the energy storage module activates a low-temperature self-activation heating mode, releasing latent heat through the internal phase change material to maintain the chemical activity of the battery. At the same time, the zoned power supply management unit prioritizes the operation of the encryption module and the communication module. After the power module is restored, thermal shock is avoided by using stepped current sharing charging technology, and the battery health status is monitored in real time during the charging process. This ensures that the quantum safety core board can work continuously for more than two hours in low-temperature environments without losing critical business data.

[0039] In this way, the power module in the quantum-safe wireless communication device supplies power to the service data reception and processing module, encryption module, and communication module, providing continuous and stable power support for the normal operation of these modules and ensuring the smooth operation of data reception, processing, encryption, and transmission processes. Meanwhile, the energy storage module continues to supply power to the aforementioned modules when the power module loses power. This helps prevent modules from ceasing operation due to power interruptions, thereby reducing data transmission interruptions or loss, maintaining the continuity of system functions, and improving the reliability and fault tolerance of the quantum-safe wireless communication device in scenarios with unstable power supply.

[0040] In an optional embodiment of this application, the quantum-safe core board includes a main control module, a cryptographic module, and a secure storage module. The main control module includes a first interface, a second interface, and a third interface. The cryptographic module is connected to the main control module via the first interface, integrates a quantum random number chip, generates quantum random numbers based on the quantum random number chip, and performs data encryption / decryption and digital signature operations. The secure storage module is connected to the main control module via the second interface and is used to store quantum authentication certificates, a second quantum key, and a third quantum key. The third interface of the main control module is used to connect to external devices, including a communication module of a quantum-safe wireless communication device, a gateway module of a multi-mode gateway platform, and / or a live cryptographic service system.

[0041] In this embodiment, the main control module can connect to the quantum random number chip of the cryptographic module via a first interface. This chip generates entropy source-level random numbers in real time based on the photon quantum state collapse principle. The cryptographic module integrates a streaming encryption engine, which calls the quantum random number to execute the SM4 algorithm for encryption while receiving business data, completing the calculation in a single cycle and outputting the ciphertext. The secure storage module is directly connected to the main control module via a second interface, using physically cloning-free technology to store pre-filled quantum authentication certificates and a second quantum key. The key storage area is equipped with a dynamic key obfuscation layer to prevent side-channel attacks. The third interface of the main control module is connected to the vehicle communication module via a high-speed serial bus to establish a direct transmission channel for encrypted data, avoiding the risk of memory transfer. In other embodiments, the cryptographic module can receive scheduling instructions from the main control module via the first interface, and its quantum random number chip synchronously outputs a quantum entropy verification signal to the secure storage module when generating random numbers. The secure storage module is designed with a layered isolation architecture. The read-only area storing the quantum authentication certificate at the bottom layer uses fuse protection technology; the second quantum key storage area in the middle layer is equipped with a self-destruct circuit; and the third quantum key buffer area at the top layer implements a zeroing mechanism for each session. The main control module's third interface establishes a two-way authentication link with the cryptographic service system. When transmitting keys, it enables dynamic interface masquerading technology and randomly changes electrical characteristic parameters to resist probe attacks.

[0042] In this way, the main control module in the quantum-safe core board connects to the cryptographic module and the secure storage module via the first and second interfaces, respectively, and to external devices via the third interface. This facilitates information exchange between modules and with external devices, ensuring smooth data transmission and command delivery. The cryptographic module integrates a quantum random number chip. The quantum random numbers generated by this chip have high randomness and unpredictability. Using these as the basis for data encryption / decryption and digital signature operations helps improve the security of these cryptographic operations and reduces the risk of key cracking. The secure storage module is specifically used to store quantum authentication certificates, the second quantum key, and the third quantum key, providing a secure storage environment for this sensitive information and reducing the possibility of information leakage due to unauthorized access. The main control module connects to external devices such as the communication module of the quantum-safe wireless communication device, the gateway module of the multi-mode gateway platform, and the cryptographic service system via the third interface. This facilitates collaborative work between the core board and external devices, ensuring the effective implementation of key management, encrypted data transmission, and other processes, thus improving the reliability and practicality of the quantum-safe core board in ensuring communication security.

