Key authentication method for quantum encryption call
By actively determining and sending the symmetric key and key identifier through the quantum key management server, the problem of authentication key transmission security in quantum encrypted calls is solved, achieving higher security and reliability, and protecting user communication privacy and data security.
Patent Information
- Application Number
- CN202511626299.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-07
- Publication Date
- 2026-01-13
AI Technical Summary
In quantum-encrypted calls, the authentication key can be illegally obtained by others during transmission, leading to security vulnerabilities in the authentication process and affecting call security.
By changing the direction and method of key transmission, the quantum key management server actively determines and sends the symmetric key and key identifier. The terminal does not need to directly transmit the authentication key. The authentication process is carried out through the central control station to ensure the security of the key during transmission.
It effectively reduces the risk of authentication keys being illegally intercepted during transmission, improves the security and reliability of quantum encrypted calls, and protects user communication privacy and data security.
Smart Images

Figure CN121333744A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a key authentication method for quantum encrypted calls. Background Technology
[0002] In quantum-encrypted call authentication, the first terminal typically sends the authentication key directly to the quantum key management system for authentication. However, during the transmission of the authentication key, it is vulnerable to unauthorized acquisition and unauthorized authentication by others. This authentication process presents certain security risks, impacting the security of quantum-encrypted calls. Summary of the Invention
[0003] This application provides a key authentication method for quantum encrypted calls.
[0004] The key authentication method for quantum encrypted calls provided in this application includes: The system receives an authentication request sent by the central control station and the first identity information of the first terminal, wherein the central control station generates the authentication request in response to a quantum-encrypted call request initiated by the first terminal. In response to the authentication request, a first symmetric key and a first key identifier are determined based on the first identity information, wherein the first key identifier is associated with the first symmetric key; The first symmetric key and the first key identifier are sent to the central control station, wherein the central control station performs authentication processing based on the first symmetric key and the first key identifier.
[0005] In this way, by changing the direction and method of key transmission, the traditional mode of the terminal actively sending the authentication key is transformed into the quantum key management server actively determining and sending the symmetric key and key identifier. This eliminates the need for direct transmission of the authentication key between the terminal and the quantum key management server, thus enabling terminal authentication. This effectively reduces the risk of the authentication key being illegally intercepted by others during transmission, and to a certain extent eliminates the security risks in the quantum encrypted call authentication process. As a result, it ensures the security of quantum encrypted call authentication to a certain extent, provides a secure and reliable identity verification foundation for users' quantum encrypted calls, and protects users' communication privacy and data security.
[0006] In some implementations, responding to the authentication request and determining the first symmetric key and the first key identifier based on the first identity information includes: Based on the first identity information, determine the first symmetric key set associated with the first identity information; One key is randomly selected from the first set of symmetric keys as the first symmetric key; The first key identifier is determined based on the first symmetric key.
[0007] In this way, by randomly extracting one key from the first set of symmetric keys as the first symmetric key and determining the corresponding first key identifier based on the first symmetric key, the risk of authentication key misuse caused by the predictability of symmetric key usage patterns or mismatch between symmetric keys and key identifiers is reduced to a certain extent. This improves the security and reliability of the quantum encrypted call authentication process to a certain extent and provides strong key management protection for the secure advancement of quantum encrypted calls.
[0008] In some embodiments, the method further includes: The system receives the authentication success information sent by the central control station, generates a session key, and sends the session key to the first terminal. The central control station sends the first key identifier to the first terminal. The first terminal determines the first authentication key based on the first key identifier and sends the first authentication key to the central control station. The central control station generates the authentication success information when the first symmetric key and the first authentication key satisfy the symmetric key relationship.
[0009] In this way, by verifying the symmetric key relationship, it is further ensured that only the first terminal holding the legitimate authentication key can trigger the generation of the session key. This eliminates, to a certain extent, the security risk of others impersonating the authentication key for authentication after the communication terminal is cracked and the authentication key is leaked. This ensures the security of quantum encrypted calls to a certain extent and improves the overall reliability of the quantum encrypted call system.
[0010] In some embodiments, the method further includes: The terminal receives a symmetric key set sent by the key injection server, wherein the symmetric key set includes multiple symmetric keys, each of which is associated with an authentication key and a key identifier associated with the authentication key; the terminal receives an authentication key set injected by the key injection server, wherein the authentication key set includes multiple authentication keys, each of which is associated with a key identifier.
[0011] In this way, the key filling server uniformly generates a symmetric key set and a corresponding authentication key set, sends the symmetric key set to the quantum key management server, and fills the authentication key set into the terminal. This effectively ensures that the quantum key management server and the terminal have a precisely matched key pair, providing a secure and compliant initial key resource for the subsequent authentication process. It avoids authentication risks caused by inconsistent or mismatched key sources to a certain extent. At the same time, through the unique association of key identifiers, it lays the foundation for the terminal not to directly transmit the complete authentication key to the quantum key management server in subsequent authentication, reducing the risk of the authentication key being illegally intercepted during transmission. This, in turn, ensures the security of the quantum encrypted call authentication process to a certain extent and provides reliable key protection for subsequent authentication operations.
[0012] In some embodiments, the method further includes: Receive the terminal's identity information sent by the key filling server; The identity information is associated and bound with the symmetric key set.
[0013] In this way, by receiving the terminal identity information sent by the key filling server and associating the identity information with the corresponding symmetric key set, a mapping relationship between the terminal identity and the symmetric key set is effectively established. This reduces the authentication security risks caused by chaotic key management to a certain extent. At the same time, even if an illegal terminal steals the terminal's authentication key, it cannot trigger the quantum key management server to call the associated symmetric key set due to the lack of corresponding terminal identity information. This reduces the risk of the authentication key being misused for authentication after leakage, thereby improving the security of quantum encrypted call authentication to a certain extent and enhancing the response efficiency and reliability of the authentication process.
