Iot module quantum key charging method, system, device and medium

CN121077655BActive Publication Date: 2026-08-28中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511267833.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2026-08-28
Estimated Expiration
2045-09-05

AI Technical Summary

Technical Problem

这种操作流程在安全性方面存在明显缺陷,可能导致密钥泄露或被恶意篡改等安全隐患

Benefits of technology

[0054]本申请提供的物联网模组量子密钥充注方法、系统、设备及介质,在向物联网模组导入充注密钥的过程中,采用对称加密密钥对充注密钥进行加密,采用公钥对对称加密密钥进行加密,采用第一量子随机数对私钥进行加密,对第一量子随机数也进行加密,使得第一量子随机数、私钥、对称加密密钥和充注密钥在流转过程中始终以密文的形式存在,即使在充注软件中也不可能检测到明文,且第一量子随机数、私钥、对称加密密钥和充注密钥的导入过程完全由软件完成,不以任何形式导出充注软件和物联网模组,减少了密钥被篡改、窃取和泄露的风险,确保充注密钥的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077655B_ABST
    Figure CN121077655B_ABST
Patent Text Reader

Abstract

The application provides a kind of Internet of Things module quantum key filling method, system, equipment and medium, it is related to network security communication technical field.The method comprises: according to encryption key pair acquisition request, generate and import first encrypted random number, encrypted private key and public key to target Internet of Things module, so that target Internet of Things module is decrypted to obtain private key according to first encrypted random number and encrypted private key;According to symmetric encryption key acquisition request, generate and import the encrypted symmetric encryption key to target Internet of Things module, so that target Internet of Things module is decrypted to obtain symmetric encryption key according to private key to the encrypted symmetric encryption key;According to filling key acquisition request, generate and import the encrypted filling key to target Internet of Things module, so that target Internet of Things module is decrypted to obtain filling key according to symmetric encryption key to the encrypted filling key.The application can ensure the security of key in filling process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security communication technology, and more specifically, to a method, system, device, and medium for quantum key injection into an Internet of Things (IoT) module. Background Technology

[0002] In the field of quantum communication, the current common operating mode is offline pre-charged keys. This mode requires that key data be pre-transmitted by a cryptographic service device and securely stored in the target IoT module. During this transmission process, strict security measures must be taken to ensure the confidentiality and integrity of the keys and prevent any potential risks of theft or tampering.

[0003] However, it should be noted that the key filling process for current IoT modules lacks unified technical standards and specifications. In actual production, the common practice is to export the key file from the cryptographic machine and then import it into the IoT device. This process has significant security flaws and may lead to security risks such as key leakage or malicious tampering. Summary of the Invention

[0004] The purpose of this application is to address the shortcomings of the prior art by providing a method, system, device, and medium for quantum key injection into an Internet of Things (IoT) module, so as to ensure the security of the key during the injection process.

[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of this application are as follows:

[0006] In a first aspect, embodiments of this application provide a quantum key injection method for an Internet of Things (IoT) module, applied to a injection station node of a quantum key injection system. The quantum key injection system further includes: injection software and at least one IoT module. The injection software is used to connect the injection station node and the at least one IoT module. The method includes:

[0007] Based on the encryption key pair acquisition request sent by the charging software, a first encrypted random number, an encrypted private key, and a public key are generated and imported into the target IoT module through the charging software, so that the target IoT module can decrypt and obtain the private key based on the first encrypted random number and the encrypted private key;

[0008] Based on the symmetric encryption key acquisition request sent by the filling software, an encrypted symmetric encryption key is generated and imported into the target IoT module through the filling software, so that the target IoT module can decrypt the encrypted symmetric encryption key according to the private key to obtain the symmetric encryption key.

[0009] Based on the charging key acquisition request sent by the charging software, an encrypted charging key is generated and imported into the target IoT module through the charging software, so that the target IoT module can decrypt the encrypted charging key according to the symmetric encryption key to obtain the charging key.

[0010] Optionally, the step of generating a first encrypted random number, an encrypted private key, and a public key based on the encryption key pair acquisition request sent by the filling software includes:

[0011] Based on the encryption key pair acquisition request, a first quantum random number and a public-private key pair are generated. The encryption key pair acquisition request includes: the signature public key of the target IoT module. The signature public key of the target IoT module is obtained by the charging software sending a key charging request to the target IoT module.

[0012] The first quantum random number is encrypted using the signature public key to generate the first encrypted random number;

[0013] The private key in the public-private key pair is encrypted using the first quantum random number to generate the encrypted private key.

[0014] Optionally, generating the encrypted symmetric encryption key based on the symmetric encryption key acquisition request sent by the filling software includes:

[0015] Based on the symmetric encryption key acquisition request, a second quantum random number is generated;

[0016] The second quantum random number is encrypted using the public key to generate a second encrypted random number, wherein the encrypted symmetric encryption key is the second encrypted random number.

[0017] Optionally, generating an encrypted recharge key based on the recharge key acquisition request sent by the recharge software includes:

[0018] The filling key is generated according to the filling key acquisition request;

[0019] The filling key is encrypted using the symmetric encryption key to generate the encrypted filling key.

[0020] Secondly, embodiments of this application also provide a quantum key injection method for an Internet of Things (IoT) module, applied to a target IoT module in a quantum key injection system. The quantum key injection system further includes: injection software and injection station nodes. The injection software connects the injection station nodes and at least one IoT module. The method includes:

[0021] Based on the encryption key pair import instruction sent by the refilling software, a first encrypted random number, an encryption private key, and a public key are imported into the security chip. The refilling station node is used to generate the first encrypted random number, the encryption private key, and the public key according to the encryption key pair acquisition request sent by the refilling software.