[0043] In an optional embodiment of this application, the cryptographic module further includes a national cryptographic algorithm unit, a quantum-resistant algorithm unit, and a key generation unit. The national cryptographic algorithm unit is configured with SM2, SM3, and SM4 algorithms. The SM2 algorithm is used to perform key negotiation, the SM3 algorithm is used to generate a data integrity check value, and the SM4 algorithm is used to perform symmetric encryption. The quantum-resistant algorithm unit is used to replace the national cryptographic algorithm unit in performing key negotiation and encryption operations when a quantum computing attack risk is detected. The key generation unit is connected to a quantum random number chip and is used to receive the initial quantum key transmitted by the quantum key distribution system, and generate a first quantum key, a second quantum key, and a third quantum key based on the initial quantum key and the random numbers generated by the quantum random number chip.

[0044] In this embodiment, the national cryptographic algorithm unit of the cryptographic module performs key negotiation between the vehicle and the control center using the SM2 algorithm under normal conditions, while simultaneously generating data integrity tags using SM3 and encrypting service data using SM4 to form a basic protection layer. The anti-quantum algorithm unit continuously monitors the channel's quantum noise characteristics. When the attack detection module identifies a lattice-based attack pattern, it immediately activates the algorithm switcher to take over the control flow, switching to the CRYSTALS-Dilithium algorithm to perform key negotiation and using FrodoKEM for data encryption. The key generation unit responds synchronously, performing layered confusion operations based on the true random number stream from the quantum random number chip and the initial quantum key to generate a new session key with forward security. This process achieves microsecond-level defense switching through real-time matching of attack signature databases. In other embodiments, after receiving the initial quantum key from the quantum key distribution system, the key generation unit calls the quantum random number chip to generate an entropy enhancement factor and generates a three-level key through a key tree derivation engine. The first quantum key serves as a temporary negotiation seed, the second quantum key is injected into a secure storage module for long-term storage, and the third quantum key is used exclusively for this session. When the national cryptographic algorithm unit transmits the first quantum key using the SM2 protocol, the quantum-resistant algorithm unit runs the NTRU algorithm in parallel as a shadow protection layer. When a quantum channel disturbance is detected, the dual-algorithm nesting mode is immediately activated, meaning the national cryptographic unit maintains business encryption while the quantum-resistant unit strengthens the key exchange process, and key layer isolation technology ensures the cryptographic independence of each level of key.

[0045] In this way, the national cryptographic algorithm unit is configured with SM2, SM3, and SM4 algorithms, providing conventional encryption capabilities that comply with national standards. The SM2 algorithm performs key negotiation to ensure basic communication security, the SM3 algorithm generates data integrity check values ​​to prevent information tampering, and the SM4 algorithm achieves efficient symmetric encryption. The quantum-resistant algorithm unit dynamically replaces the national cryptographic algorithm unit when a quantum computing attack risk is detected, establishing a future-oriented protection barrier through quantum-resistant cryptographic algorithms. The key generation unit integrates the initial quantum key provided by the quantum key distribution system with truly random numbers generated by a quantum random number chip to collaboratively generate the first, second, and third quantum keys. This architecture achieves smooth collaboration between classical and quantum-resistant cryptographic systems. Daily communication uses national cryptographic algorithms to ensure efficiency and compliance, while seamlessly switching to the quantum-resistant algorithm unit when faced with quantum attack threats. Simultaneously, the key generation process inherits the physical security of quantum key distribution and enhances the unpredictability of the key through the dynamic intervention of quantum random numbers, thus constructing a dual-strengthening mechanism at the algorithm and key layers, improving the system's flexibility in responding to diverse attack scenarios.

[0046] In an optional embodiment of this application, the quantum key distribution system includes a quantum key generation device, a key management device, and a quantum certificate generation device. The quantum key generation device generates an initial quantum key based on a preset quantum protocol. The key management device is connected to both the quantum key generation device and the quantum security core board, and receives the initial quantum key output by the quantum key generation device, verifies and stores the initial quantum key, and, according to instructions from the cryptographic service system, uses the verified initial quantum key as a second quantum key to fill the secure storage module of the quantum security core board. The quantum certificate generation device is connected to the key management device, and generates a quantum authentication certificate based on the initial quantum key generated by the quantum key generation device, and transmits the quantum authentication certificate to the secure storage module of the quantum security core board through the key management device.

