Quantum electronic student identity card and secure communication method, device and system
By introducing quantum-safe chips and quantum encryption technology into electronic student ID cards, the problem of insufficient data security has been solved, enabling efficient and secure information transmission and identity authentication in a variety of new scenarios.
Patent Information
- Application Number
- CN202411719334.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-12-30
AI Technical Summary
Existing electronic student ID cards lack data security when facing new demands, especially in scenarios such as taking public transportation, campus spending, digital RMB transactions, and free admission authentication at scenic spots and museums, where there is a risk that information can be easily intercepted and copied.
A quantum-safe chip is used to store the quantum key store, and quantum encryption and decryption technologies are used to protect the information. By combining the quantum-safe chip with electronic student ID cards, secure information transmission and system access are achieved.
It improves the information security of electronic student ID cards, ensures data transmission security in new usage scenarios, provides reliable identity authentication and high-level key management functions, and prevents information from being cracked and copied.
Smart Images

Figure CN121234976A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a quantum electronic student card, a secure communication method and device, system, program product and storage medium. BACKGROUND
[0002] Electronic student cards have been popularized in colleges and universities at all levels in China. In addition to basic needs such as attendance, positioning, and communication, other life, financial, and government-related scenarios such as taking public transportation, campus consumption, digital renminbi transactions, and free admission to scenic spots and museums are expected to be represented by the market environment. The electronic student card needs to adapt to more new demands. Some new demands have brought more challenges to the data security of the electronic student card during use. At present, the state and local governments and various educational institutions have a large amount of resources for the age group of primary and secondary school students, and provide rich subsidies and other preferential policies. How to create an efficient and secure electronic student card in line with market trends is a problem we need to solve. SUMMARY
[0003] To solve the above technical problems, the present application provides a quantum electronic student card, a secure communication method and device, system, program product and storage medium.
[0004] The quantum electronic student card provided by the present application comprises an electronic student card and a quantum security chip; wherein,
[0005] The quantum security chip is used for storing a quantum key library, and the quantum key library is used for quantum encryption of first information to be sent by the electronic student card and / or quantum decryption of second information received by the electronic student card;
[0006] The electronic student card is used for sending the quantum encrypted first information and / or receiving the quantum encrypted second information.
[0007] The secure communication method provided by the present application is applied to the above-mentioned quantum electronic student card; wherein, the secure communication method comprises:
[0008] Sending a first request to the quantum security chip, the first request being used for requesting communication;
[0009] After receiving the first response sent by the quantum security chip, requesting and obtaining a first quantum key from the network, the first response being used for responding to communication;
[0010] Selecting a matched second quantum key from the quantum key library stored in the quantum security chip, generating encrypted information based on the first quantum key and the second quantum key, and using the encrypted information to perform quantum encryption on the first information to be sent and / or quantum decryption on the second information received.
[0011] The security communication device provided by the application is a main chip in a quantum electronic student card; the security communication device comprises:
[0012] The interaction unit is configured to send a first request to the quantum security chip, the first request being used to request communication; and receive a first response sent by the quantum security chip, the first response being used to respond to the communication.
[0013] The communication unit is configured to request and obtain a first quantum key from a network.
[0014] The processing unit is configured to select a matched second quantum key from a quantum key library stored in the quantum security chip, generate encrypted information based on the first quantum key and the second quantum key, and perform quantum encryption on first information to be sent and / or quantum decryption on second information received by using the encrypted information.
[0015] The security communication system provided by the application comprises the quantum electronic student card, a quantum security gateway, a quantum security TSM server, and a quantum key cloud control system; wherein,
[0016] The quantum electronic student card is configured to send a second request to the quantum security gateway through a mobile network, the second request being used to request a quantum key.
[0017] The quantum security gateway is configured to send the second request to the quantum security TSM server through an encrypted channel.
[0018] The quantum security TSM server is configured to send the second request to the quantum key cloud control system through an encrypted channel.
[0019] The quantum key cloud control system is configured to send a second quantum key to the quantum security TSM server through an encrypted channel, the second quantum key being a quantum key requested by the second request.
[0020] The quantum security TSM server is configured to send the second quantum key to the quantum security gateway through an encrypted channel.
[0021] The quantum security gateway is configured to send the second quantum key to the quantum electronic student card through a mobile network.
[0022] The quantum electronic student card provided by the application comprises a processor and a memory, the memory being used to store a computer program, and the processor being used to call and run the computer program stored in the memory to execute the above security communication method.
[0023] The computer program product provided by the application comprises a computer program, the computer program being used to implement the above security communication method when executed by a processor.
[0024] The computer-readable storage medium provided in this application is used to store a computer program that causes a computer to execute the above-described secure communication method.
[0025] In the technical solution of this application, the quantum electronic student ID card includes an electronic student ID card and a quantum-secure chip. The quantum-secure chip stores a quantum key store, which is used for quantum encryption of the first information to be sent by the electronic student ID card and / or quantum decryption of the second information received by the electronic student ID card. The electronic student ID card is used to send the quantum-encrypted first information and / or receive the quantum-encrypted second information. Thus, by combining the quantum-secure chip with the electronic student ID card, and by using the quantum-secure chip to encrypt and / or decrypt the electronic student ID card, the secure transmission of information from the electronic student ID card is ensured, and the security of system access is guaranteed. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 1 ;
[0027] Figure 2 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 2 ;
[0028] Figure 3 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 3 ;
[0029] Figure 4 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 4 ;
[0030] Figure 5 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 5 ;
[0031] Figure 6 This is a flowchart illustrating the secure communication method provided in an embodiment of this application;
[0032] Figure 7 This is a schematic diagram of the structural composition of the secure communication device provided in the embodiments of this application;
[0033] Figure 8 This is a schematic diagram of a secure communication system provided in an embodiment of this application;
[0034] Figure 9 This is a schematic diagram of the interaction process of the secure communication system provided in the embodiments of this application;
[0035] Figure 10 This is a schematic diagram of the NFC + quantum security chip dual-module structure provided in the embodiments of this application;
[0036] Figure 11 This is a schematic diagram of the hardware block diagram of the quantum electronic student ID card provided in the embodiments of this application;
[0037] Figure 12 This is a schematic diagram of a quantum application provided in this application via a near-field communication channel;
[0038] Figure 13 This is a schematic structural diagram of a quantum electronic student ID card provided in an embodiment of this application;
[0039] Figure 14 This is a schematic structural diagram of the chip according to an embodiment of this application. Detailed Implementation
[0040] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0041] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0042] It should also be noted that the terms "first," "second," and "third" used in the embodiments of this application are only used to distinguish similar objects and do not represent a specific order of objects. It is understood that "first," "second," and "third" can be interchanged in a specific order or sequence where permissible, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein. The term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship. It should also be understood that the "instruction" mentioned in the embodiments of this application can be a direct instruction, an indirect instruction, or an indication of an association relationship. For example, A instructing B can mean that A directly instructs B, for example, B can be obtained through A; it can also mean that A indirectly instructs B, for example, A instructs C, and B can be obtained through C; or it can mean that there is an association relationship between A and B. It should also be understood that the term "correspondence" mentioned in the embodiments of this application may indicate a direct or indirect correspondence between the two, or an association between the two, or a relationship of instruction and being instructed, configuration and being configured, etc.
