Quantum key acquisition method, related equipment, storage medium and computer program product

By storing the encrypted quantum key within the device and reading it directly from memory when certain conditions are met, the bottleneck problem of quantum key relay devices is solved, and the efficiency of quantum key distribution is improved.

CN121217318APending Publication Date: 2025-12-26CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410841758.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing quantum key relay devices suffer from frequent calls and forwarding processes when terminal devices require quantum keys, which affects the distribution efficiency of quantum keys, becoming a bottleneck and leading to a decrease in distribution efficiency.

Method used

By storing N encrypted quantum keys in the device, after receiving key request information, it is determined whether the extraction requirements are met. If they are met, the quantum key is directly read from memory and sent, avoiding frequent calls to the QKD device and improving distribution efficiency.

Benefits of technology

This alleviates the problem of excessive quantum key usage and insufficient generation rate during peak periods, and improves the efficiency of quantum key distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121217318A_ABST
    Figure CN121217318A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a quantum key acquisition method, related equipment, a storage medium and a computer program product, the method is applied to first equipment, and the method comprises the following steps: the first equipment receives first key request information sent by a first server; judging whether first information corresponding to the first key request information meets a preset extraction requirement or not; under the condition that the first information meets a preset extraction requirement, reading an encrypted first quantum key corresponding to the first information from a first memory address interval, and sending first key identifiers corresponding to the first quantum key and a second quantum key to a first server; wherein the first memory address interval comprises a memory address interval of the first equipment, and the first memory address interval stores N encrypted quantum keys, so that the distribution efficiency of the quantum keys is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum communication technology, and in particular to a quantum key acquisition method, related equipment, storage medium, and computer program product. Background Technology

[0002] Currently, quantum key distribution (QKD) devices can interface with quantum key relay devices. QKD devices can include QKD-A devices and QKD-B devices. QKD-A devices represent quantum key senders, and QKD-B devices represent quantum key receivers. Quantum key relay devices can send quantum keys retrieved from QKD devices to terminal devices via transparent transmission / forwarding. Quantum key relay devices themselves do not generate or store any quantum keys.

[0003] However, current quantum key relay devices require a call to the QKD device when a terminal device needs a quantum key, and then forward the obtained quantum key to the terminal device. However, during peak periods, this frequent calling and forwarding process can impact quantum key distribution efficiency, making the quantum key relay device a bottleneck and leading to a decrease in distribution efficiency. Summary of the Invention

[0004] This application implements a method for obtaining quantum keys, related equipment, storage media, and computer program products that can improve the efficiency of quantum key distribution.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a quantum key acquisition method, the method being applied to a first device, the method comprising:

[0007] Receive a first key request message sent by a first server; wherein the first key request message includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information;

[0008] Determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called;

[0009] If the first information satisfies the preset extraction requirements, the encrypted first quantum key corresponding to the first information is read from the first memory address range, and the first key identifier corresponding to the first quantum key and the second quantum key is sent to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0010] Secondly, embodiments of this application provide a quantum key acquisition method, the method being applied to a first server, the method comprising:

[0011] The system receives a second key request information sent by a first terminal device; wherein the second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information;

[0012] A first key request information is sent to the first device based on the second key request information; wherein, the first key request information includes one or more of the following: first identification information corresponding to the first server, the key length information, and the key unit information;

[0013] The device receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0014] Thirdly, embodiments of this application provide a quantum key acquisition method, which is applied to a second server, and the method includes:

[0015] Receive a third key request message sent by a second terminal device; wherein the third key request message includes a fourth identification message and a first key identifier corresponding to the second terminal device;

[0016] A fourth key request is sent to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes the fifth identification information corresponding to the second server and the first key identifier;

[0017] Receive the encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys;

[0018] The eighth quantum key is sent to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0019] Fourthly, embodiments of this application provide a quantum key acquisition method, which is applied to a third device, and the method includes:

[0020] Receive a fourth key request message sent by a second server; wherein the fourth key request message includes a fifth identification message and a first key identifier corresponding to the second server;

[0021] Based on the first key identifier, the encrypted eighth quantum key corresponding to the first key identifier is queried in the second memory address range. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0022] The eighth quantum key is sent to the second server, so that the second server sends the eighth quantum key to the second terminal device.

[0023] Fifthly, embodiments of this application provide a first device, the first device comprising: a first receiving unit, a judging unit, a reading unit, and a first sending unit; wherein,

[0024] The first receiving unit is configured to receive a first key request information sent by a first server; wherein the first key request information carries one or more of the following: first identification information corresponding to the first server, key length information, and key unit information;

[0025] The judgment unit is used to determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called;

[0026] The reading unit is used to read the encrypted first quantum key corresponding to the first information from the first memory address range when the first information meets the preset extraction requirements;

[0027] The first sending unit is configured to send the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key after decryption of the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0028] Sixthly, embodiments of this application provide a first device, the first device comprising: a first processor and a first memory; wherein,

[0029] The first memory is used to store computer programs that can run on the processor;

[0030] The first processor is configured to execute the quantum key acquisition method as described above when running the computer program.

[0031] Seventhly, embodiments of this application provide a first server, which includes: a second receiving unit and a second sending unit; wherein,

[0032] The second receiving unit is configured to receive a second key request information sent by the first terminal device; wherein the second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information; and to receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device.

[0033] The second sending unit is configured to send a first key request information to a first device based on the second key request information; wherein the first key request information includes one or more of the first identifier information corresponding to the first server, the key length information, and the key unit information; and to send the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0034] Eighthly, embodiments of this application provide a first server, the first server comprising: a second processor and a second memory; wherein,

[0035] The second memory is used to store computer programs that can run on the processor;

[0036] The second processor is configured to execute the quantum key acquisition method as described above when running the computer program.

[0037] Ninthly, embodiments of this application provide a second server, the second server comprising: a third receiving unit and a third sending unit; wherein,

[0038] The third receiving unit is configured to receive a third key request information sent by the second terminal device; wherein the third key request information includes a fourth identification information and a first key identification corresponding to the second terminal device; and to receive an encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys.

[0039] The third sending unit is configured to send a fourth key request information to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes a fifth identification information corresponding to the second server and a first key identification; and to send the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0040] In a tenth aspect, embodiments of this application provide a second server, the second server comprising: a third processor and a third memory; wherein,

[0041] The third memory is used to store computer programs that can run on the processor;

[0042] The third processor is used to execute the quantum key acquisition method as described above when running the computer program.

[0043] In one aspect, embodiments of this application provide a third device, the third device comprising: a fourth receiving unit, a querying unit, and a fourth sending unit; wherein,

[0044] The fourth receiving unit is used to receive a fourth key request information sent by the second server; wherein the fourth key request information includes a fifth identification information and a first key identification corresponding to the second server;

[0045] The query unit is used to query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0046] The fourth sending unit is used to send the eighth quantum key to the second server, so that the second server sends the eighth quantum key to the second terminal device.

[0047] In a twelfth aspect, embodiments of this application provide a third device, the third device comprising: a fourth processor and a fourth memory; wherein,

[0048] The fourth memory is used to store computer programs that can run on the processor;

[0049] The fourth processor is used to execute the quantum key acquisition method as described above when running the computer program.

[0050] In a thirteenth aspect, embodiments of this application provide a computer-readable storage medium storing computer program code, which, when executed by a computer, implements the quantum key acquisition method as described above.

[0051] In a fourteenth aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the quantum key acquisition method as described above.

[0052] This application provides a quantum key acquisition method, related equipment, storage medium, and computer program product. A first device receives first key request information sent by a first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The device determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called. If the first information meets the preset extraction requirements, the device reads the encrypted first quantum key corresponding to the first information from a first memory address range and sends the first quantum key and the first key identifier corresponding to the second quantum key to the first server. The first memory address range includes the memory address range of the first device, which includes at least a gateway device. The second quantum key includes the decrypted quantum key of the first quantum key. The first memory address range stores N encrypted quantum keys, and the N encrypted quantum keys include the first quantum key, where N is a positive integer. The first server receives information sent by a first terminal device. The second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information; the second server sends the first key request information to the first device based on the second key request information; the server receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device; the second server receives the third key request information sent by the second terminal device, including the fourth identification information corresponding to the second terminal device and the first key identifier; the server sends the fourth key request information to the third device based on the third key request information; the server receives the encrypted eighth quantum key sent by the third device, wherein the eighth quantum key and the first quantum key are symmetric keys; the server sends the eighth quantum key to the second terminal device, so that the second terminal device decrypts the encrypted data based on the eighth quantum key to obtain the original data; the third device receives the fourth key request information sent by the second server, including the fifth identification information corresponding to the second server and the first key identifier;Based on the first key identifier, the encrypted eighth quantum key corresponding to the first key identifier is queried in the second memory address range. The second memory address range includes the memory address range of the third device and includes M second data structure objects. The M second data structure objects represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys. The eighth quantum key is sent to the second server so that the second server can send the eighth quantum key to the second terminal device. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can pre-store N encrypted quantum keys in the memory address range, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the efficiency of quantum key distribution. Attached Figure Description

[0053] Figure 1 Schematic diagram of quantum key transfer architecture Figure 1 ;

[0054] Figure 2 Schematic diagram of quantum key transfer architecture Figure 2 ;

[0055] Figure 3 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 1 ;

[0056] Figure 4 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 2 ;

[0057] Figure 5 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 3 ;

[0058] Figure 6 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 4 ;

[0059] Figure 7 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 5 ;

[0060] Figure 8 This is a schematic diagram of the quantum key acquisition architecture proposed in an embodiment of this application;

[0061] Figure 9 This is a schematic diagram of the algorithm flow proposed in the embodiments of this application;

[0062] Figure 10 This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application. Figure 1 ;

[0063] Figure 11 This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application. Figure 2 ;

[0064] Figure 12 This is a schematic diagram of the composition structure of the first server proposed in the embodiments of this application. Figure 1 ;

[0065] Figure 13 This is a schematic diagram of the composition structure of the first server proposed in the embodiments of this application. Figure 2 ;

[0066] Figure 14 This is a schematic diagram of the composition structure of the second server proposed in the embodiments of this application. Figure 1 ;

[0067] Figure 15 This is a schematic diagram of the composition structure of the second server proposed in the embodiments of this application. Figure 2 ;

[0068] Figure 16 This is a schematic diagram of the composition structure of the third device proposed in the embodiments of this application. Figure 1 ;

[0069] Figure 17 This is a schematic diagram of the composition structure of the third device proposed in the embodiments of this application. Figure 2 . Detailed Implementation

[0070] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining the relevant application and not for limiting the application. Furthermore, it should be noted that, for ease of description, only the parts related to the relevant application are shown in the accompanying drawings.

[0071] Current quantum key relay technologies mainly include the following two types: Figure 1 Schematic diagram of quantum key transfer architecture Figure 1 ,like Figure 1As shown, (1) the QKD device connects to the quantum key relay device. The QKD-A device is the QKD key sender, and the QKD-B device is the QKD key receiver. The role of the quantum key relay is to connect to the interface for calling or pushing quantum keys and pass the quantum key to the end user (which can be one or more) through transparent transmission / forwarding. The quantum key relay itself does not generate or store any keys. (2) the QKD device connects to the quantum key relay management device. The QKD-A device is the QKD key sender, and the QKD-B device is the QKD key receiver. Figure 2 Schematic diagram of quantum key transfer architecture Figure 2 ,like Figure 2 As shown, the quantum key management device actively initiates a request to access the quantum key and stores the received quantum key in a database for key management. Quantum keys deployed in different metropolitan area networks are synchronized through the quantum key management platform to ensure that the quantum keys stored in the two quantum key management devices are paired and matched during distribution. The distribution of quantum keys is completed by the quantum key management device.

