Method for key replenishment for quantum local area networks

By introducing the concepts of directed keys and local area network keys into quantum local area networks, the problems of single quantum keys and limited authentication methods in existing technologies are solved, enabling the selection of keys for authentication based on needs, and improving the flexibility and security of quantum encrypted communication.

CN121283618BActive Publication Date: 2026-07-21中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
中电信量子信息科技集团有限公司
Filing Date
2025-09-26
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing quantum key injection schemes, the quantum key type is limited, which cannot meet the diverse needs of communication terminals in different scenarios. Furthermore, the authentication methods are limited, and they cannot provide diversified quantum encrypted communication services.

Method used

By introducing the concepts of directional keys and local area network keys into the quantum local area network, the quantum key injector sends different key injecting requests to the central control station. The central control station generates and distributes directional keys or local area network keys according to a preset distribution strategy, ensuring the targeting and diversification of the key injecting process.

Benefits of technology

It enables the selection of appropriate keys for authentication based on the needs of communication terminals, providing quantum encrypted communication services with different ranges, improving the flexibility and security of quantum encrypted communication, and reducing the risk of keys being eavesdropped on and stolen.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121283618B_ABST
    Figure CN121283618B_ABST
Patent Text Reader

Abstract

The application discloses a key filling method for a quantum local area network, the quantum local area network comprising a first control station, a quantum key filling machine and a key distribution center, the first control station and the quantum key filling machine being in communication connection, and the method comprising: the quantum key filling machine sending a key filling request to the first control station. The first control station determines a target distribution strategy from preset distribution strategies according to the type of the key filling request, the preset distribution strategies comprising a first preset key distribution strategy and a second preset key distribution strategy. The first control station distributes the obtained quantum symmetric key to the quantum key filling machine and / or the key distribution center according to the target distribution strategy to perform key filling, wherein the quantum symmetric key distributed based on the first preset key distribution strategy is a directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is a local area network key. Thus, the problem that the quantum key is single and cannot provide diversified services is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum encrypted communication, and more specifically, to a key injection method for quantum local area networks. Background Technology

[0002] Quantum communication has become an important technology in current communication methods, capable of providing quantum-encrypted communication services. When quantum communication is initiated, a quantum key is randomly selected from the key storage device to establish a connection with the backend and verify identity information, achieving quantum-encrypted authentication and ensuring communication security. However, in existing quantum key injection schemes, there is only one type of quantum key, and the injected quantum key is only compared with the key distribution center for authentication, which cannot provide diversified quantum-encrypted communication services for communication terminals. Summary of the Invention

[0003] This application provides a key injection method for quantum local area networks.

[0004] This application provides a key injection method for a quantum local area network (QLAN), wherein the QLAN includes a first control station, a quantum key injection machine, and a key distribution center, and the first control station and the quantum key injection machine establish a communication connection. The method includes: The quantum key injector sends a key injecting request to the first central control station. The key injecting request includes a first key injecting request and / or a second key injecting request. The first key injecting request is used to apply for a directional key, and the second key injecting request is used to apply for a local area network key. The first centralized control station determines a target distribution strategy from a preset distribution strategy based on the type of the key injection request, wherein the preset distribution strategy includes a first preset key distribution strategy and a second preset key distribution strategy; The first centralized control station distributes the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy to perform the key injection. The quantum symmetric key distributed based on the first preset key distribution strategy is the directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is the local area network key.

[0005] Thus, the quantum key generator sends a key injection request to the first central control station. This request includes a first key injection request and / or a second key injection request. The first request is used to request a directional key, and the second request is used to request a local area network (LAN) key. Next, the first central control station determines a target distribution strategy from a preset distribution strategy based on the type of the key injection request. This preset distribution strategy includes a first preset key distribution strategy and a second preset key distribution strategy. Then, the first central control station distributes the acquired quantum symmetric key to the quantum key generator and / or the key distribution center according to the target distribution strategy for key injection. The quantum symmetric key distributed based on the first preset key distribution strategy is the directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is the LAN key. In this way, by dividing the key into directional keys and LAN keys, and corresponding them to different injection requests and distribution strategies, the communication terminal can subsequently select the appropriate key for authentication as needed, thereby obtaining quantum encrypted communication services of different ranges. This solves the problem of existing technologies having a single quantum key and being unable to provide diversified services. Furthermore, the first centralized control station selects the corresponding distribution strategy based on different key filling request types, making the key generation, distribution, and filling process more targeted.

[0006] In some embodiments, the quantum local area network further includes a terminal key storage medium, and the method further includes: The quantum key injection machine acquires device information from the terminal key storage medium; The quantum key injector determines the key injection request based on the device information.

[0007] Thus, the quantum local area network also includes a terminal key storage medium, and the quantum key injector acquires the device information of the terminal key storage medium. Then, based on the device information, the quantum key injector determines the key injecting request. In this way, by acquiring the device information of the terminal key storage medium, the quantum key injector can determine the corresponding key injecting request, making the key injecting more closely aligned with the actual needs of the terminal device and the user. Furthermore, determining the injecting request based on device information ensures that the type and quantity of injected keys match the characteristics and usage scenario of the terminal key storage medium, avoiding the injection of unsuitable keys, thereby guaranteeing the normal use of keys in subsequent quantum encrypted communication and providing reliable support for identity authentication and encryption processes.

[0008] In some embodiments, the method further includes: Upon receiving the key injection request, the first centralized control station generates the quantum symmetric key based on a quantum random number generator; or Upon receiving the key injection request, the first centralized control station determines the quantum symmetric key from the pre-stored quantum keys.

[0009] Thus, upon receiving a key injection request, the first control station generates a quantum symmetric key using a quantum random number generator. Alternatively, upon receiving a key injection request, the first control station determines the quantum symmetric key from a pre-stored set of quantum keys. This provides two key acquisition methods, allowing the first control station to choose the appropriate method based on the actual situation when receiving a key injection request.

[0010] In some implementations, determining the target distribution strategy from a preset distribution strategy based on the type of the key injection request includes: When the key injection request is the first key injection request, the first central control station determines the first preset key distribution strategy as the target distribution strategy; If the key injection request is the second key injection request, the first central control station will determine the second preset key distribution strategy as the target distribution strategy; When the key injection request is either the first key injection request or the second key injection request, the first central control station determines the first preset key distribution strategy and the second preset key distribution strategy as the target distribution strategy.

[0011] Thus, when the key injection request is the first key injection request, the first central control station determines the first preset key distribution strategy as the target distribution strategy. Next, when the key injection request is the second key injection request, the first central control station determines the second preset key distribution strategy as the target distribution strategy. Finally, when the key injection request is both the first and second key injection requests, the first central control station determines both the first and second preset key distribution strategies as the target distribution strategies. In this way, according to different types of key injection requests, the first central control station determines a single or combined target distribution strategy, ensuring that the directed key and the quantum LAN key each adopt a distribution method adapted to their characteristics, making the entire process from quantum key generation to injection more targeted.