[0022] Decrypt the first encrypted random number and the encrypted private key to generate a private key;

[0023] Based on the symmetric encryption key import instruction sent by the filling software, the encrypted symmetric encryption key is imported into the security chip. The filling station node is used to generate the encrypted symmetric encryption key according to the symmetric encryption key acquisition request sent by the filling software.

[0024] The encrypted symmetric encryption key is decrypted using the private key to generate a symmetric encryption key.

[0025] Based on the charging key import instruction sent by the charging software, the encrypted charging key is imported into the security chip. The charging station node is used to generate the encrypted charging key according to the charging key acquisition request sent by the charging software.

[0026] The symmetric encryption key is used to decrypt the encryption injection key to generate the injection key.

[0027] Optionally, the step of decrypting the first encrypted random number and the encrypted private key to generate a private key includes:

[0028] The first encrypted random number is decrypted using the signature private key to generate a first quantum random number. The first encrypted random number is generated by encrypting the first quantum random number using the signature public key of the target IoT module.

[0029] The encrypted private key is decrypted using the first quantum random number to generate the private key, wherein the encrypted private key is generated by encrypting the private key using the first quantum random number.

[0030] Optionally, after decrypting the encrypted symmetric encryption key using the private key to generate a symmetric encryption key, the method further includes:

[0031] If the encrypted symmetric encryption key is successfully decrypted using the private key, a verification result is sent to the refilling software to instruct the refilling software to send a request to the refilling station node to obtain the refilling key.

[0032] Thirdly, embodiments of this application provide an IoT module quantum key injection device, applied to an injection station node of a quantum key injection system. The quantum key injection system further includes: injection software and at least one IoT module. The injection software is used to connect the injection station node and the at least one IoT module. The device includes:

[0033] The key pair encryption module is used to generate, and import a first encrypted random number, an encrypted private key, and a public key into the target IoT module through the charging software according to the encryption key pair acquisition request sent by the charging software, so that the target IoT module can decrypt and obtain the private key according to the first encrypted random number and the encrypted private key;

[0034] The symmetric key encryption module is used to generate and import an encrypted symmetric encryption key into the target IoT module through the filling software according to the symmetric encryption key acquisition request sent by the filling software, so that the target IoT module can decrypt the encrypted symmetric encryption key according to the private key to obtain the symmetric encryption key.

[0035] The charging key encryption module is used to generate an encrypted charging key according to the charging key acquisition request sent by the charging software and import it into the target IoT module through the charging software, so that the target IoT module can decrypt the encrypted charging key according to the symmetric encryption key to obtain the charging key.

[0036] Optionally, the key pair encryption module is specifically configured to generate a first quantum random number and a public-private key pair according to the encryption key pair acquisition request. The encryption key pair acquisition request includes: the signature public key of the target IoT module, which is obtained by the charging software sending a key charging request to the target IoT module; encrypting the first quantum random number according to the signature public key to generate the first encrypted random number; and encrypting the private key in the public-private key pair according to the first quantum random number to generate the encrypted private key.

[0037] Optionally, the symmetric key encryption module is specifically used to generate a second quantum random number according to the symmetric encryption key acquisition request; and to encrypt the second quantum random number according to the public key to generate a second encrypted random number, wherein the encrypted symmetric encryption key is the second encrypted random number.

[0038] Optionally, the refill key encryption module is specifically used to generate the refill key according to the refill key acquisition request; and to encrypt the refill key according to the symmetric encryption key to generate the encrypted refill key.

[0039] Fourthly, this application also provides an IoT module quantum key injection device, applied to a target IoT module in a quantum key injection system. The quantum key injection system further includes: injection software and injection station nodes. The injection software connects the injection station nodes and at least one IoT module. The device includes:

[0040] The key pair import module is used to import a first encrypted random number, an encrypted private key, and a public key into the security chip based on the encryption key pair import instruction sent by the refilling software. The refilling station node is used to generate the first encrypted random number, the encryption private key, and the public key according to the encryption key pair acquisition request sent by the refilling software.

[0041] The private key decryption module is used to decrypt the first encrypted random number and the encrypted private key to generate a private key;

[0042] The symmetric key import module is used to import the encrypted symmetric encryption key into the security chip based on the symmetric encryption key import instruction sent by the filling software. The filling station node is used to generate the encrypted symmetric encryption key according to the symmetric encryption key acquisition request sent by the filling software.

[0043] The symmetric key decryption module is used to decrypt the encrypted symmetric encryption key according to the private key and generate a symmetric encryption key.

[0044] The recharge key import module is used to import an encrypted recharge key into the security chip based on the recharge key import instruction sent by the recharge software. The recharge station node is used to generate the encrypted recharge key according to the recharge key acquisition request sent by the recharge software.

[0045] The filling key decryption module is used to decrypt the encrypted filling key according to the symmetric encryption key to generate the filling key.

[0046] Optionally, the private key decryption module is specifically used to decrypt the first encrypted random number according to the signing private key to generate a first quantum random number, wherein the first encrypted random number is generated by encrypting the first quantum random number according to the signing public key of the target IoT module; and to decrypt the encrypted private key according to the first quantum random number to generate the private key, wherein the encrypted private key is generated by encrypting the private key using the first quantum random number.

[0047] Optionally, the device further includes:

[0048] The result sending module is used to send a verification result to the filling software if the encrypted symmetric encryption key is successfully decrypted according to the private key, so as to instruct the filling software to send a filling key acquisition request to the filling station node.