[0043] Electronic student IDs are now widely used in schools at all levels across my country. Beyond basic needs like attendance, location tracking, and phone calls, the market anticipates adapting electronic student IDs to new demands in various aspects of life, finance, and government affairs, such as public transportation use, campus spending, digital RMB transactions, and free admission to attractions and museums. Some of these new demands pose greater challenges to data security during the use of electronic student IDs. Currently, national and local governments, as well as various educational institutions, allocate significant resources and offer substantial subsidies and other preferential policies to primary and secondary school students. Creating an efficient and secure electronic student ID that aligns with market trends is a pressing issue that needs to be addressed.
[0044] Quantum encryption technology refers to various security methods for encrypting and transmitting secure data based on the naturally existing and immutable laws of quantum mechanics. Unlike traditional encryption methods based on mathematics, quantum encryption is based on physical laws and is theoretically unbreakable. Currently, quantum encryption technology has been applied in the following fields:
[0045] 1) Financial sector: Quantum encryption technology can be used to protect the security of financial transactions, such as bank transfers and electronic payments.
[0046] 2) Government sector: Government agencies can use quantum encryption technology to protect the transmission of sensitive information, such as national security information and diplomatic secrets.
[0047] 3) Medical field: Quantum encryption technology can be used to protect the security of medical data, such as electronic medical records and medical images.
[0048] 4) In the field of network security: Quantum encryption technology can be used to protect the security of network communications, such as Virtual Private Network (VPN) connections and email.
[0049] Most existing electronic student ID cards lack secure authentication capabilities, only offering basic functions such as attendance, location tracking, and call functionality. Some electronic student ID cards only possess simple identity verification (ID card) features. If the card number is not encrypted, the card information is easily intercepted and copied; even if the card number is encrypted using basic mathematical methods, a powerful computing system can still crack and copy the data through trial and error. Therefore, improving the security of electronic student ID cards is a crucial issue. To address this, the following technical solutions are proposed in the embodiments of this application.
[0050] Quantum-safe chips feature large storage capacity and EAL4+ security certification, making them independent devices for key storage and encryption / decryption. They possess independent processors and storage units to store keys and feature data. Quantum-safe chips offer the following key characteristics: Hardware encryption / decryption: Hardware-level encryption / decryption is more difficult to crack than software-based encryption / decryption; Attack protection: Employs multiple measures to prevent physical and logical attacks; Authentication: Provides reliable authentication to ensure the legitimacy of system access; Key management: Offers advanced key management capabilities to ensure key security.
[0051] To facilitate understanding of the technical solutions of the embodiments of this application, the technical solutions of this application are described in detail below through specific embodiments. The above-mentioned related technologies are optional solutions and can be arbitrarily combined with the technical solutions of the embodiments of this application, all of which fall within the protection scope of the embodiments of this application. The embodiments of this application include at least some of the following contents.
[0052] Figure 1 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 1 ,like Figure 1 As shown, the quantum electronic student ID 100 includes an electronic student ID 101 and a quantum security chip 102; wherein,
[0053] The quantum-safe chip 102 is used to store a quantum key store, which is used to quantum encrypt the first information to be sent by the electronic student ID and / or quantum decrypt the second information received by the electronic student ID.
[0054] Electronic student ID 101 is used to send quantum-encrypted first information and / or receive quantum-encrypted second information.
[0055] Among them, quantum-safe chips can also be called quantum-safe elements (SE).
[0056] In some embodiments, the electronic student ID 101 includes a main chip 10101 and a Near Field Communication (NFC) chip 10102, with the quantum-safe chip 102 encapsulated outside the NFC chip 10102; wherein, the NFC chip 10102 has a first SWP channel and a second SWP channel, the first Single Wire Protocol (SWP) channel is used to connect to a Subscriber Identity Module (SIM) card, and the second SWP channel is used to connect to the quantum-safe chip 102. Figure 2 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 2 ,likeFigure 3 As shown, the electronic student ID 101 also includes a touchscreen 10103, buttons 10104, a speaker (SPK) 10105, a motor 10106, a microphone (MIC) 10107, a power supply 10108, FEM&PA 10109, RFID 10110, a positioning component 10111, a BT 10112, an NFC chip 10102, and a quantum security chip 102. The quantum security chip 102 is packaged outside the NFC chip 10102. Figure 3 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 3 ,like Figure 4 As shown, the NFC chip has a first SWP channel and a second SWP channel. The first SWP channel is used to connect to the SIM card, and the second SWP channel is used to connect to the quantum security chip 102. The main chip transmits data with the quantum security chip through the second SWP channel.
