Conference encryption system and method, electronic equipment and storage medium

By using quantum cryptography technology to achieve quantum key negotiation between the terminal and the multi-point control unit in the encrypted conferencing system, the problem of high resource consumption of the multi-point control unit is solved, and the user experience is improved.

CN121125144APending Publication Date: 2025-12-12CHINA MOBILE COMM GRP TERMINAL +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510396053.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In traditional encrypted conferencing systems, the high resource consumption of multipoint control units negatively impacts user experience.

Method used

Quantum cryptography is used for secure encryption, and the resource consumption of the multi-point control unit is reduced through quantum key negotiation between the first terminal and the multi-point control unit.

Benefits of technology

While ensuring security, the resource consumption of the multi-point control unit was reduced, thus improving the user experience of the conference system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125144A_ABST
    Figure CN121125144A_ABST
Patent Text Reader

Abstract

The invention discloses a conference encryption system and method, electronic equipment and a storage medium, and belongs to the technical field of communication. Comprising a first terminal, a multi-point control unit connected with the first terminal, and at least one second terminal connected with the multi-point control unit, the first terminal is used for sending a first conference request to the multipoint control unit; the multi-point control unit is used for sending a first conference response to the first terminal, and the first conference response comprises at least one second quantum key encrypted by a third quantum key corresponding to the first terminal; and the first terminal is used for completing key negotiation with the at least one third terminal according to the second quantum key corresponding to the at least one third terminal to obtain a shared session quantum key, so that the first terminal and the at least one third terminal perform a conference through the shared session quantum key. On the premise of performing security encryption based on quantum cryptography, resource occupation of a multi-point control unit can be reduced, and the user experience of a conference system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present document relates to the field of communication technology, and in particular to a system and method for encrypting a conference, an electronic device, and a storage medium. BACKGROUND

[0002] In a conventional system for encrypting a conference, the communication between a multipoint control unit and a terminal adopts a data encryption mode of transmission, and the nodes of each terminal can only perform media stream encryption through the multipoint control unit as a conference intermediary regardless of the size of the conference, resulting in high resource occupancy of the multipoint control unit and affecting the conference experience of users. SUMMARY

[0003] An object of the embodiments of the present specification is to provide a system and method for encrypting a conference and a storage medium, to reduce the resource occupancy of a multipoint control unit and improve the user experience of a conference system on the premise of secure encryption based on quantum cryptography.

[0004] To solve the above technical problems, the embodiments of the present disclosure are implemented through the following aspects.

[0005] According to a first aspect of the embodiments of the present disclosure, a system for encrypting a conference is provided, comprising a first terminal, a multipoint control unit connected to the first terminal, and at least one second terminal connected to the multipoint control unit. The first terminal is configured to send a first conference request to the multipoint control unit if a first preset condition is met, wherein the first conference request is encrypted by a first quantum key pre-stored by the first terminal, and is configured to request at least one second quantum key corresponding to at least one third terminal as a conference participant in the at least one second terminal, and the first preset condition includes that the number of conference participants is less than a first preset number threshold. The multipoint control unit is configured to decrypt the first conference request and send a first conference response to the first terminal, wherein the first conference response includes the at least one second quantum key encrypted by a third quantum key corresponding to the first terminal. The first terminal is configured to complete key negotiation according to the second quantum key corresponding to the at least one third terminal and the at least one third terminal, to obtain a shared session quantum key, so that the first terminal and the at least one third terminal perform a conference through the shared session quantum key.

[0006] According to a second aspect of the embodiments of the present disclosure, a method for implementing a conference encryption is provided, the method comprising: In the case of meeting the first preset condition, a first conference request is sent to the multipoint control unit, the first conference request is encrypted by a first quantum key pre-stored by the first terminal, and is used to request a second quantum key corresponding to at least one third terminal as a conference participant in the at least one second terminal respectively, and the first preset condition includes that the number of conference participants is less than a first preset number threshold; A first conference response sent by the multipoint control unit is received, and the first conference response includes the second quantum key corresponding to the at least one third terminal encrypted by a third quantum key corresponding to the first terminal; According to the second quantum key corresponding to the at least one third terminal respectively and the at least one third terminal completing key negotiation, a shared session quantum key is obtained, so that the first terminal and the at least one third terminal conduct a conference through the shared session quantum key.