[0049] Fifthly, embodiments of this application also provide a quantum key injection system, the quantum key injection system comprising: an injection station node, injection software, and at least one Internet of Things (IoT) module, wherein the injection software is used to connect the injection station node and the at least one IoT module;

[0050] The refilling station node is configured to perform the method as described in any of the first aspects, and the IoT module is configured to perform the method as described in any of the second aspects, so that the refilling station node can refill the key to the IoT module through the refilling software.

[0051] Sixthly, embodiments of this application also provide an electronic device, including: a processor, a storage medium, and a bus, wherein the storage medium stores program instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the program instructions to perform the method as described in any of the first aspects, or the method as described in any of the second aspects.

[0052] In a seventh aspect, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the method as described in any of the first aspects, or the method as described in any of the second aspects.

[0053] The beneficial effects of this application are:

[0054] The method, system, device, and medium for quantum key injection into IoT modules provided in this application encrypt the injection key using a symmetric encryption key, encrypt the symmetric encryption key using a public key, encrypt the private key using a first quantum random number, and encrypt the first quantum random number itself. This ensures that the first quantum random number, private key, symmetric encryption key, and injection key always exist in ciphertext form during the transfer process, making it impossible to detect plaintext even in the injection software. Furthermore, the entire process of importing the first quantum random number, private key, symmetric encryption key, and injection key is completed by the software, without exporting the injection software or IoT module in any form. This reduces the risk of key tampering, theft, and leakage, ensuring the security of the injection key. Attached Figure Description

[0055] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 A system architecture diagram of the quantum key injection system provided in the embodiments of this application;

[0057] Figure 2 This is an architectural diagram of the security chip provided in an embodiment of this application;

[0058] Figure 3 A flowchart illustrating the quantum key injection method for IoT modules provided in this application embodiment. Figure 1 ;

[0059] Figure 4 A flowchart illustrating the quantum key injection method for IoT modules provided in this application embodiment. Figure 2 ;

[0060] Figure 5 An interactive schematic diagram of the quantum key injection method for an IoT module provided in this application embodiment;

[0061] Figure 6 A schematic diagram of the structure of the quantum key injection device for the Internet of Things module provided in this application embodiment. Figure 1 ;

[0062] Figure 7 A schematic diagram of the structure of the quantum key injection device for the Internet of Things module provided in this application embodiment. Figure 2 ;

[0063] Figure 8 A schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0064] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of this application, but not all embodiments.

[0065] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0066] Furthermore, the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Additionally, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0067] It should be noted that, where there is no conflict, the features in the embodiments of this application can be combined with each other.

[0068] To better understand the quantum key injection method for IoT modules provided in this solution, we will first introduce the quantum key injection system used in this method.

[0069] Figure 1 The system architecture diagram of the quantum key injection system provided in the embodiments of this application is as follows: Figure 1 As shown, the quantum key injection system includes: injection station nodes, injection software, and at least one Internet of Things (IoT) module. The injection software is used to connect the injection station nodes and at least one IoT module.

[0070] In this embodiment, the filling software and the filling station node can be deployed on the same electronic device or on different electronic devices; this embodiment does not impose any restrictions on this.

[0071] The key filling software is responsible for managing and coordinating the entire key filling process. It obtains keys by sending requests to filling station nodes and interacts with IoT modules to control the IoT modules to import keys into the security chip.

[0072] The refilling station node can be deployed with a random number generation module and a key generation module. The random number generation module is used to generate quantum random numbers, and the key generation module is used to generate keys using a preset key generation algorithm. The refilling station node can also use a preset encryption algorithm to encrypt the quantum random numbers and keys.

[0073] In some embodiments, such as Figure 1 As shown, the quantum key injection system may further include: a cryptographic service platform node, an injection station node connected to the cryptographic service platform node, a key generated by the key service platform node using a preset key generation algorithm, and the key provided to the injection station node.

[0074] The module fixture includes at least one IoT module, and each IoT module is connected to the filling software through a serial port on the module fixture.

[0075] The key-charging software can enumerate all serial port devices on the electronic device by calling the operating system API. For each enumerated serial port device, a new thread is created, and the thread attempts to open the serial port to determine if it is connected to an IoT module. Then, for each potentially connected serial port device, the software tries different baud rate settings to determine the baud rate at which a successful connection can be established. If the serial port can be opened and a connection is successfully established at the specified baud rate, then the connected IoT module is considered suitable for key charging. A user interface is provided on the electronic device to display the IoT modules that can be charged.

[0076] The filling software communicates with the filling station nodes using Hypertext Transfer Protocol Secure (HTTPS), and communicates with the IoT module using Attention Command (AT).

[0077] In some embodiments, each IoT module has a National Cryptographic Security Chip, which uses national cryptographic algorithms (SM series algorithms) certified by the State Cryptography Administration of China for data encryption, identity authentication and secure storage, and has a hardware-level anti-tampering design.

[0078] Figure 2 The architecture diagram of the security chip provided in the embodiments of this application is as follows: Figure 2 As shown, the security chip can be integrated inside the microcontroller unit (MCU), or the security chip can be integrated with the MCU on the same circuit board and communicate with the MCU through the on-chip bus. On-chip communication methods include, but are not limited to, the inter-integrated circuit (IIC) bus, serial port, etc. This embodiment does not limit this.

[0079] In some embodiments, the quantum key delivery system further includes: a network node, such as Figure 1 As shown, multiple network nodes constitute a quantum key distribution network, which are interconnected through a quantum network link control center to form a stable communication network. These nodes may be distributed in different geographical locations to realize cross-regional data transmission and resource sharing. Each network node corresponds to a cryptographic service platform node.

