Data communication system and method based on same-level areas

By generating relay keys in real time between peer regions and asynchronously transmitting data ciphertext and encryption keys, the problem of low relay key security in cross-regional communication is solved, achieving higher data communication security and reliability.

CN121125097APending Publication Date: 2025-12-12MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511525475.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In quantum communication across regions at the same level, the security of relay keys is difficult to guarantee. Current technologies assume that relay network elements are trustworthy, but this is difficult to guarantee in practical applications, leading to key leakage that threatens the security of the communication system.

Method used

A real-time negotiation relay key mechanism is adopted. Relay key files are generated through the key centers of two primary regions, and the final relay key is generated in real time through negotiation between gateways to ensure the security of the relay key. Data ciphertext and encryption key are transmitted through asynchronous paths to enhance security.

Benefits of technology

It improves the security of relay keys, making them more difficult to attack, ensuring the security of data communication, preventing key leakage, and enhancing the reliability of cross-regional communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125097A_ABST
    Figure CN121125097A_ABST
Patent Text Reader

Abstract

The invention discloses a data communication system and method based on same-level areas. The system comprises a first first-level area and a second first-level area which are connected with each other, the first primary area is used for performing data encryption operation on to-be-sent data, generating a relay key with the second primary area, generating a transmission ciphertext from the encrypted data ciphertext by using the relay key, and sending the transmission ciphertext to the second primary area; and the second primary region decrypts the transmission ciphertext by using the relay key, and decrypts the decrypted data again by using the decrypted key to finally obtain the data to be sent. According to the invention, the relay key is negotiated in real time and cannot be predicted, so that the transmission security of the encryption key is ensured; moreover, the relay key file is simultaneously related to local key files of the first-level key centers in the two first-level areas, and a bad user needs to attack the two key centers at the same time and also needs to know a splicing scheme negotiated by the two key centers in real time, which is very difficult.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication data transmission technology, and specifically to a data communication system and method based on inter-regional communication. Background Technology

[0002] With the rapid development of the information society, communication security and data processing capabilities are facing unprecedented challenges. To address these challenges, quantum communication technology has emerged. Quantum communication provides a theoretically unconditionally secure communication method. Its core advantages stem primarily from fundamental properties of quantum mechanics, such as the no-cloning theorem and the quantum measurement collapse principle, which bring revolutionary benefits to communication security. In recent years, quantum communication technology has gradually been applied in society, and quantum metropolitan area networks have been built and put into use in several cities, achieving secure communication between terminals within the region.

[0003] However, in existing quantum communication processes, when terminals in different quantum communication metropolitan area networks (MANs) conduct secure communication, in addition to encrypting and relaying data, a key relay strategy is also required to ensure smooth real-time data communication between MAN areas. Employing a key relay strategy generates a large number of relay keys, and the security of these keys during transmission determines the security of the entire communication system.

[0004] Current technologies for relay key transmission almost universally involve pre-deploying symmetric keys between the network elements requiring relay, essentially pre-deploying the same key to achieve data relay encryption and decryption. However, the security of the relay network elements still needs to be guaranteed. This means that if a relay network element is controlled by a third party, it could lead to key leakage, thereby threatening the security of the entire communication system. The trustworthiness of relay network elements is difficult to guarantee. Most existing solutions assume that the relay network elements are completely trustworthy, but this is difficult to guarantee in practical applications, especially in cross-regional communication scenarios.

[0005] In summary, when the communicating parties are located in interconnected cross-regional areas at the same level, ensuring the security of the relay key and achieving secure data communication across cross-regional areas at the same level has become a pressing technical challenge. Summary of the Invention

[0006] Purpose of the Invention: The purpose of this invention is to provide a data communication system and method based on inter-regional communication at the same level, solving the problem of low security of existing relay keys, which easily leads to key leakage and thus threatens secure data communication. In this invention, the relay key file containing the relay key is simultaneously associated with the local key files of the primary key centers in both primary regions, making it difficult for malicious users to attack both key centers at the same time. Furthermore, the relay key file is generated through real-time negotiation between the two primary key centers, thereby improving the security of the relay key and indirectly ensuring secure data communication.

[0007] Technical solution: The present invention provides a data communication system based on inter-regional communication at the same level, the system comprising a first-level region and a second-level region connected to each other;

[0008] The first-level area is used to perform data encryption operation on the data to be sent, and generate a relay key with the second-level area. The relay key is used to generate transmission ciphertext from the encrypted data and send it to the second-level area.