[0057] In some implementations, the electronic student ID 101 includes a main chip 10101 and an NFC chip 10102. The quantum security chip 102 is packaged within the NFC chip 10102 to form a two-in-one chip. The NFC chip 10102 has a first SWP channel for connecting a SIM card. Figure 4 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 5 ,like Figure 5 As shown, the electronic student ID 101 also includes a touch screen 10103, buttons 10104, a speaker (SPK) 10105, a motor 10106, a microphone (MIC) 10107, a power supply 10108, FEM&PA 10109, RFID 10110, a positioning component 10111, BT 10112, and an NFC chip 10102. The quantum security chip 102 is packaged within the NFC chip 10102, forming a two-in-one chip. Figure 5 This is a schematic diagram of the quantum electronic student ID card structure provided in the embodiments of this application. Figure 6 ,like Figure 6 As shown, the NFC chip has a first SWP channel, which is used to connect the SIM card. The second SWP channel will be directly integrated into the NFC chip.
[0058] In some implementations, System-in-a-Package (SIP) technology is used to redesign the wafer-level circuit packaging of the NFC chip and the quantum security chip, encapsulating the two separate chips into a single chip. This involves packaging the quantum security chip into the NFC chip. The resulting encapsulated NFC module can then be used as a pin-to-pin replacement for the NFC module integrated into existing electronic student ID cards. In this way, the encapsulated NFC module not only helps upgrade existing electronic student ID cards with quantum encryption functionality but also avoids many redundant design and manufacturing process modifications.
[0059] The quantum electronic student ID card fully encompasses the functional components of a conventional electronic student ID card in terms of hardware, and incorporates a quantum-safe chip at the same end as the NFC module. This design allows the main chip to communicate with the NFC module and also interact with the quantum-safe chip.
[0060] In some implementations, the NFC chip 10102 is used as a channel for information exchange between the main chip 101 and the quantum-safe chip 102.
[0061] In some implementations, the main chip 101 of the quantum electronic student ID 100 communicates with the NFC chip via the IIC (Inter-Integrated Circuit) protocol, while the NFC chip 10102 connects to the quantum safety chip 102 via a SWIO port. During the interaction between the quantum safety chip 102 and the main chip 101, the NFC chip 10102 only acts as a data channel and does not participate in data processing.
[0062] In some implementations, the main chip 10101 is used to send a first request to the quantum security chip 102, the first request being for requesting communication; the quantum security chip 102, upon receiving the first request from the main chip 10101, sends a first response to the main chip, the first response being for responding to communication; the main chip 10101, upon receiving the first response from the quantum security chip 102, requests and obtains a first quantum key from the network; it is also used to select a matching second quantum key from the quantum key library stored in the quantum security chip 102, generate encrypted information based on the first and second quantum keys, and use the encrypted information to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information. The channel through which this encrypted information is transmitted is called the encryption channel. The main chip 10101 and the quantum security chip 102 interact via NFC.
[0063] In some implementations, the main chip 10101 of the quantum electronic student ID card requests and obtains a first quantum key from the network, including: the quantum electronic student ID card sending a second request to a quantum security gateway via a mobile network, the second request being used to request a quantum key; the quantum security gateway sending the second request to a quantum secure trusted service manager (TSM) server via an encrypted channel; the quantum security TSM server sending the second request to a quantum key cloud control system via an encrypted channel; the quantum key cloud control system sending the first quantum key to the quantum security TSM server via an encrypted channel, the first quantum key being the quantum key requested in the second request; the quantum security TSM server sending the first quantum key to the quantum security gateway via an encrypted channel; and the quantum security gateway sending the first quantum key to the quantum electronic student ID card via the mobile network.
[0064] In some implementations, to further ensure the security of data within the quantum-safe chip, the system also has one or more of the following protection mechanisms:
[0065] If an interaction request is initiated 3 times within 500ms, the quantum safety chip will not respond to the request.
[0066] If three consecutive matching failures occur during the key verification phase, the system will stop the interaction process; if two consecutive three-failures occur during the key verification phase, the system will clear the onboard data.
[0067] Because the quantum-encrypted data stored in the system is completely random, the data cannot be extracted, read, or cracked after the quantum-safe chip suffers physical damage.
[0068] The time interval for initiating interactive requests can be determined based on actual circumstances, and this application does not impose specific limitations on it. Similarly, the number of consecutive matching failures can also be determined based on actual circumstances, and this application does not impose specific limitations on it.
[0069] In some implementations, the quantum key store stored in the quantum-safe chip contains a fixed number of quantum keys. If a second quantum key in the quantum key store has been used, the second quantum key is invalidated after its use.
[0070] In some implementations, the quantum key generation and filling terminal fills the quantum key library stored in the quantum security chip with a fixed number of quantum keys. For example, it can fill 30,000 to 100,000 quantum keys. The specific number of keys filled can be determined according to the actual situation, and this application does not make a specific limitation on this.
[0071] In some implementations, when encrypted information is generated using the first and second quantum keys, and the encrypted information is used to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information, the first and second quantum keys become permanently invalid once the information exchange begins using the encrypted information.
[0072] In some implementations, once the quantum electronic student ID card has exhausted the quantum keys stored in its quantum-safe chip, it needs to be returned to the factory for refilling.
[0073] The technical solution provided in this application embodiment includes a quantum electronic student ID card comprising an electronic student ID card and a quantum-secure chip. The quantum-secure chip stores a quantum key library, which is used for quantum encryption of first information to be sent by the electronic student ID card and / or quantum decryption of second information received by the electronic student ID card. The electronic student ID card is used to send the quantum-encrypted first information and / or receive the quantum-encrypted second information. Thus, by combining the quantum-secure chip with the electronic student ID card, and by using the quantum-secure chip to encrypt and / or decrypt the electronic student ID card, the secure transmission of information from the electronic student ID card is ensured, and the security of system access is guaranteed.
[0074] Figure 7 This is a flowchart illustrating the secure communication method provided in an embodiment of this application, as shown below. Figure 7 As shown, the secure communication method is applied to the aforementioned quantum electronic student ID card; the secure communication method includes the following steps:
[0075] Step 601: Send a first request to the quantum security chip. The first request is used to request communication.
[0076] Step 602: After receiving the first response from the quantum-safe chip, request and obtain the first quantum key from the network. The first response is used to respond to the communication.