[0014] This application provides a key authentication method for quantum encrypted calls, the method being used in a centralized control station, the method comprising: In response to a quantum-encrypted call request initiated by the first terminal, an authentication request is generated, and the authentication request and the first identity information of the first terminal are sent to the quantum key management server. The system receives a first symmetric key and a first key identifier sent by the quantum key management server, wherein the quantum key management server, in response to the authentication request, determines the first symmetric key and the first key identifier based on the first identity information. Authentication is performed based on the first symmetric key and the first key identifier.
[0015] In this way, by conducting local authentication processing based on the first symmetric key and the first key identifier through the central control station, the direct data interaction between the first terminal and the quantum key management server is effectively isolated, which reduces the risk of the authentication key being illegally intercepted in the long-distance transmission link to a certain extent, thereby ensuring the security of quantum encrypted call authentication to a certain extent.
[0016] In some implementations, receiving the first symmetric key and the first key identifier sent by the quantum key management server includes: Store the first symmetric key and send the first key identifier to the first terminal.
[0017] In this way, the central control station stores the first symmetric key and sends the first key identifier to the first terminal to obtain the first authentication key, avoiding the indiscriminate transmission of the authentication key, reducing the risk of authentication key leakage to a certain extent, and ensuring the security of quantum encrypted call authentication.
[0018] In some implementations, the authentication process based on the first symmetric key and the first key identifier includes: Upon receiving the first symmetric key and the first key identifier, a key request is generated; The key request and the first key identifier are sent to the first terminal, wherein the first terminal responds to the key request, determines the first authentication key based on the first key identifier, and sends the first authentication key to the central control station; Authentication is performed based on the first authentication key and the first symmetric key.
[0019] In this way, the central control station receives the first authentication key and completes the authentication comparison locally, which reduces the risk of the authentication key being illegally intercepted in long-distance transmission links to a certain extent. At the same time, the extraction and transmission of the first authentication key depends on the key request and accurate first key identifier of the central control station. This makes it difficult for others to impersonate the stolen authentication key to pass authentication if the first terminal is cracked and the authentication key is leaked, due to the lack of corresponding request guidance and identifier matching. This improves the security and accuracy of the quantum encrypted call authentication process to a certain extent.
[0020] In some implementations, the authentication process based on the first authentication key and the first symmetric key includes: The first authentication key and the first symmetric key are compared. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the authentication is deemed successful. If authentication is successful, an authentication success message is generated and sent to the quantum key management server.
[0021] In this way, by comparing the first authentication key with the first symmetric key, authentication is confirmed to be successful when the two satisfy the symmetric key relationship, and authentication success information is generated and sent to the quantum key management server. This effectively ensures that only terminals holding legitimate authentication keys can pass authentication. From the result determination stage, it blocks the possibility of others impersonating others by intercepting or stealing keys, and reduces the authentication security risk caused by the illegal acquisition of authentication keys to a certain extent. At the same time, the reliable transmission of authentication success information provides an accurate basis for the quantum key management server to start the subsequent session key generation and distribution process. To a certain extent, it realizes the smooth connection between the authentication process and the quantum encrypted call preparation process, and improves the security and collaborative efficiency of the entire system.
[0022] This application provides a key authentication method for quantum encrypted calls. The method is used in a quantum encrypted call key authentication system, which includes a quantum key management server, a central control station, and a first terminal. The method includes: The first terminal sends a quantum-encrypted call request to the central control station; The central control station responds to the quantum encrypted call request, generates an authentication request, and sends the authentication request and the first identity information of the first terminal to the quantum key management server; The quantum key management server receives the authentication request and the first identity information; The quantum key management server responds to the authentication request and determines a first symmetric key and a first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key; The quantum key management server sends the first symmetric key and the first key identifier to the central control station; The central control station performs authentication based on the first symmetric key and the first key identifier.
[0023] In this way, by changing the direction and method of key transmission, the traditional mode of the terminal actively sending the authentication key is transformed into the quantum key management server actively determining and sending the symmetric key and key identifier. This eliminates the need for direct transmission of the authentication key between the terminal and the quantum key management server, thus enabling terminal authentication. This effectively reduces the risk of the authentication key being illegally intercepted by others during transmission, and to a certain extent eliminates the security risks in the quantum encrypted call authentication process. As a result, it ensures the security of quantum encrypted call authentication to a certain extent, provides a secure and reliable identity verification foundation for users' quantum encrypted calls, and protects users' communication privacy and data security.
[0024] Additional aspects and advantages of embodiments of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of embodiments of this application. Attached Figure Description
[0025] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, wherein: Figure 1 This is one of the flowcharts illustrating a key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 2 This is a second flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 3 This is the third flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 4 This is the fourth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 5 This is the fifth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 6 This is the sixth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 7 This is the seventh flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 8 This is the eighth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 9 This is the ninth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 10 This is the tenth flowchart illustrating the key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 11 This is a timing diagram of a key authentication method for quantum encrypted calls according to certain embodiments of this application; Figure 12 This is a schematic diagram of the system structure of a key authentication method for quantum encrypted calls according to certain embodiments of this application. Detailed Implementation
[0026] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the embodiments of this application, and should not be construed as limiting the embodiments of this application.
[0027] The standard operating procedure for quantum-encrypted calls includes: the communication terminal initiating a call request; verifying the communication terminal's authorization to initiate a quantum-encrypted call; a key distribution device distributing quantum keys to both parties; and both parties using the quantum keys for encrypted communication. Specifically, when a communication terminal wants to initiate a quantum-encrypted call, it randomly extracts an authentication key from the pre-loaded authentication keys in the quantum-encrypted SIM card and sends it directly to the quantum key management system. The quantum key management system searches its own pre-stored authentication keys for a corresponding symmetric key. If a matching symmetric key is found, authentication is successful, and the communication terminal gains authorization to initiate a quantum-encrypted call. However, during the transmission of the authentication key, there is a risk that others may illegally obtain the authentication key for authentication. This authentication process presents certain security vulnerabilities, affecting the security of quantum-encrypted calls.