[0009] The second-level area uses the relay key to decrypt the transmitted ciphertext, and then uses the decrypted key to perform a decryption operation on the decrypted data again, finally obtaining the data to be sent.

[0010] Furthermore, the first-level area includes a transmitter, a first access gateway, a first-level key center, and a first-level gateway connected in sequence, with the first access gateway also connected to the first-level gateway; the second-level area includes a second-level gateway, a second-level key center, a second access gateway, and a receiver connected in sequence, with the second-level gateway also connected to the first-level gateway and the second access gateway respectively.

[0011] The sending end is used to send the data to be sent to the first access gateway;

[0012] The first access gateway requests an encryption key from the first-level key center based on the data to be sent (data) and performs a data encryption operation, and then transmits the encrypted data ciphertext to the first-level gateway.

[0013] The first-level key center is used to provide encryption keys to the first access gateway and the first-level gateway, and also to provide intermediate relay keys to the first-level gateway;

[0014] The first-level gateway is used to negotiate with the second-level gateway in real time to generate the final relay key, and is also used to encrypt the data ciphertext with the final relay key to obtain the transmission ciphertext, and forward it to the second-level gateway.

[0015] The second-level gateway is used to negotiate with the first-level gateway in real time to generate the final relay key, and is also used to decrypt the transmitted ciphertext, send the decrypted key to the second-level key center, and send the decrypted data to the second access gateway.

[0016] The second-level key center is used to forward the decrypted key to the second access gateway;

[0017] The second access gateway is used to perform a decryption operation to obtain the data to be sent, and then send it to the receiving end;

[0018] The receiving end is used to receive the data to be sent.

[0019] The present invention also includes a method for a data communication system based on peer regions, the method comprising the following steps:

[0020] (1) Determine the data transmission routing paths for the first-level area and the second-level area based on the sending and receiving ends of the data communication;

[0021] (2) Based on the data transmission routing path, determine the gateway and key center on the path, encrypt the data to be sent by the sender and forward it to the first-level gateway; then, determine the relay path of the encryption key between the first-level area and the second-level area according to the connection relationship between the gateway and the key center.

[0022] (3) The first-level gateway and the second-level gateway at the same level on the relay path negotiate the relay key in real time. After the negotiation is completed, the first-level gateway and the second-level gateway perform data relay operation.

[0023] (4) The second-level gateway sends the data obtained from the relay to the second access gateway. The second access gateway performs a decryption operation and sends the decrypted data to be sent to the receiving end.

[0024] Furthermore, the specific process of step (1) is as follows:

[0025] 1) Based on the connection path from the transmitter to the first key center in the first level area, a first sub-path from the transmitter to the first access gateway to the first key center is obtained; based on the connection path from the receiver to the second key center in the second level area, a second sub-path from the receiver to the second access gateway to the second key center is obtained; and based on the shortest gateway path between the first key center and the second key center, a third sub-path from the first key center to the first gateway to the second gateway to the second key center is obtained.

[0026] 2) Construct a complete data transmission routing path based on the common network elements in the above three sub-paths. First, based on the common network element of the first sub-path and the third sub-path as the first level key center, the first sub-path and the third sub-path are concatenated to obtain the first concatenated path. Then, based on the common network element of the third sub-path and the second sub-path as the second level key center, the third sub-path and the second sub-path are concatenated to obtain the second concatenated path. Finally, based on the fact that both of the above concatenated paths contain a third sub-path, the complete data transmission routing path from the first sub-path to the third sub-path to the second sub-path is obtained by using the third sub-path as the concatenation point.

[0027] Furthermore, encrypting the data to be sent by the sending end and forwarding it to the first-level gateway means:

[0028] The sending end sends the data to be sent, data, to the first access gateway. The first access gateway requests the first encryption key, key1, from the first level-one key center based on the data to be sent, data. After receiving the request, the first level-one key center sends the first encryption key, key1, to the first access gateway. The first access gateway then performs the encryption operation on the data to be sent, data, to obtain the first ciphertext, DATA = data ⊕ key1, and then transmits the first ciphertext, DATA, to the first level-one gateway. The first level-one key center then transmits the first encryption key, key1, to the first level-one gateway.