[0077] Step 603: Select a matching second quantum key from the quantum key library stored in the quantum-safe chip, generate encrypted information based on the first and second quantum keys, and use the encrypted information to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information.
[0078] In some implementations, the main chip in the quantum electronic student ID first sends a first request to the quantum security chip to request communication. Upon receiving this first request, the quantum security chip sends a first response to the main chip of the quantum electronic student ID to respond to the communication. At this point, the quantum electronic student ID requests and obtains a first quantum key from the network, selects a matching second quantum key from the quantum key library stored in the quantum security chip, and generates encrypted information based on the first and second quantum keys. The main chip uses this encrypted information to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information. The channel through which this encrypted information is transmitted is called the encryption channel. In this way, the secure transmission of electronic student ID information is achieved through the quantum security chip, ensuring the security of the electronic student ID.
[0079] In some implementations, the main chip uses two encrypted channels generated by quantum keys to exchange data. After the exchange is completed, the quantum key used in this exchange becomes permanently invalid. The next exchange requires the main chip to initiate a new request to obtain the key and select another stored key to exchange, and then complete the full verification process.
[0080] In some implementations, to further ensure the security of data within the quantum-safe chip, the system also has one or more of the following protection mechanisms:
[0081] If an interaction request is initiated 3 times within 500ms, the quantum safety chip will not respond to the request.
[0082] If three consecutive matching failures occur during the key verification phase, the system will stop the interaction process; if two consecutive three-failures occur during the key verification phase, the system will clear the onboard data.
[0083] Because the quantum-encrypted data stored in the system is completely random, the data cannot be extracted, read, or cracked after the quantum-safe chip suffers physical damage.
[0084] The time interval for initiating interactive requests can be determined based on actual circumstances, and this application does not impose specific limitations on it. Similarly, the number of consecutive matching failures can also be determined based on actual circumstances, and this application does not impose specific limitations on it.
[0085] In some implementations, the quantum electronic student ID card requests and obtains a first quantum key from the network, including: the quantum electronic student ID card sending a second request to a quantum security gateway via a mobile network, the second request being used to request the quantum key; the quantum security gateway sending the second request to a quantum secure trusted service manager (TSM) server via an encrypted channel; the quantum security TSM server sending the second request to a quantum key cloud control system via an encrypted channel; the quantum key cloud control system sending the first quantum key to the quantum security TSM server via an encrypted channel, the first quantum key being the quantum key requested in the second request; the quantum security TSM server sending the first quantum key to the quantum security gateway via an encrypted channel; and the quantum security gateway sending the first quantum key to the quantum electronic student ID card via the mobile network.
[0086] In some implementations, the quantum key generation and charging terminal is used to charge a fixed number of quantum keys into the quantum secure chip in the quantum electronic student ID card, and to charge the quantum key cloud control system with the quantum secure chip corresponding to the quantum key.
[0087] In some implementations, if the second quantum key in the quantum key store has been used, it becomes invalid after its use. That is, when encrypted information is generated using the first and second quantum keys, and the encrypted information is used to quantum encrypt the first information to be sent and / or to quantum decrypt the received second information, the first and second quantum keys become permanently invalid once information exchange begins using this encrypted information.
[0088] In some implementations, once the quantum electronic student ID card has exhausted the quantum keys stored in its quantum-safe chip, it needs to be returned to the factory for refilling.
[0089] In some implementations, the quantum electronic student ID card is charged with 30,000 to 100,000 quantum keys. The specific number of quantum keys charged is determined based on the actual situation, and this application does not impose a specific limitation on it.
[0090] The technical solution provided in this application involves a quantum electronic student ID card sending a first request to a quantum secure chip, the first request being used to request communication; upon receiving a first response from the quantum secure chip, a first quantum key is requested from the network and obtained, the first response being used to respond to the communication; a matching second quantum key is selected from the quantum key library stored in the quantum secure chip; encrypted information is generated based on the first and second quantum keys; and the encrypted information is used to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information. Thus, the encrypted transmission of electronic student ID card information and / or the decryption of related encrypted information received by the electronic student ID card are achieved through the quantum secure chip, ensuring the security of the electronic student ID card.
[0091] Figure 7 This is a schematic diagram of the structural composition of the secure communication device provided in this application embodiment, applied to the main chip in a quantum electronic student ID card; as shown... Figure 7 As shown, the secure communication device includes:
[0092] The interaction unit 701 is used to send a first request to the quantum security chip, the first request being used to request communication; and to receive a first response sent by the quantum security chip, the first response being used to respond to communication.
[0093] Communication unit 702 is used to request and obtain the first quantum key from the network;
[0094] The processing unit 703 is used to select a matching second quantum key from the quantum key library stored in the quantum-safe chip, generate encrypted information based on the first quantum key and the second quantum key, and use the encrypted information to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information.
[0095] Those skilled in the art should understand that Figure 8 The functions of each unit in the security communication device shown can be understood by referring to the relevant description of the aforementioned method. Figure 8 The functions of each unit in the security communication device shown can be implemented by a program running on a processor or by specific logic circuits.
[0096] This application provides a secure communication system, which includes the aforementioned quantum electronic student ID, quantum secure gateway, quantum secure TSM server, and quantum key cloud control system. The quantum electronic student ID is used to send a second request to the quantum secure gateway via a mobile network, the second request being for a quantum key. The quantum secure gateway is used to send the second request to the quantum secure TSM server via an encrypted channel. The quantum secure TSM server is used to send the second request to the quantum key cloud control system via an encrypted channel. The quantum key cloud control system is used to send a second quantum key to the quantum secure TSM server via an encrypted channel, the second quantum key being the quantum key requested in the second request. The quantum secure TSM server is used to send the second quantum key to the quantum secure gateway via an encrypted channel. The quantum secure gateway is used to send the second quantum key to the quantum electronic student ID via the mobile network.
[0097] In some implementations, the secure communication system further includes a quantum key generation and charging terminal; wherein the quantum key generation and charging terminal is used to charge a fixed number of quantum keys into the quantum secure chip in the quantum electronic student ID card, and to charge the quantum key cloud control system with the quantum secure chip corresponding to the quantum key.
