A cross-trust domain data security convergence system, method, device and medium

By combining a quantum entangled state pre-distribution network and a dynamic trust evaluation engine, the problem of static keys being vulnerable to attack in cross-network and cross-domain data transmission is solved. This achieves high-security, high-real-time, and high-reliability cross-trust domain data security aggregation, enhancing the security and auditing capabilities of data transmission.

CN121462322BActive Publication Date: 2026-04-07NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-05
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies for cross-network and cross-domain data transmission and identity authentication suffer from problems such as static keys being vulnerable to attacks, low authentication efficiency, and insufficient compatibility, making it difficult to meet the requirements of key areas for high security, high real-time performance, and high reliability.

Method used

By introducing a quantum entangled state pre-distribution network as a key generation raw material library, and combining it with a dynamic trust assessment engine and an authentication audit blockchain, dynamic identity authentication and key generation are realized. Through a quantum random number source cluster and a zero-knowledge proof mechanism, a quantum-enabled, data-driven cross-trust domain security convergence system is formed.

Benefits of technology

It enables the pre-configuration and asynchronous processing of security resources, ensures that identity authentication and key generation strategies are bound to data attributes, reduces the risk of data leakage and tampering, improves the security and real-time performance of cross-domain data interaction, and enhances audit depth and authentication capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462322B_ABST
    Figure CN121462322B_ABST
Patent Text Reader

Abstract

The application relates to a cross-trust-domain data security convergence system, method, device and medium, and belongs to the technical field of network security. The system comprises a quantum-enabled resource layer, an intelligent security control layer and a security execution layer; the quantum-enabled resource layer comprises a quantum entangled state pre-distribution network and a quantum random number source cluster; the intelligent security control layer comprises a dynamic trust evaluation engine and a strategy arrangement center, which are respectively used for performing dynamic trust evaluation on a cross-domain communication request party and generating a session security strategy package; the security execution layer comprises a cross-domain intelligent security gateway and an authentication audit blockchain, which are used for performing identity authentication and key generation under the constraint of the session security strategy package, performing cross-trust-domain data security convergence based on the generated key, and recording a security narrative chain to be used for audit tracing and authentication. The system can effectively support large-scale, high real-time and high-security cross-network cross-domain data security convergence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a cross-trust domain data security aggregation system, method, device and medium. Background Technology

[0002] As the digital transformation continues to deepen, the informatization of key sectors such as government affairs, finance, energy, and healthcare is advancing, gradually forming a diverse and heterogeneous network and security domain system. Among them, government extranets, industry-specific private networks, private cloud platforms, and public cloud services serve as core infrastructure, supporting the stable operation of businesses in various fields. However, due to factors such as business attributes and security level requirements, these networks and security domains are generally isolated from each other, forming multiple relatively independent "information silos."

[0003] With the increasing demand for business collaboration and the emergence of new application scenarios such as big data analytics and intelligent decision-making, cross-network and cross-domain data aggregation has become a rigid requirement for driving the digital upgrade of key areas. Integrating core data resources within different network domains can effectively break down information barriers, improve business processing efficiency, optimize resource allocation, and enhance the scientific and accurate nature of decision-making. However, different network domains have developed heterogeneous security strategies, independent trust systems, and strict network boundaries over the long term. These intertwined factors pose significant challenges to the secure transmission of cross-network and cross-domain data and the authentication of cross-domain entities.

[0004] Currently, technical solutions for cross-network and cross-domain data transmission and identity authentication still have many significant defects and limitations. Existing technologies mostly adopt a static processing mode of "authentication first - allocation of fixed key - transmission later". Under this mode, once the key is allocated, it is used permanently and lacks a dynamic update mechanism, making it vulnerable to being stolen and cracked by attackers, which can lead to security risks such as data leakage and tampering. At the same time, static authentication methods are difficult to adapt to the dynamic changes in the identity of the subject and the flexible adjustment of business needs in cross-domain scenarios, resulting in low authentication efficiency and insufficient compatibility. They cannot fully meet the high security, high real-time and high reliability requirements of key areas for cross-network and cross-domain data interaction, thus hindering the in-depth advancement of digital transformation. Summary of the Invention

[0005] Therefore, it is necessary to provide a cross-trust domain data security aggregation system, method, device, and medium to address the aforementioned technical issues.

