Data transmission system and method based on quantum device identity

By using a quantum device identity-based data transmission system, which transmits ciphertext and key index separately, the problem of IP address exposure at the sending and receiving ends is solved, enabling secure and efficient data transmission, improving communication security, and simplifying key distribution.

CN121308967APending Publication Date: 2026-01-09MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511385998.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

In existing network data transmission processes, the IP addresses of sending and receiving devices are often exposed in the communication network, posing a risk that malicious users may steal communication IPs and launch network attacks, thus affecting network security.

Method used

A quantum device identity-based data transmission system is adopted. Through quantum secure terminals, servers, key access gateways, and CA servers, quantum device identities are generated and encrypted/decrypted. The ciphertext and key index are transmitted separately to ensure that the IP address is not exposed. Attackers can only obtain the device identity but cannot decrypt the data.

Benefits of technology

It enables secure data transmission without exposing IP addresses, avoids the risk of attacks on quantum-secure terminals, improves communication security, and simplifies the management of key distribution institutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121308967A_ABST
    Figure CN121308967A_ABST
Patent Text Reader

Abstract

The invention discloses a data transmission system and method based on quantum device identities, and the system is characterized in that a first quantum security terminal is connected with a first quantum security terminal server, and a second quantum security terminal is connected with a second quantum security terminal server; the first quantum security terminal server is connected with the second quantum security terminal server through the Internet, and the quantum security CA server is connected with the first quantum security terminal, the second quantum security terminal, the first quantum security terminal server and the second quantum security terminal server. And the quantum key access gateway is respectively connected with the first quantum security terminal server and the second quantum security terminal server. The IP address of the quantum security terminal is not exposed in a communication network, even if a bad user attacks, the bad user can only get the device identity DID, and because the bad user does not know the generation rule of the DID, the bad user can not find the position of the quantum security terminal, and the risk that the quantum security terminal is attacked is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, and specifically to a data transmission system and method based on quantum device identity. Background Technology

[0002] With the development of internet data transmission, people have not only adopted encryption keys to improve data transmission security, but have also begun to focus on protecting the IP addresses of network devices. An IP address is a unique identifier for a device on a network, used for communication and data transmission between devices. Each device has a unique IP address so that other devices on the network can identify and distinguish it. However, if an IP address is leaked, it can pose several risks.

[0003] In existing network data transmission processes, the IP addresses of sending and receiving devices are often exposed within the communication network, providing opportunities for malicious users to steal these IP addresses. Once an IP address is leaked, hackers may attempt various network attacks, such as DDoS attacks, port scanning, and malware implantation, thereby compromising network security. If a malicious user obtains an IP address, they may exploit network resources for illegal activities, such as sending spam or conducting phishing attacks, consuming network bandwidth and disrupting normal network usage. Furthermore, once the network activity originating from an IP address is flagged as malicious, network reputation may be damaged, leading to restrictions on data transmission and access to certain websites or services.

[0004] In summary, how to prevent the device IP addresses from being exposed in the communication network when transmitting data is a technical issue that needs to be considered. Summary of the Invention

[0005] Purpose of the Invention: The purpose of this invention is to provide a data transmission system and method based on quantum device identity, solving the problem that in existing systems, the IP addresses of transmitting and receiving devices are often exposed in the communication network, leading to malicious users stealing the communication IP addresses. This invention does not expose the IP address in the communication network; even if a malicious user attacks, they can only obtain the device identity (DID), thus avoiding the risk of attacks on both the transmitting and receiving devices.

[0006] Technical Solution: This invention provides a data transmission system based on quantum device identity. The system includes a first quantum secure terminal, a second quantum secure terminal, a first quantum secure terminal server, a second quantum secure terminal server, a quantum key access gateway, and a quantum secure CA server. The first quantum secure terminal is connected to the first quantum secure terminal server, the second quantum secure terminal is connected to the second quantum secure terminal server, the first quantum secure terminal server and the second quantum secure terminal server are connected via the Internet, the quantum secure CA server is connected to the first quantum secure terminal, the second quantum secure terminal, the first quantum secure terminal server, and the second quantum secure terminal server, respectively, and the quantum key access gateway is connected to the first quantum secure terminal server and the second quantum secure terminal server, respectively.

[0007] The first quantum-secure terminal is used to encrypt and transmit the data.