[0047] In this embodiment, the quantum key generation device can be deployed along the urban rail fiber optic network, generating an initial quantum key based on the polarization coding BB84 protocol. After receiving the initial quantum key through a dedicated quantum channel, the key management device performs adaptive quantum error rate verification, dynamically adjusting the error correction threshold according to the real-time noise level of the fiber optic channel, retaining only the key segments that pass verification. The verified initial quantum key serves as the second quantum key and is transmitted to the secure storage module of the onboard quantum security core board via an opto-isolated charging channel. The quantum certificate generation device simultaneously acquires the initial quantum key, generates a digital certificate using quantum key fingerprint binding technology, and pairs and charges the certificate with the second quantum key through the key management device, achieving integrated secure storage of the key and certificate. In other embodiments, the quantum key generation device is installed at a base station along the rail line, transmitting the initial quantum key to the moving train via free-space laser transmission. When the key management device receives the key at the onboard end, it initiates a motion compensation verification algorithm to eliminate beam jitter errors caused by vehicle vibration. Before storing the verified initial quantum key as the second quantum key in the secure storage module, a key fragment shuffling and recombination operation is performed to scramble the original sequence structure. When generating a certificate based on the initial quantum key, the quantum certificate generation device embeds a geographic location tag and a base station identifier to form a spatially bound quantum authentication certificate. The certificate and the recombined second quantum key are simultaneously injected by the key management device to establish a key-certificate association system resistant to physical interception.

[0048] In this way, the quantum key generation device in the quantum key distribution system generates an initial quantum key based on a preset quantum protocol. This protocol provides a quantum-level security foundation for the initial quantum key, making it resistant to eavesdropping. The key management device connects to both the quantum key generation device and the quantum security core board. After receiving the initial quantum key, it verifies and stores it, ensuring its accuracy and security. Then, according to instructions from the cryptographic service system, it uses the verified initial quantum key as a second quantum key to fill the secure storage module of the quantum security core board, standardizing the key management and filling process and ensuring the reliability of key supply. The quantum certificate generation device generates a quantum authentication certificate based on the initial quantum key and transmits it to the secure storage module through the key management device. Combined with the security of the initial quantum key, the quantum authentication certificate enhances the credibility of identity authentication and confirms the legitimacy of both communicating parties. Through the collaborative work of these three devices, a complete chain is formed from initial key generation, verification, storage, filling to quantum certificate generation and transmission, improving the security and reliability of keys and certificates. This provides a solid key foundation and identity authentication guarantee for quantum-secure communication, ensuring the confidentiality and integrity of data transmission.