[0006] A cross-trust domain data security aggregation system, the system comprising:

[0007] The quantum-enabled resource layer includes a quantum entangled state pre-distribution network as a key generation raw material library, and a quantum random number source cluster as a guarantee of random source for identity authentication;

[0008] The intelligent security control layer includes a dynamic trust assessment engine and a policy orchestration center deployed in each trust domain gateway. The dynamic trust assessment engine is used to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester. The policy orchestration center is used to parse the attributes of the communication data to be transmitted and integrate them with the real-time trust score to form a session security policy package for this communication session, and send it to the cross-domain communication receiver.

[0009] The security execution layer includes cross-domain intelligent security gateways deployed in each trust domain gateway and an authentication and auditing blockchain. The cross-domain intelligent security gateway is used to perform identity authentication of cross-domain communication requesters based on a quantum random number source cluster under the constraints of the session security policy package, and to perform key generation for both parties in cross-domain communication based on a quantum entangled state pre-distribution network, obtain real-time quantum keys, and perform cross-trust domain transmission and secure aggregation of communication data. The authentication and auditing blockchain is used to record the complete context of each communication session, forming an immutable security narrative chain, and providing full-process, verifiable support for the auditing, tracing, and authentication of each communication session.

[0010] Furthermore, the quantum entangled state pre-distribution network consists of entangled sources and quantum memories deployed in each trust domain gateway. It is used to periodically establish and store quantum entangled pairs between any two trust domain gateways that need to communicate, forming a distributed entangled resource pool as a key generation raw material library.

[0011] Furthermore, the dynamic trust assessment engine includes:

[0012] The multi-source trust data collector is used to collect multi-source trust data related to the cross-domain communication requester in the current communication session in real time after each trust domain gateway participates in the blockchain consensus. The multi-source trust data includes the cross-domain communication requester's historical behavior records on the blockchain, the response time and complexity of historical identity authentication, communication environment situation awareness information, and third-party reputation scores.

[0013] The trust quantification model is used to perform fusion analysis of multi-source trust data using machine learning models, and outputs the real-time trust score of the cross-domain communication requester to the policy orchestration center.

[0014] Furthermore, the strategy orchestration center includes:

[0015] The data attribute sensor is used to parse the data attributes of the communication data to be transmitted in the current communication session on the cross-domain communication requester, forming a data security profile; the data attributes include the tag, format, and size of the communication data to be transmitted;

[0016] The security policy fusion unit is used to merge real-time trust scores and data security profiles to form a session security policy package for the current communication session and send it to the cross-domain communication recipient to ensure that both parties in the cross-domain communication reach an agreement on the security parameters transmitted in this communication session.

[0017] Furthermore, the cross-domain intelligent security gateway includes:

[0018] The identity authentication module is used to perform dynamic identity authentication of cross-domain communication requesters under the constraints of the session security policy package, using random numbers provided by the quantum random number source cluster as challenge values ​​and employing an identity authentication mechanism based on zero-knowledge proof.

[0019] The on-demand key generation module is used to request pre-stored quantum entangled pairs from both parties in cross-domain communication under the constraints of the session security policy package, and to generate real-time quantum keys for the current communication session synchronously between the two parties by performing Bell state measurements on the quantum entangled pairs.

[0020] The attribute-based encryption adapter is used by the requester in cross-domain communication to use a real-time quantum key as the master key for encrypting communication data. It also combines data attributes to perform fine-grained encryption control on the communication data. Finally, the encrypted communication data, along with the context identifier of the current communication session, is transmitted to the receiver in cross-domain communication. After the receiver decrypts the communication data based on the same real-time quantum key and session security policy package, cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, used to verify the integrity and consistency of the session security policy package.

[0021] Furthermore, the complete context of each communication session recorded by the authentication audit blockchain includes: the cross-domain communication requester, real-time trust score, data security profile obtained by parsing the attributes of the communication data to be transmitted, session security policy package, quantum entanglement pair ID consumed during key generation, and hash value of the generated real-time quantum key.