[0028] Furthermore, there is a risk that the communication terminal may be cracked by others, leading to the leakage of authentication keys. Others could then use the stolen authentication keys to initiate authentication with the quantum key management system, thereby launching illegal quantum encrypted calls and threatening the security of quantum encrypted calls.
[0029] Based on the above issues, please refer to Figure 1 This application provides a key authentication method for quantum encrypted calls, the method comprising: 01: Receive the authentication request and the first identity information of the first terminal sent by the central control station, wherein the central control station generates the authentication request in response to the quantum encrypted call request initiated by the first terminal; 02: In response to the authentication request, determine the first symmetric key and the first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key; 03: Send the first symmetric key and the first key identifier to the central control station, whereby the central control station performs authentication processing based on the first symmetric key and the first key identifier.
[0030] This application provides a key authentication device for quantum encrypted calls. The key authentication method for quantum encrypted calls according to this application can be implemented by the key authentication device for quantum encrypted calls according to this application. Specifically, the key authentication device for quantum encrypted calls includes a receiving module, a determining module, and a sending module. The receiving module is used to receive an authentication request sent by a central control station and first identity information of a first terminal, wherein the central control station generates an authentication request in response to a quantum encrypted call request initiated by the first terminal. The determining module is used to respond to the authentication request and determine a first symmetric key and a first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key. The sending module is used to send the first symmetric key and the first key identifier to the central control station, wherein the central control station performs authentication processing based on the first symmetric key and the first key identifier.
[0031] This application also provides a server, which includes a memory and a processor. The key authentication method for quantum encrypted calls according to this application can be implemented by the server of this application. Specifically, the memory stores a computer program, and the processor is used to receive an authentication request sent by a central control station and first identity information of a first terminal, wherein the central control station generates an authentication request in response to a quantum encrypted call request initiated by the first terminal. The processor is also used to respond to the authentication request and determine a first symmetric key and a first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key. The processor is also used to send the first symmetric key and the first key identifier to the central control station, wherein the central control station performs authentication processing based on the first symmetric key and the first key identifier.
[0032] Specifically, a communication method that achieves high-security identity authentication and call content protection based on quantum key technology is called quantum encrypted calling.
[0033] Taking quantum-encrypted calls between communication devices equipped with quantum-encrypted SIM cards as an example, compared to traditional encrypted calls, the communication devices have modified ordinary dialing components to protect the identity authentication information of the callers with quantum session keys, and have built-in quantum-safe middleware to invoke the charging key in the quantum-encrypted SIM card.
[0034] Each time a quantum-encrypted call is initiated, the communication device randomly selects the charging key from the quantum-encrypted SIM card and establishes a connection with the backend to verify the legitimacy of the identity. After successful authentication, the key distribution device generates a session key and distributes it to the communication device. Finally, the communication devices conduct quantum-encrypted communication based on the session key.
[0035] A quantum key management server is a server capable of performing operations such as verifying user identity and distributing call keys; for example, it could be a quantum key service system. A quantum key service system can manage the set of symmetric keys associated with a terminal's identity, providing key support for the authentication process.
[0036] Within a quantum metropolitan area network, the central control station is a quantum-encrypted communication service base station capable of providing quantum-encrypted channel base station services to terminals. The central control station functions similarly to a traditional cellular network base station, serving to forward information between terminals and the quantum key management server.
[0037] The request used to apply to the quantum key management server for verification of the first terminal's call permission is an authentication request. The authentication request is generated by the central control station after receiving the quantum encrypted call request from the first terminal.
[0038] The terminal that initiates the quantum-encrypted call request is the first terminal, which needs to obtain quantum-encrypted call permissions through authentication. For example, the first terminal can be a smartphone, tablet, or other device equipped with a quantum-encrypted SIM card.
[0039] The information used to identify the first terminal is called the first identity information, such as the ID information of a quantum encrypted SIM card. The first identity information is associated with a pre-stored set of symmetric keys in the quantum key management server to ensure that the quantum key management server can accurately find the symmetric key corresponding to the first terminal.
[0040] The quantum key management server determines the symmetric key used for authentication based on the first identity information as the first symmetric key, and the first symmetric key forms a symmetric relationship with a certain authentication key in the first terminal hardware security module.
[0041] The first key identifier is the identification information associated with the first symmetric key, and can be a key number or a random data segment, etc. The first key identifier can be used by the first terminal to quickly locate the corresponding authentication key, thereby ensuring that the key can be accurately matched during the authentication process.
[0042] When the first terminal needs to initiate a quantum-encrypted call, it will send a quantum-encrypted call request to the central control station of the quantum metropolitan area network to which the first terminal is connected.
[0043] Upon receiving a quantum-encrypted call request, the central control station immediately responds and generates an authentication request, while simultaneously obtaining the primary identity information of the first terminal. Subsequently, the central control station sends the generated authentication request and the obtained primary identity information to the quantum key management server.
[0044] After receiving the authentication request and first identity information from the central control station, the quantum key management server locates the first symmetric key set bound to the first identity information by querying the stored association data between the terminal identity information and the symmetric key set. Then, the quantum key management server randomly extracts a symmetric key from the first symmetric key set as the first symmetric key required for this authentication, and simultaneously obtains the first key identifier associated with the first symmetric key.
[0045] Understandably, the determination of the first symmetric key depends on the first identity information of the first terminal. This means that even if the first terminal is cracked and the authentication key is leaked, others will not be able to trigger the quantum key management server to send the first symmetric key and the first key identifier due to the lack of the first identity information. As a result, the leaked authentication key is difficult to use for authentication, thus solving to some extent the problem of the authentication key being misused by others for authentication after it is leaked.