[0008] The second quantum-secure terminal is used to decrypt the received data;

[0009] Both the first and second quantum-secure terminal servers are used to provide data encryption / decryption and ciphertext transmission functions for connected quantum-secure terminals;

[0010] The quantum key access gateway is used to relay keys and key indexes.

[0011] The quantum-safe CA server is used to generate and issue quantum device identities for the first quantum-safe terminal and the second quantum-safe terminal, and to synchronize the quantum device identities of the quantum-safe terminals to the corresponding connected quantum-safe terminal servers for storage.

[0012] Furthermore, the transmit key pool preset by the first quantum secure terminal is the same as the first key pool preset by the first quantum secure terminal server; the second key pool preset by the first quantum secure terminal server is the same as the third key pool preset by the second quantum secure terminal server; and the fourth key pool preset by the second quantum secure terminal server is the same as the receive key pool preset by the second quantum secure terminal.

[0013] Furthermore, the first quantum secure terminal and the first quantum secure terminal server are under the jurisdiction of the first key distribution institution; the second quantum secure terminal and the second quantum secure terminal server are under the jurisdiction of the second key distribution institution; the first quantum secure terminal server and the second quantum secure terminal server are under the jurisdiction of the third key distribution institution; the first key distribution institution, the second key distribution institution, and the third key distribution institution are the same key distribution institution or different key distribution institutions.

[0014] The present invention also includes a method for a data transmission system based on quantum device identity as described in the preceding claims, the method comprising the following steps:

[0015] (1) The quantum-safe CA server generates and issues corresponding quantum device identity DIDs for the first quantum-safe terminal and the second quantum-safe terminal. 发送 and DID 接收 and will use quantum device identity DID 发送 and DID 接收 Synchronize with the first quantum-secure terminal server and the second quantum-secure terminal server respectively;

[0016] The first and second quantum-secure terminal servers respectively obtain their respective communication IPs in the communication network. 发送 and communication IP 接收 The first quantum-secure terminal server will receive the quantum device identity DID from the quantum-secure CA server. 发送 With its own communication IP 发送 The corresponding data is stored and sent to the quantum key access gateway. The second quantum secure terminal server then stores the quantum device's identity (DID). 接收 With its own communication IP 接收 The corresponding data is stored and sent to the quantum key access gateway;

[0017] (2) The first quantum secure terminal generates a request req1 to send data to the second quantum secure terminal. The req1 includes the ciphertext MES1 of the data to be sent mes, the index idx1 of the first encryption key for encrypting the data mes, and the DID of the second quantum secure terminal. 接收 Then, request req1 is sent to the first quantum-safe terminal server.

[0018] (3) The first quantum-safe terminal server receives request req1 and, based on the DID of the second quantum-safe terminal in request req1... 接收 Vector key access gateway request to obtain DID 接收 Corresponding communication IP 接收 The first quantum-secure terminal server is based on communication IP. 接收 Knowing that the next recipient of the data is the second quantum-secure terminal server; the first quantum-secure terminal server generates the ciphertext MES2 of the data to be sent (mes) based on the request req1, and the index idx2 of the second encryption key used to generate the ciphertext MES2, and sends the ciphertext MES2 to the second quantum-secure terminal server, and sends the communication IP address. 接收 The index idx2 of the second encryption key is sent to the quantum key access gateway;

[0019] (4) The quantum key access gateway is based on the communication IP.接收 The index idx2 of the second encryption key is sent to the second quantum secure terminal server; the second quantum secure terminal server generates a request req2 based on the received ciphertext MES2 and the index idx2 of the second encryption key, and then sends the request req2 to the second quantum secure terminal. The req2 includes the ciphertext MES3 of the data to be sent mes and the index idx3 of the third encryption key used to generate the ciphertext MES3.

[0020] (5) The second quantum secure terminal receives the request req2, and obtains the decryption key from the local receiving key pool based on the index idx3 of the third encryption key in the request req2 to decrypt the ciphertext MES3 and obtain the data mes to be sent.

[0021] Furthermore, the process of generating the ciphertext MES1 of the data to be sent mes includes: the first quantum secure terminal obtains the first encryption key k1 from the local transmission key pool, records the index idx1 of the first encryption key, and encrypts the data to be sent mes using the first encryption key k1 to obtain the ciphertext MES1.