[0012] In some embodiments, the quantum local area network further includes a terminal key storage medium, and the step of distributing the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy for key injection includes: When the target distribution strategy is the first preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; The key distribution center stores the first quantum key; The first centralized control station stores the second quantum key from the quantum symmetry key; Based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate first confidential information; The first centralized control station sends the first confidential information to the quantum key injection machine; The quantum key filling machine fills the terminal key storage medium with the first confidential information.

[0013] Thus, under the first preset key distribution strategy, based on the quantum channel, the first centralized control station sends the first quantum key from the quantum symmetric key to the key distribution center. Next, the key distribution center stores the first quantum key. Then, the first centralized control station stores the second quantum key from the quantum symmetric key. Subsequently, based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate first confidential information. Next, the first centralized control station sends the first confidential information to the quantum key injection machine. Finally, the quantum key injection machine injects the terminal key storage medium according to the first confidential information. In this way, for the directional key corresponding to the first preset key distribution strategy, the first centralized control station sends the first quantum key to the key distribution center through the quantum channel, utilizing the high security of the quantum channel to ensure that the key transmission process is not easily eavesdropped. Simultaneously, the first centralized control station stores the second quantum key, encrypts it to generate first confidential information, and sends it to the quantum key injection machine, binding the key injected into the terminal key storage medium to a specific centralized control station. This ensures that the key can only be authenticated through this centralized control station to the key distribution center, achieving secure control of the directional service.

[0014] In some embodiments, the quantum local area network further includes a terminal key storage medium, and the step of distributing the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy for key injection includes: When the target distribution strategy is the second preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; The key distribution center stores the first quantum key; The first centralized control station, based on a classical network, sends the second quantum key from the quantum symmetric key to the quantum key injection machine; The quantum key filling machine fills the terminal key storage medium with the second quantum key.

[0015] Thus, when the target distribution strategy is the second preset key distribution strategy, based on the quantum channel, the first centralized control station sends the first quantum key from the quantum symmetric key to the key distribution center. Next, the key distribution center stores the first quantum key. Then, based on the classical network, the first centralized control station sends the second quantum key from the quantum symmetric key to the quantum key injection machine. Finally, the quantum key injection machine injects the terminal key storage medium according to the second quantum key. In this way, for the local area network key corresponding to the second preset key distribution strategy, the first centralized control station sends the first quantum key to the key distribution center through the quantum channel, ensuring that key transmission is not easily intercepted thanks to the security of the quantum channel. Simultaneously, sending the second quantum key to the quantum key injection machine through the classical network allows the key injected into the terminal key storage medium to be applicable to any centralized control station within the quantum local area network, meeting the service requirement without specific centralized control station restrictions and realizing the universality of encrypted communication services within the local area network.

[0016] In some embodiments, the quantum local area network further includes a second central control station, and the method further includes: If the second control station receives an encryption assistance request sent by the quantum key injection machine, the second control station generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key; The second control station sends the auxiliary encryption key to the first control station; The second central control station sends the auxiliary decryption key to the key distribution center and the quantum key injection machine.

[0017] Thus, if the second control station receives an encryption assistance request from the quantum key injector, it generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station. Finally, the second control station sends the auxiliary decryption key to the key distribution center and the quantum key injector. In this way, by introducing the auxiliary symmetric key generated by the second control station, the first control station uses the auxiliary encryption key to encrypt the quantum symmetric key before transmission, and the key distribution center and the quantum key injector decrypt the key using the auxiliary decryption key. This avoids the risk of plaintext leakage when the first control station and the quantum key injector transmit the key over a classical network, reducing the possibility of key eavesdropping or theft.

[0018] In some embodiments, the method further includes: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; The first centralized control station sends the first encrypted information to the key distribution center; The first centralized control station stores the second quantum key of the quantum symmetry key; The first centralized control station encrypts the second quantum key based on a preset encryption algorithm to generate first confidential information; The first centralized control station encrypts the first confidential information according to the auxiliary encryption key to generate secondary encrypted information; The first centralized control station sends the secondary encryption information to the quantum key injection machine.

[0019] Thus, the first control station encrypts the first quantum key of the quantum symmetry key using the auxiliary encryption key to determine the first encrypted information. Next, the first control station sends the first encrypted information to the key distribution center. Then, the first control station stores the second quantum key of the quantum symmetry key. Next, the first control station encrypts the second quantum key using a preset encryption algorithm to generate the first confidential information. Subsequently, the first control station encrypts the first confidential information using the auxiliary encryption key to generate the second encrypted information. Finally, the first control station sends the second encrypted information to the quantum key injection machine. In this way, through multiple encryption mechanisms, the transmitted key information is protected layer by layer, reducing the risk of the quantum key being stolen or cracked during transmission over a classical network.

[0020] In some embodiments, the method further includes: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; The quantum key injection machine decrypts the secondary encryption information according to the auxiliary decryption key to obtain the first confidential information; The quantum key filling machine fills the terminal key storage medium with the first confidential information.

[0021] Thus, the key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key. Next, the quantum key injection machine decrypts the second encrypted information using the auxiliary decryption key to obtain the first confidential information. Finally, the quantum key injection machine injects the terminal key storage medium with the first confidential information. This process, using the auxiliary decryption key to complete the decryption operation, forms a closed loop with the previous encryption process, ensuring that only devices possessing the legitimate decryption key can access the original key information, effectively preventing the risk of the key being illegally intercepted and cracked during transmission.

[0022] In some embodiments, the quantum local area network further includes a quantum key decryption machine, and the method further includes: If the second control station receives an encryption assistance request sent by the quantum key injection machine, the second control station generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key; The second control station sends the auxiliary encryption key to the first control station; The second central control station sends the auxiliary decryption key to the key distribution center and the quantum key decryption machine.

[0023] Thus, if the second control station receives an encryption assistance request from the quantum key injection machine, it generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station. Finally, the second control station sends the auxiliary decryption key to the key distribution center and the quantum key decryptor. By sending the auxiliary decryption key to the quantum key decryptor instead of the quantum key injection machine, the quantum key injection machine cannot directly decrypt the received encryption key. Instead, it directly injects the encrypted quantum key into the storage device. Subsequent decryption is then performed by a separate quantum key decryptor within the storage device. This avoids the risk of key leakage due to eavesdropping on the quantum key injection machine and strengthens the security of the entire key transmission and injection process.

[0024] In some embodiments, the method further includes: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; The first centralized control station sends the first encrypted information to the key distribution center; The first centralized control station stores the second quantum key of the quantum symmetry key; The first centralized control station encrypts the second quantum key based on a preset encryption algorithm to generate first confidential information; The first centralized control station encrypts the first confidential information according to the auxiliary encryption key to generate secondary encrypted information; The first centralized control station sends the secondary encryption information to the quantum key injection machine.