[0080] Based on the quantum key injection system provided in the above embodiments, the following describes the specific implementation of the quantum key injection method for IoT modules applied to injection station nodes.

[0081] Figure 3 A flowchart illustrating the quantum key injection method for IoT modules provided in this application embodiment. Figure 1 ,like Figure 3 As shown, the method may include:

[0082] S110. Based on the encryption key pair acquisition request sent by the charging software, generate and import a first encrypted random number, an encrypted private key, and a public key into the target IoT module through the charging software, so that the target IoT module can decrypt and obtain the private key based on the first encrypted random number and the encrypted private key.

[0083] In this embodiment, the user triggers a process of injecting a charging key into a target IoT module in at least one IoT module through charging software. The charging software sends a charging request instruction to the target IoT module and receives the response from the target IoT module to the charging request instruction. If the response to the charging request instruction indicates that the target IoT module accepts the charging of the charging key, the charging software sends an encryption key pair acquisition request to the charging station node.

[0084] The encryption key pair acquisition request is used to instruct the recharge station node to generate a public-private key pair, where the public key is used for encryption of the recharge station node and the private key is used for decryption of the target IoT module.

[0085] To ensure the security of injecting the charging key into the target IoT module, the charging station node encrypts the charging key using a symmetric encryption key and transmits it in ciphertext. During the transmission of the symmetric encryption key to the target IoT module, in order to prevent the symmetric encryption key from being stolen, the symmetric encryption key is encrypted using the public key, and the private key corresponding to the public key is also encrypted, so that the charging key, the symmetric encryption key, and the private key are all transmitted in ciphertext.

[0086] In some embodiments, the refilling station node generates a public-private key pair based on the encryption key pair acquisition request, encrypts the private key using a preset encryption method, generates an encrypted private key, and imports the encrypted private key and public key into the target IoT module through the refilling software. The target IoT module decrypts the encrypted private key using an encryption method corresponding to the preset encryption method to obtain the private key.

[0087] In other embodiments, the refill station node generates a first quantum random number and a public-private key pair based on the encryption key pair acquisition request, encrypts the private key using the first quantum random number, and generates an encrypted private key. In order to prevent the first quantum random number from being stolen and thus causing the encrypted private key and the encrypted refill key to be encrypted, the first quantum random number is also encrypted to generate a first encrypted random number.

[0088] The charging station node sends the first encrypted random number, the encrypted private key, and the public key to the charging software. The charging software sends an encrypted key pair import instruction to the target IoT module. The target IoT module imports the first encrypted random number, the encrypted private key, and the public key into the security chip based on the encrypted key pair import instruction. The security chip can first decrypt the first encrypted random number to generate a first quantum random number, and then decrypt the encrypted private key based on the first quantum random number to determine the private key.

[0089] S120. Based on the symmetric encryption key acquisition request sent by the charging software, generate and import the encrypted symmetric encryption key into the target IoT module through the charging software, so that the target IoT module can decrypt the encrypted symmetric encryption key according to the private key to obtain the symmetric encryption key.

[0090] In this embodiment, after receiving the successful import indication of the encryption key pair sent by the target IoT module, the charging software sends a symmetric encryption key acquisition request to the charging station node. The symmetric encryption key acquisition request is used to instruct the charging station node to generate a symmetric encryption key to encrypt the charging key. The symmetric encryption key is the same key used for encryption and decryption. The charging station node uses the symmetric encryption key to encrypt the charging key, and the security chip also uses the symmetric encryption key to decrypt the encrypted charging key.

[0091] To prevent the symmetric encryption key from being stolen during transmission, this scheme uses the public key generated in S110 to encrypt the symmetric encryption key, thus generating the encrypted symmetric encryption key. Since the private key has already been imported into the security chip of the target IoT module, after the encrypted symmetric encryption key is imported into the security chip of the target IoT module, it can be decrypted using the private key to obtain the symmetric encryption key.

[0092] S130. Based on the charging key acquisition request sent by the charging software, generate and import an encrypted charging key into the target IoT module through the charging software, so that the target IoT module can decrypt the encrypted charging key according to the symmetric encryption key to obtain the charging key.

[0093] In this embodiment, after receiving a successful symmetric encryption key import indication from the target IoT module, the charging software sends a charging key acquisition request to the charging station node. The charging key acquisition request is used to instruct the charging station node to generate a charging key, which is the key ultimately used by the security chip for encryption, authentication, etc.

[0094] As described above, to prevent the charging key from being stolen, this solution uses the symmetric encryption key generated in S120 to encrypt the charging key, generating an encrypted charging key. Since the symmetric encryption key has already been imported into the security chip of the target IoT module, after importing the encrypted charging key into the security chip of the target IoT module, the encrypted charging key can be decrypted using the symmetric encryption key to obtain the charging key.

[0095] The quantum key injection method for IoT modules provided in the above embodiments encrypts the injection key using a symmetric encryption key, encrypts the symmetric encryption key using a public key, encrypts the private key using a first quantum random number, and also encrypts the first quantum random number itself. This ensures that the first quantum random number, private key, symmetric encryption key, and injection key always exist in ciphertext form during the transfer process, making it impossible to detect plaintext even in the injection software. Furthermore, the import process of the first quantum random number, private key, symmetric encryption key, and injection key is entirely completed by the software, without exporting the injection software or IoT module in any form. This reduces the risk of key tampering, theft, and leakage, ensuring the security of the injection key.