[0098] In some implementations, the quantum key library stored in the quantum-safe chip is filled with a fixed number of quantum keys. For example, 30,000 to 100,000 quantum keys can be filled. The specific number of keys filled can be determined according to the actual situation, and this application does not make a specific limitation on this.
[0099] In some implementations, when encrypted information is generated using the first and second quantum keys, and the encrypted information is used to perform quantum encryption on the first information to be sent and / or quantum decryption on the received second information, the first and second quantum keys become permanently invalid once information exchange begins using the encrypted information.
[0100] In some implementations, once the quantum electronic student ID card has exhausted the quantum keys stored in its quantum-safe chip, it needs to be returned to the factory for refilling.
[0101] In some implementations, to further ensure the security of data within the quantum-safe chip, the system also has one or more of the following protection mechanisms:
[0102] If an interaction request is initiated 3 times within 500ms, the quantum safety chip will not respond to the request.
[0103] If three consecutive matching failures occur during the key verification phase, the system will stop the interaction process; if two consecutive three-failures occur during the key verification phase, the system will clear the onboard data.
[0104] Because the quantum-encrypted data stored in the system is completely random, the data cannot be extracted, read, or cracked after the quantum-safe chip suffers physical damage.
[0105] The time interval for initiating interactive requests can be determined based on actual circumstances, and this application does not impose specific limitations on it. Similarly, the number of consecutive matching failures can also be determined based on actual circumstances, and this application does not impose specific limitations on it.
[0106] For example, Figure 9 This is a schematic diagram of a secure communication system provided in an embodiment of this application, such as... Figure 9 As shown, the quantum electronic student ID interacts with the mobile network via quantum encryption. The mobile network interacts with the quantum security gateway via quantum encryption, the quantum security gateway interacts with the quantum security TSM server via quantum encryption, and the quantum security TSM server interacts with the quantum key management system via quantum encryption. A quantum key generation and charging terminal charges the quantum electronic student ID and the quantum key management system with quantum keys. For example, the number of keys stored in a quantum security chip typically ranges from 30,000 to 100,000. Quantum decryption can also be achieved in this way.
[0107] For example, Figure 2 This is a schematic diagram of the interaction process of the secure communication system provided in the embodiments of this application, such as... Figure 3 As shown, the main chip of the quantum electronic student ID card requests interaction with the quantum-safe chip. Upon receiving a response from the quantum-safe chip, the quantum electronic student ID card interacts with the quantum-safe gateway via a mobile network channel. Through an encrypted channel, the quantum-safe gateway interacts with the quantum-safe TSM server. Based on the unique identification code (such as IMEI number, SN number, etc.) reported by the main chip of the quantum electronic student ID card, the quantum-safe TSM server requests the quantum key cloud control system to issue the corresponding quantum key requested by the quantum electronic student ID card. After receiving the key through the encrypted channel, the main chip of the quantum electronic student ID card will match and verify it with the key stored in the quantum-safe chip. Upon successful verification, the system establishes a secure channel between the server and the terminal using this unique pair of quantum keys and officially begins the interaction of data-sensitive data. After this interaction process ends, this set of quantum keys is permanently invalidated. It is understandable that a key is used in the request process; if the corresponding key used by the responding end does not match, the request will not be responded to correctly; if a match is found, an encrypted channel is established.
[0108] The secure communication system provided in this application embodiment achieves data interaction through an encrypted channel by interacting with an electronic student ID, a quantum security gateway, a quantum security TSM server, and a quantum key cloud control system, thus ensuring the security of data transmission.
[0109] The technical solutions of the embodiments of this application are illustrated below with specific application examples.
[0110] Most existing electronic student ID cards lack secure authentication capabilities, only offering basic functions like attendance, location tracking, and call processing. Some electronic student ID cards only provide simple identity verification (ID card) security. If the card number is not encrypted, the card information is easily intercepted and copied; even if the card number is encrypted using basic mathematical methods, efficient computing systems can still crack and copy the data through sufficient computing power and trial-and-error. Quantum encryption technology, however, is based on the naturally existing and immutable laws of quantum mechanics. Its keys are naturally generated in pairs, possessing uncopyable randomness. Each key is discarded after use, ensuring that key data is unique and lacks observable patterns. Quantum encryption technology cannot be derived through formulas and is unbreakable, possessing the highest level of security in critical areas such as finance and identity verification. Therefore, quantum encryption technology can achieve efficient and secure interaction in sensitive information usage scenarios such as digital RMB consumption, public transportation / tourist attractions, and government identity verification. Currently, mainstream quantum encryption technology products are mostly found on platforms using intelligent main chips and advanced operating systems, such as smartphones, personal computers, and professional payment devices. Mainstream electronic student ID products typically utilize non-intelligent main chips and more basic Real-Time Operating System (RTOS) operating systems due to considerations such as energy consumption and durability. There are currently no hardware, software, or system solutions on the market that integrate RTOS systems and basic main chips with quantum encryption technology. Therefore, this application provides a quantum encryption technology and related system compatible with an RTOS environment. The specific decryption process is explained in the encryption process description and will not be repeated here. The detailed description is as follows:
[0111] 1) Integrating a quantum-safe chip into existing electronic student ID cards and developing a chip operating system (COS) and RTOS software compatible with the RTOS system. Quantum encryption is easier to implement on common smart operating system devices such as Android phones and Windows computers and has already been commercially deployed on a large scale. However, due to limitations in CPU processing power within an RTOS operating system environment, no manufacturer has yet launched such quantum encryption products. This application mainly focuses on the cooperation between the RTOS operating system and the quantum-safe chip, utilizing the unique security mechanisms and algorithms of the quantum-safe chip to complete the quantum encryption and decryption process; the RTOS system CPU only needs to process the data in the interaction channel. Therefore, the terminal product of this application needs to develop a COS operating system and RTOS software compatible with the RTOS system.