[0029] Furthermore, determining the relay path of the encryption key between the first-level area and the second-level area based on the connection relationship between the gateway and the key center refers to:

[0030] Find the first-level gateways that are directly connected between the first-level area and the second-level area, that is, obtain the first-level gateways and the second-level gateways that are directly connected; at the same time, the first-level gateways and the second-level gateways are the gateways for their respective first-level areas to interact with the outside world, and only one first-level key center is deployed in each first-level area. Then the connection path between the first-level gateways and the second-level gateways is the relay path of the encryption key between the first-level area and the second-level area.

[0031] Furthermore, the real-time negotiation of the relay key refers to:

[0032] The first-level key center in the first-level area selects a key file locally as the first relay key file file1 and sends the first relay key file file1 to the first-level gateway; similarly, the second-level key center in the second-level area selects a key file locally as the second relay key file file2 and sends the second relay key file file2 to the second-level gateway.

[0033] The first-level gateway and the second-level gateway negotiate in real time how to concatenate the two relay key files and form a third key relay file file3, which is the final relay key file.

[0034] Furthermore, the splicing method involves performing an XOR operation on the first relay key file file1 and the second relay key file file2 to obtain the third key relay file file3;

[0035] The splicing method can be as follows: the first-level gateway and the second-level gateway negotiate a splicing location in real time, then find the splicing location in the second relay key file file2, and splice the first relay key file file1 into the second relay key file file2 to obtain the third key relay file file3; wherein, the position of the splicing location is determined by generating a true random number using a true random number generator.

[0036] Furthermore, the data relay operation between the first-level gateway and the second-level gateway refers to:

[0037] The first-level gateway selects the second encryption key key2 from the local third key relay file file3 and records the index idx-k2 of the second encryption key key2; then it uses the second encryption key key2 to encrypt the first data ciphertext DATA and the first encryption key key1 to obtain the transmission ciphertext MES=(DATA|key1)⊕key2;

[0038] The first-level gateway then sends the encrypted MES and index idx-k2 to the second-level gateway;

[0039] The second-level gateway obtains the relay decryption key 'key2' from the local third key relay file file3 based on the index idx-k2, and uses the relay decryption key 'key2' to perform a decryption operation on the transmitted ciphertext MES to obtain the ciphertext 'DATA' and the key 'key1'.

[0040] Furthermore, the second-level gateway sends the relayed data to the second access gateway, and the specific process of the second access gateway performing the decryption operation is as follows:

[0041] The second-level gateway directly sends the decrypted ciphertext DATA' to the second access gateway, and forwards the decrypted key key1' to the second access gateway through the second-level key center;

[0042] The second access gateway uses key1' to decrypt the ciphertext DATA', obtaining plaintext data'=DATA'⊕key1', and plaintext data' is the data to be sent.

[0043] The beneficial effects of this invention are:

[0044] (1) In this invention, the relay key used to encrypt the ciphertext of the data and the first encryption key is negotiated in real time and cannot be predicted, thus ensuring the security of the transmission of the encryption key; moreover, the third relay key file where the relay key is located is related to the local key files of the first-level key centers in two first-level areas at the same time. Malicious users need to know the splicing scheme negotiated in real time to attack the two key centers at the same time, which is very difficult.

[0045] (2) The encrypted data DATA and the relay encryption key are sent to the first-level gateway or the second access gateway through different paths. The asynchronous transmission method ensures the security of the encrypted transmission and the encryption key in the separate transmission paths. No malicious user can obtain the plaintext data by accessing either path. Attached Figure Description

[0046] Figure 1 This is a schematic diagram of the data communication system structure between regions of the same level according to the present invention;

[0047] Figure 2 This is a schematic diagram of the data communication method between regions at the same level according to the present invention;

[0048] Figure 3 A schematic diagram showing the structure of the third key relay file obtained by concatenating the first and second relay key files. Detailed Implementation

[0049] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0050] In existing quantum communication processes, secure communication between terminals in different quantum communication metropolitan area networks requires not only encrypted data relay but also a key relay strategy. This strategy generates a large number of relay keys. Relay key transmission almost always involves pre-deploying identical keys between the network elements requiring relay, and then performing data relay encryption and decryption. This means that if a relay network element is controlled by a third party, key leakage could occur, threatening the security of the entire communication system. Therefore, ensuring the security of relay keys and achieving secure data communication across interconnected regions at the same level is a pressing technical challenge when both communicating parties are located in interconnected, cross-regional areas.