[0007] According to a third aspect of the embodiments of the present disclosure, an electronic device is provided, including: a processor; a memory for storing instructions executable by the processor; and wherein the processor is configured to execute the steps of the method for encrypting a conference according to the first aspect.

[0008] According to a fourth aspect of the embodiments of the present disclosure, a computer readable storage medium is provided, the computer readable storage medium stores one or more programs, when the one or more programs are executed by an electronic device including a plurality of application programs, the electronic device executes the steps of the method for encrypting a conference according to the first aspect.

[0009] One of the above technical solutions has the following advantages or beneficial effects: under the premise of secure encryption based on quantum cryptography, the resource occupation of the multipoint control unit is reduced, and the user experience of the conference system is improved.

[0010] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure.

[0011] Other features and advantages of the present disclosure will be described in detail in the following specific embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments described in the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor.

[0013] Figure 1This diagram illustrates a system schematic of an encrypted conference provided by an embodiment of the present disclosure; Figure 2 This diagram illustrates a flowchart of an implementation method for an encrypted conference provided in an embodiment of this disclosure. Figure 3 This diagram illustrates another flowchart of the method for implementing encrypted conferencing provided in this embodiment of the present disclosure. Figure 4 This diagram illustrates yet another flowchart of the method for implementing encrypted conferencing provided in this embodiment of the present disclosure; Figure 5 A schematic diagram of the hardware structure of an electronic device for performing the encrypted conferencing method provided in the embodiments of this disclosure. Detailed Implementation

[0014] To enable those skilled in the art to better understand the technical solutions in this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this disclosure.

[0015] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.

[0016] Figure 1 This illustration shows a schematic diagram of an encrypted conferencing system provided by an embodiment of the present disclosure, such as... Figure 1 As shown, the encrypted conferencing system includes a first terminal 100, a multipoint control unit 200 connected to the first terminal, and at least one second terminal 300 connected to the multipoint control unit 200.

[0017] In some possible implementations, the first terminal, the multipoint control unit, and the second terminal can be connected via... Figure 1 The transmission networks shown are interconnected to enable encrypted conferencing. This application does not limit the type of transmission network. The first and second terminals can be video conferencing terminals, equipped with modules such as cameras, display devices, microphones, and speakers, and capable of transmitting media stream data, such as audio data, video data, or audio-visual data, over the network.

[0018] In the encrypted conferencing system provided in this embodiment, the first terminal and each of the second terminals pre-store at least one quantum key for encrypted communication, and the multipoint control unit also stores the identification information of each terminal and at least one quantum key for encrypted communication corresponding to each terminal.

[0019] The quantum keys stored in the terminal and the multipoint control unit can be acquired and stored in various ways. In some possible implementations, the pre-stored quantum key can be randomly generated when the terminal leaves the factory. The user can then use the randomly generated quantum key to store the terminal's identification information and the corresponding quantum key for encrypted communication at the multipoint control unit. In another possible implementation, the multipoint control unit can include a quantum key generation module (e.g., a quantum random number generation module) to generate the quantum key corresponding to the terminal. The generated quantum key and the terminal's identification information are stored in a disposable medium, and the terminal can read and save the quantum key through the disposable medium.

[0020] One-time use media refers to storage devices that can be hot-swapped on multi-point control units and terminals. Specifically, these can be USB flash drives, TF cards, CF cards, flash memory cards, portable hard drives, recordable optical discs, etc., used to store a certain number of keys. This one-time use media can be controlled by a preset program to allow only terminals corresponding to preset identification information to read it, and only allow reading once (for example, the quantum key is deleted after a successful reading), thereby avoiding security risks caused by loss of storage media or dissemination of quantum keys.

[0021] First embodiment: The first terminal is used to send a first conference request to a multipoint control unit when a first preset condition is met. The first conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to request the second quantum keys corresponding to at least one third terminal, which is a conference participant, in at least one second terminal. The first preset condition includes that the number of conference participants is less than a first preset number threshold.