[0112] 2) Develop a TSM platform (Trusted Service Management Platform) that matches the quantum electronic student ID card, enabling functions such as sending quantum applications or pre-installing quantum applications via the network.
[0113] 3) The entire system comprises a quantum electronic student ID card and its platform, along with backend components such as a quantum-secure gateway, a quantum-secure TSM server, a quantum key cloud control system, and a quantum key generation and charging terminal. This system enables quantum encryption and decryption, quantum applications, and other functions for the quantum electronic student ID card, ensuring the integrity of product functionality and data security during use by primary and secondary school students in new usage scenarios such as public transportation use, cafeteria spending, digital RMB transactions, and free admission authentication at scenic spots and museums.
[0114] This application proposes an electronic student ID and system based on quantum encryption technology. It innovatively adds quantum encryption technology and related modules to the traditional electronic student ID. Through hardware encryption, it provides high-level protection for identity information, payment data, etc., and provides reliable identity authentication and key management, thus ensuring the security of system access.
[0115] The electronic student ID card technology solution described in this application has two specific implementation methods. The first method uses an independent quantum-safe chip, as detailed below. Figure 10 As shown, the student card terminal uses an independent quantum-safe chip for encrypted information transmission; the second method uses a combined NFC and quantum-safe chip, such as... Figure 10 As shown, the terminal uses the quantum-safe chip in the integrated chip for encrypted information transmission. Method two, which directly replaces the traditional NFC-enabled student ID card design with a Pin-to-Pin NFC module, offers better application operability than method one. Therefore, the following technical solutions mainly focus on method two.
[0116] Method two will use a combined NFC and quantum security chip, that is, encapsulating the quantum security chip into the NFC chip. Utilizing SiP packaging technology, the wafer-level circuit packaging of the NFC chip and the quantum security chip will be redesigned, combining the two independent chips into a single chip to provide more convenient upgrades for older terminals. Figure 11 This is a schematic diagram of the NFC + quantum security chip integrated module structure provided in the embodiments of this application, as shown below. Figure 11As shown, in the original design, the NFC chip had two SWP channels. One channel, SWP1, connected to the Super SIM card, ensuring system compatibility with the Super SIM card's security applications. The other channel, SWP2, connected to the quantum security chip, enabling data transmission between the main chip and the quantum security chip. After using SIP packaging technology, the SWP2 channel is directly integrated into the NFC chip, while SWP1 remains external for the Super SIM card. This encapsulated NFC module can be used for pin-to-pin replacement with the existing NFC module in electronic student ID cards. Thus, the encapsulated NFC module not only helps upgrade existing electronic student ID cards with quantum encryption functionality but also avoids many redundant design and manufacturing process modifications.
[0117] Figure 9 This is a schematic diagram of the hardware block diagram of the quantum electronic student ID card provided in the embodiments of this application, such as... Figure 8 As shown, the quantum electronic student ID card comprehensively covers the functional components of a conventional electronic student ID card in terms of hardware, and incorporates a quantum-safe chip at the same end as the NFC module. This design allows the main chip to communicate with both the NFC module and the quantum-safe chip for data interaction. The main chip communicates with the NFC module and interacts with the quantum-safe chip for data interaction. The quantum-safe chip features large storage capacity and EAL4+ security certification, and is a device capable of independent key storage, encryption, and decryption. It has an independent processor and storage unit to store keys and feature data. The quantum-safe chip has the following characteristics: 1) Hardware encryption: Hardware-level encryption is more difficult to crack than software-based encryption; 2) Attack protection: It employs multiple measures to prevent physical and logical attacks; 3) Identity authentication: It provides reliable identity authentication to ensure the legitimacy of system access; 4) Key management: It provides high-level key management functions to ensure key security. Currently, quantum-safe chips on the market lack support for RTOS operating systems, and quantum encryption devices are still limited by common operating system platforms such as Android or Windows. This application proposes a quantum key application based on the quantum COS operating system and a matching RTOS system application, thereby realizing the interaction between the quantum electronic student ID card main chip and the quantum security chip.
[0118] The quantum electronic student ID card main chip (hereinafter referred to as the main chip) communicates with the NFC chip via the IIC protocol, while the NFC chip connects to the quantum safety chip (also referred to as the quantum SE) via the SWIO port. During the interaction between the quantum safety chip and the main chip, the NFC chip only acts as a data channel and does not participate in data processing. The quantum encryption authentication process is as follows: The main chip first requests communication with the quantum safety chip and waits for a response. Upon receiving the response, the main chip requests quantum key data via the network and selects a key from the quantum key database stored in the quantum safety chip for matching. The specific request process is as follows: Figure 9 As shown, details will not be repeated here. After a successful matching process, the main chip uses two encrypted channels generated by quantum keys to exchange data. After the interaction is complete, the device disconnects, and the quantum key used this time becomes permanently invalid. The next interaction requires the main chip to initiate a new request to obtain a key and select another stored key for interaction, followed by the complete repeat verification process.
[0119] To further ensure the security of data within the quantum-safe chip, the system also has multiple protection mechanisms:
[0120] 1. If an interaction request is initiated 3 times within 500ms, the quantum safety chip will not respond to the request.
[0121] 2. If three consecutive matching failures occur during the key verification stage, the system will stop the interaction process; if two consecutive three-failures occur during the key verification stage, the system will clear the onboard data.
[0122] 3. Because the quantum-encrypted data stored in the system is completely random, the data cannot be extracted, read, or cracked after the quantum-safe chip is physically damaged.
[0123] The system provided in the embodiments of this application is as follows: Figure 12 As shown, this system consists of a quantum electronic student ID card, a quantum secure gateway, a quantum secure TSM server, a quantum key cloud control system, and a quantum key generation and charging terminal. As a terminal used by primary and secondary school students, in addition to basic functions such as attendance, location tracking, calls, button interaction, and screen interaction, the electronic student ID card should also have 2G, 3G, and 4G mobile network connectivity. To ensure the communication security of sensitive and private data, a quantum secure chip is incorporated into the quantum electronic student ID card for the storage and verification of quantum key data. Due to limited storage space, the number of keys stored in the quantum secure chip typically ranges from 30,000 to 100,000. Therefore, ordinary information such as heartbeats, location information, whitelist information, and function requests exchanged between the quantum electronic student ID card and the backend server does not use quantum key encryption but follows the same interaction mode as common electronic student ID cards. Important and sensitive information such as application over-the-air issuance, personalized data transmission and opening, electronic ID card issuance, financial data, and government data will employ quantum encryption.