[0025] Thus, the first control station encrypts the first quantum key of the quantum symmetry key using the auxiliary encryption key to determine the first encrypted information. Next, the first control station sends the first encrypted information to the key distribution center. Then, the first control station stores the second quantum key of the quantum symmetry key. Next, the first control station encrypts the second quantum key using a preset encryption algorithm to generate the first confidential information. Subsequently, the first control station encrypts the first confidential information using the auxiliary encryption key to generate the second encrypted information. Finally, the first control station sends the second encrypted information to the quantum key injection machine. In this way, through a multi-layered encryption mechanism, the key information during transmission is protected in multiple rounds, reducing the risk of the quantum key being stolen and cracked during transmission over a classical network.

[0026] In some embodiments, the method further includes: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; The quantum key filling machine fills the terminal key storage medium with the secondary encryption information. The quantum key decryption machine decrypts the secondary encryption information with the auxiliary decryption key. The decryption operation is performed within the terminal key storage medium, and the quantum key does not enter the quantum key decryption machine.

[0027] Thus, the key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key. Next, the quantum key injection machine injects the terminal key storage medium with the second encrypted information. The quantum key decryption machine decrypts the second encrypted information using the auxiliary decryption key, and this decryption operation is performed within the terminal key storage medium; the quantum key does not enter the quantum key decryption machine. This ensures that the decryption operation is performed within the terminal key storage medium, preventing the quantum key from entering the decryption machine and avoiding the risk of key leakage due to eavesdropping on the quantum key decryption machine, thus further enhancing the security of the entire key injection process.

[0028] Additional aspects and advantages of embodiments of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of embodiments of this application. Attached Figure Description

[0029] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, wherein: Figure 1 This is one of the flowcharts illustrating the key filling method according to an embodiment of this application; Figure 2This is a second flowchart illustrating the key filling method according to an embodiment of this application; Figure 3 This is the third flowchart illustrating the key filling method according to the embodiments of this application; Figure 4 This is the fourth flowchart illustrating the key filling method according to the embodiments of this application; Figure 5 This is the fifth flowchart illustrating the key filling method according to the embodiments of this application; Figure 6 This is the sixth flowchart illustrating the key filling method according to the embodiments of this application; Figure 7 This is the seventh flowchart illustrating the key filling method according to the embodiments of this application; Figure 8 This is the eighth flowchart illustrating the key filling method according to the embodiments of this application; Figure 9 This is the ninth flowchart illustrating the key filling method according to the embodiments of this application; Figure 10 This is the tenth flowchart illustrating the key filling method according to the embodiments of this application; Figure 11 This is eleventh of the flowcharts illustrating the key filling method according to the embodiments of this application; Figure 12 This is the twelfth flowchart of the key filling method according to the embodiments of this application; Figure 13 This is the thirteenth flowchart of the key filling method according to the embodiments of this application. Detailed Implementation

[0030] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the embodiments of this application, and should not be construed as limiting the embodiments of this application.

[0031] Quantum communication, with its high security based on the principles of quantum mechanics, occupies an increasingly important position in the modern communication field, especially demonstrating unique advantages in quantum-encrypted communication services. Taking quantum-encrypted calls as an example, when a communication terminal equipped with a quantum SIM card initiates a communication, it randomly selects a quantum key from its built-in key storage device. By establishing a connection with the backend system and verifying identity information, it leverages the characteristics of the quantum key to achieve high-strength authentication, thereby providing core protection for the security of the communication content.

[0032] However, existing quantum key filling schemes have significant limitations: on the one hand, the type of quantum key filled is limited, which cannot meet the diverse needs of communication terminals in different scenarios. For example, some users may need to use encrypted services in a specific area (such as the coverage area of ​​a certain base station), while other users need to flexibly access services in a wider local area network, but a single key cannot adapt to these differentiated scenarios; on the other hand, the authentication method is relatively limited. The filled quantum key can only be compared with the key distribution center to complete the authentication, lacking a collaborative authentication mechanism with other network nodes (such as the central control station), resulting in a fixed service form and making it difficult to expand into richer types of encrypted communication services.

[0033] Specifically, in the existing key-generating process, whether keys are generated through negotiation between paired quantum key distribution devices or by using a quantum random number generator, a single type of key is ultimately stored in the storage device. Furthermore, the sole authentication target for these keys is the key distribution center. In this model, communication terminals can only rely on this one key for authentication. This makes it impossible to provide differentiated services based on different service areas (such as the coverage area of ​​a specific control station versus the entire quantum local area network), and it is also difficult to provide corresponding key support for communication needs at different security levels. This significantly limits the diversified development of quantum encrypted communication services.

[0034] Based on the above issues, please refer to Figure 1 This application provides a key injection method for a quantum local area network (QLAN). The QLAN includes a first control station, a quantum key injection machine, and a key distribution center. The first control station and the quantum key injection machine establish a communication connection. The method includes: 011: The quantum key generator sends a key injection request to the first central control station; 012: The first centralized control station determines the target distribution strategy from the preset distribution strategy based on the type of key injection request; 013: The first central control station distributes the acquired quantum symmetric key to the quantum key injector and / or key distribution center according to the target distribution strategy for key injection.

[0035] Specifically, a quantum local area network (QLAN) refers to a metropolitan area-wide local communication network built based on quantum communication technology. A QLAN includes nodes such as a key distribution center, several control stations, and quantum key injection machines, forming the basic network environment for quantum key injection and encrypted communication. The QLAN connects devices through a quantum encryption network and classical channels (used to transmit encrypted information), providing quantum encrypted communication support for communication terminals within the area.

[0036] The first control station is one of the core nodes for quantum key generation and distribution. It can connect to the key distribution center through a quantum encryption network, providing authentication and subsequent encrypted communication services for devices connected to the quantum local area network. During the key filling process, the first control station can generate quantum keys according to the requests of the quantum key filling machine and distribute the keys according to a preset strategy.

[0037] It should be noted that the term "first control station" does not refer to a specific control station, but rather to any control station node in a quantum local area network (QLAN) that performs key generation, distribution, and response to key injection requests. The core role of the first control station is as the "key processing hub" in the quantum key injection process. Based on the request type (directed key or LAN key) sent by the quantum key injector, it executes the corresponding preset distribution strategy to complete the generation, encryption, and transmission of the quantum symmetric key. In practical applications, multiple control stations may exist within a quantum LAN. When a control station is selected by the quantum key injector and receives an injection request, that control station becomes the "first control station" in the current process. The term "first control station" is not a physical or numbered limitation on the control station, but rather clarifies the functional positioning of the control station responsible for processing key requests in a specific injection scenario, reflecting the adaptability of the key injection method for quantum LANs provided in this application to multi-control station collaborative scenarios.

[0038] A quantum key injector is a dedicated device used to write quantum keys into quantum key storage devices (such as quantum SIM cards). It is typically fixed within a quantum key injector station and connected to a quantum local area network via a central control station. During the key injector process, the quantum key injector reads information from the key storage device, obtains the injector scheme, sends a key injector request to the central control station, and then writes the received key into the storage device.