[0049] In the application embodiments, such as Figure 1As shown, in a specific embodiment of a quantum-secure wireless communication system applicable to rail transit, the system horizontally encompasses a subsidiary layer, a vehicle-to-ground transmission layer, and a ground control center layer, and vertically constructs a multi-layered quantum-secure communication system to resist quantum computing attacks. Subsidiary 1 (technology scenario) deploys Subsystem 1 and QKD equipment (quantum key generation equipment for quantum key distribution system). Subsidiary 2 (intelligent manufacturing scenario) and Subsidiary 3 (operation / maintenance system scenario) are respectively configured with Subsystem 2, Subsystem 3, and a quantum IPSec gateway (multi-mode gateway platform). The three are connected to the PHM center through a data transmission link, and the PHM center then interacts with the quantum IPSec gateway (multi-mode gateway platform). The vehicle-to-ground transmission layer deploys trackside APs along the track, which are connected to the onboard quantum-secure wireless communication device through a wireless network, supporting PQC post-quantum encryption channel, QKD key distribution channel, SM2+QRNG channel, etc. Multi-mode quantum secure channels, including QKD encrypted channels, single-photon key distribution channels, and unencrypted channels, are implemented to achieve secure transmission protocols based on public key infrastructure (PKI) and quantum random number generation technology (QRNG), key service protocols based on quantum key distribution systems, and quantum-resistant (PQC) key exchange protocols. The ground control center integrates QKD servers (key management devices for quantum key distribution systems), monitoring screens, CSP cryptographic service platforms, data management modules, switches (including wireless controllers and network management functions), zero-trust servers, and data storage services, and achieves internal interconnection and external communication through switches. The quantum-safe wireless communication device incorporates a quantum-safe core board. Within its secure storage module, the QKD system and the quantum CA system (quantum certificate generation device) collaboratively inject quantum keys (second quantum keys) and quantum CA certificates, ensuring the architecture is compatible with both quantum encryption and classical PKI encryption systems. The cryptographic service system (CSP platform) is responsible for channel-side key distribution. It authenticates the quantum-safe wireless communication device and the quantum IPSec gateway (multi-mode gateway platform) by calling the pre-injected quantum CA certificate. It negotiates and generates the first quantum key using the national cryptographic SM2 algorithm, and combines it with the pre-injected second quantum key to generate the third quantum key (session key). Both ends of the device use the third quantum key for symmetric encryption using the national cryptographic SM4 algorithm. The cryptographic module of the quantum-safe core board integrates a quantum random number chip (QRNG) and a quantum-resistant algorithm unit (supporting ML-KEM-512, Kyber-512, etc.), responsible for source-side key generation and data encryption. Its national cryptographic algorithm unit supports SM2 / SM3 / SM4 algorithms, forming a collaborative defense system of classical and quantum-resistant cryptography.In terms of key management, quantum keys are pre-charged through the QKD system, and the cryptographic service system monitors the key balance in the quantum-safe core board. When the balance falls below a threshold, quantum keys are replenished online using quantum random number generation technology. For cross-domain communication, the zero-trust server and the quantum IPSec gateway deploy a quantum-safe IPSec tunnel protocol (zero-trust transmission channel), incorporating a quantum-safe IPSec tunnel module, an anti-quantum key update module, and an attack detection module to ensure end-to-end transmission reliability. Vehicle business data is encrypted in layers by the quantum-safe core board (quantum-safe engine) and then transmitted by the communication module through a quantum-safe channel to the quantum IPSec gateway (multi-mode gateway platform) for decryption, preventing data leakage or tampering throughout the process and ensuring safe wireless communication for rail transit.

[0050] In the embodiments of this application, such as Figure 2 and Figure 3As shown, the hardware and software architecture of the quantum-safe wireless communication device collaboratively realizes the secure processing and transmission of vehicle data, and is compatible with the existing vehicle system. On the hardware side, the service data receiving and processing module includes a service data communication board and the existing vehicle core board (vehicle security core board). It connects to the quantum-safe board (quantum-safe core board, i.e., the encryption module) via UART, SPI, and I2C interfaces. It receives vehicle data and processes it into the first service data. When the encryption module malfunctions, this module directly transmits the first service data to the trackless vehicle project maintenance platform via the existing communication link. The encryption module operates based on the quantum-safe board (quantum-safe core board) and supports three authentication methods: quantum-safe PKI, quantum key distribution, and PQC key exchange. The authentication and key negotiation method involves receiving vehicle service data via an internal socket, encrypting it, and then transmitting it to the backend multi-mode quantum security gateway via the network module. The communication module integrates an NB-IoT module, a 5G / 4G module, a WIFI module, and a satellite module (including BeiDou positioning). It connects to the main control unit through a high-speed interface, and has a built-in signal processing unit to optimize communication quality. It supports mainstream cellular network frequency bands and automatic switching of network links. An external universal antenna interface adapts to multiple scenarios, and the encryption module protects service data during transmission. The power module supplies power to all modules, and the energy storage module seamlessly replenishes power during power outages to ensure continuous operation of the equipment. The software adopts a layered design: the application layer provides user-facing services such as encrypted transmission, authentication, protocol switching, transparent transmission, and comprehensive management; the quantum-safe protocol stack includes a quantum-resistant key exchange protocol, a PKI quantum-safe transmission protocol, a QKD quantum key service protocol, and a quantum-safe protocol record layer, achieving full lifecycle protection for authentication and key negotiation; the quantum-safe multi-mode service engine is responsible for protocol processing, X.509 certificate verification, quantum-resistant algorithm invocation, and QKD key management, and provides open interfaces for the quantum-safe core board, quantum key service SDK, and quantum-resistant cryptographic computation; the infrastructure layer provides network communication, internal board communication, and system resource management, relying on the quantum-safe core board, PQC algorithm library, secure storage, and key management to support underlying cryptographic computation. Each hardware module interacts loosely through standardized interfaces, supporting independent development, replacement, and reuse. When a module fails, only targeted maintenance is required, adapting to technological iterations and multi-scenario applications.