[0046] After determining the first symmetric key and the first key identifier, the quantum key management server sends the first symmetric key and the first key identifier to the central control station through a secure transmission channel. After receiving the first symmetric key and the first key identifier, the central control station performs subsequent authentication processing.
[0047] In this way, by changing the direction and method of key transmission, the traditional mode of the terminal actively sending the authentication key is transformed into the quantum key management server actively determining and sending the symmetric key and key identifier. This eliminates the need for direct transmission of the authentication key between the terminal and the quantum key management server, thus enabling terminal authentication. This effectively reduces the risk of the authentication key being illegally intercepted by others during transmission, and to a certain extent eliminates the security risks in the quantum encrypted call authentication process. As a result, it ensures the security of quantum encrypted call authentication to a certain extent, provides a secure and reliable identity verification foundation for users' quantum encrypted calls, and protects users' communication privacy and data security.
[0048] Please see Figure 2 In some implementations, step 02 includes: 021: Based on the first identity information, determine the first symmetric key set associated with the first identity information; 022: Randomly select one key from the first symmetric key set as the first symmetric key; 023: Determine the first key identifier based on the first symmetric key.
[0049] In some implementations, the determining module is further configured to determine a first set of symmetric keys associated with the first identity information based on the first identity information. The determining module is further configured to randomly extract a key from the first set of symmetric keys as the first symmetric key. The determining module is further configured to determine a first key identifier based on the first symmetric key.
[0050] In some implementations, the processor is further configured to determine a first set of symmetric keys associated with the first identity information based on the first identity information. The processor is further configured to randomly extract a key from the first set of symmetric keys as the first symmetric key. The processor is further configured to determine a first key identifier based on the first symmetric key.
[0051] Specifically, the set of multiple symmetric keys associated with the first identity information of the first terminal is called the first symmetric key set. The first symmetric key set is pre-stored in the quantum key management server. Each symmetric key can form a symmetric key relationship with a certain authentication key stored in the first terminal, providing multiple sets of alternative key resources for authentication.
[0052] When the quantum key management server receives the authentication request and first identity information forwarded by the central control station, it retrieves the first symmetric key set data bound to the first identity information from the database and determines the corresponding first symmetric key set.
[0053] After determining the first symmetric key set, the quantum key management server randomly selects a symmetric key from the first symmetric key set as the first symmetric key.
[0054] Among them, the quantum key management server can generate truly random numbers through a quantum random number generator, determine the quantum random index of the key, randomly select a symmetric key, or randomly select a symmetric key based on a quantum random hash mapping that matches the random number and the key hash value. It can also select a symmetric key through cryptographically secure pseudo-random methods to ensure the unpredictability and uniformity of the extraction process and meet the security requirements of quantum encrypted call authentication.
[0055] Finally, the quantum key management server determines the first key identifier based on the pre-stored association between symmetric keys and key identifiers, ensuring a unique correspondence between the first key identifier and the first symmetric key. This association is defined and bound synchronously when the key filling server generates the first symmetric key set.
[0056] In this way, by randomly extracting one key from the first set of symmetric keys as the first symmetric key and determining the corresponding first key identifier based on the first symmetric key, the risk of authentication key misuse caused by predictable symmetric key usage patterns or mismatch between symmetric keys and key identifiers is reduced to a certain extent. This improves the security and reliability of the quantum encrypted call authentication process to a certain extent and provides strong key management protection for the secure advancement of quantum encrypted calls.
[0057] Please see Figure 3 In some implementations, the key authentication method for quantum encrypted calls further includes: 04: Receive the authentication success information sent by the central control station, generate a session key, and send the session key to the first terminal. The central control station sends the first key identifier to the first terminal. The first terminal determines the first authentication key based on the first key identifier and sends the first authentication key to the central control station. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the central control station generates the authentication success information.
[0058] In some implementations, the receiving module is further configured to receive authentication success information sent by the central control station, generate a session key, and send the session key to the first terminal. In this case, the central control station sends a first key identifier to the first terminal, the first terminal determines a first authentication key based on the first key identifier, and sends the first authentication key to the central control station. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the central control station generates authentication success information.
[0059] In some implementations, the processor is further configured to receive authentication success information sent by the central control station, generate a session key, and send the session key to the first terminal. In this case, the central control station sends a first key identifier to the first terminal, the first terminal determines a first authentication key based on the first key identifier, and sends the first authentication key to the central control station. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the central control station generates authentication success information.
[0060] Specifically, the signal generated by the central control station to inform the quantum key management server that authentication has been successful is the authentication success message. The generation of the authentication success message is premised on the first symmetric key and the first authentication key satisfying the symmetric key relationship.
[0061] After successful authentication, the quantum key management server generates a symmetric key for this quantum-encrypted call, which serves as the session key. The session key can be used to encrypt call data between terminals, is valid during the call period, and is destroyed immediately after the call ends, thus ensuring the real-time security of the call content to a certain extent.
[0062] The first authentication key is an authentication key that is pre-stored in the first terminal. The first authentication key and the first symmetric key determined by the quantum key management server are symmetric keys. After the central control station sends the first key identifier, the first terminal locates and retrieves the key based on the first key identifier.
[0063] Data encrypted with the first symmetric key can be decrypted with the first authentication key, and data encrypted with the first authentication key can also be decrypted with the first symmetric key. This symmetric key relationship is a symmetric key relationship. The symmetric key relationship can be used to verify the legitimacy of the first terminal's identity. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the central control station determines that authentication is successful.
[0064] After receiving the first symmetric key and the first key identifier from the quantum key management server, the central control station sends the first key identifier to the first terminal.
[0065] The first terminal extracts the first authentication key corresponding to the first key identifier from the stored authentication key set according to the first key identifier, and sends the extracted first authentication key to the central control station.
[0066] After receiving the first authentication key, the central control station verifies whether the first authentication key and the stored first symmetric key satisfy the symmetric key relationship; if the symmetric key relationship is satisfied, the central control station generates authentication success information and sends the authentication success information to the quantum key management server.