[0022] Furthermore, the specific process of generating the ciphertext MES2 of the data to be sent (mes) is as follows:

[0023] 1) The first quantum-safe terminal server obtains the decryption key k1' from the local first key pool according to the index idx1 of the first encryption key in the request req1, and uses the decryption key k1' to decrypt the ciphertext MES1 to obtain the data mes to be sent;

[0024] 2) The first quantum-safe terminal server obtains the second encryption key k2 from the local second key pool and records the index idx2 of the second encryption key. It then uses the second encryption key k2 to encrypt the data mes to be sent, obtaining the ciphertext MES2, and sends the ciphertext MES2 to the second quantum-safe terminal server. Specifically, the index idx2 of the second encryption key is compared with the communication IP address. 发送 Correspondingly.

[0025] Furthermore, the second quantum-secure terminal server generates request req2 based on the received ciphertext MES2 and the index idx2 of the second encryption key, which refers to:

[0026] A1: The second quantum-secure terminal server obtains the sending IP corresponding to index idx2 of the received second encryption key as the communication IP. 发送 Then, it iterates through the received, unprocessed data locally, and if it finds a corresponding communication IP address locally... 发送 If the encrypted MES2 is found, proceed to the next step of processing the encrypted MES2; if it is not found locally, continue to wait for the encrypted MES2.

[0027] A2: Response to finding the corresponding communication IP locally 发送 The encrypted text MES2 is then decrypted using the index idx2 of the second encryption key from the local third key pool to obtain the decryption key k2'. The decryption key k2' is then used to decrypt the encrypted text MES2 to obtain the data mes to be sent.

[0028] A3: The second quantum-safe terminal server obtains the third encryption key k3 from the local fourth key pool and records the index idx3 of the third encryption key. It uses the third encryption key k3 to encrypt the data mes to be sent to obtain the ciphertext MES3. The ciphertext MES3 and the index idx3 of the third encryption key are combined to form the request req2.

[0029] The beneficial effects of this invention are:

[0030] (1) The present invention ensures the security of data transmission by transmitting ciphertext and key index separately. Malicious users can only attack the transmission link between quantum security terminal servers or the transmission link of quantum key access gateway, but they cannot obtain the complete transmission data and therefore cannot decrypt the plaintext content of the transmission data.

[0031] (2) No symmetric key pool needs to be deployed between quantum-safe terminals. In real-world deployments, it is very difficult for a key distribution agency to distribute symmetric keys to two quantum-safe terminals that are far apart. The solution proposed in this application solves this problem. The key distribution agency only needs to distribute symmetric keys to the devices on both sides of the communication link. The two devices that directly establish a communication link are often connected by a single optical fiber, and their physical distance is limited. It is also practically feasible for them to belong to the same key distribution agency for key distribution.

[0032] (3) All data transmissions between quantum-secure terminals are quantum-encrypted ciphertexts, which elevates the security of data transmission to the level of communication security across the entire communication domain.

[0033] (4) The IP address of the quantum secure terminal of the present invention is not exposed in the communication network. Even if a malicious user attacks, he can only obtain the device identity DID. Since the malicious user (the user who is not in this communication network) does not know the generation rule of DID, he cannot find the location of the quantum secure terminal, thus avoiding the risk of the quantum secure terminal being attacked. Attached Figure Description

[0034] Figure 1 This is a schematic diagram of the data transmission system structure based on quantum device identity according to the present invention;

[0035] Figure 2 This is a schematic diagram showing the correspondence of key pools between each end in the data transmission system of the present invention;

[0036] Figure 3 This is a schematic diagram of the data transmission method based on quantum device identity according to the present invention. Detailed Implementation

[0037] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0038] In current network data transmission processes, the IP addresses of both sending and receiving devices are often exposed within the communication network, providing opportunities for malicious users to steal these IP addresses. Once IP addresses are leaked, hackers may attempt various network attacks, such as DDoS attacks, port scanning, and malware implantation, thereby compromising network security. Therefore, ensuring that the IP addresses of sending and receiving devices are not exposed within the communication network during data transmission is a crucial technical issue that needs to be addressed.