[0096] In one possible implementation, the process of generating a first encrypted random number, an encrypted private key, and a public key based on the encryption key pair acquisition request sent by the filling software in step S110 may include:

[0097] Based on the encryption key pair acquisition request, a first quantum random number and a public-private key pair are generated. The encryption key pair acquisition request includes: the signature public key of the target IoT module, which is obtained by the injection software sending a key injection request to the target IoT module; the first quantum random number is encrypted based on the signature public key to generate a first encrypted random number; the private key in the public-private key pair is encrypted based on the first quantum random number to generate an encrypted private key.

[0098] In this embodiment, the user triggers a process of injecting a charging key into a target IoT module in at least one IoT module through charging software. The charging software sends a request charging command to the target IoT module and receives the identification information ID of the security chip on the target IoT module and the signature public key Sign-pub of the security chip returned by the target IoT module in response to the request charging command.

[0099] The filling software sends an encryption key pair retrieval request to the filling station node based on the security chip's identification information ID and the security chip's signature public key Sign-pub. The encryption key pair retrieval request includes the security chip's identification information ID and the security chip's signature public key Sign-pub.

[0100] The recharge station node generates a first quantum random number Ka and a public-private key pair En-pub and En-pri based on the encryption key pair acquisition request. It uses the signature public key Sign-pub to encrypt the first quantum random number Ka using a preset encryption method to generate a first encrypted random number Sign-pub(Ka). It uses the first quantum random number Ka to encrypt the private key En-pri using a preset encryption method to generate an encrypted private key Ka(En-pri).

[0101] The IoT module quantum key injection method provided in the above embodiments uses a first quantum random number to encrypt the private key and the signature public key of the target IoT module to encrypt the first quantum random number, so that the first quantum random number and the private key always exist in ciphertext form during transmission, avoiding the theft or tampering of the first quantum random number and the private key, and ensuring the security of the injection key.

[0102] In one possible implementation, the process of generating the encrypted symmetric encryption key in step S120 based on the symmetric encryption key acquisition request sent by the filling software may include:

[0103] Based on the symmetric encryption key acquisition request, a second quantum random number is generated; the second quantum random number is encrypted using the public key to generate a second encrypted random number, and the encrypted symmetric encryption key is the second encrypted random number.

[0104] In this embodiment, after receiving the successful import indication of the encryption key pair sent by the target IoT module, the charging software sends a symmetric encryption key acquisition request to the charging station node. The charging station node generates a second quantum random number Kb, which is used as the symmetric encryption key. The second quantum random number Kb is encrypted using the public key En-pub to generate a second encrypted random number En-pub(Kb), which is used as the encrypted symmetric encryption key.

[0105] The IoT module quantum key injection method provided in the above embodiments uses a public key to encrypt the second quantum random number, so that the second quantum random number always exists in ciphertext form during transmission, preventing the second quantum random number from being stolen or tampered with, and ensuring the security of the injection key.

[0106] In one possible implementation, the process of generating an encrypted charging key based on the charging key acquisition request sent by the charging software in step S130 may include:

[0107] Generate a charging key based on the charging key acquisition request; encrypt the charging key using a symmetric encryption key to generate an encrypted charging key.

[0108] In this embodiment, after receiving the symmetric encryption key import success indication sent by the target IoT module, the charging software sends a charging key acquisition request to the charging station node. The charging station node generates a charging key Key based on the charging key acquisition request. Specifically, it can be generated using a preset key generation algorithm, or it can be obtained by decryption through a cryptographic service platform. This embodiment does not impose any restrictions on this.

[0109] After obtaining the charging key Key, the charging station node encrypts the charging key Key using a symmetric encryption key. In some embodiments, the symmetric encryption key is a second quantum random number Kb. The charging key Key is encrypted using the second quantum random number Kb to generate an encrypted charging key Kb(Key).

[0110] The quantum key injection method for IoT modules provided in the above embodiments uses a symmetric encryption key to encrypt the injection key, so that the injection key always exists in ciphertext form during transmission, preventing the injection key from being stolen or tampered with, and ensuring the security of the injection key.

[0111] The following describes the specific implementation of the quantum key injection method for IoT modules, applied to IoT modules, with reference to specific embodiments.

[0112] Figure 4 A flowchart illustrating the quantum key injection method for IoT modules provided in this application embodiment. Figure 2 ,like Figure 4 As shown, the method may include:

[0113] S210. Based on the encryption key pair import instruction sent by the refilling software, the first encrypted random number, encryption private key and public key are imported into the security chip. The refilling station node is used to generate the first encrypted random number, encryption private key and public key according to the encryption key pair acquisition request sent by the refilling software.

[0114] In this embodiment, the filling station node generates a first encrypted random number Sign-pub(Ka), an encrypted private key Ka(En-pri), and a public key En-pub in the manner described in S110 above, and sends them to the filling software.

[0115] The filling software sends an encrypted key pair import command to the target IoT module. The target IoT module converts the first encrypted random number Sign-pub(Ka), the encrypted private key Ka(En-pri), and the public key En-pub into a digital envelope format and imports them into the security chip using the SKF_ImportECCKeyPair interface. For details, please refer to GM / T 0016-2012 Smart Cryptographic Key Application Interface Specification.

[0116] S220. Decrypt the first encrypted random number and the encrypted private key to generate a private key.

[0117] In this embodiment, the security chip encrypts the first encrypted random number Sign-pub(Ka) to generate a first quantum random number Ka, and uses the first quantum random number Ka to decrypt the encrypted private key Ka(En-pri) to generate the private key En-pri.

[0118] In some embodiments, the process of decrypting the first encrypted random number and the encrypted private key in step S220 to generate a private key may include:

[0119] The first encrypted random number is decrypted using the signature private key to generate a first quantum random number. The first encrypted random number is generated by encrypting the first quantum random number using the signature public key of the target IoT module. The encrypted private key is then decrypted using the first quantum random number to generate a private key. The encrypted private key is generated by encrypting the private key using the first quantum random number.