[0039] The key distribution center is the core node within a quantum local area network that centrally manages keys. Its main responsibilities include generating session keys and distributing them to both communicating parties, as well as providing authentication services to ensure that only authorized users can obtain the session keys. During key filling, it receives and stores the keys sent by the central control station for subsequent authentication with the key storage device. In other words, by verifying the matching of pre-set keys between the key distribution center and the key storage device (or the relevant central control station), it ensures that only communication terminals holding legitimate keys can pass authentication and obtain the session keys for quantum encrypted communication services.

[0040] A key injection request refers to a request message sent by the quantum key injector to the first central control station to apply for a specific type of quantum key injection, including a first key injection request (applying for a directed key) and a second key injection request (applying for a local area network key). The first and second key injection requests can be initiated individually or simultaneously, determined based on the key requirements of the terminal key storage medium, and serve as instructions to initiate the key injection process.

[0041] The preset distribution strategy includes a first preset key distribution strategy and a second preset key distribution strategy, which are key distribution rules determined by the first centralized control station based on the key injection request type. The first preset strategy corresponds to the distribution of directed keys, while the second preset strategy corresponds to the distribution of local area network keys. Different strategies specify the key transmission method, storage requirements, etc.

[0042] It should be noted that the core difference between directed keys and local area network keys does not stem from the properties of quantum keys themselves (both are generated using quantum methods and possess the same randomness and security), but is determined by the different distribution strategies, which in turn leads to the differentiation in authentication methods and functional positioning.

[0043] Quantum symmetric keys refer to symmetric keys generated by the central control station for quantum encrypted communication, including directed keys and local area network (LAN) keys. Directed keys require a connection between a specific central control station and the key distribution center for authentication. They are suitable for scenarios with clearly defined service ranges, enabling precise access control for communication terminals. This avoids indiscriminate distribution of directed keys across the entire network, reducing unnecessary key resource consumption and improving operational efficiency. LAN keys can be authenticated by connecting to the key distribution center from any central control station within the quantum LAN. They are suitable for scenarios where users can move freely within the LAN or where there are no specific range restrictions, improving the convenience and coverage of quantum communication services.

[0044] It should be noted that in the key injection method for quantum local area networks provided in this application, both the injected directional key and the local area network key are authentication keys, used for identity authentication when the communication terminal initiates quantum encrypted communication. Specifically, when a communication terminal needs to access a quantum encrypted communication service, a corresponding authentication key is randomly selected from the communication terminal's key storage device—if the requested service is of type one (such as encrypted communication limited to the coverage area of ​​a specific control station), the directional key is selected; if the requested service is of type two (such as encrypted communication within the quantum local area network without the restriction of a specific control station), the local area network key is selected. Identity information verification is then performed with the control station and the key distribution center.

[0045] After authentication, the directed key and the local area network key are not directly used as session keys in the communication process. The quantum local area network will generate new session keys in real time to encrypt the communication content, and the session keys are "discarded after use", which can further improve security.

[0046] First, the quantum key generator sends a key injection request to the first central control station. This request is divided into first and second key injection requests, corresponding to the application for a directional key and a local area network key, respectively. The directional key requires a connection between a specific central control station and the key distribution center for authentication, while the local area network key can be authenticated by connecting to the key distribution center from any central control station within the quantum local area network.

[0047] Next, the first central control station determines the target distribution strategy from the preset first and second preset key distribution strategies based on the type of the received key injection request. The first and second preset key distribution strategies correspond to the distribution rules for directional keys and local area network keys, respectively, including the key transmission method, storage requirements, etc.

[0048] Finally, after acquiring the quantum symmetric key, the first control station distributes it to the quantum key injection machine and / or key distribution center according to the target distribution strategy, completing the injection. Specifically, the key distributed based on the first preset strategy is a directional key, while the key distributed based on the second preset strategy is a local area network key. This ensures that the key distribution center and key storage device store the corresponding keys, providing support for authentication and other operations in subsequent communications.

[0049] In summary, in the key injection method for quantum local area networks provided by this application, the quantum key injection machine sends a key injection request to a first central control station. The key injection request includes a first key injection request and / or a second key injection request. The first key injection request is used to request a directional key, and the second key injection request is used to request a local area network key. Next, the first central control station determines a target distribution strategy from a preset distribution strategy based on the type of the key injection request. The preset distribution strategy includes a first preset key distribution strategy and a second preset key distribution strategy. Then, the first central control station distributes the obtained quantum symmetric key to the quantum key injection machine and / or a key distribution center according to the target distribution strategy for key injection. The quantum symmetric key distributed based on the first preset key distribution strategy is the directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is the local area network key. In this way, by dividing the keys into directional keys and local area network keys, and corresponding them to different key filling requests and distribution strategies, communication terminals can subsequently select the appropriate key for authentication as needed, thereby obtaining quantum encrypted communication services of different ranges. This solves the problem of existing technologies having a single quantum key and being unable to provide diversified services. Furthermore, the first central control station selects the corresponding distribution strategy according to different key filling request types, making the key generation, distribution, and filling process more targeted.

[0050] Please see Figure 2 In some implementations, the quantum local area network further includes a terminal key storage medium, and the method further includes: 016: The quantum key injection machine obtains device information about the terminal key storage medium; 017: The quantum key injector determines the key injecting request based on the device information.

[0051] Specifically, a terminal key storage medium refers to a device used to store quantum keys, typically integrated into communication equipment to provide quantum encrypted communication support, such as a quantum encrypted SIM card. The terminal key storage medium stores a directional key and a local area network key, used by the communication terminal for authentication and other operations with the backend during quantum encrypted calls.

[0052] Device information refers to information about the terminal key storage medium itself, including the type of storage medium and user service permission configuration information. This device information is the basis for the quantum key injection machine to determine the key injection request, ensuring that the injected key matches the usage requirements of the storage medium and the user's service plan.

[0053] When a terminal key storage medium (such as a quantum SIM card) is inserted into a quantum key injector, the injector first reads the device information of the medium. Then, based on this device information, the injector determines a key injecting request. For example, if the user service permission configuration information includes targeted service permissions, a first key injecting request for a targeted key is generated; if the user service permission configuration information includes local area network (LAN) general service permissions, a second key injecting request for a LAN key is generated; or both key injecting requests may be generated simultaneously based on the user service permission configuration information, thereby ensuring that the injected quantum key matches the usage requirements of the terminal key storage medium and the user's permissions.

[0054] Thus, the quantum local area network also includes a terminal key storage medium, and the quantum key injector acquires the device information of the terminal key storage medium. Then, based on the device information, the quantum key injector determines the key injecting request. In this way, by acquiring the device information of the terminal key storage medium, the quantum key injector can determine the corresponding key injecting request, making the key injecting more closely aligned with the actual needs of the terminal device and the user. Furthermore, determining the injecting request based on device information ensures that the type and quantity of injected keys match the characteristics and usage scenario of the terminal key storage medium, avoiding the injection of unsuitable keys, thereby guaranteeing the normal use of keys in subsequent quantum encrypted communication and providing reliable support for identity authentication and encryption processes.