[0022] A method for secure data aggregation across trust domains, the method being implemented based on the aforementioned secure data aggregation system across trust domains, includes the following steps:

[0023] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication;

[0024] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver;

[0025] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0026] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0027] Furthermore, step 3 includes:

[0028] Under the constraints of the session security policy package, random numbers provided by the quantum random number source cluster are used as challenge values, and a zero-knowledge proof-based identity authentication mechanism is adopted to perform dynamic identity authentication of cross-domain communication requesters.

[0029] Under the constraints of the session security policy package, the quantum entangled state pre-distribution network requests the quantum entangled pairs pre-stored by both parties in the cross-domain communication, and generates the real-time quantum key for this communication session synchronously by performing Bell state measurement on the quantum entangled pairs.

[0030] On the cross-domain communication requester, a real-time quantum key is used as the master key for encrypting communication data. At the same time, fine-grained encryption control is applied to the communication data in conjunction with data attributes. Finally, the encrypted communication data and the context identifier of this communication session are transmitted to the cross-domain communication receiver. After the cross-domain communication receiver decrypts the communication data based on the same real-time quantum key and session security policy package, the cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, which is used to verify the integrity and consistency of the session security policy package.

[0031] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program performing the following steps:

[0032] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication;

[0033] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver;

[0034] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0035] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0036] A computer-readable storage medium having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0037] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication;

[0038] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver;

[0039] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0040] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0041] The aforementioned cross-trust domain data security aggregation system, method, device, and medium, compared to the traditional static model of "authentication first, then fixed key distribution, then transmission," creatively proposes a "quantum-enabled, data-driven, trust-evolution" cross-trust domain security aggregation system, which has the following beneficial effects: First, it introduces a quantum entangled state pre-distribution network as the physical basis for subsequent on-demand quantum key generation, rather than directly distributing the key itself, thus solving the problems of quantum key distribution requiring real-time connection establishment and being sensitive to channel quality, and realizing the pre-positioning and asynchronous nature of security resources; Second, it introduces a dynamic trust evaluation engine to perform real-time, quantitative trust scoring of the cross-domain communication requester, and integrates the real-time trust score with the data to be transmitted. The system transmits communication data attributes to form a session security policy package for this communication session. Based on the constraints of this session security policy package, identity authentication and key generation are performed. This ensures that the identity authentication and key generation policies are deeply bound to the attributes of the communication data to be transmitted and the real-time trust score, achieving "one data, one policy, one key." This effectively reduces the risk of data leakage and tampering, and meets the high security, high real-time performance, and high reliability requirements of critical areas for cross-network and cross-domain data interaction. Furthermore, the system introduces an authentication audit blockchain to record the complete context of each communication session, forming an immutable security narrative chain. This not only records "what was done" but also traces "why it was done," greatly enhancing the audit depth and authentication capabilities of data security aggregation. Attached Figure Description

[0042] Figure 1 This is a schematic diagram of the structure of a cross-trust domain data security aggregation system in one embodiment;

[0043] Figure 2 This is a flowchart illustrating a cross-trust domain data security aggregation method in one embodiment;

[0044] Figure 3 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0046] In one embodiment, such as Figure 1 As shown, a cross-trust domain data security aggregation system is provided, including a quantum-enabled resource layer, an intelligent security control layer, and a security execution layer.

[0047] The quantum-enabled resource layer includes a quantum entangled state pre-distribution network as a raw material library for key generation, and a quantum random number source cluster as a random source guarantee for identity authentication.

[0048] The intelligent security control layer includes a dynamic trust assessment engine and a policy orchestration center deployed on each trust domain gateway. The dynamic trust assessment engine is used to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester. The policy orchestration center is used to parse the attributes of the communication data to be transmitted and integrate them with the real-time trust score to form a session security policy package for this communication session, and send it to the cross-domain communication receiver.