[0072] However, for the first technical solution, the quantum key relay device does not have the function of storing and managing quantum keys. It only transmits the calls from the upper-layer terminal to the lower-layer QKD device, which changes the distribution of quantum keys between the QKD device and the terminal from one-to-one to one-to-many. However, since the keys generated by quantum keys QKD-A and QKD-B are output in pairs, if multiple terminals call the quantum QKD keys concurrently, the upper layer needs to perform pair matching of the acquired quantum keys. The communication channel opened by the upper layer for matching quantum keys becomes a security vulnerability. In addition, the quantum key relay device becomes one of the bottlenecks in QKD key distribution, affecting the distribution efficiency of quantum QKD keys. The second technical solution involves a quantum key management device that stores and manages the quantum key database sent by the QKD device. Terminals are customized with a quantum key management client program, requiring pre-registration, authentication, and quantum key allocation to establish quantum-secure communication with the quantum key management device. Quantum keys are then distributed through this communication channel. To ensure that terminals across metropolitan area networks receive a matching pair of quantum keys, a quantum key management platform is needed for message synchronization. Furthermore, communication between the quantum key management platform and each quantum key management device also requires a quantum-secure communication channel. This method demands customized installation of a matching key management client on the terminal, requiring deep integration of the business terminal with quantum key management. It lacks flexibility and universal applicability. Additionally, because all quantum keys must be stored in the quantum key management device, the quantum key device becomes a security vulnerability.

[0073] In summary, the main problems with current quantum key relay technology solutions include: when a terminal device needs a quantum key, the quantum key relay device will initiate a call to the QKD device and then forward the obtained quantum key to the terminal device. During busy periods, the frequent calls and forwarding processes will affect the distribution efficiency of quantum keys, making the quantum key relay device one of the bottlenecks in quantum key distribution and leading to a decrease in the distribution efficiency of quantum keys.

[0074] To address the current issue of declining efficiency in quantum key distribution, this application provides a quantum key acquisition method, related equipment, storage medium, and computer program product. A first device receives first key request information sent by a first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The device determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called. If the first information meets the preset extraction requirements, the device reads the encrypted first quantum key corresponding to the first information from a first memory address range and sends the first quantum key and the first key identifier corresponding to the second quantum key. The first server receives a second key request from a first terminal device. The second key request includes one or more of the following: a first memory address range containing the memory address range of a first device, which includes at least a gateway device; a second quantum key containing a decrypted quantum key; the first memory address range storing N encrypted quantum keys, each containing the first quantum key, where N is a positive integer; the first server receives a second key request from a first terminal device; the second key request includes one or more of the following: a third identifier corresponding to the first terminal device, key length information, and key unit information; the server sends a first key request to the first device based on the second key request; the server receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key from the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.The second server receives a third key request message from the second terminal device; wherein the third key request message includes a fourth identification message corresponding to the second terminal device and a first key identifier; based on the third key request message, it sends a fourth key request message to the third device; it receives an encrypted eighth quantum key from the third device; wherein the eighth quantum key and the first quantum key are symmetric keys; it sends the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data; the third device receives a fourth key request message from the second server; wherein the fourth key request message includes a fifth identification message corresponding to the second server and a first key identifier. Key identification; based on the first key identifier, query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range, wherein the second memory address range includes the memory address range of the third device, the second memory address range includes M second data structure objects, the M second data structure objects respectively represent M third key-value pairs, the third key-value pairs include a key and a value, the key is used to represent the key identifier, the value is used to represent the encrypted quantum key, the encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys; send the eighth quantum key to the second server, so that the second server sends the eighth quantum key to the second terminal device. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can store N encrypted quantum keys in the memory address range in advance, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the efficiency of quantum key distribution.

[0075] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0076] Example 1

[0077] This application provides a quantum key acquisition method, which is applied to a first device. Figure 3 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 1 ,like Figure 3 As shown, the quantum key acquisition method may include the following steps:

[0078] Step 101: Receive the first key request information sent by the first server; wherein the first key request information includes one or more of the first identifier information, key length information and key unit information corresponding to the first server.

[0079] In embodiments of this application, the first device may receive a first key request message sent by a first server.

[0080] It should be noted that, in the embodiments of this application, the first device may include a gateway device, and this application does not specifically limit the device type of the first device.

[0081] It should be noted that, in the embodiments of this application, the first server may include a business server, which may be connected to one or more terminal devices, thereby avoiding the first device corresponding to multiple terminal devices and improving the transmission security of quantum keys.

[0082] It should be noted that, in the embodiments of this application, the first key request information includes one or more of the first identifier information, key length information, and key unit information corresponding to the first server, and may also include other parameter information. This application does not specifically limit the number and type of information included in the first key request information.

[0083] Step 102: Determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called.

[0084] In the embodiments of this application, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements.

[0085] It should be noted that, in the embodiments of this application, the first information may include first parameter information and second parameter information, and may also include other parameter information. This application does not specifically limit the number and type of information included in the first information.

[0086] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it may determine that the first information meets the preset extraction requirements if the first parameter information meets the first data type and the second parameter information is greater than the first preset threshold; wherein, the first data type includes integer type.

[0087] It should be noted that in the embodiments of this application, the first preset threshold can be any integer, for example, the first preset threshold can be set to 10. This application does not specifically limit the size of the first preset threshold.

[0088] For example, in an embodiment of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, if the data type of the quantum key corresponding to the key length information and key unit information in the first information is integer, and the cumulative number of calls to the quantum key corresponding to the key length information and key unit information is greater than 10, then the first information is determined to meet the preset extraction requirements.

[0089] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it may determine that the first information does not meet the preset extraction requirements if the first parameter information meets the first data type and the second parameter information is less than or equal to the first preset threshold.

[0090] For example, in an embodiment of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, if the data type of the quantum key corresponding to the key length information and key unit information in the first information is integer, and the cumulative number of calls to the quantum key corresponding to the key length information and key unit information is less than or equal to 10 times, then it is determined that the first information does not meet the preset extraction requirements.

[0091] It should be noted that, in the embodiments of this application, the first memory address range includes the memory address range of the first device, and the first memory address range may include M first data structure objects, the M first data structure objects include M first key-value pairs, the first key-value pairs include a key and a value, the key is used to represent the key identifier, and the value is used to represent the encrypted quantum key.

[0092] It should be noted that, in the embodiments of this application, the first data structure object includes a QHashMap data structure object, and this application does not specifically limit the type of the first data structure object.

[0093] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it can also determine that the first information meets the preset extraction requirements if the first parameter information meets the second data type and the first data structure object is not empty; wherein, the second data type includes the HashMap data type.

[0094] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it can also determine that the first information does not meet the preset extraction requirements if the first parameter information meets the second data type and the first data structure object is empty.

[0095] Step 103: If the first information meets the preset extraction requirements, read the encrypted first quantum key corresponding to the first information from the first memory address range, and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key after decryption of the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0096] In the embodiments of this application, after determining whether the first information corresponding to the first key request information meets the preset extraction requirements, the first device can read the encrypted first quantum key corresponding to the first information from the first memory address range if the first information meets the preset extraction requirements, and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server.

[0097] It should be noted that in the embodiments of the application, the first key identifier can be generated based on the second quantum key. For example, assuming that the second quantum key is 256 bits and is denoted as QKD-key, the SM3 / SHA-256 data signature algorithm can be used to calculate the hash value of the quantum key, and then a 256-bit hash value can be generated, denoted as QID (first key identifier). The algorithm can be as shown in the following formula (1).

[0098] QID=QHash(QKD-key)=SM3.HASH(QKD-key||'QHashSecret') (1)

[0099] Here, QKD-key represents the second quantum key, and QID represents the first key identifier.

[0100] It should be noted that, in the embodiments of the application, the first memory address range includes the memory address range of the first device. In this embodiment, N encrypted quantum keys can be stored in the first memory address range in advance. Thus, when the first information corresponding to the first key request information meets the preset extraction requirements, the corresponding encrypted quantum key can be directly obtained from the memory address range without calling the QKD device, which greatly improves the distribution efficiency of quantum keys.

[0101] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the first data type and the second parameter information is less than or equal to the first preset threshold, after the first device determines that the first information does not meet the preset extraction requirements, it can send a first key call request to the second device. The first key call request carries at least one or more of the second identification information, key length information, and key unit information corresponding to the first device. Then, it can receive the encrypted quantum key sent by the second device, and decrypt the encrypted quantum key to obtain the third quantum key. Then, it can send the second key identifier corresponding to the third quantum key and the encrypted third quantum key to the first server.

[0102] It should be noted that, in the embodiments of the application, the second device is at least used for distributing keys, and the second device may include a QKD device. This application does not specifically limit the device type of the second device.

[0103] In other words, in the embodiments of this application, after determining that the first information does not meet the preset extraction requirements, the first device can initiate a key call request to the second device, and then receive the encrypted quantum key sent by the second device, and then send the corresponding key and key identifier to the first server.

[0104] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the second data type (HashMap data type) and the first data structure object is not empty, after the first device determines that the first information meets the preset extraction requirements, it can obtain the second key-value pair corresponding to the first key request information from the first data structure object; then it can obtain the encrypted fourth quantum key based on the second key-value pair, and decrypt the encrypted fourth quantum key to obtain the fifth quantum key; then it can send the third key identifier corresponding to the fifth quantum key and the encrypted fourth quantum key to the first server.

[0105] It should be noted that in the embodiments of the application, the third key identifier is obtained based on the fifth quantum key, and the third key identifier can be obtained through the above formula (1).

[0106] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the second data type (HashMap data type) and the first data structure object is empty, after the first device determines that the first information does not meet the preset extraction requirements, it can send a second key call request to the second device; wherein, the second device is at least used to distribute keys, and the second key call request carries one or more of the second identification information, key length information, and key unit information corresponding to the first device; then, it can receive the encrypted sixth quantum key sent by the second device, and decrypt the encrypted sixth quantum key to obtain the seventh quantum key; then, it can store the fourth key identifier corresponding to the seventh quantum key and the encrypted sixth quantum key in the first memory address range so that the first server can perform quantum key call processing and record the first timestamp of storing the fourth key identifier and the encrypted sixth quantum key.

[0107] It should be noted that, in the embodiments of the application, the second device may be a QKD device, and this application does not specifically limit the device type of the second device.

[0108] In other words, in the embodiment of the application, when the first parameter information meets the second data type (HashMap data type) and the first data structure object is empty, after the first device determines that the first information does not meet the preset extraction requirements, it can send a key call request to the QKD device, store the encrypted quantum key and key identifier sent by the second device in the first memory address range, and record the first timestamp of the storage.

[0109] Furthermore, in the embodiments of the application, the first device can determine whether to delete the target data structure object based on the current timestamp and the first timestamp, and / or can determine whether to delete the target data structure object based on the current timestamp and the second timestamp; wherein, the target data structure object includes a key identifier and an encrypted quantum key stored under a preset timestamp, the preset timestamp includes the first timestamp and / or the second timestamp, the second timestamp includes the timestamp corresponding to the encrypted first quantum key, the current timestamp includes the current timestamp corresponding to the encrypted first quantum key, and / or the current timestamp corresponding to the encrypted sixth quantum key; then, under the condition that the deletion of the target data structure object is satisfied, the key-value pairs in the target data structure object can be released.

[0110] It should be noted that, in the embodiments of this application, when the first device determines that the conditions for deleting the target data structure object are met, it releases the key-value pairs in the target data structure object. This can be done by releasing the key identifier and the encrypted quantum key corresponding to the key-value pairs in the target data structure object.

[0111] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the first timestamp, if the difference between the current timestamp and the first timestamp is greater than the second preset threshold, it is determined that the condition for deleting the target data structure object is met.

[0112] It should be noted that in the embodiments of this application, the second preset threshold can be 1200 seconds or other values, and this application does not specifically limit the size of the second preset threshold.

[0113] For example, in an embodiment of this application, if the difference between the current timestamp corresponding to the encrypted sixth quantum key and the first timestamp storing the encrypted sixth quantum key is greater than 1200 seconds, then it is determined that the condition for deleting the target data structure object is met.

[0114] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the first timestamp, if the difference between the current timestamp and the first timestamp is less than or equal to the second preset threshold, it is determined that the conditions for deleting the target data structure object are not met.

[0115] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the second timestamp, if the difference between the current timestamp and the second timestamp is greater than the second preset threshold, it is determined that the condition for deleting the target data structure object is met.

[0116] For example, in an embodiment of this application, if the difference between the current timestamp corresponding to the encrypted first quantum key and the second timestamp storing the encrypted first quantum key is greater than 1200 seconds, then it is determined that the condition for deleting the target data structure object is met.