[0022] The first preset threshold can be 5. Of course, the first preset threshold can also be flexibly determined according to the distribution of the number of meeting participants. For example, when most meetings have fewer than 4 participants, the first preset threshold can be flexibly adjusted to 4. Of course, the first preset condition can also be flexibly set with other first preset conditions in combination with the terminal's bandwidth, processing power, storage capacity, etc., and this application does not impose any restrictions on this.

[0023] When there is only one pre-stored first quantum key, the first terminal can encrypt the first conference request using that pre-stored first quantum key. When there are multiple pre-stored first quantum keys, the first terminal can select one of the multiple pre-stored first quantum keys to encrypt the first conference request, and send the key identifier of the selected first quantum key along with the encrypted first conference request to the multipoint control unit. Both the multipoint control unit and the first terminal store the first terminal's corresponding quantum keys KEY1-1, KEY1-2, and KEY1-3, with corresponding key identifiers 1-1, 1-2, and 1-3, respectively. The first terminal can use KEY1-1 as the first quantum key to encrypt the first conference request, and send the key identifier 1-1 along with it to the multipoint control unit, so that the multipoint control unit can select the corresponding quantum key KEY1-1 for decryption based on the key identifier 1-1.

[0024] In some possible implementations, the specific encryption algorithm can be the Chinese national standard SM4 encryption algorithm, or other encryption algorithms can be used. This application does not impose any restrictions on this.

[0025] A multipoint control unit is used to decrypt the first conference request and send a first conference response to the first terminal. The first conference response includes at least one second quantum key encrypted by the third quantum key corresponding to the first terminal.

[0026] The multi-point control unit can decrypt the first conference request using the first quantum key corresponding to the first terminal. The specific decryption algorithm can be the national cryptographic SM4 decryption algorithm, or other encryption algorithms. This application does not restrict this.

[0027] After receiving the first conference request, the multipoint control unit obtains the second quantum key corresponding to at least one third terminal requested by the first terminal, and encrypts the second quantum key corresponding to at least one third terminal using the third quantum key corresponding to the first terminal, and sends it as the first conference response to the first terminal.

[0028] It is understandable that the number of second quantum keys corresponding to the third terminal can be one or more, and the first conference response also includes the key identifiers corresponding to the multiple second quantum keys corresponding to the third terminal.

[0029] Understandably, to distinguish different third terminals, when there are multiple third terminals, the first conference response also needs to include the terminal identifier of the third terminal. The first quantum key and the third quantum key can be the same or different. For example, both the multi-point control unit and the first terminal store the quantum keys KEY1-1, KEY1-2, and KEY1-3 corresponding to the first terminal, with corresponding key identifiers 1-1, 1-2, and 1-3 respectively. The first terminal can use KEY1-1 as the first quantum key to encrypt the first conference request, and the multi-point control unit can use KEY1-3 as the third quantum key to encrypt the first conference response. Of course, the multi-point control unit can also use KEY1-1 as the third quantum key to encrypt the first conference response.

[0030] Specifically, after verifying the authenticity and integrity of the first terminal by correctly decrypting the first conference request, the multi-point control unit can query the quantum key distribution record of each third terminal, retrieve the valid quantum key corresponding to each third terminal, and select some or all of the valid quantum keys of each third terminal as the corresponding second quantum key.

[0031] The first terminal is used to complete key negotiation with at least one third terminal based on the second quantum key corresponding to at least one third terminal, and obtain a shared session quantum key, so that the first terminal and at least one third terminal can hold a meeting through the shared session quantum key.

[0032] A shared session quantum key is a temporary quantum key used for encryption and decryption during a conference between a first terminal and at least one third terminal. The shared session quantum key can be destroyed after the conference ends, allowing conference participants to interact with media streams within a secure channel built by the temporary quantum key, thereby further enhancing the security of the encrypted conference.

[0033] In some embodiments, the first terminal constructs a first key package, encrypts the first key package with a second quantum key corresponding to at least one third terminal, and sends it to the corresponding third terminal. The first key package includes a fourth quantum key corresponding to the first terminal and a second quantum key corresponding to at least one third terminal.