[0051] In this embodiment, the quantum security core board is based on a modular hardware architecture and is paired with a layered software architecture to achieve quantum-level security processing capabilities, with each layer's functions working in deep collaboration with the hardware modules. At the hardware level, the main control module adopts a high-performance multi-core processor and is connected to the cryptographic module (integrated with a quantum random number chip, certified by the State Cryptography Administration, supporting real-time generation of quantum-secure true random numbers), the secure storage module (configured with a large-capacity high-speed storage chip to store sensitive information such as system keys and quantum authentication certificates, and set with strict access control policies to prevent unauthorized access) and the interface module (supporting MiniPCI-E interface, complying with the "PCI Cryptographic Card Technical Specification" and the "GM / T0018-2012 Cryptographic Device Application Interface Specification", corresponding to the first, second, and third interfaces of the main control module, meeting the connection requirements with external devices) via a high-speed serial bus. It undertakes system control, protocol processing, key management, and high-speed data transmission between modules, ensuring the smooth operation of the operating system and applications. The cryptographic module, as the core computing unit, supports national cryptographic algorithms such as SM2, SM3, and SM4 and PQC algorithms, and can perform data encryption and decryption, digital signatures, and quantum key injection. Its key generation unit generates and updates various keys based on random numbers generated by the quantum random number chip and the initial quantum key. At the software architecture level, the management layer provides a command-line management interface based on the main control module, supporting user management, permission management, and key management (linked with key generation in the cryptographic module and key storage in the secure storage module); the data layer interfaces with the cryptographic and secure storage modules, responsible for key pair generation / update, key state storage, private key access control code setting, and digital signature (calling the national cryptographic algorithm and PQC algorithm of the cryptographic module and storing the results in the secure storage module); the platform support layer provides a unified access interface for hardware resources through the interface module, shielding underlying differences, reducing hardware module coupling, improving encryption operation performance, and working with the high-speed bus of the main control module to ensure high-reliability system operation, realizing efficient scheduling and secure management of hardware resources by the software.

[0052] In the embodiments of this application, such as Figure 4As shown, the QKD system is divided into a three-layer architecture: quantum security and business terminal, quantum security and business system, and QKD system. The quantum security and business terminal layer includes business terminals and quantum security terminals (encryption modules). The quantum security terminal has a built-in quantum security chip (integrated into the quantum security core board), which has SM2 / SM3 / SM4 algorithm capabilities and more than five true random number generators (containing quantum random number generation QRNG function, corresponding to the quantum random number chip in the cryptographic module). The business terminal and the quantum security terminal are connected via a wireless network. The quantum security terminal acts as a gateway integrating routing, switching, VPN, NAT, firewall, and quantum secure communication. It adopts a domestically developed hardware platform and software architecture, integrates quantum key distribution technology, and supports the SM commercial cryptographic algorithms released by the State Cryptography Administration. The IPSec VPN protocol based on quantum keys enables encrypted data transmission. The quantum security and business system layer deploys a high-speed QRNG module (providing support for quantum random number generation), a quantum CA server (quantum certificate generation device), a quantum key management server, a business application server, and a main station business platform. The random numbers generated by the high-speed QRNG module are used by the quantum CA server, which in turn uses the quantum root key to generate quantum authentication certificates (stored in the secure storage module of the quantum security core board). These certificates are then transmitted to quantum security terminals via a quantum certificate distribution mechanism, enabling quantum certificate authentication at each terminal to solve the identity authentication problem. The quantum key management server is responsible for receiving... The system integrates and manages the quantum key distribution (QKD) process. The QKD system layer comprises two quantum key distribution (QKD) units (quantum key generation devices, classified as single-sender (Type A) and single-receiver (Type B),) a switch, and a key system exchange cipher (key management device). The two QKD units are based on the decoy state BB84 protocol and employ polarization coding technology. They integrate quantum signal transmission or reception modules and key storage management modules, and are paired to form a point-to-point quantum key distribution network. They are connected to the key system exchange cipher through the switch. The key system exchange cipher has quantum key distribution control (managing the managed quantum key distribution terminals) and quantum key secure storage (receiving the initial output of the quantum key distribution QKDs). The system includes quantum key distribution, quantum key exchange (collaborating with the key distribution network management system to complete key relay), quantum key output (outputting keys to the secure storage module of the quantum security core board via the quantum key management server), standard cryptographic services (providing random number generation, encryption and decryption, etc.), and network management (for monitoring by the network management server). The key distribution network management system (cryptographic service system) serves as the quantum key business process control software, realizing quantum device management, key generation, and routing control. Its quantum network management agent software supports access management of devices such as quantum key generation terminals, and the key distribution network management system client software supports key generation control and relay routing control.During business data transmission, plaintext generated by the business terminal is first transmitted to the quantum-safe terminal (encryption module). The quantum-safe terminal uses the quantum key obtained from the QKD system to encrypt the plaintext, generating ciphertext, which is then transmitted back to the business network. After the ciphertext is transmitted to the receiving end via the business network, it is first transmitted to the peer quantum-safe terminal. The peer quantum-safe terminal uses a symmetric quantum key to decrypt the ciphertext back to plaintext and then transmits it back to the business terminal. Throughout the process, the quantum-safe terminal accesses the business network in a bypass mode, without changing the existing network structure or business scenario. The main station business platform and the business application server collaboratively process the decrypted business data, realizing quantum key distribution and quantum-safe data encryption transmission between the two points.