[0051] In view of this, this embodiment proposes a data communication system based on inter-regional communication at the same level, such as... Figure 1As shown, the system includes a first-level area 1 and a second-level area 2 connected to each other; both the first-level area 1 and the second-level area 2 are first-level areas and are interconnected; the first-level area 1 is used to perform data encryption on the data to be sent, and generate a relay key with the second-level area 2, and use the relay key to generate transmission ciphertext from the encrypted data and send it to the second-level area 2; the second-level area 2 uses the relay key to decrypt the transmission ciphertext, and uses the decrypted key to perform decryption operation on the decrypted data again, finally obtaining the data to be sent.

[0052] The first-level area 1 includes a transmitter 11, a first access gateway 12, a first-level key center 13, and a first-level gateway 14 connected in sequence, with the first access gateway 12 also connected to the first-level gateway 14; the second-level area 2 includes a second-level gateway 21, a second-level key center 22, a second access gateway 23, and a receiver 24 connected in sequence, with the second-level gateway 21 also connected to the first-level gateway 14 and the second access gateway 23 respectively.

[0053] The sending end 11 is used to send the data to be sent to the first access gateway 12;

[0054] The first access gateway 12 requests an encryption key from the first level key center 13 based on the data to be sent and performs data encryption operation, and transmits the encrypted data ciphertext to the first level gateway 14.

[0055] The first-level key center 13 is used to provide encryption keys to the first access gateway 12 and the first-level gateway 14, and also to provide intermediate relay keys to the first-level gateway 14.

[0056] The first-level gateway 14 is used to negotiate with the second-level gateway 21 in real time to generate the final relay key, and is also used to encrypt the data ciphertext with the final relay key to obtain the transmission ciphertext, and forward it to the second-level gateway 21.

[0057] The second-level gateway 21 is used to negotiate with the first-level gateway 14 in real time to generate the final relay key, and is also used to decrypt the transmitted ciphertext, send the decrypted key to the second-level key center 22, and send the decrypted data to the second access gateway 23.

[0058] The second-level key center 22 is used to forward the decrypted key to the second access gateway 23;

[0059] The second access gateway 23 is used to perform decryption to obtain the data to be sent and send it to the receiving end 24;

[0060] The receiver 24 is used to receive the data to be sent.

[0061] In this invention, the encrypted data and the relay encryption key are sent to the first-level gateway 14 or the second access gateway 23 through different paths. This asynchronous sending method ensures the security of the data during the transmission path.

[0062] This embodiment also proposes a method based on a data communication system between regions at the same level, such as... Figure 2 As shown, this method targets two interconnected first-level regions, namely, a first-level region 1 and a second-level region 2. Specifically, the transmitting end 11 in the first-level region 1 transmits plaintext data to the receiving end 24 in the second-level region 2. The method includes the following steps:

[0063] (1) Based on the sending end 11 and receiving end 24 for data communication, determine the data transmission routing path of the first-level area 1 and the second-level area 2. The specific process is as follows:

[0064] 1) Based on the connection path from the transmitter 11 to the first-level key center 13 in the first-level area 1, the first sub-path from the transmitter 11 to the first access gateway 12 to the first-level key center 13 is obtained; that is, starting from the transmitter 11, the first access gateway 12 directly connected to the transmitter 11 is determined, and then the first-level key center 13 directly connected to the first access gateway 12 is determined, thus obtaining the first sub-path from the transmitter 11 to the first access gateway 12 to the first-level key center 13.

[0065] Based on the connection path from receiver 24 to second-level key center 22 in second-level area 2, a second sub-path from receiver 24 to second access gateway 23 to second-level key center 22 is obtained; similarly, starting from receiver 24, the second access gateway 23 directly connected to receiver 24 is determined, and then the second-level key center 22 directly connected to the second access gateway 23 is determined, thus obtaining the second sub-path from receiver 24 to second access gateway 23 to second-level key center 22;

[0066] And based on the shortest gateway path between the first-level key center 13 and the second-level key center 22, the third sub-path from the first-level key center 13 to the first-level gateway 14 to the second-level gateway 21 to the second-level key center 22 is obtained; that is, the shortest gateway path (i.e. the path that traverses the fewest gateways) between the first-level key center 13 and the second-level key center 22 is determined, and the third sub-path from the first-level key center 13 to the first-level gateway 14 to the second-level gateway 21 to the second-level key center 22 is obtained.