[0034] For example, the third terminal includes three terminals, terminals 2-4. The first terminal obtains the second quantum key KEY2-2 and key identifier 2-2 corresponding to terminal 2, the second quantum keys KEY3-1 and KEY3-2 and key identifiers 3-1 and 3-2 corresponding to terminal 3, and the second quantum keys KEY4-1 and KEY4-3 and key identifiers 4-1 and 4-3 corresponding to terminal 4 through the first conference response. The first terminal can select its own fourth quantum key KEY1-1 and key identifier 1-1 from the pre-stored quantum keys. The first terminal can package all the above quantum keys and their corresponding key identifiers into a first key packet, encrypt it using KEY2-2, and send the encrypted first key packet and key identifier 2-2 together to terminal 2; encrypt it using KEY3-1, and send the encrypted first key packet and key identifier 3-1 together to terminal 3; encrypt it using KEY4-3, and send the encrypted first key packet and key identifier 4-3 together to terminal 4. Of course, when sending the first key packet to the target terminal, the second quantum key corresponding to the target terminal can be removed. For example, in the first key packet sent to terminal 2, the second quantum key KEY2-2 and key identifier 2-2 corresponding to terminal 2 can be removed, which can further compress the length of the first key packet.

[0035] The third terminal decrypts the encrypted first key packet according to its corresponding second quantum key, and obtains the fourth quantum key corresponding to the first terminal and the second quantum key corresponding to the other third terminals respectively.

[0036] Taking terminal 3 in the above example as an example, after receiving key identifier 3-1 and the first key packet encrypted with KEY3-1, terminal 3 determines the second quantum key KEY3-1 used for decryption through key identifier 3-1, and decrypts the encrypted first key packet through KEY3-1, thereby obtaining the quantum keys and key identifiers corresponding to the conference participants respectively. For example, the fourth quantum key KEY1-1 and key identifier 1-1 of the first terminal, the second quantum key KEY2-2 and key identifier 2-2 of the terminal 2, and the second quantum keys KEY4-1 and KEY4-3 and key identifiers 4-1 and 4-3 of the terminal 4.

[0037] The first terminal and at least one third terminal negotiate the obtained quantum key to obtain a shared session quantum key.

[0038] Since each terminal (including the first and third terminals) participating in the conference has obtained the quantum keys and key identifiers of the other terminals, they can negotiate keys with each other, so that each terminal participating in the conference can obtain the shared session quantum key.

[0039] The shared session quantum key can be obtained in several ways. For example, the terminals of the conference participants (including the first and third terminals) can generate the shared session quantum key through the elected target terminal. Alternatively, the terminals of the conference participants (including the first and third terminals) can each generate candidate shared session quantum keys and determine the shared session quantum key from the candidate shared session quantum keys according to predetermined rules, such as selecting the smallest quantum key among the candidate shared session quantum keys. The aforementioned "generating the shared session quantum key" and "generating candidate shared session quantum keys" can be generated by the corresponding terminal through a quantum key generation module, or the corresponding terminal can select the quantum key from a pre-stored quantum key pool.

[0040] When the first terminal and at least one third terminal hold a conference by sharing a session quantum key, the first terminal and at least one third terminal elect a fourth terminal. Other terminals besides the fourth terminal interact with the fourth terminal to encrypt the conference media stream, and the encrypted conference media stream is encrypted by sharing a session quantum key.

[0041] The specific election rules can be set flexibly. For example, a terminal with stronger capabilities can be selected as the fourth terminal based on factors such as the bandwidth of the terminal and the transmission network, the processing power of the terminal, and the storage capacity of the terminal. This fourth terminal can then handle the encrypted conference media stream in a dual role as a multipoint control unit and a conference participant during the conference.

[0042] By adopting the above technical solution, it is possible to reduce the resource consumption of multi-point control units and improve the user experience of the conference system while ensuring secure encryption based on quantum cryptography.

[0043] Second embodiment: In some embodiments, the first terminal is further configured to send a second conference request to the multipoint control unit if the first preset condition is not met. The second conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to initiate a conference through the multipoint control unit.

[0044] The specific technical solution for encrypting the second conference request by the first terminal is described in the first embodiment above, and will not be repeated here.