[0117] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the second timestamp, if the difference between the current timestamp and the second timestamp is less than or equal to the second preset threshold, it is determined that the condition for deleting the target data structure object is not met.

[0118] In other words, in the embodiments of this application, the first device can poll the stored quantum keys on a regular basis, release quantum keys that have expired and have not been called, and cache quantum keys with high calling frequency in advance. Compared with the current database storage technology for storing quantum keys, the embodiments of this application can use memory for dynamic storage and release, which can better prevent data leakage, while the read and write speed is higher and the memory space occupied can be dynamically adjusted, thereby improving the distribution efficiency of quantum keys.

[0119] In summary, the embodiments of this application can pre-store N encrypted quantum keys in the memory address range of the first device. After receiving the first key request information sent by the first server, it can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the preset extraction requirements are met, the corresponding encrypted quantum key can be directly obtained from the memory address range without calling the QKD device, which greatly improves the distribution efficiency of quantum keys. At the same time, the first device can also periodically poll the quantum keys stored in the memory address range and release quantum keys that have expired and have not been called, thereby further improving the distribution efficiency of quantum keys.

[0120] This application provides a quantum key acquisition method. The method is applied to a first device, which receives first key request information sent by a first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The method determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called. If the first information meets the preset extraction requirements, the method reads the encrypted first quantum key corresponding to the first information from a first memory address range and sends the first quantum key and the first key identifier corresponding to the second quantum key to the first server. The first memory address range includes the memory address range of the first device, which includes at least a gateway device. The second quantum key includes the decrypted quantum key of the first quantum key. The first memory address range stores N encrypted quantum keys, and the N encrypted quantum keys include the first quantum key, where N is a positive integer. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can store N encrypted quantum keys in the memory address range in advance, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the quantum key distribution efficiency.

[0121] Example 2

[0122] Based on the above embodiments, another embodiment of this application provides a quantum key acquisition method, which is applied to a first server. Figure 4 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 2 ,like Figure 4 As shown, the quantum key acquisition method may include the following steps:

[0123] Step 201: Receive second key request information sent by the first terminal device; wherein the second key request information includes one or more of the third identification information, key length information, and key unit information corresponding to the first terminal device.

[0124] In embodiments of this application, the first server may receive a second key request message sent by the first terminal device.

[0125] It should be noted that, in the embodiments of this application, the first server may include a business server, which may be connected to one or more terminal devices, thereby avoiding the first gateway device corresponding to multiple terminal devices and improving the transmission security of quantum keys.

[0126] It should be noted that, in the embodiments of this application, the second key request information may include one or more of the third identification information, key length information, and key unit information corresponding to the first terminal device, or may include other parameter information. This application does not specifically limit the type and quantity of information included in the second key request information.

[0127] Step 202: Send first key request information to the first device based on the second key request information; wherein, the first key request information includes one or more of the first identifier information corresponding to the first server, key length information, and key unit information.

[0128] In the embodiments of this application, after receiving the second key request information sent by the first terminal device, the first server can send the first key request information to the first device based on the second key request information.

[0129] It should be noted that, in the embodiments of this application, the first device may include a gateway device, and this application does not specifically limit the device type and number of the first device.

[0130] Step 203: Receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and send the first quantum key and the first key identifier to the first terminal device so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0131] In the embodiments of this application, after the first server sends the first key request information to the first device based on the second key request information, it can receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and send the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0132] It should be noted that, in the embodiments of this application, the first server can obtain the server certificate and the corresponding terminal device certificate through the quantum certificate distribution center, thereby enhancing the security of the communication channel between the first server and the first terminal device.

[0133] It should be noted that, in the embodiments of this application, the first server can also receive the second key identifier and the encrypted third quantum key corresponding to the third quantum key sent by the first device; then the second key identifier and the third quantum key can be sent to the first terminal device so that the first terminal device can encrypt the data based on the third quantum key and send the encrypted data and the second key identifier to the second terminal device.

[0134] It should be noted that, in the embodiments of this application, the first server can also receive the third key identifier corresponding to the fifth quantum key sent by the first device and the encrypted fourth quantum key; then it can send the third key identifier and the fourth quantum key to the first terminal device, so that the first terminal device can encrypt the data based on the fourth quantum key, and send the encrypted data and the third key identifier to the second terminal device.

[0135] In summary, the first server can receive the second key request information sent by the first terminal device, and send the first key request information to the first device based on the second key request information. It can then receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, as well as the second key identifier corresponding to the third quantum key and the encrypted third quantum key sent by the first device. It can also receive the third key identifier corresponding to the fifth quantum key and the encrypted fourth quantum key sent by the first device. Finally, it can send the corresponding quantum keys and key identifiers to the first terminal device, enabling the first terminal device to encrypt the data based on the corresponding quantum keys and send the encrypted data and key identifiers to the second terminal device.

[0136] This application provides a quantum key acquisition method. The method is applied to a first server, which can receive a second key request message sent by a first terminal device. The second key request message includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information. Based on the second key request message, the method sends a first key request message to the first device. The first key request message includes one or more of the following: first identification information corresponding to the first server, key length information, and key unit information. The method receives an encrypted first quantum key and a first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts data based on the first quantum key and sends the encrypted data and the first key identifier to the second terminal device. Therefore, the first server can send a first key request message to the first device based on the second key request message sent by the first terminal device. Then, it can receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and send the first quantum key and the first key identifier to the first terminal device. In this embodiment, the first server can be connected to one or more terminal devices, avoiding the first device corresponding to multiple terminal devices, and strengthening the security of the communication channel between the first server and the first terminal device, thereby improving the transmission security of the quantum key.

[0137] Example 3

[0138] Based on the above embodiments, another embodiment of this application provides a quantum key acquisition method, which is applied to a second server. Figure 5 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 3 ,like Figure 5 As shown, the quantum key acquisition method may include the following steps:

[0139] Step 301: Receive the third key request information sent by the second terminal device; wherein the third key request information includes the fourth identification information and the first key identifier corresponding to the second terminal device.

[0140] In embodiments of this application, the second server may receive a third key request message sent by the second terminal device.

[0141] It should be noted that, in the embodiments of this application, the second server may include a business server, which may be connected to one or more terminal devices, thereby avoiding the gateway device corresponding to multiple terminal devices and improving the transmission security of quantum keys.

[0142] It should be noted that, in the embodiments of this application, the second server can obtain the server certificate and the corresponding terminal device certificate through the quantum certificate distribution center, thereby enhancing the security of the communication channel between the second server and the second terminal device.

[0143] It should be noted that, in the embodiments of this application, the third key request information includes the fourth identification information and the first key identification corresponding to the second terminal device, and may also include other parameter information. This application does not specifically limit the type and quantity of information included in the third key request information.

[0144] Step 302: Send a fourth key request to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes the fifth identification information and the first key identifier corresponding to the second server.

[0145] In the embodiments of this application, after receiving the third key request information sent by the second terminal device, the second server can send the fourth key request information to the third device based on the third key request information.

[0146] It should be noted that, in the embodiments of this application, the third device may include a gateway device, and this application does not specifically limit the device type and number of the first device.

[0147] It should be noted that in the embodiments of this application, the clocks of the third device and the second device are consistent, that is, the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operation based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. On this basis, the data transmission efficiency between terminal devices can be improved.

[0148] Step 303: Receive the encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys.

[0149] In the embodiments of this application, after the second server sends the fourth key request information to the third device based on the third key request information, it can receive the encrypted eighth quantum key sent by the third device.

[0150] Step 304: Send the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0151] In the embodiments of this application, after receiving the encrypted eighth quantum key sent by the third device, the second server can send the eighth quantum key to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0152] In other words, in the embodiments of this application, after receiving the third key request information sent by the second terminal device, the second server can forward the key request information to the third device. The key request information carries a corresponding key identifier, so that the third device can query the corresponding encrypted quantum key based on the key identifier, and send the quantum key returned by the third device to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the quantum key, thereby obtaining the original data.

[0153] It should be noted that, in the embodiments of this application, the second server can also receive a fifth key request information sent by the second terminal device; wherein the fifth key request information includes a fourth identification information and a second key identifier; then it can send a sixth key request information to the third device based on the fifth key request information; wherein the sixth key request information includes a fifth identification information and a second key identifier; furthermore, it can receive an encrypted ninth quantum key sent by the third device; wherein the ninth quantum key and the third quantum key are symmetric keys; and send the ninth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the ninth quantum key to obtain the original data.

[0154] It should be noted that, in the embodiments of this application, the second server can also receive a seventh key request information sent by the second terminal device; wherein the seventh key request information includes a fourth identification information and a third key identifier; then it can send an eighth key request information to the third device based on the seventh key request information; wherein the eighth key request information includes a fifth identification information and a third key identifier; furthermore, it can receive an encrypted tenth quantum key sent by the third device; wherein the tenth quantum key and the fourth quantum key are symmetric keys; and send the tenth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the tenth quantum key to obtain the original data.

[0155] In summary, after receiving the key request information sent by the second terminal device, the second server can forward the key request information to the third device. The key request information carries a corresponding key identifier, so that the third device can query the corresponding encrypted quantum key based on the key identifier. The third device then sends the quantum key returned by the third device to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the quantum key and obtain the original data.

[0156] This application provides a quantum key acquisition method. The method is applied to a second server, which receives a third key request message from a second terminal device. The third key request message includes a fourth identifier and a first key identifier corresponding to the second terminal device. Based on the third key request message, the server sends a fourth key request message to a third device. The third device includes at least a gateway device, and the fourth key request message includes a fifth identifier and the first key identifier corresponding to the second server. The server receives an encrypted eighth quantum key from the third device, where the eighth quantum key and the first quantum key are symmetric keys. The eighth quantum key is then sent to the second terminal device, enabling the second terminal device to decrypt the encrypted data based on the eighth quantum key to obtain the original data. Therefore, the second server can send a key request message to the third device based on corresponding key request information, including the server's identifier and a corresponding key identifier. It can then receive the encrypted quantum key from the third device and send it to the second terminal device, enabling the second terminal device to decrypt the encrypted data based on the quantum key to obtain the original data. The second server in this embodiment can be connected to one or more terminal devices, avoiding the need for a third device to correspond to multiple terminal devices and improving the security of quantum key transmission.

[0157] Example 4

[0158] Based on the above embodiments, another embodiment of this application provides a quantum key acquisition method, which is applied to a third device. Figure 6 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 4 ,like Figure 6 As shown, the quantum key acquisition method may include the following steps:

[0159] Step 401: Receive the fourth key request information sent by the second server; wherein the fourth key request information includes the fifth identification information and the first key identifier corresponding to the second server.

[0160] In embodiments of this application, the third device may receive a fourth key request message sent by the second server.

[0161] It should be noted that, in the embodiments of this application, the third device may include a gateway device, and this application does not specifically limit the device type of the third device.

[0162] Step 402: Based on the first key identifier, query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects represent M third key-value pairs respectively. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0163] In the embodiments of this application, after receiving the fourth key request information sent by the second server, the third device can query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier.

[0164] It should be noted that, in the embodiments of this application, the second data structure object includes a QHashMap data structure object, and this application does not specifically limit the type of the second data structure object.

[0165] It should be noted that in the embodiments of this application, the clocks of the third device and the second device are consistent, that is, the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operation based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. On this basis, the data transmission efficiency between terminal devices can be improved.

[0166] In other words, in the embodiments of this application, the third device and the second device store symmetric quantum keys in their memory address ranges. After receiving the key request information sent by the second server, the third device can query the corresponding key-value pair in the second memory address range based on the key identifier in the key request information, thereby determining the encrypted quantum key corresponding to the key identifier, without having to initiate a key call to the QKD device, which can greatly improve the efficiency of quantum key retrieval.

[0167] Step 403: Send the eighth quantum key to the second server so that the second server can send the eighth quantum key to the second terminal device.

[0168] In the embodiments of this application, after the third device queries the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier, it can send the eighth quantum key to the second server so that the second server can send the eighth quantum key to the second terminal device.