[0067] 2) Then, based on the common network elements in the above three sub-paths, a complete data transmission routing path is constructed: First, based on the common network element of the first and third sub-paths, the first-level key center 13, is used as the connection point to concatenate the first and third sub-paths to obtain the first concatenated path; then, based on the common network element of the third and second sub-paths, the second-level key center 22, is used as the connection point to concatenate the third and second sub-paths to obtain the second concatenated path; finally, based on the fact that both of the above concatenated paths contain a third sub-path, the complete data transmission routing path from the first sub-path to the third sub-path to the second sub-path is obtained by using the third sub-path as the connection point, as shown below. Figure 1 As shown.

[0068] (2) Based on the data transmission routing path, determine the gateway and key center on the path, encrypt the data to be sent by the sender 11 and forward it to the first-level gateway 14; then, determine the relay path of the encryption key between the first-level area 1 and the second-level area 2 according to the connection relationship between the gateway and the key center.

[0069] Specifically, encrypting the data to be sent by the sending end 11 and forwarding it to the first-level gateway 14 means: the sending end 11 sends the data to be sent to the first access gateway 12; the first access gateway 12 requests the first encryption key key1 from the first-level key center 13 based on the data to be sent; the first-level key center 13 sends the first encryption key key1 to the first access gateway 12 after receiving the request; the first access gateway 12 then performs the encryption operation on the data to be sent to obtain the first ciphertext DATA=data⊕key1, and then transmits the first ciphertext DATA to the first-level gateway 14 through the first ciphertext transmission path; the first-level key center 13 then transmits the first encryption key key1 to the first-level gateway 14.

[0070] Determining the relay path of the encryption key between the first-level area 1 and the second-level area 2 based on the connection relationship between the gateway and the key center means: finding the first-level gateways that are directly connected between the first-level area 1 and the second-level area 2, that is, obtaining the directly connected first-level gateway 14 and the second-level gateway 21; at the same time, the first-level gateway 14 and the second-level gateway 21 are the gateways for their respective first-level areas to interact with the outside world, and only one first-level key center is deployed in each first-level area. Therefore, the connection path between the first-level gateway 14 and the second-level gateway 21 is the relay path of the encryption key between the first-level area 1 and the second-level area 2.

[0071] (3) The first-level gateway 14 and the second-level gateway 21 located on the relay path negotiate the relay key in real time. After the negotiation is completed, the first-level gateway 14 and the second-level gateway 21 perform data relay operation.

[0072] The two primary key centers directly connected to the first-level gateway 14 and the second-level gateway 21 are determined from the data transmission routing path. Since the first-level gateway 14 is managed by the first-level key center 13 and the second-level gateway 21 is managed by the second-level key center 22, and the first-level key center 13 and the second-level key center 22 belong to two different primary areas and do not communicate directly, it is impossible for the key files sent by the first-level key center 13 and the second-level key center 22 to their respective primary gateways to be the same (i.e., symmetric). In order to obtain the symmetric key to perform encryption operations on the first encryption key, real-time negotiation of the relay key is required.

[0073] Real-time negotiation of relay keys refers to the following: the first-level key center 13 in the first-level area 1 selects a key file locally as the first relay key file file1 and sends the first relay key file file1 to the first-level gateway 14; similarly, the second-level key center 22 in the second-level area 2 selects a key file locally as the second relay key file file2 and sends the second relay key file file2 to the second-level gateway 21; the first-level gateway 14 and the second-level gateway 21 negotiate in real time how to concatenate the two relay key files and form a third key relay file file3, which is the final relay key file used.

[0074] like Figure 3 As shown, the concatenation method can be to XOR the first relay key file file1 and the second relay key file file2 to obtain the third key relay file file3. Alternatively, the first-level gateway 14 and the second-level gateway 21 can negotiate a concatenation position in real time, find this concatenation position in the second relay key file file2, and concatenate the first relay key file file1 into the second relay key file file2 to obtain the third key relay file file3. The position of the concatenation position is determined by generating a truly random number using a true random number generator. Conversely, the second relay key file file2 can be concatenated into the first relay key file file1 to obtain the third key relay file file3.