[0045] The multipoint control unit is also used to decrypt the second conference request and send a conference notification to at least one third terminal, which is a participant in the conference, among at least one second terminal. The conference notification is encrypted using the second quantum key corresponding to each of the third terminals.

[0046] The technical solution for the multipoint control unit to decrypt the second meeting request refers to the description in the first embodiment above. After obtaining at least one third terminal as a meeting participant included in the second meeting request, a meeting notification can be sent to the third terminal respectively. The meeting notification may include information such as meeting identifier, meeting time, meeting topic, and meeting participants.

[0047] The multi-point control unit can encrypt the conference notification according to the second quantum key corresponding to the third terminal. When there are multiple second quantum keys corresponding to the third terminal, the multi-point control unit can select one second quantum key from the multiple second quantum keys corresponding to the third terminal for encryption, and send the encrypted conference notification and the key identifier of the selected second quantum key together to the third terminal.

[0048] The multipoint control unit is also used to negotiate keys with the first terminal and the third terminal respectively to obtain a shared session quantum key, so that the first terminal and at least one third terminal can hold a conference via the multipoint control unit through the shared session quantum key.

[0049] In some possible implementations, the multi-point control unit can generate the shared session quantum key through a quantum key generation module (e.g., a quantum random number generation module), encrypt it using the quantum key corresponding to the terminal, and send it to the corresponding terminal. After receiving confirmation messages from all terminals, the negotiation of the shared session quantum key is considered complete.

[0050] When a first terminal and at least one third terminal hold a conference via a multipoint control unit using a shared session quantum key, both the first terminal and the third terminal encrypt the conference media stream through the multipoint control unit, and the encrypted conference media stream is encrypted using the shared session quantum key.

[0051] By adopting the above technical solution, encrypted meetings can be flexibly organized through multi-point control units even when preset conditions are not met. Secure encryption based on quantum cryptography can effectively ensure the security of the meeting.

[0052] In the first and second embodiments described above, after the meeting concludes, the first terminal and at least one third terminal can execute a quantum key destruction procedure to delete the shared session quantum key and meeting-related data cache. This ensures that no trace remains that could be used to recover meeting information, while providing new security for key generation for the next meeting. After the meeting, the encrypted meeting system can generate a comprehensive security audit report by the multi-point control unit or an elected fourth terminal. This report covers key data such as quantum key usage, authentication, and potential anomaly identification, allowing users to assess meeting security based on the audit report and conduct subsequent analysis and improvements.

[0053] Third embodiment: The multipoint control unit is also configured to generate at least one initial quantum key corresponding to the conference terminal in response to a user's instruction, or, in response to receiving a quantum key request sent by the first terminal, generate a fifth quantum key corresponding to the first terminal and send a quantum key response including the fifth quantum key to the first terminal.

[0054] In some embodiments, the multipoint control unit can generate at least one initial quantum key corresponding to a conference terminal in response to a user's instruction, so as to store at least one initial quantum key in a disposable medium, thereby enabling the corresponding conference terminal to read the disposable medium once and store the initial quantum key in the conference terminal. When there are multiple initial quantum keys, the initial quantum keys and their corresponding key identifiers can be processed together.

[0055] In related technologies, quantum keys are usually stored in physical media. The time from generation to use of quantum keys stored in this way may be several months or even a year, which poses a risk of quantum keys being stolen and spread. At the same time, after the quantum keys are used up, they need to be refilled using physical media, which is a complicated and costly process.

[0056] In another embodiment, in response to receiving a quantum key request sent by a first terminal, a fifth quantum key corresponding to the first terminal is generated, and a quantum key response including the fifth quantum key is sent to the first terminal.

[0057] The quantum key request can be sent by the first terminal to the multipoint control unit when the pre-stored quantum key meets the second preset condition.

[0058] The second preset condition may include any one of the following: The storage time of the pre-stored quantum cryptography exceeds the preset time threshold; The number of times the pre-stored quantum cryptography has been used exceeds a preset threshold. Received the user's quantum cryptography update instruction; Suspicious data packets indicating quantum cryptography failure have been detected.