[0169] Furthermore, in the embodiments of this application, the third device can also receive a sixth key request information sent by the second server; wherein, the sixth key request information includes a fifth identification information and a second key identification; then, it can query the encrypted ninth quantum key corresponding to the second key identification in the second memory address range based on the second key identification; and then send the ninth quantum key to the second server so that the second server sends the ninth quantum key to the second terminal device.

[0170] Furthermore, in the embodiments of this application, the third device can also receive the eighth key request information sent by the second server; wherein, the eighth key request information includes the fifth identification information and the third key identification; then, it can query the encrypted tenth quantum key corresponding to the third key identification in the second memory address range based on the third key identification; and then send the tenth quantum key to the second server so that the second server sends the tenth quantum key to the second terminal device.

[0171] It should be noted that, in the embodiments of this application, when the first device receives the encrypted eleventh quantum key sent by the second device, the third device can receive the encrypted twelfth quantum key synchronously pushed by the fourth device and store the twelfth quantum key in the second memory address range; wherein, the fourth device is at least used for key distribution, the twelfth quantum key and the eleventh quantum key are symmetric keys, the eleventh quantum key includes at least the encrypted third quantum key and the encrypted fourth quantum key, the twelfth quantum key includes at least the encrypted ninth quantum key and the encrypted tenth quantum key, and the clocks of the first device and the third device are synchronized.

[0172] It should be noted that, in the embodiments of this application, the second device and the fourth device can be QKD devices, and the second device and the fourth device are peer devices.

[0173] In other words, in the embodiments of this application, when the first device receives the encrypted eleventh quantum key sent by the QKD device, the third device can receive the encrypted twelfth quantum key, which is symmetrical to the encrypted eleventh quantum key, synchronously pushed by the QKD device at the other end.

[0174] In summary, the clocks of the third device and the second device are synchronized, meaning that the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operations based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. After receiving the fourth key request information sent by the second server, the third device can query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier in the fourth key request information, and then send the eighth quantum key to the second server, so that the second server can send the eighth quantum key to the second terminal device.

[0175] This application provides a quantum key acquisition method. The method is applied to a third device, which receives a fourth key request message from a second server. The fourth key request message includes a fifth identifier and a first key identifier corresponding to the second server. Based on the first key identifier, the method queries a second memory address range for an encrypted eighth quantum key corresponding to the first key identifier. The second memory address range includes the memory address range of the third device and contains M second data structure objects. Each of the M second data structure objects represents M third key-value pairs, each containing a key and a value. The key represents the key identifier, and the value represents the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys. The eighth quantum key is then sent to the second server, which in turn sends the eighth quantum key to a second terminal device. Therefore, it can be seen that the symmetric quantum key is stored in the memory address range of the third device and the second device. After receiving the key request information sent by the second server, the third device can query the corresponding key-value pair in the second memory address range based on the key identifier in the key request information, thereby determining the encrypted quantum key corresponding to the key identifier, without having to initiate a key call to the QKD device, which can greatly improve the efficiency of quantum key call.

[0176] Example 5

[0177] Based on the above embodiments, another embodiment of this application provides a quantum key acquisition method. This method is applied to a first device, a first server, a second server, and a third device. The quantum key acquisition method may include the following steps:

[0178] Step 501: The first server receives the second key request information sent by the first terminal device; wherein the second key request information includes one or more of the third identification information, key length information, and key unit information corresponding to the first terminal device.

[0179] It should be noted that, in the embodiments of this application, the first server may include a business server, which may be connected to one or more terminal devices, thereby avoiding the first gateway device corresponding to multiple terminal devices and improving the transmission security of quantum keys.

[0180] It should be noted that, in the embodiments of this application, the second key request information may include one or more of the third identification information, key length information, and key unit information corresponding to the first terminal device, or may include other parameter information. This application does not specifically limit the type and quantity of information included in the second key request information.

[0181] Step 502: The first server sends a first key request information to the first device based on the second key request information; wherein, the first key request information includes one or more of the first identifier information, key length information, and key unit information corresponding to the first server.

[0182] It should be noted that, in the embodiments of this application, the first device may include a gateway device, and this application does not specifically limit the device type and number of the first device.

[0183] Step 503: The first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called.

[0184] It should be noted that, in the embodiments of this application, the first information may include first parameter information and second parameter information, and may also include other parameter information. This application does not specifically limit the number and type of information included in the first information.

[0185] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it may determine that the first information meets the preset extraction requirements if the first parameter information meets the first data type and the second parameter information is greater than the first preset threshold; wherein, the first data type includes integer type.

[0186] It should be noted that in the embodiments of this application, the first preset threshold can be any integer, for example, the first preset threshold can be set to 10. This application does not specifically limit the size of the first preset threshold.

[0187] For example, in an embodiment of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, if the data type of the quantum key corresponding to the key length information and key unit information in the first information is integer, and the cumulative number of calls to the quantum key corresponding to the key length information and key unit information is greater than 10, then the first information is determined to meet the preset extraction requirements.

[0188] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it may determine that the first information does not meet the preset extraction requirements if the first parameter information meets the first data type and the second parameter information is less than or equal to the first preset threshold.

[0189] For example, in an embodiment of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, if the data type of the quantum key corresponding to the key length information and key unit information in the first information is integer, and the cumulative number of calls to the quantum key corresponding to the key length information and key unit information is less than or equal to 10 times, then it is determined that the first information does not meet the preset extraction requirements.

[0190] It should be noted that, in the embodiments of this application, the first memory address range includes the memory address range of the first device, and the first memory address range may include M first data structure objects, the M first data structure objects include M first key-value pairs, the first key-value pairs include a key and a value, the key is used to represent the key identifier, and the value is used to represent the encrypted quantum key.

[0191] It should be noted that, in the embodiments of this application, the first data structure object includes a QHashMap data structure object, and this application does not specifically limit the type of the first data structure object.

[0192] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it can also determine that the first information meets the preset extraction requirements if the first parameter information meets the second data type and the first data structure object is not empty; wherein, the second data type includes the HashMap data type.

[0193] It should be noted that, in the embodiments of this application, when the first device determines whether the first information corresponding to the first key request information meets the preset extraction requirements, it can also determine that the first information does not meet the preset extraction requirements if the first parameter information meets the second data type and the first data structure object is empty.

[0194] Step 504: If the first information meets the preset extraction requirements, the first device reads the encrypted first quantum key corresponding to the first information from the first memory address range, and sends the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key after decryption of the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0195] It should be noted that, in the embodiments of the application, the first memory address range includes the memory address range of the first device. In this embodiment, N encrypted quantum keys can be stored in the first memory address range in advance. Thus, when the first information corresponding to the first key request information meets the preset extraction requirements, the corresponding encrypted quantum key can be directly obtained from the memory address range without calling the QKD device, which greatly improves the distribution efficiency of quantum keys.

[0196] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the first data type and the second parameter information is less than or equal to the first preset threshold, after the first device determines that the first information does not meet the preset extraction requirements, it can send a first key call request to the second device. The first key call request carries at least one or more of the second identification information, key length information, and key unit information corresponding to the first device. Then, it can receive the encrypted quantum key sent by the second device, and decrypt the encrypted quantum key to obtain the third quantum key. Then, it can send the second key identifier corresponding to the third quantum key and the encrypted third quantum key to the first server.

[0197] It should be noted that, in the embodiments of the application, the second device is at least used for distributing keys, and the second device may include a QKD device. This application does not specifically limit the device type of the second device.

[0198] In other words, in the embodiments of this application, after determining that the first information does not meet the preset extraction requirements, the first device can initiate a key call request to the second device, and then receive the encrypted quantum key sent by the second device, and then send the corresponding key and key identifier to the first server.

[0199] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the second data type (HashMap data type) and the first data structure object is not empty, after the first device determines that the first information meets the preset extraction requirements, it can obtain the second key-value pair corresponding to the first key request information from the first data structure object; then it can obtain the encrypted fourth quantum key based on the second key-value pair, and decrypt the encrypted fourth quantum key to obtain the fifth quantum key; then it can send the third key identifier corresponding to the fifth quantum key and the encrypted fourth quantum key to the first server.

[0200] It should be noted that in the embodiments of the application, the third key identifier is obtained based on the fifth quantum key, and the third key identifier can be obtained through the above formula (1).

[0201] It should be noted that, in the embodiments of the application, when the first parameter information satisfies the second data type (HashMap data type) and the first data structure object is empty, after the first device determines that the first information does not meet the preset extraction requirements, it can send a second key call request to the second device; wherein, the second device is at least used to distribute keys, and the second key call request carries one or more of the second identification information, key length information, and key unit information corresponding to the first device; then, it can receive the encrypted sixth quantum key sent by the second device, and decrypt the encrypted sixth quantum key to obtain the seventh quantum key; then, it can store the fourth key identifier corresponding to the seventh quantum key and the encrypted sixth quantum key in the first memory address range so that the first server can perform quantum key call processing and record the first timestamp of storing the fourth key identifier and the encrypted sixth quantum key.

[0202] It should be noted that, in the embodiments of the application, the second device may be a QKD device, and this application does not specifically limit the device type of the second device.

[0203] In other words, in the embodiment of the application, when the first parameter information meets the second data type (HashMap data type) and the first data structure object is empty, after the first device determines that the first information does not meet the preset extraction requirements, it can send a key call request to the QKD device, store the encrypted quantum key and key identifier sent by the second device in the first memory address range, and record the first timestamp of the storage.

[0204] Furthermore, in the embodiments of the application, the first device can determine whether to delete the target data structure object based on the current timestamp and the first timestamp, and / or can determine whether to delete the target data structure object based on the current timestamp and the second timestamp; wherein, the target data structure object includes a key identifier and an encrypted quantum key stored under a preset timestamp, the preset timestamp includes the first timestamp and / or the second timestamp, the second timestamp includes the timestamp corresponding to the encrypted first quantum key, the current timestamp includes the current timestamp corresponding to the encrypted first quantum key, and / or the current timestamp corresponding to the encrypted sixth quantum key; then, under the condition that the deletion of the target data structure object is satisfied, the key-value pairs in the target data structure object can be released.

[0205] It should be noted that, in the embodiments of this application, when the first device determines that the conditions for deleting the target data structure object are met, it releases the key-value pairs in the target data structure object. This can be done by releasing the key identifier and the encrypted quantum key corresponding to the key-value pairs in the target data structure object.

[0206] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the first timestamp, if the difference between the current timestamp and the first timestamp is greater than the second preset threshold, it is determined that the condition for deleting the target data structure object is met.

[0207] It should be noted that in the embodiments of this application, the second preset threshold can be 1200 seconds or other values, and this application does not specifically limit the size of the second preset threshold.

[0208] For example, in an embodiment of this application, if the difference between the current timestamp corresponding to the encrypted sixth quantum key and the first timestamp storing the encrypted sixth quantum key is greater than 1200 seconds, then it is determined that the condition for deleting the target data structure object is met.

[0209] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the first timestamp, if the difference between the current timestamp and the first timestamp is less than or equal to the second preset threshold, it is determined that the conditions for deleting the target data structure object are not met.

[0210] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the second timestamp, if the difference between the current timestamp and the second timestamp is greater than the second preset threshold, it is determined that the condition for deleting the target data structure object is met.

[0211] For example, in an embodiment of this application, if the difference between the current timestamp corresponding to the encrypted first quantum key and the second timestamp storing the encrypted first quantum key is greater than 1200 seconds, then it is determined that the condition for deleting the target data structure object is met.

[0212] It should be noted that, in the embodiments of this application, when the first device determines whether to delete the target data structure object based on the current timestamp and the second timestamp, if the difference between the current timestamp and the second timestamp is less than or equal to the second preset threshold, it is determined that the condition for deleting the target data structure object is not met.

[0213] In other words, in the embodiments of this application, the first device can poll the stored quantum keys on a regular basis, release quantum keys that have expired and have not been called, and cache quantum keys with high calling frequency in advance. Compared with the current database storage technology for storing quantum keys, the embodiments of this application can use memory for dynamic storage and release, which can better prevent data leakage, while the read and write speed is higher and the memory space occupied can be dynamically adjusted, thereby improving the distribution efficiency of quantum keys.

[0214] Step 505: The first server sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key and sends the encrypted data and the first key identifier to the second terminal device.