[0067] Upon receiving the successful authentication message, the quantum key management server immediately generates a session key for this quantum-encrypted call and sends the generated session key to the first terminal. The first terminal, upon receiving the session key, can then conduct a quantum-encrypted call with its communication counterpart.
[0068] In this way, by verifying the symmetric key relationship, it is further ensured that only the first terminal holding the legitimate authentication key can trigger the generation of the session key. This eliminates, to a certain extent, the security risk of others impersonating the authentication key for authentication after the communication terminal is cracked and the authentication key is leaked. This ensures the security of quantum encrypted calls to a certain extent and improves the overall reliability of the quantum encrypted call system.
[0069] Please see Figure 4 In some implementations, the key authentication method for quantum encrypted calls further includes: 05: Receive a symmetric key set sent by the key filling server, wherein the symmetric key set includes multiple symmetric keys, each symmetric key is associated with an authentication key and a key identifier associated with the authentication key, and the terminal receives an authentication key set filled by the key filling server, wherein the authentication key set includes multiple authentication keys, each authentication key is associated with a key identifier.
[0070] In some implementations, the receiving module is further configured to receive a symmetric key set sent by the key injection server, wherein the symmetric key set includes multiple symmetric keys, each symmetric key is associated with an authentication key and a key identifier associated with the authentication key, and the terminal receives an authentication key set injected by the key injection server, wherein the authentication key set includes multiple authentication keys, each authentication key is associated with a key identifier.
[0071] In some implementations, the processor is further configured to receive a symmetric key set sent by a key injection server, wherein the symmetric key set includes multiple symmetric keys, each symmetric key is associated with an authentication key and a key identifier associated with the authentication key, and the terminal receives an authentication key set injected by the key injection server, wherein the authentication key set includes multiple authentication keys, each authentication key is associated with a key identifier.
[0072] Specifically, the key injection server is the device responsible for key generation, management, and distribution. The key injection server can generate multiple sets of symmetric authentication keys and symmetric keys, with each key pair associated with a unique key identifier. The key injection server injects the authentication keys into the terminal's quantum encryption module via a secure link, forming the terminal's authentication key set.
[0073] At the same time, the key filling server sends the corresponding multiple symmetric keys and key identifiers to the quantum key management server. The multiple symmetric keys form a symmetric key set, completing the pre-distribution of keys.
[0074] A set of multiple symmetric keys generated by the key filling server and sent to the quantum key management server is called a symmetric key set. Each symmetric key has a corresponding authentication key and a key identifier.
[0075] The set of multiple authentication keys generated by the key injection server and injected into the terminal is called the authentication key set. Each authentication key forms a symmetric relationship with a certain symmetric key in the symmetric key set and is associated with a corresponding key identifier.
[0076] The identification information that corresponds one-to-one with the symmetric key and the authentication key is the key identifier. The key identifier can be a numerical number, a combination of characters, or a hash value. It can be used to establish a mapping relationship between the symmetric key set and the authentication key set, thereby ensuring that the quantum key management server, the central control station, and the terminal can accurately locate the corresponding key during the authentication process and avoid key confusion.
[0077] After the terminal subscribes to the quantum encrypted call package, the key filling server first starts the key generation process, generating multiple symmetric keys and corresponding authentication keys, and at the same time generating the same key identifier for each symmetric key and corresponding authentication key.
[0078] Subsequently, the key filling server organizes all the generated symmetric keys into a symmetric key set, which is then sent to the quantum key management server through a secure communication channel.
[0079] Simultaneously, the key injection server organizes all generated authentication keys into an authentication key set, which is then injected into the terminal's hardware security module via a secure communication channel. For example, the key injection server injects the authentication key set into the terminal's quantum encryption SIM card.
[0080] Finally, after receiving the symmetric key set, the quantum key management server associates and stores the symmetric key set with the identity information of the first terminal, completing the initial key filling and storage.
[0081] In this way, the key filling server uniformly generates a symmetric key set and a corresponding authentication key set, sends the symmetric key set to the quantum key management server, and fills the authentication key set into the terminal. This effectively ensures that the quantum key management server and the terminal have a precisely matched key pair, providing a secure and compliant initial key resource for the subsequent authentication process. It avoids authentication risks caused by inconsistent or mismatched key sources to a certain extent. At the same time, through the unique association of key identifiers, it lays the foundation for the terminal not to directly transmit the complete authentication key to the quantum key management server in subsequent authentication, reducing the risk of the authentication key being illegally intercepted during transmission. This, in turn, ensures the security of the quantum encrypted call authentication process to a certain extent and provides reliable key protection for subsequent authentication operations.
[0082] Please see Figure 5 In some implementations, the key authentication method for quantum encrypted calls further includes: 06: Receive the terminal's identity information sent by the key filling server; 07: Associate and bind identity information with the symmetric key set.
[0083] In some implementations, the receiving module is further configured to receive the terminal's identity information sent by the key filling server. The receiving module is also configured to associate and bind the identity information with a symmetric key set.
[0084] In some implementations, the processor is also configured to receive the terminal's identity information sent by the key injection server. The processor is further configured to associate and bind the identity information with a symmetric key set.
[0085] Specifically, the exclusive information used to identify the terminal is the terminal's identity information, such as the chip ID of the quantum encryption SIM card and the terminal device number.
[0086] The operation of establishing a fixed mapping relationship between a terminal's identity information and its corresponding symmetric key set is called the association and binding operation. Through association and binding, the quantum key management server can use the terminal's identity information as a retrieval condition to quickly locate the terminal's unique symmetric key set, thereby avoiding the problem of mismatch between key resources and terminal identity to a certain extent.
[0087] After generating the symmetric key set and the authentication key set, the key filling server obtains the terminal's identity information, packages the identity information and the symmetric key set, and sends them to the quantum key management server through a secure communication channel.