[0059] For example, the first terminal can send a quantum key request when the "pre-stored quantum key storage time exceeds a preset time threshold" to update the stored quantum key and avoid the security risks caused by the quantum key not being updated for a long time.

[0060] The first terminal can send a quantum key request when the number of times the pre-stored quantum key is used exceeds a preset threshold, so as to update the stored quantum key and avoid the security risks caused by the multiple uses of quantum key.

[0061] The first terminal can update the stored quantum key when it receives the user's quantum cryptography update instruction to ensure the flexibility of the quantum key update method.

[0062] After a meeting, the first terminal can detect a suspicious data packet that is invalid in quantum cryptography (e.g., the received data packet fails to be decrypted, which may be a spoofed data packet sent by an attacker) and send a quantum key request after the meeting ends to update the stored quantum key.

[0063] To further enhance security, when the multipoint control unit interacts with the first terminal, both parties must include their own device model, device serial number, MAC address, and other information in the information. This allows the first terminal and the multipoint control unit to compare the obtained device information with the information in their own databases. If the comparison results match, two-way authentication of the device identity is completed. Subsequent information interaction can only proceed after successful authentication. Otherwise, a rejection message can be sent, and corresponding alarms and / or logs can be triggered.

[0064] By adopting the above technical solution, a fifth quantum key corresponding to the conference terminal is generated in response to the quantum key request initiated by the conference terminal based on the second preset condition, so that the conference terminal can update the stored quantum key in a timely manner. This avoids the problems of high cost, untimely updates and security risks caused by repeated refilling through physical media in related technologies.

[0065] Fourth embodiment: Figure 2 This illustration shows a flowchart of an implementation method for an encrypted conference provided in an embodiment of this disclosure, such as... Figure 2 As shown, this method can be applied to a first terminal in the encrypted conference system shown in the first aspect embodiment, and the method may include the following steps: In step S101, if the first preset condition is met, a first conference request is sent to the multipoint control unit.

[0066] The first meeting request is encrypted using a first quantum key pre-stored in the first terminal, and is used to request the second quantum key corresponding to at least one third terminal, which is a participant in the meeting, in at least one second terminal. The first preset condition includes that the number of participants in the meeting is less than a first preset number threshold.

[0067] In step S102, the first conference response sent by the multipoint control unit is received.

[0068] The first conference response includes a second quantum key corresponding to at least one third terminal, which is encrypted by the third quantum key corresponding to the first terminal.

[0069] In step S103, key negotiation is completed with at least one third terminal based on the second quantum key corresponding to each third terminal to obtain a shared session quantum key, so that the first terminal and at least one third terminal can hold a meeting through the shared session quantum key.

[0070] The specific technical solution for implementing the above-described encrypted conferencing method can be found in the description of the first embodiment, and will not be elaborated further here. By adopting the above technical solution, while ensuring secure encryption based on quantum cryptography, the resource consumption of the multi-point control unit can be reduced, thus improving the user experience of the conferencing system.

[0071] Fifth embodiment: Figure 3 This illustration shows another flowchart of the implementation method of the encrypted conference provided in the embodiments of this disclosure, such as... Figure 3 As shown, the method also includes the following steps: In step S104, if the first preset condition is not met, a second conference request is sent to the multipoint control unit.

[0072] The second meeting request is encrypted using the first quantum key pre-stored in the first terminal, and is used to initiate the meeting through the multi-point control unit.

[0073] The second meeting request may include relevant meeting information, such as meeting identifier, meeting time, meeting topic, meeting participants (e.g., the terminal identifier of at least one third terminal that is a meeting participant), etc.

[0074] In step S105, a key negotiation is performed with the multipoint control unit to obtain a shared session quantum key, so that the first terminal and at least one third terminal, which is a participant in the meeting, can hold a meeting via the multipoint control unit through the shared session quantum key.

[0075] The specific technical solution for implementing the above-described encrypted conference can be found in the description of the second embodiment, and will not be elaborated further here. By adopting the above technical solution, encrypted conferences can be flexibly organized through a multi-point control unit even when preset conditions are not met. Secure encryption based on quantum cryptography effectively ensures the security of the conference.