[0055] Please see Figure 3 and Figure 4 In some implementations, the method further includes: 018: Upon receiving a key injection request, the first centralized control station generates a quantum symmetric key based on a quantum random number generator; or 019: Upon receiving a key injection request, the first central control station determines the quantum symmetric key from the pre-stored quantum key.

[0056] Specifically, a quantum random number generator can produce quantum random numbers, which can be used as quantum keys.

[0057] Pre-stored quantum keys refer to quantum keys that are pre-stored in the relevant devices. When the first central control station receives a key charging request, it can extract a series of quantum keys from these pre-stored quantum keys to determine the required quantum symmetry key.

[0058] When the first central control station receives a key injection request, it can use a quantum random number generator to generate the required quantum symmetric key.

[0059] Alternatively, when the first central control station receives a key injection request, it can extract a series of keys that meet the requirements from the pre-stored quantum keys and use them as quantum symmetric keys.

[0060] Thus, upon receiving a key injection request, the first control station generates a quantum symmetric key using a quantum random number generator. Alternatively, upon receiving a key injection request, the first control station determines the quantum symmetric key from a pre-stored set of quantum keys. This provides two key acquisition methods, allowing the first control station to choose the appropriate method based on the actual situation when receiving a key injection request.

[0061] Please see Figure 5 In some implementations, step 012 (determining the target distribution strategy from preset distribution strategies based on the type of key injection request) includes: 0121: When the key injection request is the first key injection request, the first central control station determines the first preset key distribution strategy as the target distribution strategy; 0122: When the key injection request is the second key injection request, the first central control station determines the second preset key distribution strategy as the target distribution strategy; 0123: When the key injection request is the first key injection request and the second key injection request, the first central control station determines the first preset key distribution strategy and the second preset key distribution strategy as the target distribution strategy.

[0062] Specifically, when the key filling request is the first key filling request (i.e., applying for a targeted key), the first central control station will select the first preset key distribution strategy. The first preset key distribution strategy corresponds to the rules for the generation, transmission and filling of the targeted key, ensuring that the targeted key can only be authenticated through a specific central control station.

[0063] When the key injection request is the second key injection request (i.e., requesting a local area network key), the first central control station will select the second preset key distribution strategy. This second preset key distribution strategy is applicable to the processing of local area network keys, ensuring that the local area network key can be authenticated by any central control station within the quantum local area network.

[0064] When two key injection requests exist simultaneously, the first central control station will simultaneously activate two preset distribution strategies to process the injection of the directed key and the local area network key respectively, so as to meet the needs of communication terminals for diversified quantum encryption services.

[0065] Thus, when the key injection request is the first key injection request, the first central control station determines the first preset key distribution strategy as the target distribution strategy. Next, when the key injection request is the second key injection request, the first central control station determines the second preset key distribution strategy as the target distribution strategy. Finally, when the key injection request is both the first and second key injection requests, the first central control station determines both the first and second preset key distribution strategies as the target distribution strategies. In this way, according to different types of key injection requests, the first central control station determines a single or combined target distribution strategy, ensuring that the directed key and the quantum LAN key each adopt a distribution method adapted to their characteristics, making the entire process from quantum key generation to injection more targeted.

[0066] Please see Figure 6 The quantum local area network also includes a terminal key storage medium. Step 013 (distributing the obtained quantum symmetric key to the quantum key injection machine and / or key distribution center for key injection according to the target distribution strategy) includes: 0131: When the target distribution strategy is the first preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; 0132: The key distribution center stores the first quantum key; 0133: The first central control station stores the second quantum key in the quantum symmetry key; 0134: Based on a preset encryption algorithm, the first central control station encrypts the second quantum key to generate the first confidential information; 0135: The first centralized control station sends the first confidential information to the quantum key filling machine; 0136: The quantum key filling machine fills the terminal key storage medium with the first confidential information.

[0067] Specifically, a quantum channel refers to a dedicated channel used for transmitting quantum keys.

[0068] The first quantum key is part of the quantum symmetric key. Under the first preset key distribution strategy, it is sent from the first central control station to the key distribution center through the quantum channel and stored by the key distribution center for subsequent comparison and authentication with the key filled in the terminal key storage medium.

[0069] The second quantum key, which is also part of the quantum symmetric key, is stored by the first central control station under the first preset key distribution strategy. It has a corresponding relationship with the first quantum key and is the key key for achieving targeted authentication.

[0070] A preset encryption algorithm refers to a pre-defined algorithm used to encrypt the key, such as a symmetric encryption algorithm. The first central control station uses this algorithm to encrypt the second quantum key to ensure its security during transmission.

[0071] The first confidential information refers to the information generated after the first central control station encrypts the second quantum key using a preset encryption algorithm. This first confidential information ensures the secure transmission of the encrypted second quantum key to the quantum key injector, preventing it from being stolen during transmission.

[0072] The filling process refers to the process by which a quantum key injector writes the received initial confidential information into the terminal key storage medium. Through the filling process, the terminal key storage medium stores the corresponding encrypted information, providing a key basis for subsequent operations such as identity authentication.

[0073] The first centralized control station sends the first quantum key from the quantum symmetric key to the key distribution center via a quantum channel. The key distribution center stores this key as the basis for comparison in subsequent authentication.

[0074] The first control station stores the second quantum key from the quantum symmetry key set and encrypts it using a preset encryption algorithm to generate first confidential information, which is then sent to the quantum key injection machine. The quantum key injection machine receives the first confidential information and writes it into the terminal key storage medium, completing the injection process. At this point, the information in the terminal storage medium is bound to the second quantum key stored at the first control station. Subsequent use requires verification by the first control station to be effective, demonstrating the "directional" characteristic of directional keys.

[0075] When a communication terminal applies for targeted encryption service, the communication terminal needs to access a specific centralized control station bound to the targeted key (i.e., the first centralized control station associated with the key during recharge). The specific centralized control station will first verify the terminal's access permissions (such as whether the device identifier is in the targeted service whitelist).

[0076] After access is granted, the communication terminal retrieves pre-filled first confidential information from its built-in key storage medium and sends the encrypted first confidential information to the first central control station. Subsequently, the first central control station decrypts the first confidential information using a decryption algorithm corresponding to the preset encryption algorithm, restoring it to a second quantum key, and sends this second quantum key to the key distribution center. The key distribution center then compares the second quantum key with its own stored first quantum key to verify key consistency.

[0077] If the first control station successfully decrypts the key and the key distribution center matches, authentication is successful. At this point, the first control station generates a one-time session key (the directional key itself is not directly used for communication encryption) and transmits it to the communication terminal via a quantum channel for encrypting the current communication content.

[0078] It should be noted that the session key expires immediately after the communication ends ("use-and-discard"), while the directional key, as an authentication credential, will be refilled by the communication terminal to a specific central control station after meeting preset conditions (such as the maximum number of uses, expiration of validity period, and use-and-discard), to ensure long-term security.