[0053] In practical applications, such as Figure 5-7As shown, the overall architecture of the QKD system is deployed at User Station 1 and User Station 2 to achieve end-to-end quantum-secure communication. At the service layer, User Station 1 deploys a service router, a quantum-secure encryption router (encryption module), a switch, and service terminals. User Station 2 also deploys the same service router, quantum-secure encryption router (encryption module), switch, and service terminals. The service routers of the two stations establish a data transmission channel (service network) via an IPSec tunnel for transmitting service data. Plaintext data generated by the service terminals of User Station 1 and User Station 2 is first transmitted via their respective service routers to their local quantum-secure encryption routers (encryption modules). This router, as the core device of the data encryption / decryption layer, uses a quantum key to encrypt the plaintext and generate ciphertext. The ciphertext is then transmitted back to the data transmission channel (service network) via the service router and transmitted to the peer user station via the IPSec tunnel. The ciphertext from the peer user station is first transmitted to its local quantum-secure encryption router (encryption module), which uses a symmetric quantum key to decrypt the ciphertext and generate plaintext, which is then transmitted back to the peer user station's service terminal. At the distribution layer, User 1 station deploys quantum key distribution equipment (receiving type, quantum key generation equipment), a key system exchange cryptographic machine (key management equipment), and a key distribution network management system server (cryptographic service system). User 2 station deploys quantum key distribution equipment (transmitting type, quantum key generation equipment). The quantum key distribution equipment (receiving type, quantum key generation equipment) and the quantum key distribution equipment (transmitting type, quantum key generation equipment) establish a quantum key distribution link through a quantum channel (including an optical fiber channel as the quantum key channel), generating an initial quantum key based on a preset quantum protocol. The key system exchange cryptographic machine (key management equipment) is connected to the quantum key distribution equipment. The receiver-type quantum key generation device connects to the quantum-safe encryption router (encryption module) at User 1 station, receives, verifies, and stores the initial quantum key. Following instructions from the key distribution network management system server (cryptographic service system), it fills the verified initial quantum key into the secure storage module of the quantum-safe core board built into the quantum-safe encryption router (encryption module). The key distribution network management system server (cryptographic service system) connects to the key system exchange cryptographic machine (key management device), the quantum key distribution device (receiver-type quantum key generation device), and the switch at User 1 station to manage and control the generation and routing of quantum keys within the system. The switches at User 1 station and User 2 station are connected via a classical channel (containing a quantum negotiation channel) for transmitting control information such as key negotiation. All devices at both stations are physically connected via network cables or optical fibers to ensure stable transmission of business data and quantum key-related information.