[0076] Sixth embodiment: Figure 4 This illustration shows yet another flowchart of the implementation method for encrypted conferencing provided in this disclosure, such as... Figure 4 As shown, the method may further include the following steps: In step S106, if the second preset condition is met, a quantum key request is sent to the multi-point control unit, and the fifth quantum key in the quantum key response sent by the multi-point control unit is used as the new pre-stored quantum key.

[0077] The second preset condition includes any one of the following: The storage time of the pre-stored quantum cryptography exceeds the preset time threshold; The number of times the pre-stored quantum cryptography has been used exceeds a preset threshold. Received the user's quantum cryptography update instruction; Suspicious data packets indicating quantum cryptography failure have been detected.

[0078] It is understandable that, in response to receiving a quantum key request from the first terminal, the multi-point control unit generates a fifth quantum key corresponding to the first terminal and sends a quantum key response including the fifth quantum key to the first terminal. The specific technical solution for implementing the above-described encrypted conferencing method can be found in the description of the third embodiment, and will not be elaborated further here. Using the above technical solution, by responding to a quantum key request initiated by the conferencing terminal based on the second preset condition, a fifth quantum key corresponding to the conferencing terminal is generated. This allows the conferencing terminal to update the stored quantum key in a timely manner, thereby avoiding the problems of high cost, untimely updates, and security risks associated with repeated refilling through physical media in related technologies.

[0079] Seventh embodiment: Figure 5 This diagram illustrates the hardware structure of an electronic device implementing embodiments of the present disclosure, such as... Figure 5 As shown, at the hardware level, the electronic device includes at least one processor, and optionally, an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or it may also include non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.

[0080] The processor, network interface, and memory can be interconnected via an internal bus, which can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be categorized as an address bus, data bus, control bus, etc. For ease of illustration, only a single bidirectional arrow is used in this diagram, but this does not imply that there is only one bus or one type of bus.

[0081] Memory stores programs. Specifically, the program may include program code, which includes at least one computer operation instruction. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0082] At least one processor reads a corresponding computer program from non-volatile memory into memory and then runs it, forming a device for locating a target user at the logical level. At least one processor executes the program stored in memory and specifically performs the method disclosed in the embodiments of the second aspect, achieving the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0083] The methods disclosed in the embodiments shown in the second aspect of this disclosure can be applied to at least one processor, or implemented by at least one processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the hardware or by instructions in software form within at least one processor. The processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0084] The electronic device can also execute the methods described in the preceding method embodiments and achieve the functions and beneficial effects of the methods described in the preceding method embodiments, which will not be repeated here.

[0085] Of course, in addition to software implementation, the electronic device disclosed herein does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0086] This disclosure also proposes a computer-readable storage medium that stores one or more programs, which, when executed by at least one processor, implement the methods disclosed in the embodiments of the second aspect and achieve the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0087] The computer-readable storage medium mentioned above includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0088] This application provides a computer program product, which includes a computer program. When executed by a processor, the computer program implements the various processes of the method disclosed in the second aspect embodiment and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0089] In summary, the above description is merely a preferred embodiment of this disclosure and does not limit the scope of protection of this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

[0090] The systems, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0091] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can store information accessible to a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0092] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0093] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A system for encrypted conferencing, characterized in that, include: A first terminal, a multipoint control unit connected to the first terminal, and at least one second terminal connected to the multipoint control unit; The first terminal is used to send a first conference request to the multipoint control unit when a first preset condition is met. The first conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to request the second quantum key corresponding to at least one third terminal, which is a conference participant, among the at least one second terminal. The first preset condition includes that the number of conference participants is less than a first preset number threshold. The multipoint control unit is used to decrypt the first conference request and send a first conference response to the first terminal. The first conference response includes at least one second quantum key encrypted by the third quantum key corresponding to the first terminal. The first terminal is used to complete key negotiation with the at least one third terminal based on the second quantum key corresponding to each of the at least one third terminal, to obtain a shared session quantum key, so that the first terminal and the at least one third terminal can conduct a conference through the shared session quantum key.