[0079] Thus, under the first preset key distribution strategy, based on the quantum channel, the first centralized control station sends the first quantum key from the quantum symmetric key to the key distribution center. Next, the key distribution center stores the first quantum key. Then, the first centralized control station stores the second quantum key from the quantum symmetric key. Subsequently, based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate first confidential information. Next, the first centralized control station sends the first confidential information to the quantum key injection machine. Finally, the quantum key injection machine injects the terminal key storage medium according to the first confidential information. In this way, for the directional key corresponding to the first preset key distribution strategy, the first centralized control station sends the first quantum key to the key distribution center through the quantum channel, utilizing the high security of the quantum channel to ensure that the key transmission process is not easily eavesdropped. Simultaneously, the first centralized control station stores the second quantum key, encrypts it to generate first confidential information, and sends it to the quantum key injection machine, binding the key injected into the terminal key storage medium to a specific centralized control station. This ensures that the key can only be authenticated through this centralized control station to the key distribution center, achieving secure control of the directional service.

[0080] Please see Figure 7 The quantum local area network also includes a terminal key storage medium. Step 013 (distributing the obtained quantum symmetric key to the quantum key injection machine and / or key distribution center for key injection according to the target distribution strategy) includes: 0137: When the target distribution strategy is the second preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; 0138: The key distribution center stores the first quantum key; 0139: The first centralized control station, based on a classical network, sends the second quantum key from the quantum symmetric key to the quantum key injection machine; 0140: The quantum key filling machine fills the terminal key storage medium with the second quantum key.

[0081] Specifically, when the communication terminal requests a second key injection, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center through the quantum channel. The key distribution center stores the first quantum key as the basis for comparison in subsequent authentication.

[0082] Meanwhile, the first central control station sends the second quantum key from the quantum symmetric key to the quantum key injector via a classical network. Compared to the encrypted transmission of directional keys, the local area network key is transmitted directly through a classical network, emphasizing the convenience of transmission to suit its universality within a local area network.

[0083] After receiving the second quantum key, the quantum key injector writes it into the terminal key storage medium, completing the injection process. At this point, the second quantum key in the terminal storage medium corresponds to the first quantum key stored in the key distribution center. In subsequent use, the communication terminal can complete authentication with the key distribution center through any central control station within the quantum local area network, demonstrating the "local area network universal" characteristic of the local area network key.

[0084] When a communication terminal requests a local area network encryption service, the communication terminal needs to connect to any centralized control station bound to the directional key (the optimal centralized control station can be automatically selected based on signal strength and load conditions). The specific centralized control station will first verify the terminal's access permissions (such as whether the device identifier is in the directional service whitelist).

[0085] After access is granted, the communication terminal retrieves the pre-loaded second quantum key from its built-in key storage medium and sends it to the currently accessed central control station (any station capable of accessing the central control station). The central control station then sends the second quantum key to the key distribution center. Next, the key distribution center compares the second quantum key with its own stored first quantum key to verify key consistency.

[0086] If the key distribution center matches the data, authentication is successful. At this point, the currently accessing central control station will generate a one-time session key (the directional key itself is not directly used for communication encryption) and transmit it to the communication terminal via a quantum channel for encryption of the current communication content.

[0087] It should be noted that the session key expires immediately after the communication ends ("use-and-discard"), while the directional key, as an authentication credential, will be refilled by the communication terminal to a specific central control station after meeting preset conditions (such as the maximum number of uses, expiration of validity period, and use-and-discard), to ensure long-term security.

[0088] Thus, when the target distribution strategy is the second preset key distribution strategy, based on the quantum channel, the first centralized control station sends the first quantum key from the quantum symmetric key to the key distribution center. Next, the key distribution center stores the first quantum key. Then, based on the classical network, the first centralized control station sends the second quantum key from the quantum symmetric key to the quantum key injection machine. Finally, the quantum key injection machine injects the terminal key storage medium according to the second quantum key. In this way, for the local area network key corresponding to the second preset key distribution strategy, the first centralized control station sends the first quantum key to the key distribution center through the quantum channel, ensuring that key transmission is not easily intercepted thanks to the security of the quantum channel. Simultaneously, sending the second quantum key to the quantum key injection machine through the classical network allows the key injected into the terminal key storage medium to be applicable to any centralized control station within the quantum local area network, meeting the service requirement without specific centralized control station restrictions and realizing the universality of encrypted communication services within the local area network.

[0089] Please see Figure 8 In some implementations, the quantum local area network further includes a second central control station, and the method further includes: 0141: If the second control station receives an encryption assistance request from the quantum key injector, the second control station generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key; 0142: The second control station sends an auxiliary encryption key to the first control station; 0143: The second central control station sends the auxiliary decryption key to the key distribution center and the quantum key injection machine.

[0090] Specifically, when transmitting quantum keys over classical networks, they are vulnerable to eavesdropping through methods such as traffic interception and network sniffing, causing the "quantum-level security" of the quantum key to fail during transmission. For these reasons, encryption can be used to assist in transmitting quantum keys over classical networks, thus mitigating the security vulnerabilities of quantum keys transmitted through classical channels.

[0091] A cryptographic assistance request refers to a request sent by the quantum key generator to the second control station, requesting the second control station to provide cryptographic assistance services. The quantum key generator sends this request when the key injection request involves a first key injection request (requesting a directed key), or both requests simultaneously, in order to enhance the security of key transmission with the help of the second control station's cryptographic assistance.

[0092] The auxiliary symmetric key refers to the symmetric key generated by the second central control station after receiving the encryption assistance request. It includes an auxiliary encryption key and an auxiliary decryption key, which are used in pairs to encrypt and protect the transmission process of the quantum symmetric key, thereby enhancing the security of classical network transmission during the key filling process.

[0093] The auxiliary encryption key refers to a part of the auxiliary symmetric key, which is sent from the second control station to the first control station for the first control station to encrypt the quantum symmetric key to be distributed, so as to prevent the key from being stolen during transmission.

[0094] The auxiliary decryption key refers to another part of the auxiliary symmetric key, which is sent by the second central control station to the key distribution center and the quantum key injector. It is used to decrypt the quantum symmetric key encrypted by the first central control station to obtain the original quantum symmetric key, ensuring that the key distribution center and the quantum key injector can correctly receive and use the key.

[0095] To prevent key eavesdropping during transmission, the quantum key injector can send an encryption assistance request to the second control station. The second control station then generates a pair of auxiliary symmetric keys, including an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station for encrypting the quantum key to be transmitted; simultaneously, it sends the auxiliary decryption key to both the key distribution center and the quantum key injector, ensuring that both can decrypt the encrypted key.

[0096] Thus, if the second control station receives an encryption assistance request from the quantum key injector, it generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station. Finally, the second control station sends the auxiliary decryption key to the key distribution center and the quantum key injector. In this way, by introducing the auxiliary symmetric key generated by the second control station, the first control station uses the auxiliary encryption key to encrypt the quantum symmetric key before transmission, and the key distribution center and the quantum key injector decrypt the key using the auxiliary decryption key. This avoids the risk of plaintext leakage when the first control station and the quantum key injector transmit the key over a classical network, reducing the possibility of key eavesdropping or theft.