[0124] The system interaction flow provided in the embodiments of this application is as follows: Figure 12 As shown, when the quantum electronic student ID needs to execute commands requiring quantum encryption, such as background empty issuance, empty activation, and empty charging, the main chip requests interaction with the quantum-safe chip. Upon receiving a response from the quantum-safe chip, the quantum electronic student ID interacts with the quantum-safe gateway via the mobile network channel. Through an encrypted channel, the quantum-safe gateway interacts with the quantum-safe TSM server. Based on the reported unique identification code (such as IMEI number, SN number, etc.), the quantum-safe TSM server requests the quantum key cloud control system to issue the corresponding quantum key requested by the quantum electronic student ID. After receiving the key through the encrypted channel, the main chip of the quantum electronic student ID will match and verify it with the key stored in the quantum-safe chip. Upon successful verification, the system establishes a secure channel between the server and the terminal using this unique pair of quantum keys and officially begins the interaction of data-sensitive data. After this interaction process ends, this set of quantum keys is permanently invalidated.
[0125] Because quantum keys inherently possess physical randomness, each quantum key pair is not generated using cryptographic algorithms. Therefore, each quantum electronic student ID terminal needs to be loaded with 30,000 to 100,000 quantum keys before leaving the factory, depending on the storage capacity of its quantum-safe chip. Simultaneously, the corresponding quantum keys currently stored in the quantum-safe chip are loaded into the quantum key cloud control system. If the quantum keys stored in the current device terminal are exhausted, the quantum electronic student ID needs to be returned to the factory for reloading. Even if the number of quantum keys stored in the terminal is limited, 30,000 or even more keys are sufficient to fully support the daily needs of primary and secondary school students during a three-year education period.
[0126] Figure 13 This is a schematic diagram of a quantum application provided in this application via a near-field communication channel, as shown in the embodiment. Figure 13As shown, in common campus cafeteria consumption or public transportation payments, account and payment information are processed via NFC channels without the need for the quantum electronic student ID card's main chip or other system intervention. Data in such application scenarios lacks the incentive for widespread copying and theft. For example, meals paid for at School A's cafeteria cannot be used at off-campus stores, so users do not need to worry excessively about such data being intercepted and copied, resulting in serious financial or privacy losses. However, data generated during digital currency transactions and government information communication can be redeemed across multiple platforms or lead to improper leakage of personal information. For example, digital RMB accounts can be stolen, causing financial losses, or personal identity information can be leaked, leading to fraud. Therefore, in scenarios involving sensitive information exchange, the system needs to use quantum applications to establish encrypted channels to ensure secure and private communication between the terminal and the server. It is important to note that the corresponding quantum interaction terminals, such as card readers, also need to have quantum encryption capabilities and connect to the backend quantum key cloud control system via the network for key data verification.
[0127] When making a payment, the electronic student ID is simulated as a contactless smart card and sends the simulated RFID number to the contactless card reader for data interaction and verification. Once the verification is successful, the transaction can be completed.
[0128] This application provides a quantum electronic student ID card implementing quantum encryption technology, including its hardware components, a quantum-safe chip based on an RTOS, and a quantum-safe application corresponding to the RTOS operating system. It innovatively adds quantum encryption technology functionality and related modules to the traditional electronic student ID card, providing high-level protection for identity information and payment data through hardware encryption. Based on the quantum electronic student ID card, a system for issuing, opening, and charging quantum keys is constructed, including a quantum-safe gateway, a quantum-safe TSM server, a quantum key cloud control system, and a quantum key generation and charging terminal. This application's quantum electronic student ID card innovatively adds quantum encryption technology functionality and related modules to the traditional electronic student ID card, providing high-level protection for identity information and payment data through hardware encryption; it provides reliable identity authentication and key management, ensuring system access security; and it enables quantum issuance functionality. Furthermore, the solution provided in this application can directly upgrade and transform a traditional electronic student ID card by replacing the NFC module with a Pin-to-Pin module, giving it quantum encryption capabilities. It implements encryption application functionality on the basis of a traditional electronic student ID card, and the encryption level is currently the highest in the market. It combines all the functions of traditional electronic student ID cards, and can also guarantee additional information security needs in other business payment, personal identity verification and government affairs scenarios. It truly realizes the application of electronic student ID cards from a closed market to a public market, greatly enriching the applicable scenarios and frequency of use of electronic student ID cards.
[0129] Figure 13 This is a schematic structural diagram of a quantum electronic student ID card 1300 provided in an embodiment of this application. Figure 13 The quantum electronic student ID 1300 shown includes a processor 1310, which can call and run computer programs from memory to implement the methods in the embodiments of this application.
[0130] Optionally, such as Figure 14 As shown, the quantum electronic student ID card 1300 may further include a memory 1320. The processor 1310 can retrieve and run computer programs from the memory 1320 to implement the methods described in this embodiment.
[0131] The memory 1320 can be a separate device independent of the processor 1310, or it can be integrated into the processor 1310.
[0132] Optionally, such as Figure 14 As shown, the quantum electronic student ID card 1300 may also include a transceiver 1330, and the processor 1310 may control the transceiver 1330 to communicate with other devices. Specifically, it may send information or data to other devices or receive information or data sent by other devices.
[0133] The transceiver 1330 may include a transmitter and a receiver. The transceiver 1330 may further include an antenna, and the number of antennas may be one or more.
[0134] The quantum electronic student ID card 1300 can implement the corresponding processes implemented by the quantum electronic student ID card in the various methods of the embodiments of this application, which will not be described in detail here for the sake of brevity.