2. The system according to claim 1, characterized in that, The step of obtaining a shared session quantum key by completing key negotiation with the at least one third terminal based on the second quantum key corresponding to each of the at least one third terminal includes: The first terminal constructs a first key packet, encrypts the first key packet with the second quantum key corresponding to each of the at least one third terminal, and sends it to the corresponding third terminal. The first key packet includes a fourth quantum key corresponding to the first terminal and a second quantum key corresponding to each of the at least one third terminal. The third terminal decrypts the encrypted first key packet according to its corresponding second quantum key to obtain the fourth quantum key corresponding to the first terminal and the second quantum key corresponding to the other third terminals respectively. The first terminal and the at least one third terminal negotiate a key using the obtained quantum key to obtain the shared session quantum key.

3. The system according to claim 1, characterized in that, The first terminal and the at least one third terminal conduct a conference via the shared session quantum key, including: The first terminal and the at least one third terminal are elected to form a fourth terminal; Other terminals besides the fourth terminal interact with the encrypted conference media stream through the fourth terminal, and the encrypted conference media stream is encrypted using the shared session quantum key.

4. The system according to claim 1, characterized in that, The first terminal is also used to send a second conference request to the multipoint control unit when the first preset condition is not met. The second conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to initiate a conference through the multipoint control unit. The multipoint control unit is also used to decrypt the second conference request and send a conference notification to at least one third terminal among the at least one second terminal that is a conference participant. The conference notification is encrypted using the second quantum key corresponding to each of the third terminals. The multipoint control unit is further configured to negotiate keys with the first terminal and the third terminal respectively to obtain a shared session quantum key, so that the first terminal and the at least one third terminal can hold a conference via the multipoint control unit through the shared session quantum key.

5. The system according to claim 4, characterized in that, The first terminal and the at least one third terminal conduct a conference via the multipoint control unit using the shared session quantum key, including: Both the first terminal and the third terminal interact with the encrypted conference media stream through the multi-point control unit, and the encrypted conference media stream is encrypted using the shared session quantum key.

6. The system according to any one of claims 1 to 5, characterized in that, The multipoint control unit is further configured to generate at least one initial quantum key corresponding to the conference terminal in response to a user's instruction, or, in response to receiving a quantum key request sent by the first terminal, generate a fifth quantum key corresponding to the first terminal and send a quantum key response including the fifth quantum key to the first terminal.

7. A method for implementing encrypted conferencing, characterized in that, The method includes: Under the condition of meeting the first preset condition, a first conference request is sent to the multipoint control unit. The first conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to request the second quantum key corresponding to at least one third terminal that is a conference participant in at least one second terminal. The first preset condition includes that the number of conference participants is less than a first preset number threshold. The system receives a first conference response sent by the multipoint control unit, the first conference response including a second quantum key corresponding to each of the at least one third terminal, which is encrypted by a third quantum key corresponding to the first terminal; Based on the second quantum key corresponding to each of the at least one third terminal, key negotiation is completed with the at least one third terminal to obtain a shared session quantum key, so that the first terminal and the at least one third terminal can conduct a conference through the shared session quantum key.

8. The method according to claim 7, characterized in that, The method further includes: If the first preset condition is not met, a second conference request is sent to the multipoint control unit. The second conference request is encrypted with a first quantum key pre-stored in the first terminal and is used to initiate a conference through the multipoint control unit. The multipoint control unit negotiates a key to obtain a shared session quantum key, enabling the first terminal and at least one third terminal, which is a participant in the conference, to conduct a conference via the multipoint control unit using the shared session quantum key.

9. The method according to claim 7 or 8, characterized in that, The method further includes: Under the condition that the second preset condition is met, a quantum key request is sent to the multi-point control unit, and the fifth quantum key in the quantum key response sent by the multi-point control unit is used as the new pre-stored quantum key. The second preset condition includes any one of the following: The storage time of the pre-stored quantum cryptography exceeds the preset time threshold; The number of times the pre-stored quantum cryptography has been used exceeds a preset threshold. Received the user's quantum cryptography update instruction; Suspicious data packets indicating quantum cryptography failure were detected.

10. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the method of implementing an encrypted conference as claimed in any one of claims 7 to 9.