[0097] Please see Figure 9 In some implementations, the method further includes: 0144: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; 0145: The first centralized control station sends the first encrypted information to the key distribution center; 0146: The second quantum key stored at the first central control station for quantum symmetry; 0147: Based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate the first confidential information; 0148: The first centralized control station encrypts the first confidential information according to the auxiliary encryption key, generating secondary encrypted information; 0149: The first centralized control station sends secondary encryption information to the quantum key filling machine.

[0098] Specifically, the first encrypted information refers to the information obtained after the first central control station encrypts the first quantum key in the quantum symmetric key using an auxiliary encryption key. The first encrypted information ensures the security of the first quantum key during transmission to the key distribution center, prevents the first quantum key from being stolen during transmission, and ensures that the key distribution center receives encrypted key information.

[0099] The double-encryption refers to the information obtained by first encrypting the second quantum key using a preset encryption algorithm to generate the first confidential information at the first control station, and then encrypting the first confidential information again using an auxiliary encryption key. Double-encryption enhances the security of information related to the second quantum key during transmission to the quantum key injection machine, making it difficult to decrypt even if the information is intercepted during transmission without obtaining the auxiliary decryption key, thus better protecting the security of the second quantum key.

[0100] The first control station uses the auxiliary encryption key provided by the second control station to encrypt the first quantum key in the quantum symmetry key, generating the first encrypted information, and sends it to the key distribution center. Next, the first control station stores the second quantum key, first encrypting it using a preset encryption algorithm to generate the first confidential information, then using the auxiliary encryption key to encrypt the first confidential information a second time, generating the second encrypted information, which is then sent to the quantum key injection machine.

[0101] Thus, the first control station encrypts the first quantum key of the quantum symmetry key using the auxiliary encryption key to determine the first encrypted information. Next, the first control station sends the first encrypted information to the key distribution center. Then, the first control station stores the second quantum key of the quantum symmetry key. Next, the first control station encrypts the second quantum key using a preset encryption algorithm to generate the first confidential information. Subsequently, the first control station encrypts the first confidential information using the auxiliary encryption key to generate the second encrypted information. Finally, the first control station sends the second encrypted information to the quantum key injection machine. In this way, through multiple encryption mechanisms, the transmitted key information is protected layer by layer, reducing the risk of the quantum key being stolen or cracked during transmission over a classical network.

[0102] Please see Figure 10 In some implementations, the method further includes: 0150: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; 0151: The quantum key injection machine decrypts the secondary encrypted information using the auxiliary decryption key to obtain the first confidential information; 0152: The quantum key injection machine injects the terminal key storage medium with the first confidential information.

[0103] Specifically, the key distribution center uses the auxiliary decryption key provided by the second central control station to decrypt the first encrypted information received from the first central control station, obtain the first quantum key, and store it.

[0104] The quantum key injector also uses an auxiliary decryption key to decrypt the received secondary encrypted information, obtaining the first confidential information. Subsequently, the quantum key injector writes the decrypted first confidential information into the terminal key storage medium, completing the injection process.

[0105] Thus, the key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key. Next, the quantum key injection machine decrypts the second encrypted information using the auxiliary decryption key to obtain the first confidential information. Finally, the quantum key injection machine injects the terminal key storage medium with the first confidential information. This process, using the auxiliary decryption key to complete the decryption operation, forms a closed loop with the previous encryption process, ensuring that only devices possessing the legitimate decryption key can access the original key information, effectively preventing the risk of the key being illegally intercepted and cracked during transmission.

[0106] Please see Figure 11 In some implementations, the quantum local area network further includes a quantum key decryption machine, and the method further includes: 0153: If the second control station receives an encryption assistance request from the quantum key injector, the second control station generates an auxiliary symmetric key; 0154: The second control station sends an auxiliary encryption key to the first control station; 0155: The second central control station sends an auxiliary decryption key to the key distribution center and the quantum key decryption machine.

[0107] Specifically, to prevent eavesdropping on the key during transmission, the quantum key injector can send an encryption assistance request to the second control station. The second control station then generates a pair of auxiliary symmetric keys, including an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station for encrypting the quantum key to be transmitted; simultaneously, it sends the auxiliary decryption key to both the key distribution center and the quantum key injector, ensuring that both can decrypt the encrypted key.

[0108] Thus, if the second control station receives an encryption assistance request from the quantum key injector, it generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key. Next, the second control station sends the auxiliary encryption key to the first control station. Finally, the second control station sends the auxiliary decryption key to the key distribution center and the quantum key injector. In this way, by introducing the auxiliary symmetric key generated by the second control station, the first control station uses the auxiliary encryption key to encrypt the quantum symmetric key before transmission, and the key distribution center and the quantum key injector decrypt the key using the auxiliary decryption key. This avoids the risk of plaintext leakage when the first control station and the quantum key injector transmit the key over a classical network, reducing the possibility of key eavesdropping or theft.

[0109] Please see Figure 12 In some implementations, the method further includes: 0156: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; 0157: The first centralized control station sends the first encrypted information to the key distribution center; 0158: The second quantum key stored at the first central control station for quantum symmetry; 0159: Based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate the first confidential information; 0160: The first centralized control station encrypts the first confidential information according to the auxiliary encryption key to generate secondary encrypted information; 0161: The first centralized control station sends secondary encryption information to the quantum key filling machine.

[0110] Specifically, the first control station uses the auxiliary encryption key provided by the second control station to encrypt the first quantum key in the quantum symmetry key, generating first encrypted information, and sends it to the key distribution center. Next, the first control station stores the second quantum key, first encrypting it using a preset encryption algorithm to generate first confidential information, then using the auxiliary encryption key to encrypt the first confidential information a second time, generating second encrypted information, which is then sent to the quantum key injection machine.

[0111] Thus, the first control station encrypts the first quantum key of the quantum symmetry key using the auxiliary encryption key to determine the first encrypted information. Next, the first control station sends the first encrypted information to the key distribution center. Then, the first control station stores the second quantum key of the quantum symmetry key. Next, the first control station encrypts the second quantum key using a preset encryption algorithm to generate the first confidential information. Subsequently, the first control station encrypts the first confidential information using the auxiliary encryption key to generate the second encrypted information. Finally, the first control station sends the second encrypted information to the quantum key injection machine. In this way, through a multi-layered encryption mechanism, the key information during transmission is protected in multiple rounds, reducing the risk of the quantum key being stolen and cracked during transmission over a classical network.

[0112] Please see Figure 13 In some implementations, the method further includes: 0162: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; 0163: The quantum key filling machine fills the terminal key storage medium with secondary encryption information.

[0113] Specifically, the key distribution center uses the auxiliary decryption key provided by the second central control station to decrypt the first encrypted information received from the first central control station, obtain the first quantum key, and store it to provide a basis for comparison for subsequent authentication.