[0120] In this embodiment, the first encrypted random number Sign-pub(Ka) is decrypted using the signature private key corresponding to the signature public key of the security chip to generate a first quantum random number Ka. The first quantum random number Ka is then used to decrypt the encrypted private key Ka(En-pri) to generate the private key En-pri.

[0121] S230. Based on the symmetric encryption key import instruction sent by the filling software, the encrypted symmetric encryption key is imported into the security chip. The filling station node is used to generate the encrypted symmetric encryption key according to the symmetric encryption key acquisition request sent by the filling software.

[0122] In this embodiment, the filling station node generates an encrypted symmetric encryption key in the manner described in S120 above, and sends it to the filling software.

[0123] The charging software sends a symmetric encryption key import command to the target IoT module. The target IoT module converts the encrypted symmetric encryption key into a digital envelope format and imports it into the security chip using the SKF_ImportSessionKey interface.

[0124] S240. Decrypt the encrypted symmetric encryption key using the private key to generate a symmetric encryption key.

[0125] In this embodiment, the security chip decrypts the encrypted symmetric encryption key using the private key En-pri obtained from the decryption in S220 above, and obtains the symmetric encryption key.

[0126] In some embodiments, the encrypted symmetric encryption key is a second encrypted random number En-pub(Kb), and the second encrypted random number En-pub(Kb) is decrypted using a private key to obtain a second quantum random number Kb as the symmetric encryption key.

[0127] In some embodiments, after decrypting the encrypted symmetric encryption key using the private key in step S240 to generate a symmetric encryption key, the method may further include:

[0128] If the encrypted symmetric encryption key is successfully decrypted using the private key, a verification result is sent to the refilling software to instruct the refilling software to send a refilling key retrieval request to the refilling station node.

[0129] In this embodiment, to prevent the symmetric encryption key from being tampered with during transmission, the private key is used to decrypt the encrypted symmetric encryption key. If decryption is successful, it is determined that the symmetric encryption key has not been tampered with, and a verification result is sent to the filling software to instruct the filling software to send a filling key acquisition request to the filling station node to obtain the encrypted filling key. If decryption fails, it is determined that the symmetric encryption key has been tampered with, and the first quantum random number, public-private key pair, and encrypted symmetric encryption key are discarded, and the key is reacquired.

[0130] S250: Based on the charging key import instruction sent by the charging software, the encrypted charging key is imported into the security chip. The charging station node is used to generate the encrypted charging key according to the charging key acquisition request sent by the charging software.

[0131] In this embodiment, the filling station node generates an encrypted filling key in the manner described in S130 above and sends it to the filling software.

[0132] The charging software sends a charging key import command to the target IoT module, and the target IoT module calls the SKF_WriteFile interface to import the encrypted charging key into the security chip.

[0133] S260. Decrypt the encrypted injection key using the symmetric encryption key to generate the injection key.

[0134] In this embodiment, the security chip decrypts the encryption key using the symmetric encryption key obtained from the decryption in S240 above, and obtains the injection key.

[0135] In some embodiments, the symmetric encryption key is a second quantum random number Kb, and the encryption filling key Kb(Key) is decrypted using the second quantum random number Kb to generate the filling key Key.

[0136] The quantum key injection method for IoT modules provided in the above embodiments encrypts the first quantum random number, private key, symmetric encryption key, and injection key imported into the IoT module. This ensures that the first quantum random number, private key, symmetric encryption key, and injection key always exist in ciphertext form during the transfer process, making it impossible to detect plaintext even in the injection software. Furthermore, the import process of the first quantum random number, private key, symmetric encryption key, and injection key is entirely completed by software, without exporting the injection software or IoT module in any form. This reduces the risk of key tampering, theft, and leakage, ensuring the security of the injection key.

[0137] Figure 5 This is an interactive schematic diagram of the quantum key injection method for an IoT module provided in an embodiment of this application, as shown below. Figure 5 As shown, the quantum key injection process for an IoT module may include:

[0138] S310: The charging software sends a charging request command to the IoT module. The charging request command is an AT command.

[0139] The S320 IoT module returns the security chip's ID and signature public key (Sign-pub) to the filling software.

[0140] The S330 and the filling software send an encryption key pair acquisition request to the filling station node, carrying the security chip ID and the signature public key Sign-pub.

[0141] S340, the charging station node generates a first quantum random number Ka, a public-private key pair En-pub, and En-pri, encrypts the first quantum random number Ka and the public-private key pair En-pub, and generates a first encrypted random number Sign-pub(Ka) and an encrypted private key Ka(En-pri).

[0142] S350, the filling station node returns the first encrypted random number Sign-pub(Ka), the encrypted private key Ka(En-pri), and the public key En-pub to the filling software.

[0143] The S360 and the charging software send an encryption key pair import command to the IoT module, carrying the first encrypted random number Sign-pub (Ka), the encrypted private key Ka (En-pri), and the public key En-pub. The encryption key pair import command is an AT command.

[0144] The S370 IoT module sends a message to the filling software indicating that the imported encryption key pair has been successfully imported.

[0145] S380, the filling software sends a symmetric encryption key acquisition request to the filling station node.

[0146] S390. The charging station node generates a second quantum random number Kb and encrypts the second quantum random number Kb using the public key to generate a second encrypted random number En-pub(Kb).

[0147] S400, the filling station node returns a second encrypted random number En-pub(Kb) to the filling software.