[0215] It should be noted that, in the embodiments of this application, the first server can obtain the server certificate and the corresponding terminal device certificate through the quantum certificate distribution center, thereby enhancing the security of the communication channel between the first server and the first terminal device.

[0216] It should be noted that, in the embodiments of this application, the first server can also receive the second key identifier and the encrypted third quantum key corresponding to the third quantum key sent by the first device; then the second key identifier and the third quantum key can be sent to the first terminal device so that the first terminal device can encrypt the data based on the third quantum key and send the encrypted data and the second key identifier to the second terminal device.

[0217] It should be noted that, in the embodiments of this application, the first server can also receive the third key identifier corresponding to the fifth quantum key sent by the first device and the encrypted fourth quantum key; then it can send the third key identifier and the fourth quantum key to the first terminal device, so that the first terminal device can encrypt the data based on the fourth quantum key, and send the encrypted data and the third key identifier to the second terminal device.

[0218] Step 506: The second server receives the third key request information sent by the second terminal device; wherein the third key request information includes the fourth identification information and the first key identifier corresponding to the second terminal device.

[0219] It should be noted that, in the embodiments of this application, the second server may include a business server, which may be connected to one or more terminal devices, thereby avoiding the gateway device corresponding to multiple terminal devices and improving the transmission security of quantum keys.

[0220] It should be noted that, in the embodiments of this application, the second server can obtain the server certificate and the corresponding terminal device certificate through the quantum certificate distribution center, thereby enhancing the security of the communication channel between the second server and the second terminal device.

[0221] It should be noted that, in the embodiments of this application, the third key request information includes the fourth identification information and the first key identification corresponding to the second terminal device, and may also include other parameter information. This application does not specifically limit the type and quantity of information included in the third key request information.

[0222] Step 507: The second server sends a fourth key request to the third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes the fifth identification information and the first key identifier corresponding to the second server.

[0223] It should be noted that, in the embodiments of this application, the third device may include a gateway device, and this application does not specifically limit the device type and number of the first device.

[0224] It should be noted that in the embodiments of this application, the clocks of the third device and the second device are consistent, that is, the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operation based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. On this basis, the data transmission efficiency between terminal devices can be improved.

[0225] Step 508: The third device queries the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier. The second memory address range includes the memory address range of the third device and includes M second data structure objects. The M second data structure objects represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0226] It should be noted that, in the embodiments of this application, the second data structure object includes a QHashMap data structure object, and this application does not specifically limit the type of the second data structure object.

[0227] It should be noted that in the embodiments of this application, the clocks of the third device and the second device are consistent, that is, the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operation based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. On this basis, the data transmission efficiency between terminal devices can be improved.

[0228] In other words, in the embodiments of this application, the third device and the second device store symmetric quantum keys in their memory address ranges. After receiving the key request information sent by the second server, the third device can query the corresponding key-value pair in the second memory address range based on the key identifier in the key request information, thereby determining the encrypted quantum key corresponding to the key identifier, without having to initiate a key call to the QKD device, which can greatly improve the efficiency of quantum key retrieval.

[0229] Step 509: The third device sends the eighth quantum key to the second server.

[0230] Furthermore, in the embodiments of this application, the third device can also receive a sixth key request information sent by the second server; wherein, the sixth key request information includes a fifth identification information and a second key identification; then, it can query the encrypted ninth quantum key corresponding to the second key identification in the second memory address range based on the second key identification; and then send the ninth quantum key to the second server so that the second server sends the ninth quantum key to the second terminal device.

[0231] Furthermore, in the embodiments of this application, the third device can also receive the eighth key request information sent by the second server; wherein, the eighth key request information includes the fifth identification information and the third key identification; then, it can query the encrypted tenth quantum key corresponding to the third key identification in the second memory address range based on the third key identification; and then send the tenth quantum key to the second server so that the second server sends the tenth quantum key to the second terminal device.

[0232] It should be noted that, in the embodiments of this application, when the first device receives the encrypted eleventh quantum key sent by the second device, the third device can receive the encrypted twelfth quantum key synchronously pushed by the fourth device and store the twelfth quantum key in the second memory address range; wherein, the fourth device is at least used for key distribution, the twelfth quantum key and the eleventh quantum key are symmetric keys, the eleventh quantum key includes at least the encrypted third quantum key and the encrypted fourth quantum key, the twelfth quantum key includes at least the encrypted ninth quantum key and the encrypted tenth quantum key, and the clocks of the first device and the third device are synchronized.

[0233] It should be noted that, in the embodiments of this application, the second device and the fourth device can be QKD devices, and the second device and the fourth device are peer devices.

[0234] In other words, in the embodiments of this application, when the first device receives the encrypted eleventh quantum key sent by the QKD device, the third device can receive the encrypted twelfth quantum key, which is symmetrical to the encrypted eleventh quantum key, synchronously pushed by the QKD device at the other end.

[0235] Step 510: The second server sends the eighth quantum key to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0236] In other words, in the embodiments of this application, after receiving the third key request information sent by the second terminal device, the second server can forward the key request information to the third device. The key request information carries a corresponding key identifier, so that the third device can query the corresponding encrypted quantum key based on the key identifier, and send the quantum key returned by the third device to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the quantum key, thereby obtaining the original data.

[0237] It should be noted that, in the embodiments of this application, the second server can also receive a fifth key request information sent by the second terminal device; wherein the fifth key request information includes a fourth identification information and a second key identifier; then it can send a sixth key request information to the third device based on the fifth key request information; wherein the sixth key request information includes a fifth identification information and a second key identifier; furthermore, it can receive an encrypted ninth quantum key sent by the third device; wherein the ninth quantum key and the third quantum key are symmetric keys; and send the ninth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the ninth quantum key to obtain the original data.

[0238] It should be noted that, in the embodiments of this application, the second server can also receive a seventh key request information sent by the second terminal device; wherein the seventh key request information includes a fourth identification information and a third key identifier; then it can send an eighth key request information to the third device based on the seventh key request information; wherein the eighth key request information includes a fifth identification information and a third key identifier; furthermore, it can receive an encrypted tenth quantum key sent by the third device; wherein the tenth quantum key and the fourth quantum key are symmetric keys; and send the tenth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the tenth quantum key to obtain the original data.

[0239] In summary, the embodiments of this application can pre-store N encrypted quantum keys in the memory address range of the first device. After receiving the first key request information sent by the first server, it can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the preset extraction requirements are met, the corresponding encrypted quantum key can be directly obtained from the memory address range without calling the QKD device, which greatly improves the distribution efficiency of quantum keys. At the same time, the first device can also periodically poll the quantum keys stored in the memory address range and release quantum keys that have expired and have not been called, thereby further improving the distribution efficiency of quantum keys. Furthermore, the clocks of the third device and the second device are synchronized, meaning that the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operations based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. After receiving the fourth key request information sent by the second server, the third device can query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier in the fourth key request information, and then send the eighth quantum key to the second server so that the second server can send the eighth quantum key to the second terminal device.

[0240] This application provides a quantum key acquisition method, which is applied to a first device, a first server, a second server, and a third device. The first device receives a first key request information sent by the first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The method determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called. If the first information meets the preset extraction requirements, the encrypted first quantum key corresponding to the first information is read from a first memory address range, and the first key identifier corresponding to the first quantum key and the second quantum key is sent to the first server. The first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, and the N encrypted quantum keys include the first quantum key, where N is a positive integer. The first server receives a second key request message from a first terminal device; wherein the second key request message includes one or more of the third identifier information corresponding to the first terminal device, key length information, and key unit information; based on the second key request message, it sends a first key request message to the first device; wherein the first key request message includes one or more of the first identifier information corresponding to the first server, key length information, and key unit information; it receives an encrypted first quantum key and a first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device. The second server receives a third key request message from the second terminal device; wherein the third key request message includes a fourth identifier information corresponding to the second terminal device and a first key identifier; based on the third key request message, it sends a fourth key request message to the third device; it receives an encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys; it sends the eighth quantum key to the second terminal device, so that the second terminal device decrypts the encrypted data based on the eighth quantum key to obtain the original data.The third device receives a fourth key request message sent by the second server; wherein the fourth key request message includes a fifth identifier and a first key identifier corresponding to the second server; based on the first key identifier, it queries the second memory address range for the encrypted eighth quantum key corresponding to the first key identifier, wherein the second memory address range includes the memory address range of the third device, and the second memory address range includes M second data structure objects, each of the M second data structure objects representing M third key-value pairs, each third key-value pair including a key and a value, the key being used to represent the key identifier, and the value being used to represent the encrypted quantum key, the encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair being symmetric keys; the eighth quantum key is sent to the second server, so that the second server sends the eighth quantum key to the second terminal device. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can store N encrypted quantum keys in the memory address range in advance, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the quantum key distribution efficiency.

[0241] Example 6

[0242] Based on the above embodiments, another embodiment of this application provides a quantum key acquisition method. Figure 7 This is a schematic diagram of the quantum key acquisition method proposed in the embodiments of this application. Figure 5 ,like Figure 7 As shown, a method for dynamically optimizing the number of quantum keys cached is implemented on a quantum key relay gateway (between the quantum key relay device (thin middle layer) and the quantum key management (thick middle layer)). After connecting to QKD-A (second device) (transmitter) and QKD-B (fourth device) (receiver), the number of cached quantum keys in the quantum key relay gateway's memory can be dynamically planned and adjusted according to the size of the terminal's call demand and the identifier of the calling terminal. A quantum key sequence polling mechanism is introduced to periodically clean up quantum keys that have not been called for a long time, improving memory utilization and quantum key distribution efficiency, so that the query time complexity of quantum keys at the receiving end quantum key relay gateway remains at O(n). Figure 7As shown, S10 (first device) and S20 (third device) are both quantum key relay service systems, which are the same system deployed in different metropolitan area networks. S11 (first server) and S21 (second server) are the same type of service server, which can be connected to the quantum key relay service system through the intranet by various service terminals. S13 (first terminal device) and S23 (second terminal device) are the user terminals of S11 and S21. The implementation of the service process requires communication between service servers, between service terminals, and between service terminals. S12 and S22 are quantum certificate distribution centers in their respective metropolitan area networks, which are used to issue server certificates and matching terminal certificates to service servers.

[0243] It should be noted that, in the embodiments of this application, the quantum key relay gateway can be a first device and / or a third device.

[0244] It should be noted that, in the embodiments of this application, quantum secure communication is established between the QKD device (the second device or the fourth device) and the quantum key relay gateway (the first device or the third device), and between the quantum key relay gateway and the upper-layer service server (the first server or the second server), using offline quantum key charging and identity authentication. Figure 8 This is a schematic diagram of the quantum key acquisition architecture proposed in an embodiment of this application, as shown below. Figure 8 As shown, S10 (the first server) and S01 (the first device) have a many-to-one relationship, distinguished by S10's unique identifier ID. The quantum key obtained is encrypted using the quantum key corresponding to the ID before transmission. The connection between S01, S02, and the QKD device is similar; S01 and QKD-A have a many-to-one relationship, and each quantum key gateway has a unique identifier ID. The quantum key obtained is encrypted using the quantum key corresponding to the ID before transmission. This process will not be described further below. It is important to note that the clocks of S01 and S02 (the third device) must be synchronized.

[0245] It should be noted that, in the embodiments of this application, Figure 9 This is a schematic diagram of the algorithm flow proposed in the embodiments of this application, such as... Figure 9As shown, S01 and S02 are the same quantum key relay gateway system, with the deployment location distinguished by the flag value. When the quantum key relay gateway system is deployed and connected to the transmitting end of the QKD device (the second device) (denoted as QKD-A), flag = 1, and the functional processing flow of the quantum key relay gateway system (the first device) is S10-S13; when flag = 0, the quantum key relay gateway system (the third device) connects to the receiving end of the QKD device (the fourth device) (QKD-B), and the functional processing flow is S20-S23. The implementation steps of S10-S23 are as follows: Step S10: QKD-A (the second device) connects to S01 (the quantum key relay gateway system (the first device)) and continuously returns quantum keys to S01 according to the call requirements. S01 provides a quantum key call interface to the business server (the first server). Each business server will have a unique BID that identifies the terminal. S10 calls the interface of S01, with the input parameters being the BID of S10, the length (QKD_len) and unit (QKD_unit) of the quantum key requested; Step S11: Based on the BID of the connected business service (first identification information), the requested key length QKD_len (key length information), and the requested key unit QKD_unit (key unit information), a ternary array is created, and QKD_len and QKD_unit are converted into the quantum key length QKD_bits in bits, and Pn is calculated as shown in the following formula (2).