[0135] Figure 14 This is a schematic structural diagram of the chip according to an embodiment of this application. The chip 1400 shown includes a processor 1410, which can call and run computer programs from memory to implement the methods in the embodiments of this application.
[0136] Optionally, such as As shown, chip 1400 may further include memory 1420. Processor 1410 can retrieve and run computer programs from memory 1420 to implement the methods described in this embodiment.
[0137] The memory 1420 can be a separate device independent of the processor 1410, or it can be integrated into the processor 1410.
[0138] Optionally, the chip 1400 may also include an input interface 1430. The processor 1410 can control the input interface 1430 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips.
[0139] Optionally, the chip 1400 may also include an output interface 1440. The processor 1410 can control the output interface 1440 to communicate with other devices or chips, specifically, to output information or data to other devices or chips.
[0140] This chip can implement the corresponding processes of the quantum electronic student ID card in the various methods of the embodiments of this application, which will not be described in detail here for the sake of brevity.
[0141] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0142] It should be understood that the processor in the embodiments of this application may be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0143] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0144] It should be understood that the above-described memory is exemplary and not a limiting description. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0145] This application also provides a computer program product, including a computer program.
[0146] When executed by a processor, the computer program implements the corresponding processes of the quantum electronic student ID card in the various methods of the embodiments of this application, which will not be described in detail here for the sake of brevity.
[0147] This application also provides a computer-readable storage medium for storing computer programs.
[0148] The computer program causes the computer to execute the corresponding processes implemented by the quantum electronic student ID in the various methods of the embodiments of this application, which will not be described in detail here for the sake of brevity.
[0149] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0150] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0151] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0153] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0154] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0155] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A quantum electronics student card, characterized by The quantum electronic student card comprises an electronic student card and a quantum security chip; wherein, The quantum security chip is configured to store a quantum key library, and the quantum key library is configured to perform quantum encryption on first information to be sent by the electronic student card and / or quantum decryption on second information received by the electronic student card. The electronic student card is configured to send the quantum-encrypted first information and / or receive the quantum-encrypted second information.
2. The quantum electronics student badge of claim 1, wherein, The electronic student card comprises a main chip and a near field communication (NFC) chip, and the quantum security chip is packaged outside the NFC chip. The NFC chip has a first SWP channel and a second SWP channel, the first SWP channel is configured to connect a subscriber identification (SIM) card, and the second SWP channel is configured to connect the quantum security chip.
3. The quantum electronics student badge of claim 1, wherein, The electronic student card comprises a main chip and an NFC chip, and the quantum security chip is packaged inside the NFC chip to form a two-in-one chip. The NFC chip has a first SWP channel, and the first SWP channel is configured to connect a SIM card.
4. The quantum electronics student card according to claim 2 or 3, characterized in that, The NFC chip is configured to serve as a channel for information interaction between the main chip and the quantum security chip.
5. The quantum electronic student card of claim 2 or 3, wherein The main chip is configured to send a first request to the quantum security chip, and the first request is configured to request communication. The quantum security chip is configured to send a first response to the main chip after receiving the first request sent by the main chip, and the first response is configured to respond to communication. The main chip is configured to request and obtain a first quantum key from a network after receiving the first response sent by the quantum security chip, and is further configured to select a matched second quantum key from a quantum key library stored by the quantum security chip, generate encrypted information based on the first quantum key and the second quantum key, and perform quantum encryption on the first information to be sent and / or quantum decryption on the second information received by using the encrypted information.
6. The quantum electronics student badge of claim 5, wherein, The quantum key library stored by the quantum security chip is filled with a fixed number of quantum keys, and if the second quantum key in the quantum key library is used, the second quantum key is in an invalid state after use.
7. A secure communication method characterized by, The secure communication method is applied to the quantum electronic student card of any one of claims 1 to 6, and the secure communication method comprises: sending a first request to the quantum security chip, and the first request is configured to request communication; after receiving a first response sent by the quantum security chip, requesting and obtaining a first quantum key from a network, and the first response is configured to respond to communication; selecting a matched second quantum key from a quantum key library stored by the quantum security chip, generating encrypted information based on the first quantum key and the second quantum key, and performing quantum encryption on the first information to be sent and / or quantum decryption on the second information received by using the encrypted information.
8. A secure communication device, characterized by The secure communication device is applied to a main chip in a quantum electronic student card, and the secure communication device comprises: The interaction unit is configured to send a first request to the quantum security chip, the first request being used to request communication; and receive a first response sent by the quantum security chip, the first response being used to respond to the communication. The communication unit is configured to request and obtain a first quantum key from a network. The processing unit is configured to select a matched second quantum key from a quantum key library stored in the quantum security chip, generate encryption information based on the first quantum key and the second quantum key, and perform quantum encryption on first information to be sent and / or quantum decryption on second information received by using the encryption information.
9. A secure communication system, characterized by The secure communication system comprises the quantum electronic student card, the quantum security gateway, the quantum security TSM server, and the quantum key cloud control system according to any one of claims 1 to 6; wherein The quantum electronic student card is configured to send a second request to the quantum security gateway through a mobile network, the second request being used to request a quantum key. The quantum security gateway is configured to send the second request to the quantum security TSM server through an encrypted channel. The quantum security TSM server is configured to send the second request to the quantum key cloud control system through an encrypted channel. The quantum key cloud control system is configured to send a first quantum key to the quantum security TSM server through an encrypted channel, the first quantum key being the quantum key requested by the second request. The quantum security TSM server is configured to send the first quantum key to the quantum security gateway through an encrypted channel. The quantum security gateway is configured to send the first quantum key to the quantum electronic student card through a mobile network.
10. The secure communication system of claim 9, wherein, The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system.
11. A quantum electronics student ID card, characterized by The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system.
12. A computer program product, characterised in that, The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system.
13. A computer-readable storage medium, characterized in that, The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number of quantum keys to a quantum security chip in the quantum electronic student card, and replenish quantum keys corresponding to the quantum security chip to the quantum key cloud control system. The secure communication system further comprises a quantum key generation and replenishment terminal; wherein The quantum key generation and replenishment terminal is configured to replenish a fixed number