[0088] After receiving the information, the quantum key management server associates and binds the terminal's identity information with the symmetric key set, establishes a correspondence between the two, and stores it in a dedicated database. This allows the quantum key management server to quickly locate the corresponding symmetric key set based on the terminal's identity information when the terminal initiates a quantum-encrypted call.
[0089] In this way, by receiving the terminal identity information sent by the key filling server and associating the identity information with the corresponding symmetric key set, a mapping relationship between the terminal identity and the symmetric key set is effectively established. This reduces the authentication security risks caused by chaotic key management to a certain extent. At the same time, even if an illegal terminal steals the terminal's authentication key, it cannot trigger the quantum key management server to call the associated symmetric key set due to the lack of corresponding terminal identity information. This reduces the risk of the authentication key being misused for authentication after leakage, thereby improving the security of quantum encrypted call authentication to a certain extent and enhancing the response efficiency and reliability of the authentication process.
[0090] Please see Figure 6 This application provides a key authentication method for quantum encrypted calls, the method comprising: 08: In response to the quantum-encrypted call request initiated by the first terminal, generate an authentication request and send the authentication request and the first terminal's first identity information to the quantum key management server; 09: Receive the first symmetric key and the first key identifier sent by the quantum key management server, wherein the quantum key management server responds to the authentication request and determines the first symmetric key and the first key identifier based on the first identity information; 010: Perform authentication processing based on the first symmetric key and the first key identifier.
[0091] Specifically, when the first terminal needs to initiate a quantum-encrypted call, it first searches for nearby available central control stations and sends a quantum-encrypted call request to the central control station.
[0092] After receiving the quantum-encrypted call request from the first terminal, the central control station generates an authentication request to verify whether the first terminal has the permission to make quantum-encrypted calls. At the same time, the central control station obtains the first terminal's first identity information through interaction with the first terminal.
[0093] Subsequently, the central control station packages the generated authentication request and the obtained primary identity information together and sends them to the quantum key management server through a dedicated secure communication channel.
[0094] The quantum key management server responds to the authentication request, determines the first symmetric key and the first key identifier based on the first identity information, and sends the first symmetric key and the first key identifier to the central control station.
[0095] Finally, the central control station performs authentication processing based on the received first symmetric key and first key identifier.
[0096] Understandably, by having the central control station conduct local authentication based on the first symmetric key and the first key identifier, it is ensured that only terminals that can provide legitimate authentication keys can pass the authentication. This makes it difficult for others to impersonate and pass the authentication by using stolen authentication keys, even if the terminal is cracked and the authentication key is leaked, due to the lack of authentication guidance and key matching verification from the central control station. This, to a certain extent, ensures the security of quantum encrypted call authentication.
[0097] In this way, by conducting local authentication processing based on the first symmetric key and the first key identifier through the central control station, the direct data interaction between the first terminal and the quantum key management server is effectively isolated, which reduces the risk of the authentication key being illegally intercepted in the long-distance transmission link to a certain extent, thereby ensuring the security of quantum encrypted call authentication to a certain extent.
[0098] Please see Figure 7 In some implementations, step 09 includes: 091: Store the first symmetric key and send the first key identifier to the first terminal.
[0099] Specifically, after receiving the first symmetric key and the first key identifier sent by the quantum key management server, the central control station first stores the first symmetric key in the local hardware security module for subsequent authentication and verification comparison.
[0100] Subsequently, the central control station sends the first key identifier to the first terminal to obtain the first authentication key stored in the first terminal, and completes the authentication verification comparison based on the first symmetric key and the corresponding authentication key.
[0101] In this way, the central control station stores the first symmetric key and sends the first key identifier to the first terminal to obtain the first authentication key, avoiding the indiscriminate transmission of the authentication key, reducing the risk of authentication key leakage to a certain extent, and ensuring the security of quantum encrypted call authentication.
[0102] Please see Figure 8 In some implementations, step 10 includes: 0101: Upon receiving the first symmetric key and the first key identifier, generate a key request; 0102: Send a key request and a first key identifier to the first terminal, wherein the first terminal responds to the key request, determines the first authentication key based on the first key identifier, and sends the first authentication key to the central control station; 0103: Perform authentication processing based on the first authentication key and the first symmetric key.
[0103] Specifically, after receiving the first symmetric key and the first key identifier and completing the storage of the first symmetric key, the central control station generates a key request to request the first terminal to provide the first authentication key, and packages the key request with the received first key identifier and sends it to the first terminal through a secure communication channel.
[0104] Upon receiving the key request and the first key identifier, the first terminal responds to the key request by searching for the corresponding first authentication key in its stored authentication key set based on the first key identifier, and then sends the found first authentication key to the central control station.
[0105] After receiving the first authentication key sent by the first terminal, the central control station compares the received first authentication key with the stored first symmetric key to determine whether the first authentication key and the first symmetric key satisfy the symmetric key relationship, so as to determine whether the identity of the first terminal is legitimate.
[0106] In this way, the central control station receives the first authentication key and completes the authentication comparison locally, which reduces the risk of the authentication key being illegally intercepted in long-distance transmission links to a certain extent. At the same time, the extraction and transmission of the first authentication key depends on the key request and accurate first key identifier of the central control station. This makes it difficult for others to impersonate the stolen authentication key to pass authentication if the first terminal is cracked and the authentication key is leaked, due to the lack of corresponding request guidance and identifier matching. This improves the security and accuracy of the quantum encrypted call authentication process to a certain extent.
[0107] Please see Figure 9 In some implementations, step 10 further includes: 0104: Compare the first authentication key with the first symmetric key. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the authentication is successful. 0105: If authentication is successful, generate authentication success information and send it to the quantum key management server.
[0108] Specifically, after receiving the first authentication key, the central control station retrieves the stored first symmetric key and verifies whether the first authentication key and the first symmetric key satisfy the preset symmetric key relationship. If the symmetric key relationship is satisfied, the central control station generates authentication success information and sends the authentication success information to the quantum key management server.