[0246] QKD_len=2 Pn (2)

[0247] It should be noted that, in the embodiments of this application, QKD_mem[BID][Pn] (second parameter information) is used to accumulate the number of times the BID requests a quantum key of size QKD_len and QKD_unit. When the service server (first server) requests a quantum key, S11 (first device) can search for the QKD_mem data item type (first parameter information) in memory. When the data item type (first parameter information) is an integer (first data type), and QKD_mem[ID][[Pn] (second parameter information) is less than or equal to the threshold T (first preset threshold), S11 (first device) calls the quantum key with the same parameters to QKD-A (second device), only replacing the BID (first identifier information) with the ID (second identifier) ​​of S01 (first device). The information is returned by decrypting the return value with the S01 quantum key and calculating the QID. The algorithm is shown in the above formula (1). It is then re-encrypted with the quantum key corresponding to the business service BID and the QID (second key identifier) ​​and the encrypted quantum key (encrypted third quantum key) are returned to the business service A (first server). If it is determined that QKD_mem[ID][Pn] (second parameter information) is greater than T (first preset threshold), then QKD_time[ID][Pn] = current timestamp t1 (second timestamp) and proceed to step S12: decrypt the obtained QKD-key (first quantum key), calculate the QID (first key identifier), perform hash storage in memory, and set QKD_mem[ID][Pn] to point to a QHashMap object, as shown in the following formula (3).

[0248] QHashMap.put(<QID,QKD-key> (3)

[0249] It should be noted that, in the embodiments of this application, when the data type (first parameter information) is HashMap (second data type), the first element value is directly retrieved from QHashMap (first data structure object). <qid:qkd-key>After decrypting with the S01 quantum key, it is re-encrypted with the quantum key corresponding to the business service BID, and the QID (third key identifier) ​​and the encrypted quantum key (encrypted fourth quantum key) are returned to business service A, and the element is deleted. If the data type (first parameter information) is HashMap (second data type) and QHashMap is empty, then QKD_time[ID][Pn] = current timestamp t1, continuously requesting T quantum keys (encrypted sixth quantum key) of length QKD_len and QKD_unit from the QKD device (second device), and writing them into QKD_mem in memory according to the method in step S12 above. The fourth key identifier and the encrypted sixth quantum key can be stored in the first memory address range, and the first timestamp of storing the sixth quantum key is recorded.

[0250] It should be noted that, in the embodiments of this application, the system (first device) can periodically poll the QKD_time (current timestamp) of the quantum key. When the value of the current timestamp t2-QKD_time[ID][Pnt] is greater than the timeout non-call threshold M (second preset threshold), the QHashMap element pointed to by QKD_mem[ID][Pn] (target data structure object) is cleared, and QKD_mem[ID][Pn] = 0 is set.

[0251] For example, in an embodiment of this application, if the difference between the current timestamp corresponding to the encrypted sixth quantum key and the first timestamp storing the encrypted sixth quantum key is greater than 1200 seconds, then it is determined that the condition for deleting the target data structure object is met; when the first device determines whether to delete the target data structure object based on the current timestamp and the first timestamp, if the difference between the current timestamp and the first timestamp is less than or equal to a second preset threshold, then it is determined that the condition for deleting the target data structure object is not met.

[0252] It should be noted that in the embodiments of this application, the second preset threshold can be 1200 seconds or other values, and this application does not specifically limit the size of the second preset threshold.

[0253] In other words, in the embodiments of this application, the first device can poll the stored quantum keys on a regular basis, release quantum keys that have expired and have not been called, and cache quantum keys with high calling frequency in advance. Compared with the current database storage technology for storing quantum keys, the embodiments of this application can use memory for dynamic storage and release, which can better prevent data leakage, while the read and write speed is higher and the memory space occupied can be dynamically adjusted, thereby improving the distribution efficiency of quantum keys.

[0254] It should be noted that, in the embodiments of this application, as... Figure 9 As shown, step S20 may include the following: QKD-B (the fourth device) connects to S02 (the quantum key relay gateway system (the third device)). Each time QKD-A (the second device) returns a QKD-key (encrypted quantum key) to the first device, QKD-B (the fourth device) pushes a symmetric quantum key to S02 (the third device). S02 provides a quantum key call interface to the service server (the second server). Each terminal has a unique ID that identifies the terminal. S20 calls the interface of S02, with the input parameters being QID, S20's BID, and the length (QKD_len) and unit (QKD_unit) of the requested quantum key.

[0255] It should be noted that, in the embodiments of this application, as... Figure 9 As shown, steps S21-S23 are similar to steps S11-S12, except that S02 (the third device) does not actively call the quantum key interface of QKD-B (the fourth device), but is pushed the quantum key, calculates QID and Pn from QKD_key, and stores them in memory using the same algorithm as S01.

[0256] In summary, the embodiments of this application can pre-store N encrypted quantum keys in the memory address range of the first device. After receiving the first key request information sent by the first server, it can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the preset extraction requirements are met, the corresponding encrypted quantum key can be directly obtained from the memory address range without calling the QKD device, which greatly improves the distribution efficiency of quantum keys. At the same time, the first device can also periodically poll the quantum keys stored in the memory address range and release quantum keys that have expired and have not been called, thereby further improving the distribution efficiency of quantum keys. Furthermore, the clocks of the third device and the second device are synchronized, meaning that the time parameters of the third device and the second device are set in the same way. When the second device performs operations such as storing or releasing quantum keys, the third device will perform the corresponding operations based on the same algorithm, thereby ensuring that the quantum keys stored in the third device and the second device are symmetric quantum keys. After receiving the fourth key request information sent by the second server, the third device can query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier in the fourth key request information, and then send the eighth quantum key to the second server so that the second server can send the eighth quantum key to the second terminal device.

[0257] This application provides a quantum key acquisition method, which is applied to a first device, a first server, a second server, and a third device. The first device receives a first key request information sent by the first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The method determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and key unit information has been called. If the first information meets the preset extraction requirements, the encrypted first quantum key corresponding to the first information is read from a first memory address range, and the first key identifier corresponding to the first quantum key and the second quantum key is sent to the first server. The first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, and the N encrypted quantum keys include the first quantum key, where N is a positive integer. The first server receives a second key request message from a first terminal device; wherein the second key request message includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information; based on the second key request message, the server sends a first key request message to the first device; receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device; the second server receives a third key request message from the second terminal device; wherein the third key request message includes fourth identification information corresponding to the second terminal device and the first key identifier; based on the third key request message, the server sends a fourth key request message to the third device; receives the encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys; and sends the eighth quantum key to the second terminal device, so that the second terminal device decrypts the encrypted data based on the eighth quantum key to obtain the original data.The third device receives a fourth key request message sent by the second server; wherein the fourth key request message includes a fifth identifier and a first key identifier corresponding to the second server; based on the first key identifier, it queries the second memory address range for the encrypted eighth quantum key corresponding to the first key identifier, wherein the second memory address range includes the memory address range of the third device, and the second memory address range includes M second data structure objects, each of the M second data structure objects representing M third key-value pairs, each third key-value pair including a key and a value, the key being used to represent the key identifier, and the value being used to represent the encrypted quantum key, the encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair being symmetric keys; the eighth quantum key is sent to the second server, so that the second server sends the eighth quantum key to the second terminal device. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can store N encrypted quantum keys in the memory address range in advance, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the quantum key distribution efficiency.

[0258] Example 5

[0259] Based on the above embodiments, this application provides a first device. Figure 10 Schematic diagram of the composition structure of the first device Figure 1 ,like Figure 10 As shown, the first device 10 includes: a first receiving unit 11, a judging unit 12, a reading unit 13, and a first sending unit 14; wherein,

[0260] The first receiving unit 11 is configured to receive a first key request information sent by the first server; wherein the first key request information carries one or more of the following: first identification information corresponding to the first server, key length information, and key unit information;

[0261] The judgment unit 12 is used to determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called;

[0262] The reading unit 13 is used to read the encrypted first quantum key corresponding to the first information from the first memory address range when the first information meets the preset extraction requirements;

[0263] The first sending unit 14 is used to send the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key after decryption of the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0264] In the embodiments of this application, further, Figure 11 Schematic diagram of the composition structure of the first device Figure 2 ,like Figure 11 As shown, the first device 10 proposed in this application embodiment may further include a first processor 15, a first memory 16 storing instructions executable by the first processor 15, and further, the first device 10 may also include a first communication interface 17 and a first bus 18 for connecting the first processor 15, the first memory 16 and the first communication interface 17.

[0265] In the embodiments of this application, the first processor 15 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit the specific types. The first device 10 may further include a first memory 16, which can be connected to the first processor 15. The first memory 16 is used to store executable program code, which includes computer operation instructions. The first memory 16 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.

[0266] In embodiments of this application, the first bus 18 is used to connect the first communication interface 17, the first processor 15, and the first memory 16, as well as the mutual communication between these devices.

[0267] In embodiments of this application, the first memory 16 is used to store instructions and data.

[0268] Further, in the embodiments of this application, the first processor 15 is configured to receive first key request information sent by a first server; wherein the first key request information includes one or more of the first identifier information, key length information, and key unit information corresponding to the first server; determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein the first information includes first parameter information and second parameter information, the first parameter information characterizing the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information characterizing the cumulative number of calls of the quantum key corresponding to the key length information and the key unit information; if the first information meets the preset extraction requirements, read the encrypted first quantum key corresponding to the first information from the first memory address range, and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0269] In practical applications, the first memory 16 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 15.

[0270] This application provides a first device that receives first key request information sent by a first server. The first key request information includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information. The device determines whether the first information corresponding to the first key request information meets preset extraction requirements. The first information includes first parameter information and second parameter information. The first parameter information represents the data type of the quantum key corresponding to the key length information and key unit information, and the second parameter information represents the cumulative number of calls to the quantum key corresponding to the key length information and key unit information. If the first information meets the preset extraction requirements, the device reads the encrypted first quantum key corresponding to the first information from a first memory address range and sends the first quantum key and the first key identifier corresponding to the second quantum key to the first server. The first memory address range includes the memory address range of the first device, which includes at least a gateway device. The second quantum key includes the quantum key decrypted from the first quantum key. The first memory address range stores N encrypted quantum keys, and the N encrypted quantum keys include the first quantum key, where N is a positive integer. Therefore, after receiving the first key request information sent by the first server, the first device can determine whether the first information corresponding to the first key request information meets the preset extraction requirements. If the first information meets the preset extraction requirements, it can read the encrypted first quantum key corresponding to the first information from the first memory address range and send the first key identifier corresponding to the first quantum key and the second quantum key to the first server. That is, the first device can store N encrypted quantum keys in the memory address range in advance, so that after the first server sends the key request information, it can directly extract the corresponding encrypted first quantum key from the memory address range. This alleviates the problem of excessive quantum key usage during peak periods and insufficient quantum key generation rate, thereby improving the quantum key distribution efficiency.

[0271] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the quantum key acquisition method described above.

[0272] Specifically, the program instructions corresponding to a quantum key acquisition method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a quantum key acquisition method in the storage media are read or executed by an electronic device, the following steps are included:

[0273] Receive a first key request message sent by a first server; wherein the first key request message includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information;

[0274] Determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called;

[0275] If the first information satisfies the preset extraction requirements, the encrypted first quantum key corresponding to the first information is read from the first memory address range, and the first key identifier corresponding to the first quantum key and the second quantum key is sent to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

[0276] This application also provides a computer program product, including a computer program that can be executed by a first processor 15 of a first device 10 to perform the steps described in any of the foregoing methods.