[0039] In view of this, this embodiment proposes a data transmission system based on quantum device identity. The solution in this embodiment can complete secure data transmission without exposing the client (sender and receiver). Figure 1 As shown, the system includes a first quantum secure terminal 1, a second quantum secure terminal 2, a first quantum secure terminal server 3, a second quantum secure terminal server 4, a quantum key access gateway 5, and a quantum secure CA server 6. The first quantum secure terminal 1 establishes a communication connection with the first quantum secure terminal server 3, the second quantum secure terminal 2 establishes a communication connection with the second quantum secure terminal server 4, the first quantum secure terminal server 3 and the second quantum secure terminal server 4 communicate via the Internet, the quantum secure CA server 6 connects to the first quantum secure terminal 1, the second quantum secure terminal 2, the first quantum secure terminal server 3, and the second quantum secure terminal server 4, respectively, and the quantum key access gateway 5 establishes a communication connection to the first quantum secure terminal server 3 and the second quantum secure terminal server 4, respectively.

[0040] The first quantum secure terminal 1 acts as the transmitter, encrypting and sending the data; the second quantum secure terminal 2 acts as the receiver, decrypting the received data; both the first quantum secure terminal server 3 and the second quantum secure terminal server 4 provide data encryption / decryption and ciphertext transmission functions for the connected quantum secure terminals; the quantum key access gateway 5 relays the key and key index, that is, the quantum key access gateway 5 relays the communication key between the quantum secure terminals (transmitter and receiver), including the relay communication key itself or the relay key index; the quantum secure CA server 6 generates and issues the respective quantum device identities for the first quantum secure terminal 1 and the second quantum secure terminal 2, and synchronizes the quantum device identities of the quantum secure terminals to the corresponding connected quantum secure terminal servers for storage.

[0041] like Figure 2 As shown, the key pool correspondence between each terminal is as follows: the transmit key pool preset by the first quantum secure terminal 1 is the same as the first key pool preset by the first quantum secure terminal server 3; the second key pool preset by the first quantum secure terminal server 3 is the same as the third key pool preset by the second quantum secure terminal server 4; and the fourth key pool preset by the second quantum secure terminal server 4 is the same as the receive key pool preset by the second quantum secure terminal 2.

[0042] Through this system, the first quantum secure terminal 1 and the second quantum secure terminal 2 do not communicate directly. The ciphertext of the communication is relayed through the first quantum secure terminal server 3 and the second quantum secure terminal server 4, and the communication key is relayed through the quantum key access gateway 5. Based on Figure 2 The deployment of symmetric keys in the system only requires that the two directly connected devices belong to the same key distribution authority, rather than all devices in the system belonging to the same key distribution authority.

[0043] For example: the first quantum secure terminal 1 and the first quantum secure terminal server 3 are under the jurisdiction of the first key distribution institution; the second quantum secure terminal 2 and the second quantum secure terminal server 4 are under the jurisdiction of the second key distribution institution; the first quantum secure terminal server 3 and the second quantum secure terminal server 4 are under the jurisdiction of the third key distribution institution; the first key distribution institution, the second key distribution institution and the third key distribution institution can be the same key distribution institution or they can be different key distribution institutions.

[0044] In this embodiment, no symmetric key pool needs to be deployed between quantum-safe terminals. In real-world deployments, it is very difficult for a key distribution organization to distribute symmetric keys to two quantum-safe terminals that are far apart. The solution in this embodiment precisely solves this problem. The key distribution organization only needs to allocate symmetric keys to the devices on both sides of the communication link. The two devices that directly establish a communication link are often connected by a single optical fiber, and their physical distance is limited. It is also practically feasible for them to belong to the same key distribution organization for key distribution.

[0045] This embodiment also includes a method based on the above-described quantum device identity-based data transmission system, such as... Figure 3 As shown, the method includes the following steps:

[0046] (1) The quantum-safe CA server 6 generates and issues corresponding quantum device identity DIDs for the first quantum-safe terminal 1 and the second quantum-safe terminal 2. 发送 and DID 接收 and will use quantum device identity DID 发送 and DID 接收Synchronize with the first quantum-secure terminal server 3 and the second quantum-secure terminal server 4 respectively;

[0047] The first quantum-secure terminal server 3 and the second quantum-secure terminal server 4 respectively obtain their respective communication IPs in the communication network. 发送 and communication IP 接收 The first quantum-secure terminal server 3 will receive the quantum device identity DID from the quantum-secure CA server 6. 发送 With its own communication IP 发送 The corresponding data is stored and sent to the quantum key access gateway 5, and the second quantum security terminal server 4 transmits the quantum device identity DID. 接收 With its own communication IP 接收 The corresponding data is stored and sent to the quantum key access gateway 5;

[0048] Subsequently, within this communication network, both the first quantum-secure terminal 1 and the second quantum-secure terminal 2 use DIDs for their external identities. During communication, both terminals only interact with their respective quantum-secure terminal servers, which handle data communication within the network. The DIDs are generated and issued by the quantum-secure CA server 6, and other devices outside the system cannot obtain the DIDs of the first and second quantum-secure terminals.