[0148] S410, the charging software sends a symmetric encryption key import command to the IoT module, carrying a second encrypted random number En-pub(Kb). The symmetric encryption key import command is an AT command.

[0149] The S420 IoT module decrypts the second encrypted random number En-pub(Kb) and confirms successful decryption.

[0150] The S430 and IoT module send a verification result to the filling software, indicating that the second encrypted random number En-pub(Kb) has been successfully decrypted.

[0151] S440, the filling software sends a filling key acquisition request to the filling station node.

[0152] S450, the filling station node sends the encrypted filling key Kb(Key) to the filling software.

[0153] The S460 charging software sends a charging key import command to the IoT module, carrying the encrypted charging key Kb(Key). The charging key import command is an AT command.

[0154] S470: Write the encrypted charging key Kb (Key) to the security chip.

[0155] The S480 and IoT modules send the filling results to the filling software.

[0156] Based on the above method embodiments, this application provides an IoT module quantum key injection device, which is applied to the injection station node of a quantum key injection system. The quantum key injection system further includes: injection software and at least one IoT module. The injection software is used to connect the injection station node and at least one IoT module. Figure 6 A schematic diagram of the structure of the quantum key injection device for the Internet of Things module provided in this application embodiment. Figure 1 ,like Figure 6 As shown, the device may include:

[0157] The key pair encryption module 510 is used to generate, and import a first encrypted random number, an encrypted private key and a public key into the target IoT module through the encryption key pair acquisition request sent by the filling software, so that the target IoT module can decrypt and obtain the private key based on the first encrypted random number and the encrypted private key.

[0158] The symmetric key encryption module 520 is used to generate and import the encrypted symmetric encryption key into the target IoT module through the filling software according to the symmetric encryption key acquisition request sent by the filling software, so that the target IoT module can decrypt the encrypted symmetric encryption key according to the private key to obtain the symmetric encryption key.

[0159] The charging key encryption module 530 is used to generate and import an encrypted charging key into the target IoT module through the charging software according to the charging key acquisition request sent by the charging software, so that the target IoT module can decrypt the encrypted charging key according to the symmetric encryption key to obtain the charging key.

[0160] Optionally, the key pair encryption module 510 is specifically used to generate a first quantum random number and a public-private key pair according to the encryption key pair acquisition request. The encryption key pair acquisition request includes: the signature public key of the target IoT module, which is obtained by the injection software sending a key injection request to the target IoT module; encrypting the first quantum random number according to the signature public key to generate a first encrypted random number; and encrypting the private key in the public-private key pair according to the first quantum random number to generate an encrypted private key.

[0161] Optionally, the symmetric key encryption module 520 is specifically used to generate a second quantum random number according to the symmetric encryption key acquisition request; encrypt the second quantum random number according to the public key to generate a second encrypted random number, wherein the encrypted symmetric encryption key is the second encrypted random number.

[0162] Optionally, the filling key encryption module 530 is specifically used to generate a filling key according to the filling key acquisition request; and to encrypt the filling key according to the symmetric encryption key to generate an encrypted filling key.

[0163] Based on the above method embodiments, this application embodiment also provides an IoT module quantum key injection device, which is applied to a target IoT module in a quantum key injection system. The quantum key injection system further includes: injection software and injection station nodes, wherein the injection software connects the injection station nodes and at least one IoT module. Figure 7 A schematic diagram of the structure of the quantum key injection device for the Internet of Things module provided in this application embodiment. Figure 2 ,like Figure 7 As shown, the device may include:

[0164] The key pair import module 610 is used to import a first encrypted random number, an encrypted private key, and a public key into the security chip based on the encryption key pair import instruction sent by the refilling software. The refilling station node is used to generate the first encrypted random number, an encrypted private key, and a public key according to the encryption key pair acquisition request sent by the refilling software.

[0165] The private key decryption module 620 is used to decrypt the first encrypted random number and the encrypted private key to generate a private key;

[0166] The symmetric key import module 630 is used to import the encrypted symmetric encryption key into the security chip based on the symmetric encryption key import instruction sent by the filling software. The filling station node is used to generate the encrypted symmetric encryption key according to the symmetric encryption key acquisition request sent by the filling software.

[0167] The symmetric key decryption module 640 is used to decrypt the encrypted symmetric encryption key based on the private key and generate a symmetric encryption key.

[0168] The charging key import module 650 is used to import the encrypted charging key into the security chip based on the charging key import instruction sent by the charging software. The charging station node is used to generate the encrypted charging key according to the charging key acquisition request sent by the charging software.

[0169] The filling key decryption module 660 is used to decrypt the encrypted filling key based on the symmetric encryption key and generate a filling key.

[0170] Optionally, the private key decryption module 620 is specifically used to decrypt the first encrypted random number according to the signing private key to generate a first quantum random number, wherein the first encrypted random number is generated by encrypting the first quantum random number according to the signing public key of the target IoT module; and to decrypt the encrypted private key according to the first quantum random number to generate a private key, wherein the encrypted private key is generated by encrypting the private key using the first quantum random number.

[0171] Optionally, the device may further include:

[0172] The result sending module is used to send a verification result to the filling software if the encrypted symmetric encryption key is successfully decrypted according to the private key, so as to instruct the filling software to send a filling key acquisition request to the filling station node.

[0173] The above-described device is used to execute the method provided in the foregoing embodiments, and its implementation principle and technical effect are similar, so they will not be described again here.

[0174] These modules can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more microprocessors, or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together as a system-on-a-chip (SOC).