[0277] In the embodiments of this application, further, Figure 12 This is a schematic diagram of the structure of the first server. Figure 1 ,like Figure 12 As shown, the first server 20 includes: a second receiving unit 21 and a second sending unit 22; wherein,

[0278] The second receiving unit 21 is configured to receive a second key request information sent by the first terminal device; wherein the second key request information includes one or more of the third identification information corresponding to the first terminal device, key length information, and key unit information; and to receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device.

[0279] The second sending unit 22 is configured to send a first key request information to the first device based on the second key request information; wherein the first key request information includes one or more of the first identifier information corresponding to the first server, the key length information, and the key unit information; and to send the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0280] In the embodiments of this application, further, Figure 13 This is a schematic diagram of the structure of the first server. Figure 2 ,like Figure 13 As shown, the first server 20 proposed in this application embodiment may further include a second processor 23, a second memory 24 storing instructions executable by the second processor 23, and further, the first server 20 may also include a second communication interface 25 and a second bus 26 for connecting the second processor 23, the second memory 24 and the second communication interface 25.

[0281] In the embodiments of this application, the second processor 23 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit this. The first server 20 may further include a second memory 24, which can be connected to the second processor 23. The second memory 24 is used to store executable program code, which includes computer operation instructions. The second memory 24 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.

[0282] In embodiments of this application, the second bus 26 is used to connect the second communication interface 25, the second processor 23, and the second memory 24, as well as the mutual communication between these devices.

[0283] In embodiments of this application, the second memory 24 is used to store instructions and data.

[0284] Further, in the embodiments of this application, the second processor 23 is configured to receive second key request information sent by the first terminal device; wherein the second key request information includes one or more of the third identification information, key length information, and key unit information corresponding to the first terminal device; send first key request information to the first device based on the second key request information; wherein the first key request information includes one or more of the first identification information, the key length information, and the key unit information corresponding to the first server; receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and send the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0285] In practical applications, the aforementioned second memory 24 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 23.

[0286] This application provides a first server that can receive a second key request information sent by a first terminal device. The second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information. The server then sends a first key request information to the first device based on the second key request information. The first key request information includes one or more of the following: first identification information corresponding to the first server, key length information, and key unit information. The server receives an encrypted first quantum key and a first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts data based on the first quantum key and sends the encrypted data and the first key identifier to the second terminal device. Therefore, the first server can send a first key request message to the first device based on the second key request message sent by the first terminal device. Then, it can receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and send the first quantum key and the first key identifier to the first terminal device. In this embodiment, the first server can be connected to one or more terminal devices, avoiding the first device corresponding to multiple terminal devices, and strengthening the security of the communication channel between the first server and the first terminal device, thereby improving the transmission security of the quantum key.

[0287] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the quantum key acquisition method described above.

[0288] Specifically, the program instructions corresponding to a quantum key acquisition method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a quantum key acquisition method in the storage media are read or executed by an electronic device, the following steps are included:

[0289] The system receives a second key request information sent by a first terminal device; wherein the second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information;

[0290] A first key request information is sent to the first device based on the second key request information; wherein, the first key request information includes one or more of the following: first identification information corresponding to the first server, the key length information, and the key unit information;

[0291] The device receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

[0292] This application also provides a computer program product, including a computer program that can be executed by a second processor 23 of a first server 20 to complete the steps described in any of the foregoing methods.

[0293] In the embodiments of this application, further, Figure 14 This is a schematic diagram of the structure of the second server. Figure 1 ,like Figure 14 As shown, the second server 30 includes: a third receiving unit 31 and a third sending unit 32; wherein,

[0294] The third receiving unit 31 is used to receive a third key request information sent by the second terminal device; wherein the third key request information includes a fourth identification information and a first key identification corresponding to the second terminal device; and to receive an encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys;

[0295] The third sending unit 32 is used to send a fourth key request information to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes a fifth identification information corresponding to the second server and the first key identification; and to send the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0296] In the embodiments of this application, further, Figure 15 This is a schematic diagram of the structure of the second server. Figure 2 ,like Figure 15 As shown, the second server 30 proposed in this application embodiment may further include a third processor 33, a third memory 34 storing instructions executable by the third processor 33, and further, the second server 30 may further include a third communication interface 35 and a third bus 36 for connecting the third processor 33, the third memory 34 and the third communication interface 35.

[0297] In the embodiments of this application, the third processor 33 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other, and this application embodiment does not specifically limit it. The second server 30 may further include a third memory 34, which can be connected to the third processor 33. The third memory 34 is used to store executable program code, which includes computer operation instructions. The third memory 34 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.

[0298] In embodiments of this application, the third bus 36 is used to connect the third communication interface 35, the third processor 33, and the third memory 34, as well as the mutual communication between these devices.

[0299] In embodiments of this application, a third memory 34 is used to store instructions and data.

[0300] Further, in an embodiment of this application, the third processor 33 is configured to receive a third key request information sent by a second terminal device; wherein the third key request information includes a fourth identification information and a first key identifier corresponding to the second terminal device; send a fourth key request information to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes a fifth identification information and the first key identifier corresponding to the second server; receive an encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys; and send the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0301] In practical applications, the aforementioned third memory 34 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the third processor 33.

[0302] This application provides a second server that receives a third key request message from a second terminal device. The third key request message includes a fourth identification information and a first key identifier corresponding to the second terminal device. Based on the third key request message, the server sends a fourth key request message to a third device. The third device includes at least a gateway device, and the fourth key request message includes a fifth identification information and a first key identifier corresponding to the second server. The server also receives an encrypted eighth quantum key from the third device, where the eighth quantum key and the first quantum key are symmetric keys. The server then sends the eighth quantum key to the second terminal device, enabling the second terminal device to decrypt the encrypted data based on the eighth quantum key to obtain the original data. Therefore, the second server can send a key request message to the third device based on corresponding key request information, including the identification information and the corresponding key identifier. It can then receive the encrypted quantum key from the third device and send it to the second terminal device, enabling the second terminal device to decrypt the encrypted data based on the quantum key to obtain the original data. The second server in this embodiment can be connected to one or more terminal devices, avoiding the need for a third device to correspond to multiple terminal devices and improving the security of quantum key transmission.

[0303] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the quantum key acquisition method described above.

[0304] Specifically, the program instructions corresponding to a quantum key acquisition method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a quantum key acquisition method in the storage media are read or executed by an electronic device, the following steps are included:

[0305] Receive a third key request message sent by a second terminal device; wherein the third key request message includes a fourth identification message and a first key identifier corresponding to the second terminal device;

[0306] A fourth key request is sent to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes the fifth identification information corresponding to the second server and the first key identifier;

[0307] Receive the encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys;

[0308] The eighth quantum key is sent to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

[0309] This application also provides a computer program product, including a computer program that can be executed by a third processor 33 of a second server 30 to complete the steps described in any of the foregoing methods.

[0310] This application provides a first device. Figure 16 Schematic diagram of the composition structure of the third device Figure 1 ,like Figure 16 As shown, the third device 40 includes: a fourth receiving unit 41, a query unit 42, and a fourth sending unit 43; wherein,

[0311] The fourth receiving unit 41 is used to receive a fourth key request information sent by the second server; wherein the fourth key request information includes a fifth identification information and a first key identification corresponding to the second server;

[0312] The query unit 42 is used to query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0313] The fourth sending unit 43 is used to send the eighth quantum key to the second server, so that the second server sends the eighth quantum key to the second terminal device.

[0314] In the embodiments of this application, further, Figure 17 Schematic diagram of the composition structure of the third device Figure 2 ,like Figure 17 As shown, the third device 40 proposed in this application embodiment may further include a fourth processor 44, a fourth memory 45 storing instructions executable by the fourth processor 44, and further, the third device 40 may further include a fourth communication interface 46 and a fourth bus 47 for connecting the fourth processor 44, the fourth memory 45 and the fourth communication interface 46.

[0315] In the embodiments of this application, the fourth processor 44 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit the specific types. The third device 40 may further include a fourth memory 45, which can be connected to the fourth processor 44. The fourth memory 45 is used to store executable program code, which includes computer operation instructions. The fourth memory 45 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.

[0316] In embodiments of this application, the fourth bus 47 is used to connect the fourth communication interface 46, the fourth processor 44, and the fourth memory 45, as well as the mutual communication between these devices.

[0317] In embodiments of this application, a fourth memory 45 is used to store instructions and data.

[0318] Further, in the embodiments of this application, the fourth processor 44 is configured to receive a fourth key request information sent by the second server; wherein the fourth key request information includes a fifth identifier and a first key identifier corresponding to the second server; query the encrypted eighth quantum key corresponding to the first key identifier in a second memory address range based on the first key identifier, wherein the second memory address range includes the memory address range of the third device, the second memory address range includes M second data structure objects, the M second data structure objects respectively represent M third key-value pairs, the third key-value pairs include a key and a value, the key is used to represent the key identifier, the value is used to represent the encrypted quantum key, the encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys; and send the eighth quantum key to the second server, so that the second server sends the eighth quantum key to the second terminal device.

[0319] In practical applications, the aforementioned fourth memory 45 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the fourth processor 44.

[0320] This application embodiment provides a third device that receives a fourth key request information sent by a second server. The fourth key request information includes a fifth identifier and a first key identifier corresponding to the second server. Based on the first key identifier, the third device queries a second memory address range for an encrypted eighth quantum key corresponding to the first key identifier. The second memory address range includes the memory address range of the third device and includes M second data structure objects. Each of the M second data structure objects represents M third key-value pairs, each including a key and a value. The key represents the key identifier, and the value represents the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys. The third device then sends the eighth quantum key to the second server, so that the second server sends the eighth quantum key to a second terminal device. Therefore, it can be seen that the symmetric quantum key is stored in the memory address range of the third device and the second device. After receiving the key request information sent by the second server, the third device can query the corresponding key-value pair in the second memory address range based on the key identifier in the key request information, thereby determining the encrypted quantum key corresponding to the key identifier, without having to initiate a key call to the QKD device, which can greatly improve the efficiency of quantum key call.

[0321] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the quantum key acquisition method described above.

[0322] Specifically, the program instructions corresponding to a quantum key acquisition method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a quantum key acquisition method in the storage media are read or executed by an electronic device, the following steps are included:

[0323] Receive a fourth key request message sent by a second server; wherein the fourth key request message includes a fifth identification message and a first key identifier corresponding to the second server;

[0324] Based on the first key identifier, the encrypted eighth quantum key corresponding to the first key identifier is queried in the second memory address range. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys.

[0325] The eighth quantum key is sent to the second server, so that the second server sends the eighth quantum key to the second terminal device.

[0326] This application also provides a computer program product, including a computer program that can be executed by a fourth processor 44 of a third device 40 to perform the steps described in any of the foregoing methods.

[0327] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0328] This application is described with reference to schematic and / or block diagrams of implementations of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the schematic and / or block diagrams can be implemented by computer program instructions, and combinations of blocks in the schematic and / or block diagrams can be implemented. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the schematic and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0329] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the implementation flow diagram. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0330] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0331] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. A quantum key acquisition method, characterized in that, The method is applied to a first device, and the method includes: Receive a first key request message sent by a first server; wherein the first key request message includes one or more of the following: first identifier information corresponding to the first server, key length information, and key unit information; Determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called; If the first information satisfies the preset extraction requirements, the encrypted first quantum key corresponding to the first information is read from the first memory address range, and the first key identifier corresponding to the first quantum key and the second quantum key is sent to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key decrypted from the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

2. The method according to claim 1, characterized in that, The step of determining whether the first information corresponding to the first key request information meets the preset extraction requirements includes: If the first parameter information satisfies the first data type and the second parameter information is greater than the first preset threshold, the first information is determined to meet the preset extraction requirements; wherein, the first data type includes integer type.

3. The method according to claim 1, characterized in that, The step of determining whether the first information corresponding to the first key request information meets the preset extraction requirements includes: If the first parameter information satisfies the first data type and the second parameter information is less than or equal to the first preset threshold, it is determined that the first information does not meet the preset extraction requirements.

4. The method according to claim 1, characterized in that, The first memory address range includes M first data structure objects, each of which includes M first key-value pairs. Each key-value pair includes a key and a value, where the key represents a key identifier and the value represents the encrypted quantum key. The step of determining whether the first information corresponding to the first key request information meets the preset extraction requirements includes: If the first parameter information satisfies the second data type and the first data structure object is not empty, it is determined that the first information satisfies the preset extraction requirements; wherein, the second data type includes the HashMap data type.