[0049] (2) The first quantum secure terminal 1 generates a request req1 to send data to the second quantum secure terminal 2. The req1 includes the ciphertext MES1 of the data to be sent mes, the index idx1 of the first encryption key for encrypting the data mes, and the DID of the second quantum secure terminal 2. 接收 Then, request req1 is sent to the first quantum secure terminal server 3; wherein, the process of generating the ciphertext MES1 of the data to be sent mes includes: the first quantum secure terminal 1 obtains the first encryption key k1 from the local sending key pool, records the index idx1 of the first encryption key, and uses the first encryption key k1 to encrypt the data to be sent mes to obtain the ciphertext MES1.

[0050] (3) The first quantum secure terminal server 3 receives request req1 and, based on the DID of the second quantum secure terminal 2 in request req1... 接收 Vector key access gateway 5 requests to obtain DID 接收 Corresponding communication IP 接收 The first quantum-secure terminal server 3 is based on communication IP. 接收Knowing that the next recipient of the data is the second quantum-secure terminal server 4; the first quantum-secure terminal server 3 generates the ciphertext MES2 of the data to be sent, MES2, based on the request req1, and the index idx2 of the second encryption key used to generate the ciphertext MES2, and sends the ciphertext MES2 to the second quantum-secure terminal server 4, and sends the communication IP address. 接收 The index idx2 of the second encryption key is sent to the quantum key access gateway 5;

[0051] The specific process of generating the ciphertext MES2 of the data to be sent (mess) is as follows:

[0052] 1) The first quantum-safe terminal server 3 obtains the decryption key k1' from the local first key pool according to the index idx1 of the first encryption key in the request req1, and uses the decryption key k1' to decrypt the ciphertext MES1 to obtain the data mes to be sent;

[0053] 2) The first quantum-secure terminal server 3 obtains the second encryption key k2 from the local second key pool and records the index idx2 of the second encryption key. It then uses the second encryption key k2 to encrypt the data mes to be sent, obtaining the ciphertext MES2, and sends the ciphertext MES2 to the second quantum-secure terminal server 4. Specifically, the index idx2 of the second encryption key is compared with the communication IP address. 发送 Correspondingly.

[0054] The security of data transmission is ensured by transmitting ciphertext and key index separately. Malicious users who only attack the transmission link between quantum security terminal servers or the transmission link of quantum key access gateway 5 will not be able to obtain the complete transmitted data and therefore will not be able to decrypt the plaintext content of the transmitted data.

[0055] (4) Quantum key access gateway 5 based on communication IP 接收 The index idx2 of the second encryption key is sent to the second quantum secure terminal server 4; the second quantum secure terminal server 4 generates a request req2 to be sent to the second quantum secure terminal 2 based on the received ciphertext MES2 and the index idx2 of the second encryption key, and then sends the request req2 to the second quantum secure terminal 2. The req2 includes the ciphertext MES3 of the data to be sent mes and the index idx3 of the third encryption key used to generate the ciphertext MES3.

[0056] Among them, the second quantum secure terminal server 4 generates a request req2 to be sent to the second quantum secure terminal 2 based on the received ciphertext MES2 and the index idx2 of the second encryption key.

[0057] Since the index idx2 of the second encryption key is transmitted by the quantum key access gateway 5, and the ciphertext MES2 is transmitted by the first quantum security terminal server 3, the two are transmitted asynchronously. Asynchronous transmission inevitably results in some keys arriving at the same time, specifically as follows:

[0058] A1: The second quantum-secure terminal server 4 obtains the sending IP corresponding to the received second encryption key index idx2 as the communication IP. 发送 Then, it iterates through the received, unprocessed data locally, and if it finds a corresponding communication IP address locally... 发送 If the encrypted MES2 is found, proceed to the next step of processing the encrypted MES2; if it is not found locally, it means that it has not been received yet, and continue to wait for the encrypted MES2.