[0109] After receiving the authentication success information, the quantum key management server generates a session key and sends it to the first terminal, so that the first terminal can conduct quantum-encrypted calls with the communication peer based on the session key.
[0110] In this way, by comparing the first authentication key with the first symmetric key, authentication is confirmed to be successful when the two satisfy the symmetric key relationship, and authentication success information is generated and sent to the quantum key management server. This effectively ensures that only terminals holding legitimate authentication keys can pass authentication. From the result determination stage, it blocks the possibility of others impersonating others by intercepting or stealing keys, and reduces the authentication security risk caused by the illegal acquisition of authentication keys to a certain extent. At the same time, the reliable transmission of authentication success information provides an accurate basis for the quantum key management server to start the subsequent session key generation and distribution process. To a certain extent, it realizes the smooth connection between the authentication process and the quantum encrypted call preparation process, and improves the security and collaborative efficiency of the entire system.
[0111] Please see Figure 10 This application also provides a key authentication method for quantum encrypted calls. The method is used in a quantum encrypted call key authentication system, which includes a quantum key management server, a central control station, and a first terminal. The key authentication method for quantum encrypted calls includes: 011: The first terminal sends a quantum-encrypted call request to the central control station; 012: The central control station responds to the quantum encrypted call request, generates an authentication request, and sends the authentication request and the first identity information of the first terminal to the quantum key management server; 013: The quantum key management server receives the authentication request and the initial identity information; 014: The quantum key management server responds to the authentication request and determines the first symmetric key and the first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key; 015: The quantum key management server sends the first symmetric key and the first key identifier to the central control station; 016: The central control station performs authentication based on the first symmetric key and the first key identifier.
[0112] Specifically, the system used to implement quantum encrypted call authentication is a quantum encrypted call key authentication system, which includes a quantum key management server, a central control station, and a first terminal.
[0113] When the first terminal needs to initiate a quantum-encrypted call, it will send a quantum-encrypted call request to the central control station in the quantum metropolitan area network to which the first terminal is connected.
[0114] Upon receiving a quantum-encrypted call request, the central control station immediately responds and generates an authentication request, while simultaneously obtaining the primary identity information of the first terminal. Subsequently, the central control station sends the generated authentication request and the obtained primary identity information to the quantum key management server.
[0115] After receiving the authentication request and first identity information from the central control station, the quantum key management server locates the first symmetric key set bound to the first identity information by querying the stored association data between the terminal identity information and the symmetric key set. Then, the quantum key management server randomly extracts a symmetric key from the first symmetric key set as the first symmetric key required for this authentication, and simultaneously obtains the first key identifier associated with the first symmetric key.
[0116] After determining the first symmetric key and the first key identifier, the quantum key management server sends the first symmetric key and the first key identifier to the central control station through a secure transmission channel. After receiving the first symmetric key and the first key identifier, the central control station performs subsequent authentication processing.
[0117] In this way, by changing the direction and method of key transmission, the traditional mode of the terminal actively sending the authentication key is transformed into the quantum key management server actively determining and sending the symmetric key and key identifier. This eliminates the need for direct transmission of the authentication key between the terminal and the quantum key management server, thus enabling terminal authentication. This effectively reduces the risk of the authentication key being illegally intercepted by others during transmission, and to a certain extent eliminates the security risks in the quantum encrypted call authentication process. As a result, it ensures the security of quantum encrypted call authentication to a certain extent, provides a secure and reliable identity verification foundation for users' quantum encrypted calls, and protects users' communication privacy and data security.
[0118] The following is Figure 11 The workflow of the key authentication method for quantum encrypted calls will be explained using an example: First, the key filling server, i.e. the key filling system, completes the distribution of the basic key, binds the terminal's identity information, i.e. the ID information of the quantum encryption SIM card, with the authentication key set, fills the authentication key set into the terminal, and sends the paired symmetric key set, key identifier, and ID information to the quantum key management server, i.e. the quantum key management system. The quantum key management system associates and binds the ID information with the symmetric key set, completing the pre-setting of the key before the call.
[0119] When the first terminal, i.e., the communication terminal, initiates a quantum-encrypted call request to the central control station, the central control station sends the quantum-encrypted SIM card ID information of the communication terminal to the quantum key management system. The quantum key management system determines the corresponding symmetric key set based on the ID information, randomly selects a symmetric key from the symmetric key set as the first symmetric key KEY1, determines the corresponding first key identifier S1 based on the first symmetric key KEY1, and finally packages the first symmetric key KEY1 and the first key identifier S1 and sends them to the central control station.
[0120] After receiving the first symmetric key KEY1 and the first key identifier S1, the central control station first stores the first symmetric key KEY1 and generates a key request.
[0121] Subsequently, the central control station sends the key request and the first key identifier S1 to the communication terminal.
[0122] The communication terminal determines the first authentication key KEY1' from the authentication key set based on the received first key identifier S1, and sends the first authentication key KEY1' to the central control station.
[0123] Finally, the central control station verifies the relationship between the first authentication key KEY1' and the first symmetric key KEY1, determining whether they satisfy a symmetric key relationship. If the symmetric key relationship is satisfied, the central control station generates an authentication success message and sends it to the quantum key management system. The quantum key management system then generates a session key and sends it to the communication terminal and the communication peer, ultimately establishing a quantum encrypted call.
[0124] The following is Figure 12 The actual workflow of the key authentication method for quantum encrypted calls will be explained using an example: In the quantum encrypted communication system, the basic key distribution is completed by the key filling server in the pre-processing stage. The server fills the authentication key set with the unique key identifier for each communication terminal 1 and communication terminal 2, and sends the paired symmetric key set and terminal identity information to the quantum key management system.
[0125] The quantum key management system associates and binds terminal identity information with the corresponding symmetric key set. Communication terminal 1 and communication terminal 2 store the authentication key set in the local quantum encryption SIM card, and the central control station is in standby mode to prepare to forward authentication data.