[0054] In practical applications, such as Figure 8As shown, the quantum-safe wireless communication device integrates a service data receiving module, a service data processing module, a communication module, an encryption module, and a quantum-safe protocol stack. The service data receiving module connects to dual PHY chips via an RGMII interface, constructing dual gigabit Ethernet interfaces (including one port and a reserved port). It also features an RS232 debug interface, one USB 2.0 port, and 485 and CAN industrial bus interfaces. Each interface connects to external devices via a 96P backplane connector, supporting high-speed Ethernet, debugging, peripheral interaction, and industrial control signal transmission and reception. The service data processing module uses an ARM-based RK3568 processor as the main controller, paired with LPDDR4 memory (2GB, providing high-speed data cache), EMMC memory (8GB), and an independent RTC real-time clock. It is powered by dual DC12VA and DC12VB power supplies via a 96P backplane connector, ensuring independent power supply design. Eight LEDs on the front panel indicate device status, and a single Beidou board is connected to a GPS antenna TNC via a UART interface to achieve satellite positioning. The communication module uses a 4G private network module, connected via a board... The system integrates a track-mounted device and a 4G antenna with N heads for cellular network access. Two SIM card slots support mobile network communication. The aforementioned satellite positioning unit and 4G private network module work together to adapt to remote device networking scenarios. The encryption module connects to the RK3568 via a PCIE interface, providing secure encryption for rail transit. It supports high-speed quantum random number generation and SM2 / SM4 national cryptographic algorithms for data encryption / decryption and authentication. The quantum security protocol stack defines a secure transmission protocol based on Public Key Infrastructure (PKI) and Quantum Random Number Generation (QRNG) technology, a key service protocol based on Quantum Key Distribution (QKD) networks, and a quantum-resistant (PQC) key exchange protocol. Its protocol messages have a fixed header containing the protocol version, message type, and length. The protocol data segment covers initializing the quantum key, connecting device detection, device authentication, obtaining the number of keys, the negotiation initiator's request to create a session key, key exchange, the receiver obtaining the session key, and cryptographic calculation, ensuring communication security.

[0055] The foregoing description and accompanying drawings fully illustrate embodiments of this application to enable those skilled in the art to practice them. Other embodiments may include structural and other changes. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of some embodiments may be included or substituted for parts and features of other embodiments. Embodiments of this application are not limited to the structures described above and shown in the accompanying drawings, and various modifications and changes may be made without departing from their scope. The scope of this application is limited only by the appended claims.

Claims

1. A quantum-safe wireless communication system, characterized in that, include: A quantum-safe wireless communication device is used to receive service data and encrypt the service data through a quantum-safe core board; A quantum key distribution system, connected to a quantum-safe core board, is used to provide an initial quantum key to the quantum-safe core board. A multi-mode gateway platform is used to receive encrypted data transmitted by a quantum-safe wireless communication device and decrypt the encrypted data; wherein, the quantum-safe core board includes: The main control module includes a first interface, a second interface, and a third interface; The cryptographic module connects to the main control module through the first interface and integrates an on-board quantum random number chip. The cryptographic module generates quantum random numbers based on the on-board quantum random number chip and performs data encryption / decryption and digital signature operations. The secure storage module, connected to the main control module via a second interface, is used to store the quantum authentication certificate, the second quantum key, and the third quantum key. The third interface of the main control module is used to connect to external devices, including the communication module of the quantum-safe wireless communication device, the gateway module of the multi-mode gateway platform, and / or the cryptographic service system. The cryptographic service system is connected to the quantum-safe core board, the quantum key distribution system, and the multi-mode gateway platform, respectively. It is used to authenticate the quantum-safe wireless communication device and the multi-mode gateway platform by calling the quantum authentication certificate pre-filled into the quantum-safe core board. After the authentication is successful, it generates a third quantum key for encrypted communication between the quantum-safe wireless communication device and the multi-mode gateway platform based on the first quantum key and the second quantum key. The cryptographic service system, based on a first preset algorithm, negotiates with the quantum-safe wireless communication device and the multi-mode gateway platform to generate a first quantum key; the second quantum key is pre-filled into the quantum-safe core board. When an external network attack is detected, the channel automatically switches to a quantum-resistant key exchange protocol, performs key renegotiation using the FrodoKEM-1344 algorithm, updates the transmission key, and discards historical session data. The entire process is driven by a protocol behavior feature analysis engine, which identifies channel threats in real time and triggers the optimal protocol switch.