[0059] A2: Response to finding the corresponding communication IP locally 发送 The encrypted text MES2 is then decrypted using the index idx2 of the second encryption key from the local third key pool to obtain the decryption key k2'. The decryption key k2' is then used to decrypt the encrypted text MES2 to obtain the data mes to be sent.

[0060] A3: The second quantum-safe terminal server 4 obtains the third encryption key k3 from the local fourth key pool and records the index idx3 of the third encryption key. It uses the third encryption key k3 to encrypt the data mes to be sent to obtain the ciphertext MES3. The ciphertext MES3 and the index idx3 of the third encryption key are combined to form the request req2.

[0061] (5) The second quantum security terminal 2 receives the request req2, and obtains the decryption key k3' from the local receiving key pool based on the index idx3 of the third encryption key in the request req2 to decrypt the ciphertext MES3, obtain the data to be sent mes, and complete the transmission of the data to be sent mes.

[0062] The IP address of the quantum-safe terminal of this invention is not exposed in the communication network. Even if a malicious user attacks, they can only obtain the device identity DID. Since the malicious user does not know the generation rules of the DID, they cannot find the location of the quantum-safe terminal, thus avoiding the risk of the quantum-safe terminal being attacked. Moreover, the data transmission between quantum-safe terminals is all quantum-encrypted ciphertext, which improves the security of data transmission to the communication security of the entire communication domain.

Claims

1. A data transmission system based on quantum device identity, characterized in that: The system includes a first quantum-secure terminal, a second quantum-secure terminal, a first quantum-secure terminal server, a second quantum-secure terminal server, a quantum key access gateway, and a quantum-secure CA server. The first quantum-secure terminal is connected to the first quantum-secure terminal server, the second quantum-secure terminal is connected to the second quantum-secure terminal server, the first quantum-secure terminal server and the second quantum-secure terminal server are connected via the Internet, the quantum-secure CA server is connected to the first quantum-secure terminal, the second quantum-secure terminal, the first quantum-secure terminal server and the second quantum-secure terminal server, and the quantum key access gateway is connected to the first quantum-secure terminal server and the second quantum-secure terminal server. The first quantum-secure terminal is used to encrypt and transmit the data. The second quantum-secure terminal is used to decrypt the received data; Both the first quantum-secure terminal server and the second quantum-secure terminal server are used to provide data encryption / decryption and ciphertext transmission functions for connected quantum-secure terminals; The quantum key access gateway is used to relay keys and key indexes; The quantum-safe CA server is used to generate and issue quantum device identities for the first quantum-safe terminal and the second quantum-safe terminal, and to synchronize the quantum device identities of the quantum-safe terminals to the corresponding connected quantum-safe terminal servers for storage.

2. The data transmission system based on quantum device identity according to claim 1, characterized in that: The first quantum secure terminal has a preset transmission key pool that is the same as the first key pool that is preset by the first quantum secure terminal server; the first quantum secure terminal server has a preset second key pool that is the same as the second quantum secure terminal server's preset third key pool. The fourth key pool pre-configured in the second quantum secure terminal server is the same as the receiving key pool pre-configured in the second quantum secure terminal.

3. A data transmission system based on quantum device identity according to claim 1, characterized in that: The first quantum-secure terminal and the first quantum-secure terminal server are under the jurisdiction of the first key distribution organization; The second quantum secure terminal and the second quantum secure terminal server are under the jurisdiction of the second key distribution organization; the first quantum secure terminal server and the second quantum secure terminal server are under the jurisdiction of the third key distribution organization; the first key distribution organization, the second key distribution organization and the third key distribution organization are the same key distribution organization or different key distribution organizations.