[0114] The quantum key filling machine directly fills the received secondary encryption information into the terminal key storage medium; then, the terminal key storage medium is inserted into the quantum key decryption machine, which uses an auxiliary decryption key to decrypt the secondary encryption information in the medium, but the decryption operation is completed inside the terminal key storage medium, and the quantum key is not transmitted to the decryption machine.

[0115] By confining the decryption operation to the terminal key storage medium, the quantum key is prevented from entering the decryption device, thereby further enhancing the security of the key filling process and preventing the key from being stolen during the decryption stage.

[0116] Thus, the key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key. Next, the quantum key injection machine injects the terminal key storage medium with the second encrypted information. The quantum key decryption machine decrypts the second encrypted information using the auxiliary decryption key, and this decryption operation is performed within the terminal key storage medium; the quantum key does not enter the quantum key decryption machine. This ensures that the decryption operation is performed within the terminal key storage medium, preventing the quantum key from entering the decryption machine and avoiding the risk of key leakage due to eavesdropping on the quantum key decryption machine, thus further enhancing the security of the entire key injection process.

[0117] This application also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, it causes the one or more processors to perform the method of this application.

[0118] It is understood that a computer program includes computer program code. Computer program code can be in the form of source code, object code, executable files, or some intermediate form. Computer-readable storage media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc.

[0119] In this specification, the terms "specifically," "furthermore," "particularly," "understandably," etc., refer to specific features, structures, materials, or characteristics described in connection with embodiments or examples that are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0120] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.

[0121] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A key injection method for quantum local area networks, characterized in that, The quantum local area network includes a first control station, a quantum key injection machine, and a key distribution center. The first control station and the quantum key injection machine establish a communication connection. The method includes: The quantum key injector sends a key injecting request to the first central control station. The key injecting request includes a first key injecting request and / or a second key injecting request. The first key injecting request is used to apply for a directional key, and the second key injecting request is used to apply for a local area network key. The first centralized control station determines a target distribution strategy from a preset distribution strategy based on the type of the key injection request, wherein the preset distribution strategy includes a first preset key distribution strategy and a second preset key distribution strategy; The first centralized control station distributes the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy to perform the key injection. The quantum symmetric key distributed based on the first preset key distribution strategy is the directional key, and the quantum symmetric key distributed based on the second preset key distribution strategy is the local area network key.

2. The method according to claim 1, characterized in that, The quantum local area network further includes a terminal key storage medium, and the method further includes: The quantum key injection machine acquires device information from the terminal key storage medium; The quantum key injector determines the key injection request based on the device information.

3. The method according to claim 1, characterized in that, The method further includes: Upon receiving the key injection request, the first centralized control station generates the quantum symmetric key based on a quantum random number generator; or Upon receiving the key injection request, the first centralized control station determines the quantum symmetric key from the pre-stored quantum keys.

4. The method according to claim 1, characterized in that, The step of determining the target distribution strategy from the preset distribution strategies based on the type of the key injection request includes: When the key injection request is the first key injection request, the first central control station determines the first preset key distribution strategy as the target distribution strategy; If the key injection request is the second key injection request, the first central control station will determine the second preset key distribution strategy as the target distribution strategy; When the key injection request is either the first key injection request or the second key injection request, the first central control station determines the first preset key distribution strategy and the second preset key distribution strategy as the target distribution strategy.

5. The method according to claim 4, characterized in that, The quantum local area network further includes a terminal key storage medium. The step of distributing the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy for key injection includes: When the target distribution strategy is the first preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; The key distribution center stores the first quantum key; The first centralized control station stores the second quantum key from the quantum symmetry key; Based on a preset encryption algorithm, the first centralized control station encrypts the second quantum key to generate first confidential information; The first centralized control station sends the first confidential information to the quantum key injection machine; The quantum key filling machine fills the terminal key storage medium with the first confidential information.

6. The method according to claim 4, characterized in that, The quantum local area network further includes a terminal key storage medium. The step of distributing the acquired quantum symmetric key to the quantum key injection machine and / or the key distribution center according to the target distribution strategy for key injection includes: When the target distribution strategy is the second preset key distribution strategy, the first central control station sends the first quantum key from the quantum symmetric key to the key distribution center based on the quantum channel; The key distribution center stores the first quantum key; The first centralized control station, based on a classical network, sends the second quantum key from the quantum symmetric key to the quantum key injection machine; The quantum key filling machine fills the terminal key storage medium with the second quantum key.

7. The method according to claim 4, characterized in that, The quantum local area network also includes a second central control station, and the method further includes: If the second control station receives an encryption assistance request sent by the quantum key injection machine, the second control station generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key; The second control station sends the auxiliary encryption key to the first control station; The second central control station sends the auxiliary decryption key to the key distribution center and the quantum key injection machine.

8. The method according to claim 7, characterized in that, The method further includes: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; The first centralized control station sends the first encrypted information to the key distribution center; The first centralized control station stores the second quantum key of the quantum symmetry key; The first centralized control station encrypts the second quantum key based on a preset encryption algorithm to generate first confidential information; The first centralized control station encrypts the first confidential information according to the auxiliary encryption key to generate secondary encrypted information; The first centralized control station sends the secondary encryption information to the quantum key injection machine.

9. The method according to claim 8, characterized in that, The method further includes: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; The quantum key injection machine decrypts the secondary encryption information according to the auxiliary decryption key to obtain the first confidential information; The quantum key filling machine fills the terminal key storage medium with the first confidential information.

10. The method according to claim 7, characterized in that, The method further includes: If the second control station receives an encryption assistance request sent by the quantum key injection machine, the second control station generates an auxiliary symmetric key, which includes an auxiliary encryption key and an auxiliary decryption key; The second control station sends the auxiliary encryption key to the first control station; The second central control station sends the auxiliary decryption key to the key distribution center and the quantum key decryption machine.

11. The method according to claim 10, characterized in that, The method further includes: The first centralized control station encrypts the first quantum key of the quantum symmetry key according to the auxiliary encryption key to determine the first encrypted information; The first centralized control station sends the first encrypted information to the key distribution center; The first centralized control station stores the second quantum key of the quantum symmetry key; The first centralized control station encrypts the second quantum key based on a preset encryption algorithm to generate first confidential information; The first centralized control station encrypts the first confidential information according to the auxiliary encryption key to generate secondary encrypted information; The first centralized control station sends the secondary encryption information to the quantum key injection machine.

12. The method according to claim 11, characterized in that, The quantum local area network also includes a quantum key decryption machine, and the method further includes: The key distribution center decrypts the first encrypted information using the auxiliary decryption key to obtain the first quantum key; The quantum key filling machine fills the terminal key storage medium with the secondary encryption information. The quantum key decryption machine decrypts the secondary encryption information with the auxiliary decryption key. The decryption operation is performed within the terminal key storage medium, and the quantum key does not enter the quantum key decryption machine.