[0075] After negotiation, the first-level gateway 14 and the second-level gateway 21 perform data relay operations: The first-level gateway 14 selects the second encryption key key2 from the local third key relay file file3 and records the index idx-k2 of the second encryption key key2; then it uses the second encryption key key2 to encrypt the first data ciphertext DATA and the first encryption key key1 to obtain the transmission ciphertext MES = (DATA|key1) ⊕key2; the first-level gateway 14 then sends the transmission ciphertext MES and the index idx-k2 to the second-level gateway 21; the second-level gateway 21 obtains the relay decryption key key2' from the local third key relay file file3 according to the index idx-k2, and uses the relay decryption key key2' to perform a decryption operation on the transmission ciphertext MES to obtain the ciphertext DATA' and the key key1'.

[0076] (4) The second-level gateway 21 sends the relayed data to the second access gateway 23. The second access gateway 23 performs a decryption operation and sends the decrypted data to be sent to the receiving end 24. The specific process is as follows:

[0077] The second-level gateway 21 sends the decrypted ciphertext DATA' directly to the second access gateway 23 through the second ciphertext transmission path, and forwards the decrypted key key1' to the second access gateway 23 via the second-level key center 22; the second access gateway 23 uses key key1' to perform a decryption operation on the ciphertext DATA', obtaining plaintext data'=DATA'⊕key1', and plaintext data' is the data to be sent, and finally sends plaintext data' to the receiving end 24.

[0078] In this invention, the relay key used for encrypting the ciphertext and the first encryption key is negotiated in real time and cannot be predicted, ensuring the security of the encryption key transmission. Moreover, the third relay key file containing the relay key is simultaneously associated with the local key files of the first-level key centers in both first-level regions. For a malicious user to attack both key centers simultaneously, they would need to know the concatenation scheme negotiated in real time, which is very difficult. At the same time, the ciphertext DATA and the relay encryption key are sent to the first-level gateway or the second access gateway through different paths. This asynchronous transmission method ensures the security of the ciphertext transmission and the encryption key in their respective transmission paths. Malicious users accessing either path will not be able to obtain the plaintext data.

Claims

1. A data communication system based on regions at the same level, characterized in that: The system includes interconnected first-level and second-level regions; The first-level area is used to perform data encryption on the data to be sent, and generate a relay key with the second-level area. The relay key is used to generate transmission ciphertext from the encrypted data and send it to the second-level area. The second-level area uses the relay key to decrypt the transmitted ciphertext, and then uses the decrypted key to perform a decryption operation on the decrypted data again, finally obtaining the data to be sent.

2. The data communication system based on inter-regional communication according to claim 1, characterized in that: The first-level area includes a transmitter, a first access gateway, a first-level key center, and a first-level gateway connected in sequence, with the first access gateway also connected to the first-level gateway; the second-level area includes a second-level gateway, a second-level key center, a second access gateway, and a receiver connected in sequence, with the second-level gateway also connected to the first-level gateway and the second access gateway respectively. The sending end is used to send the data to be sent to the first access gateway; The first access gateway requests an encryption key from the first-level key center based on the data to be sent (data) and performs a data encryption operation, and then transmits the encrypted data ciphertext to the first-level gateway. The first-level key center is used to provide encryption keys to the first access gateway and the first-level gateway, and also to provide intermediate relay keys to the first-level gateway; The first-level gateway is used to negotiate with the second-level gateway in real time to generate the final relay key, and is also used to encrypt the data ciphertext with the final relay key to obtain the transmission ciphertext, and forward it to the second-level gateway. The second-level gateway is used to negotiate with the first-level gateway in real time to generate the final relay key, and is also used to decrypt the transmitted ciphertext, send the decrypted key to the second-level key center, and send the decrypted data to the second access gateway. The second-level key center is used to forward the decrypted key to the second access gateway; The second access gateway is used to perform a decryption operation to obtain the data to be sent, and then send it to the receiving end; The receiving end is used to receive the data to be sent.

3. A method based on the data communication system between regions at the same level as described in claim 2, characterized in that, The method includes the following steps: (1) Determine the data transmission routing paths for the first-level area and the second-level area based on the sending and receiving ends of the data communication; (2) Based on the data transmission routing path, determine the gateway and key center on the path, encrypt the data to be sent by the sender and forward it to the first-level gateway; then, determine the relay path of the encryption key between the first-level area and the second-level area according to the connection relationship between the gateway and the key center. (3) The first-level gateway and the second-level gateway at the same level on the relay path negotiate the relay key in real time. After the negotiation is completed, the first-level gateway and the second-level gateway perform data relay operation. (4) The second-level gateway sends the data obtained from the relay to the second access gateway. The second access gateway performs a decryption operation and sends the decrypted data to be sent to the receiving end.