4. A method for a data transmission system based on quantum device identity as described in any one of claims 1 to 3, characterized in that, The method includes the following steps: (1) The quantum-safe CA server generates and issues corresponding quantum device identity DIDs for the first quantum-safe terminal and the second quantum-safe terminal. 发送 and DID 接收 and will use quantum device identity DID 发送 and DID 接收 Synchronize with the first quantum-secure terminal server and the second quantum-secure terminal server respectively; The first and second quantum-secure terminal servers respectively obtain their respective communication IPs in the communication network. 发送 and communication IP 接收 The first quantum-secure terminal server will receive the quantum device identity DID from the quantum-secure CA server. 发送 With its own communication IP 发送 The corresponding data is stored and sent to the quantum key access gateway. The second quantum secure terminal server then stores the quantum device's identity (DID). 接收 With its own communication IP 接收 The corresponding data is stored and sent to the quantum key access gateway; (2) The first quantum secure terminal generates a request req1 to send data to the second quantum secure terminal. The req1 includes the ciphertext MES1 of the data to be sent mes, the index idx1 of the first encryption key for encrypting the data mes, and the DID of the second quantum secure terminal. 接收 Then, request req1 is sent to the first quantum-safe terminal server. (3) The first quantum-safe terminal server receives request req1 and, based on the DID of the second quantum-safe terminal in request req1... 接收 Vector key access gateway request to obtain DID 接收 Corresponding communication IP 接收 The first quantum-secure terminal server is based on communication IP. 接收 It was learned that the next recipient of the data was the second quantum-safe terminal server; The first quantum-secure terminal server generates the ciphertext MES2 of the data to be sent (mes) based on request req1, and the index idx2 of the second encryption key used to generate the ciphertext MES2. It then sends the ciphertext MES2 to the second quantum-secure terminal server, and sends the communication IP address. 接收 The index idx2 of the second encryption key is sent to the quantum key access gateway; (4) The quantum key access gateway is based on the communication IP. 接收 Send the index idx2 of the second encryption key to the second quantum-secure terminal server; The second quantum secure terminal server generates a request req2 based on the received ciphertext MES2 and the index idx2 of the second encryption key, and then sends the request req2 to the second quantum secure terminal. The req2 includes the ciphertext MES3 of the data to be sent and the index idx3 of the third encryption key used to generate the ciphertext MES3. (5) The second quantum secure terminal receives the request req2, and obtains the decryption key from the local receiving key pool based on the index idx3 of the third encryption key in the request req2 to decrypt the ciphertext MES3 and obtain the data mes to be sent.

5. The method according to claim 4, characterized in that: The process of generating the ciphertext MES1 of the data to be sent mes includes: the first quantum secure terminal obtains the first encryption key k1 from the local transmission key pool, records the index idx1 of the first encryption key, and encrypts the data to be sent mes using the first encryption key k1 to obtain the ciphertext MES1.

6. The method according to claim 5, characterized in that: The specific process of generating the ciphertext MES2 of the data to be sent (mes) is as follows: 1) The first quantum-safe terminal server obtains the decryption key k1' from the local first key pool according to the index idx1 of the first encryption key in the request req1, and uses the decryption key k1' to decrypt the ciphertext MES1 to obtain the data mes to be sent; 2) The first quantum-safe terminal server obtains the second encryption key k2 from the local second key pool and records the index idx2 of the second encryption key. It then uses the second encryption key k2 to encrypt the data mes to be sent, obtaining the ciphertext MES2, and sends the ciphertext MES2 to the second quantum-safe terminal server. Specifically, the index idx2 of the second encryption key is compared with the communication IP address. 发送 Correspondingly.

7. The method according to claim 6, characterized in that: The second quantum-secure terminal server generates request req2 based on the received ciphertext MES2 and the index idx2 of the second encryption key, which refers to: A1: The second quantum-safe terminal server obtains the sending IP corresponding to index idx2 of the received second encryption key as the communication IP. 发送 Then, it iterates through the received, unprocessed data locally, and if it finds a corresponding communication IP address locally... 发送 If the encrypted MES2 is found, proceed to the next step of processing the encrypted MES2; if it is not found locally, continue to wait for the encrypted MES2. A2: Response to finding the corresponding communication IP locally 发送 The encrypted text MES2 is then decrypted using the index idx2 of the second encryption key from the local third key pool to obtain the decryption key k2'. The decryption key k2' is then used to decrypt the encrypted text MES2 to obtain the data mes to be sent. A3: The second quantum-safe terminal server obtains the third encryption key k3 from the local fourth key pool and records the index idx3 of the third encryption key. It uses the third encryption key k3 to encrypt the data mes to be sent to obtain the ciphertext MES3. The ciphertext MES3 and the index idx3 of the third encryption key are combined to form the request req2.