[0126] When any communication terminal initiates a quantum-encrypted call, it sends an encrypted call request carrying its own identity information to the central control station in the nearest quantum metropolitan area network. The central control station generates an authentication request and forwards it along with the terminal's identity information to the quantum key management system.
[0127] The quantum key management system locates the symmetric key set corresponding to the terminal through a pre-stored mapping relationship, randomly extracts the first symmetric key and the associated first key identifier and sends them back to the central control station; after storing the first symmetric key, the central control station sends the first key identifier to the initiating terminal, and the terminal extracts the first authentication key and sends it back accordingly.
[0128] The central control station verifies the symmetric relationship between the first authentication key and the first authentication key. If the authentication is successful, the authentication success information is sent to the quantum key management system. The quantum key management system generates a unique session key and sends it to the terminals at both ends of the call. The terminals at both ends encrypt the call data end-to-end based on the session key, and the quantum encrypted call is officially started.
[0129] This application also provides a computer-readable storage medium having a computer program stored thereon. When executed by a computer program processor, the program implements the steps of the key authentication method for quantum encrypted communication as described above.
[0130] It is understood that a computer program includes computer program code. Computer program code can be in the form of source code, object code, executable files, or some intermediate form. Computer-readable storage media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc.
[0131] In this specification, the terms "specifically," "furthermore," "particularly," "understandably," etc., refer to specific features, structures, materials, or characteristics described in connection with embodiments or examples that are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0132] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of executable request code comprising one or more steps for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order according to the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.
[0133] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A key authentication method for quantum encrypted calls, characterized in that, The method is used in a quantum key management server, and the method includes: The system receives an authentication request sent by the central control station and the first identity information of the first terminal, wherein the central control station generates the authentication request in response to a quantum-encrypted call request initiated by the first terminal. In response to the authentication request, a first symmetric key and a first key identifier are determined based on the first identity information, wherein the first key identifier is associated with the first symmetric key; The first symmetric key and the first key identifier are sent to the central control station, wherein the central control station performs authentication processing based on the first symmetric key and the first key identifier.
2. The key authentication method according to claim 1, characterized in that, The response to the authentication request, based on the first identity information, determines the first symmetric key and the first key identifier, including: Based on the first identity information, determine the first symmetric key set associated with the first identity information; One key is randomly selected from the first set of symmetric keys as the first symmetric key; The first key identifier is determined based on the first symmetric key.
3. The key authentication method according to claim 1, characterized in that, The method further includes: The system receives the authentication success information sent by the central control station, generates a session key, and sends the session key to the first terminal. The central control station sends the first key identifier to the first terminal. The first terminal determines the first authentication key based on the first key identifier and sends the first authentication key to the central control station. The central control station generates the authentication success information when the first symmetric key and the first authentication key satisfy the symmetric key relationship.
4. The key authentication method according to claim 1, characterized in that, The method further includes: The terminal receives a symmetric key set sent by the key injection server, wherein the symmetric key set includes multiple symmetric keys, each of which is associated with an authentication key and a key identifier associated with the authentication key; the terminal receives an authentication key set injected by the key injection server, wherein the authentication key set includes multiple authentication keys, each of which is associated with a key identifier.
5. The key authentication method according to claim 4, characterized in that, The method further includes: Receive the terminal's identity information sent by the key filling server; The identity information is associated and bound with the symmetric key set.
6. A key authentication method for quantum-encrypted calls, characterized in that, The method is used in a centralized control station, and the method includes: In response to a quantum-encrypted call request initiated by the first terminal, an authentication request is generated, and the authentication request and the first identity information of the first terminal are sent to the quantum key management server. The system receives a first symmetric key and a first key identifier sent by the quantum key management server, wherein the quantum key management server, in response to the authentication request, determines the first symmetric key and the first key identifier based on the first identity information. Authentication is performed based on the first symmetric key and the first key identifier.
7. The key authentication method according to claim 6, characterized in that, The receipt of the first symmetric key and the first key identifier sent by the quantum key management server includes: Store the first symmetric key and send the first key identifier to the first terminal.
8. The key authentication method according to claim 6, characterized in that, The authentication process based on the first symmetric key and the first key identifier includes: Upon receiving the first symmetric key and the first key identifier, a key request is generated; The key request and the first key identifier are sent to the first terminal, wherein the first terminal responds to the key request, determines the first authentication key based on the first key identifier, and sends the first authentication key to the central control station; Authentication is performed based on the first authentication key and the first symmetric key.
9. The key authentication method according to claim 8, characterized in that, The authentication process based on the first authentication key and the first symmetric key includes: The first authentication key and the first symmetric key are compared. If the first symmetric key and the first authentication key satisfy the symmetric key relationship, the authentication is deemed successful. If authentication is successful, an authentication success message is generated and sent to the quantum key management server.
10. A key authentication method for quantum encrypted calls, characterized in that, The method is used in a quantum encrypted call key authentication system, the system including a quantum key management server, a central control station, and a first terminal, and the method includes: The first terminal sends a quantum-encrypted call request to the central control station; The central control station responds to the quantum encrypted call request, generates an authentication request, and sends the authentication request and the first identity information of the first terminal to the quantum key management server; The quantum key management server receives the authentication request and the first identity information; The quantum key management server responds to the authentication request and determines a first symmetric key and a first key identifier based on the first identity information, wherein the first key identifier is associated with the first symmetric key; The quantum key management server sends the first symmetric key and the first key identifier to the central control station; The central control station performs authentication based on the first symmetric key and the first key identifier.
Citation Information
Patent Citations
D2D secure mobile communication method and system based on quantum key
CN114362944A
Identity authentication method and device and electronic equipment
CN116248290A
Credible quantum security access communication method and system
CN119211923A
Interface calling and authentication method and device based on quantum key
CN119766551A
Mail transmission method based on quantum local area network
CN120582913A