4. The method according to claim 3, characterized in that: The specific process of step (1) is as follows: 1) Based on the connection path from the transmitter to the first key center in the first level area, a first sub-path from the transmitter to the first access gateway to the first key center is obtained; based on the connection path from the receiver to the second key center in the second level area, a second sub-path from the receiver to the second access gateway to the second key center is obtained; and based on the shortest gateway path between the first key center and the second key center, a third sub-path from the first key center to the first gateway to the second gateway to the second key center is obtained. 2) Construct a complete data transmission routing path based on the common network elements in the above three sub-paths. First, based on the common network element of the first sub-path and the third sub-path as the first level key center, the first sub-path and the third sub-path are concatenated to obtain the first concatenated path. Then, based on the common network element of the third sub-path and the second sub-path as the second level key center, the third sub-path and the second sub-path are concatenated to obtain the second concatenated path. Finally, based on the fact that both of the above concatenated paths contain a third sub-path, the complete data transmission routing path from the first sub-path to the third sub-path to the second sub-path is obtained by using the third sub-path as the concatenation point.

5. The method according to claim 3, characterized in that: The step of encrypting the data to be sent by the sending end and forwarding it to the first-level gateway means: The sending end sends the data to be sent to the first access gateway. The first access gateway requests the first encryption key key1 from the first level key center based on the data to be sent. After receiving the request, the first level key center sends the first encryption key key1 to the first access gateway. The first access gateway then performs an encryption operation on the data to be sent, data, to obtain the first ciphertext DATA=data⊕key1, and then transmits the first ciphertext DATA to the first level gateway; the first level key center then transmits the first encryption key key1 to the first level gateway.

6. The method according to claim 3, characterized in that: The determination of the relay path for the encryption key between the first-level area and the second-level area based on the connection relationship between the gateway and the key center refers to: Find the first-level gateways that are directly connected between the first-level area and the second-level area, that is, obtain the first-level gateways and the second-level gateways that are directly connected; at the same time, the first-level gateways and the second-level gateways are the gateways for their respective first-level areas to interact with the outside world, and only one first-level key center is deployed in each first-level area. Then the connection path between the first-level gateways and the second-level gateways is the relay path of the encryption key between the first-level area and the second-level area.

7. The method according to claim 5, characterized in that: The real-time negotiation of the relay key refers to: The first-level key center in the first-level area selects a key file locally as the first relay key file file1 and sends the first relay key file file1 to the first-level gateway; similarly, the second-level key center in the second-level area selects a key file locally as the second relay key file file2 and sends the second relay key file file2 to the second-level gateway. The first-level gateway and the second-level gateway negotiate in real time how to concatenate the two relay key files and form a third key relay file file3, which is the final relay key file.

8. The method according to claim 7, characterized in that: The splicing method is to perform an XOR operation on the first relay key file file1 and the second relay key file file2 to obtain the third key relay file file3; The splicing method can be as follows: the first-level gateway and the second-level gateway negotiate a splicing location in real time, then find the splicing location in the second relay key file file2, and splice the first relay key file file1 into the second relay key file file2 to obtain the third key relay file file3; wherein, the position of the splicing location is determined by generating a true random number using a true random number generator.

9. The method according to claim 7, characterized in that: The data relay operation between the first-level gateway and the second-level gateway refers to: The first-level gateway selects the second encryption key key2 from the local third key relay file file3 and records the index idx-k2 of the second encryption key key2; then it uses the second encryption key key2 to encrypt the first data ciphertext DATA and the first encryption key key1 to obtain the transmission ciphertext MES=(DATA|key1)⊕key2; The first-level gateway then sends the encrypted MES and index idx-k2 to the second-level gateway; The second-level gateway obtains the relay decryption key 'key2' from the local third key relay file file3 based on the index idx-k2, and uses the relay decryption key 'key2' to perform a decryption operation on the transmitted ciphertext MES to obtain the ciphertext 'DATA' and the key 'key1'.

10. The method according to claim 9, characterized in that: The second-level gateway sends the relayed data to the second access gateway, and the specific process of the second access gateway performing the decryption operation is as follows: The second-level gateway directly sends the decrypted ciphertext DATA' to the second access gateway, and forwards the decrypted key key1' to the second access gateway through the second-level key center; The second access gateway uses key1' to decrypt the ciphertext DATA', obtaining plaintext data'=DATA'⊕key1', and plaintext data' is the data to be sent.