2. The system according to claim 1, characterized in that, The cryptographic service system integrates quantum-resistant algorithms and pre-charges a second quantum key into the quantum secure core board through a quantum key distribution system; The cryptographic service system monitors the remaining amount of the second quantum key in the quantum-safe core board. When the remaining amount is lower than the preset security threshold, the cryptographic service system uses a random number generated by quantum random number generation technology to encrypt the initial quantum key, generate the second quantum key, and then injects the second quantum key into the quantum-safe core board.

3. The system according to claim 1, characterized in that, Data is transmitted between the quantum-safe wireless communication device and the multi-mode gateway platform through a quantum-safe channel established based on a multi-mode protocol; Among them, the multi-mode protocols include secure transmission protocols based on public key infrastructure and quantum random number generation technology, key service protocols based on quantum key distribution systems, and / or quantum-resistant key exchange protocols.

4. The system according to claim 3, characterized in that, In cross-domain communication, quantum-secure channels include zero-trust transmission channels; The zero-trust transmission channel includes a quantum-safe IPSec tunnel module, a quantum-resistant key update module, and an attack detection module. The quantum-safe IPSec tunnel module is used to encrypt transmitted data based on a third quantum key; the key update module is used to periodically update the third quantum key through a quantum-resistant key exchange protocol; and the attack detection module is used to detect quantum computing attacks and trigger the key update module to switch to a quantum-resistant algorithm.

5. The system according to claim 1, characterized in that, Quantum-safe wireless communication devices include: The business data receiving and processing module includes a business data communication board and an in-vehicle safety core board, which is used to receive and process business data to obtain the first business data; The encryption module is connected to the vehicle security core board through the quantum security core board. It is used to receive the first business data and call the third quantum key generated by the quantum security core board to perform encryption operation on the first business data to generate ciphertext data. The communication module, connected to the encryption module, is used to transmit encrypted data to the multi-mode gateway platform via a quantum-secure channel; in the event of a failure of the encryption module, the first service data is transmitted to the trackless vehicle project maintenance platform.

6. The system according to claim 5, characterized in that, Quantum-safe wireless communication devices also include: The power supply module provides power to the business data receiving and processing module, the encryption module, and the communication module. The energy storage module is used to supply power to the business data receiving and processing module, encryption module and communication module when the power module is powered off.

7. The system according to claim 1, characterized in that, The cryptographic module also includes: The national cryptographic algorithm unit is equipped with SM2, SM3 and SM4 algorithms. The SM2 algorithm is used to perform key negotiation, the SM3 algorithm is used to generate data integrity verification values, and the SM4 algorithm is used to perform symmetric encryption. A quantum-resistant algorithm unit is used to replace the national cryptographic algorithm unit in performing key negotiation and encryption operations when a risk of quantum computing attack is detected. The key generation unit, connected to the quantum random number chip, is used to receive the initial quantum key transmitted by the quantum key distribution system, and generate the first quantum key, the second quantum key, and the third quantum key based on the initial quantum key and the random number generated by the quantum random number chip.

8. The system according to any one of claims 1 to 7, characterized in that, Quantum key distribution systems include: A quantum key generation device for generating an initial quantum key based on a preset quantum protocol; The key management device is connected to the quantum key generation device and the quantum security core board respectively. It is used to receive the initial quantum key output by the quantum key generation device, verify and store the initial quantum key, and fill the secure storage module of the quantum security core board with the verified initial quantum key as the second quantum key according to the instructions of the cryptographic service system. The quantum certificate generation device, connected to the key management device, is used to generate a quantum authentication certificate based on the initial quantum key generated by the quantum key generation device, and then transmits the quantum authentication certificate to the secure storage module of the quantum security core board through the key management device.

Citation Information

Patent Citations

  • Digital certificate authentication method and system based on quantum key encryption

    CN118316742A

  • Quantum encryption communication method, device and equipment for rail transit signal system

    CN119316128A