[0175] Figure 8 A schematic diagram of the electronic device provided in the embodiments of this application, such as... Figure 8 As shown, the electronic device 700 may include a processor 710, a storage medium 720, and a bus. The storage medium 720 stores program instructions executable by the processor 710. When the electronic device 700 is running, the processor 710 communicates with the storage medium 720 via the bus, and the processor 710 executes the program instructions to perform the above-described method embodiment. The specific implementation and technical effects are similar and will not be described in detail here.

[0176] Optionally, this application also provides a computer-readable storage medium storing a computer program, which is executed by a processor to perform the above-described method embodiments.

[0177] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0178] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0179] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units.

[0180] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0181] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A quantum key injection method for an Internet of Things (IoT) module, characterized in that, A charging station node is applied to a quantum key injection system, the quantum key injection system further comprising: charging software and at least one Internet of Things (IoT) module, the charging software being used to connect the charging station node and the at least one IoT module, the method comprising: Based on the encryption key pair acquisition request sent by the charging software, a first encrypted random number, an encrypted private key, and a public key are generated and imported into the target IoT module through the charging software, so that the target IoT module can decrypt and obtain the private key based on the first encrypted random number and the encrypted private key; Based on the symmetric encryption key acquisition request sent by the filling software, an encrypted symmetric encryption key is generated and imported into the target IoT module through the filling software, so that the target IoT module can decrypt the encrypted symmetric encryption key according to the private key to obtain the symmetric encryption key. Based on the charging key acquisition request sent by the charging software, an encrypted charging key is generated and imported into the target IoT module through the charging software, so that the target IoT module can decrypt the encrypted charging key according to the symmetric encryption key to obtain the charging key.

2. The method as described in claim 1, characterized in that, The step of generating a first encrypted random number, an encrypted private key, and a public key based on the encryption key pair acquisition request sent by the filling software includes: Based on the encryption key pair acquisition request, a first quantum random number and a public-private key pair are generated. The encryption key pair acquisition request includes: the signature public key of the target IoT module. The signature public key of the target IoT module is obtained by the charging software sending a key charging request to the target IoT module. The first quantum random number is encrypted using the signature public key to generate the first encrypted random number; The private key in the public-private key pair is encrypted using the first quantum random number to generate the encrypted private key.

3. The method as described in claim 1, characterized in that, The step of generating the encrypted symmetric encryption key based on the symmetric encryption key acquisition request sent by the filling software includes: Based on the symmetric encryption key acquisition request, a second quantum random number is generated; The second quantum random number is encrypted using the public key to generate a second encrypted random number, wherein the encrypted symmetric encryption key is the second encrypted random number.

4. The method as described in claim 1, characterized in that, The step of generating an encrypted charging key based on the charging key acquisition request sent by the charging software includes: Generate the filling key according to the filling key acquisition request; The filling key is encrypted using the symmetric encryption key to generate the encrypted filling key.

5. A quantum key injection method for an Internet of Things (IoT) module, characterized in that, A target IoT module is applied to a quantum key injection system, the quantum key injection system further comprising: injection software and an injection station node, the injection software connecting the injection station node and at least one IoT module, the method comprising: Based on the encryption key pair import instruction sent by the refilling software, a first encrypted random number, an encryption private key, and a public key are imported into the security chip. The refilling station node is used to generate the first encrypted random number, the encryption private key, and the public key according to the encryption key pair acquisition request sent by the refilling software. Decrypt the first encrypted random number and the encrypted private key to generate a private key; Based on the symmetric encryption key import instruction sent by the filling software, the encrypted symmetric encryption key is imported into the security chip. The filling station node is used to generate the encrypted symmetric encryption key according to the symmetric encryption key acquisition request sent by the filling software. The encrypted symmetric encryption key is decrypted using the private key to generate a symmetric encryption key. Based on the charging key import instruction sent by the charging software, the encrypted charging key is imported into the security chip. The charging station node is used to generate the encrypted charging key according to the charging key acquisition request sent by the charging software. The symmetric encryption key is used to decrypt the encryption injection key to generate the injection key.

6. The method as described in claim 5, characterized in that, The step of decrypting the first encrypted random number and the encrypted private key to generate a private key includes: The first encrypted random number is decrypted using the signature private key to generate a first quantum random number. The first encrypted random number is generated by encrypting the first quantum random number using the signature public key of the target IoT module. The encrypted private key is decrypted using the first quantum random number to generate the private key, wherein the encrypted private key is generated by encrypting the private key using the first quantum random number.

7. The method as described in claim 5, characterized in that, After decrypting the encrypted symmetric encryption key using the private key to generate a symmetric encryption key, the method further includes: If the encrypted symmetric encryption key is successfully decrypted using the private key, a verification result is sent to the refilling software to instruct the refilling software to send a request to the refilling station node to obtain the refilling key.

8. A quantum key injection system, characterized in that, The quantum key injection system includes: an injection station node, injection software, and at least one Internet of Things (IoT) module, wherein the injection software is used to connect the injection station node and the at least one IoT module; The refilling station node is used to perform the method as described in any one of claims 1-4, and the IoT module is used to perform the method as described in any one of claims 5-7, so that the refilling station node can refill the key to the IoT module through the refilling software.

9. An electronic device, characterized in that, include: The device includes a processor, a storage medium, and a bus, wherein the storage medium stores program instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the program instructions to perform the method as described in any one of claims 1-4, or the method as described in any one of claims 5-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, performs the method as described in any one of claims 1-4, or the method as described in any one of claims 5-7.

Citation Information

Patent Citations

  • Secure key charging method and system based on quantum key distribution

    CN114531238A

  • Internet of Things communication method, Internet of Things terminal, quantum cryptography service platform and quantum cryptography service system

    CN119363372A