5. The method according to claim 1, characterized in that, The step of determining whether the first information corresponding to the first key request information meets the preset extraction requirements includes: If the first parameter information satisfies the second data type and the first data structure object is empty, it is determined that the first information does not meet the preset extraction requirements.

6. The method according to claim 3, characterized in that, The method further includes: Send a first key invocation request to a second device, the second device being used at least to distribute keys, the first key invocation request carrying at least one or more of the second identification information corresponding to the first device, the key length information, and the key unit information; Receive the encrypted quantum key sent by the second device, and decrypt the encrypted quantum key to obtain the third quantum key; The second key identifier corresponding to the third quantum key and the encrypted third quantum key are sent to the first server.

7. The method according to claim 4, characterized in that, The method further includes: Obtain the second key-value pair corresponding to the first key request information from the first data structure object; Based on the second key-value pair, the encrypted fourth quantum key is obtained, and the encrypted fourth quantum key is decrypted to obtain the fifth quantum key; The third key identifier corresponding to the fifth quantum key and the encrypted fourth quantum key are sent to the first server.

8. The method according to claim 5, characterized in that, The method further includes: Send a second key invocation request to a second device; wherein the second device is at least used for distributing keys, and the second key invocation request carries one or more of the following: second identification information corresponding to the first device, the key length information, and the key unit information; Receive the encrypted sixth quantum key sent by the second device, and decrypt the encrypted sixth quantum key to obtain the seventh quantum key; The fourth key identifier corresponding to the seventh quantum key and the encrypted sixth quantum key are stored in the first memory address range so that the first server can perform quantum key calling processing and record the first timestamp of storing the fourth key identifier and the encrypted sixth quantum key.

9. The method according to claim 8, characterized in that, The method further includes: The system determines whether to delete the target data structure object based on the current timestamp and the first timestamp, and / or determines whether to delete the target data structure object based on the current timestamp and the second timestamp; wherein the target data structure object includes a key identifier and an encrypted quantum key stored under a preset timestamp, the preset timestamp includes the first timestamp and / or the second timestamp, the second timestamp includes the timestamp corresponding to the encrypted first quantum key, the current timestamp includes the current timestamp corresponding to the encrypted first quantum key, and / or the current timestamp corresponding to the encrypted sixth quantum key; If the conditions for deleting the target data structure object are met, the key-value pairs in the target data structure object are released.

10. The method according to claim 9, characterized in that, The step of determining whether to delete the target data structure object based on the current timestamp and the first timestamp includes: If the difference between the current timestamp and the first timestamp is greater than the second preset threshold, then it is determined that the conditions for deleting the target data structure object are met.

11. The method according to claim 9, characterized in that, The step of determining whether to delete the target data structure object based on the current timestamp and the first timestamp includes: If the difference between the current timestamp and the first timestamp is less than or equal to the second preset threshold, it is determined that the conditions for deleting the target data structure object are not met.

12. The method according to claim 9, characterized in that, The step of determining whether to delete the target data structure object based on the current timestamp and the second timestamp includes: If the difference between the current timestamp and the second timestamp is greater than the second preset threshold, then it is determined that the conditions for deleting the target data structure object are met.

13. The method according to claim 9, characterized in that, The step of determining whether to delete the target data structure object based on the current timestamp and the second timestamp includes: If the difference between the current timestamp and the second timestamp is less than or equal to the second preset threshold, it is determined that the conditions for deleting the target data structure object are not met.

14. A quantum key acquisition method, characterized in that, The method is applied to a first server, and the method includes: The system receives a second key request information sent by a first terminal device; wherein the second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information; A first key request information is sent to the first device based on the second key request information; wherein, the first key request information includes one or more of the following: first identification information corresponding to the first server, the key length information, and the key unit information; The device receives the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device, and sends the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

15. The method according to claim 14, characterized in that, The method further includes: Receive the second key identifier corresponding to the third quantum key sent by the first device and the encrypted third quantum key; The second key identifier and the third quantum key are sent to the first terminal device, so that the first terminal device encrypts the data based on the third quantum key, and sends the encrypted data and the second key identifier to the second terminal device.

16. The method according to claim 14, characterized in that, The method further includes: Receive the third key identifier corresponding to the fifth quantum key sent by the first device and the encrypted fourth quantum key; The third key identifier and the fourth quantum key are sent to the first terminal device, so that the first terminal device encrypts the data based on the fourth quantum key, and sends the encrypted data and the third key identifier to the second terminal device.

17. A quantum key acquisition method, characterized in that, The method is applied to a second server, and the method includes: Receive a third key request message sent by a second terminal device; wherein the third key request message includes a fourth identification message and a first key identifier corresponding to the second terminal device; A fourth key request is sent to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes the fifth identification information corresponding to the second server and the first key identifier; Receive the encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys; The eighth quantum key is sent to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

18. The method according to claim 17, characterized in that, The method further includes: Receive a fifth key request message sent by the second terminal device; wherein the fifth key request message includes the fourth identification information and the second key identifier; A sixth key request message is sent to the third device based on the fifth key request message; wherein the sixth key request message includes the fifth identification message and the second key identifier; Receive the encrypted ninth quantum key sent by the third device; wherein the ninth quantum key and the third quantum key are symmetric keys; The ninth quantum key is sent to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the ninth quantum key to obtain the original data.

19. The method according to claim 17, characterized in that, The method further includes: Receive a seventh key request message sent by the second terminal device; wherein the seventh key request message includes the fourth identification information and the third key identifier; Based on the seventh key request information, an eighth key request information is sent to the third device; wherein, the eighth key request information includes the fifth identification information and the third key identifier; Receive the encrypted tenth quantum key sent by the third device; wherein the tenth quantum key and the fourth quantum key are symmetric keys; The tenth quantum key is sent to the second terminal device, so that the second terminal device can decrypt the encrypted data based on the tenth quantum key to obtain the original data.

20. A quantum key acquisition method, characterized in that, The method is applied to a third device, and the method includes: Receive a fourth key request message sent by a second server; wherein the fourth key request message includes a fifth identification message and a first key identifier corresponding to the second server; Based on the first key identifier, the encrypted eighth quantum key corresponding to the first key identifier is queried in the second memory address range. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys. The eighth quantum key is sent to the second server, so that the second server sends the eighth quantum key to the second terminal device.

21. The method according to claim 20, characterized in that, The method further includes: Receive the sixth key request information sent by the second server; wherein the sixth key request information includes the fifth identification information and the second key identifier; Based on the second key identifier, query the encrypted ninth quantum key corresponding to the second key identifier in the second memory address range; The ninth quantum key is sent to the second server, so that the second server sends the ninth quantum key to the second terminal device.

22. The method according to claim 20, characterized in that, The method further includes: Receive the eighth key request information sent by the second server; wherein the eighth key request information includes the fifth identification information and the third key identifier; Based on the third key identifier, query the encrypted tenth quantum key corresponding to the third key identifier in the second memory address range; The tenth quantum key is sent to the second server, so that the second server sends the tenth quantum key to the second terminal device.

23. The method according to claim 20, characterized in that, The method further includes: When the first device receives the encrypted eleventh quantum key sent by the second device, it receives the encrypted twelfth quantum key synchronously pushed by the fourth device and stores the twelfth quantum key in the second memory address range; The fourth device is used at least for distributing keys, the twelfth quantum key and the eleventh quantum key are symmetric keys, the eleventh quantum key includes at least the encrypted third quantum key and the encrypted fourth quantum key, the twelfth quantum key includes at least the encrypted ninth quantum key and the encrypted tenth quantum key, and the clocks of the first device and the third device are synchronized.

24. A first device, characterized in that, The first device includes: a first receiving unit, a judging unit, a reading unit, and a first sending unit; wherein, The first receiving unit is configured to receive a first key request information sent by a first server; wherein the first key request information carries one or more of the following: first identification information corresponding to the first server, key length information, and key unit information; The judgment unit is used to determine whether the first information corresponding to the first key request information meets the preset extraction requirements; wherein, the first information includes first parameter information and second parameter information, the first parameter information represents the data type of the quantum key corresponding to the key length information and the key unit information, and the second parameter information represents the cumulative number of times the quantum key corresponding to the key length information and the key unit information has been called; The reading unit is used to read the encrypted first quantum key corresponding to the first information from the first memory address range when the first information meets the preset extraction requirements; The first sending unit is configured to send the first key identifier corresponding to the first quantum key and the second quantum key to the first server; wherein, the first memory address range includes the memory address range of the first device, the first device includes at least a gateway device, the second quantum key includes the quantum key after decryption of the first quantum key, the first memory address range stores N encrypted quantum keys, the N encrypted quantum keys include the first quantum key, and N is a positive integer.

25. A first device, characterized in that, The first device includes: a first processor and a first memory; wherein, The first memory is used to store computer programs that can run on the processor; The first processor is configured to perform the method as described in any one of claims 1-13 when running the computer program.

26. A first server, characterized in that, The first server includes: a second receiving unit and a second sending unit; wherein, The second receiving unit is configured to receive a second key request information sent by the first terminal device; wherein the second key request information includes one or more of the following: third identification information corresponding to the first terminal device, key length information, and key unit information; and to receive the encrypted first quantum key and the first key identifier corresponding to the second quantum key sent by the first device. The second sending unit is configured to send a first key request information to a first device based on the second key request information; wherein the first key request information includes one or more of the first identifier information corresponding to the first server, the key length information, and the key unit information; and to send the first quantum key and the first key identifier to the first terminal device, so that the first terminal device encrypts the data based on the first quantum key, and sends the encrypted data and the first key identifier to the second terminal device.

27. A first server, characterized in that, The first server includes: a second processor and a second memory; wherein, The second memory is used to store computer programs that can run on the processor; The second processor is configured to perform the method as described in any one of claims 14-16 when running the computer program.

28. A second server, characterized in that, The second server includes: a third receiving unit and a third sending unit; wherein, The third receiving unit is configured to receive a third key request information sent by the second terminal device; wherein the third key request information includes a fourth identification information and a first key identification corresponding to the second terminal device; and to receive an encrypted eighth quantum key sent by the third device; wherein the eighth quantum key and the first quantum key are symmetric keys. The third sending unit is configured to send a fourth key request information to a third device based on the third key request information; wherein the third device includes at least a gateway device, and the fourth key request information includes a fifth identification information corresponding to the second server and a first key identification; and to send the eighth quantum key to the second terminal device so that the second terminal device can decrypt the encrypted data based on the eighth quantum key to obtain the original data.

29. A second server, characterized in that, The second server includes: a third processor and a third memory; wherein, The third memory is used to store computer programs that can run on the processor; The third processor is configured to perform the method as described in any one of claims 17-19 when running the computer program.

30. A third device, characterized in that, The third device includes: a fourth receiving unit, a querying unit, and a fourth sending unit; wherein... The fourth receiving unit is used to receive a fourth key request information sent by the second server; wherein the fourth key request information includes a fifth identification information and a first key identification corresponding to the second server; The query unit is used to query the encrypted eighth quantum key corresponding to the first key identifier in the second memory address range based on the first key identifier. The second memory address range includes the memory address range of the third device. The second memory address range includes M second data structure objects. The M second data structure objects respectively represent M third key-value pairs. The third key-value pairs include a key and a value. The key is used to represent the key identifier, and the value is used to represent the encrypted quantum key. The encrypted quantum key contained in the second data structure object and the encrypted quantum key contained in the first data structure object pair are symmetric keys. The fourth sending unit is used to send the eighth quantum key to the second server, so that the second server sends the eighth quantum key to the second terminal device.

31. A third device, characterized in that, The third device includes: a fourth processor and a fourth memory; wherein... The fourth memory is used to store computer programs that can run on the processor; The fourth processor is configured to perform the method as described in any one of claims 20-23 when running the computer program.

32. A computer-readable storage medium, characterized in that, The storage medium stores computer program code, which, when executed by a computer, performs the method described in any one of claims 1-13, 14-16, 17-19, or 20-23.

33. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1-13, 14-16, 17-19, or 20-23.