[0049] The security execution layer includes cross-domain intelligent security gateways deployed in each trust domain gateway and an authentication and auditing blockchain. The cross-domain intelligent security gateway is used to perform identity authentication of cross-domain communication requesters based on a quantum random number source cluster under the constraints of the session security policy package, and to perform key generation for both parties in cross-domain communication based on a quantum entangled state pre-distribution network, obtain real-time quantum keys, and perform cross-trust domain transmission and secure aggregation of communication data. The authentication and auditing blockchain is used to record the complete context of each communication session, forming an immutable security narrative chain, and providing full-process, verifiable support for the auditing, tracing, and authentication of each communication session.

[0050] In the aforementioned cross-trust domain data security aggregation system, firstly, a quantum entangled state pre-distribution network is introduced as the physical basis for subsequent on-demand generation of quantum keys, rather than directly distributing the keys themselves. This solves the problems of quantum key distribution requiring real-time connection establishment and being sensitive to channel quality, achieving the pre-provisioning and asynchronous nature of security resources. Secondly, a dynamic trust evaluation engine is introduced to perform real-time, quantitative trust scoring of cross-domain communication requesters. By fusing the real-time trust score with the attributes of the communication data to be transmitted, a session security policy package for this communication session is formed. Based on the constraints of this session security policy package, identity authentication and key generation are performed, ensuring that the identity authentication and key generation strategy is deeply bound to the attributes of the communication data to be transmitted and the real-time trust score, achieving "one data, one policy, one key." This effectively reduces the risk of data leakage and tampering, meeting the high security, high real-time performance, and high reliability requirements of critical areas for cross-network and cross-domain data interaction. Finally, an authentication audit blockchain is introduced to record the complete context of each communication session, forming an immutable security narrative chain. This not only records "what was done" but also traces "why it was done," greatly enhancing the audit depth and authentication capabilities of data security aggregation.

[0051] Furthermore, the quantum entangled state pre-distribution network in the quantum-enabled resource layer consists of entangled sources and quantum memories deployed at each trust domain gateway. It is used to periodically (e.g., during off-peak periods) pre-establish and store quantum entangled pairs between any two trust domain gateways that need to communicate, forming a distributed entanglement resource pool as a key generation raw material library. It is important to note that these quantum entangled pairs themselves do not carry key information; rather, they serve as the physical basis for subsequent on-demand quantum key generation. This solves the problems of quantum key distribution requiring real-time connection establishment and being sensitive to channel quality, achieving the pre-provisioning and asynchronous nature of security resources. The quantum random number source cluster in the quantum-enabled resource layer provides distributed, high-entropy true random numbers, which can be used as challenge values ​​for zero-knowledge proof-based identity authentication, and can also be used for various randomness requirements in communication protocols.

[0052] Furthermore, the dynamic trust assessment engine includes:

[0053] The multi-source trust data collector is used to collect multi-source trust data related to the cross-domain communication requester in the current communication session in real time after each trust domain gateway participates in the blockchain consensus. The multi-source trust data includes the cross-domain communication requester's historical behavior records on the blockchain, the response time and complexity of historical identity authentication, communication environment situation awareness information, and third-party reputation scores, etc.

[0054] The trust quantization model is used to fuse and analyze multi-source trust data using machine learning models, and outputs a real-time trust score for the cross-domain communication requester to the policy orchestration center. For example, an attention-based neural network can be used to input multi-source trust data and quantify the correlation between the data through the attention mechanism, outputting a corresponding real-time trust score, which will directly determine the subsequent quantum key generation strategy.

[0055] Furthermore, the strategy orchestration center includes:

[0056] The data attribute sensor is used to parse the data attributes of the communication data to be transmitted in the current communication session on the cross-domain communication requester, forming a data security profile; the data attributes include the tag, format and size of the communication data to be transmitted.

[0057] The security policy fusion unit integrates real-time trust scores and data security profiles to form a session security policy package for the current communication session, which is then sent to the cross-domain communication recipient. This ensures that both parties in the cross-domain communication agree on the security parameters transmitted during the session. Specifically, the session security policy package can explicitly specify the following constraints required for this transmission: the number of keys, key length, key update frequency, whether to enable two-factor authentication, audit level, and other specific parameters.

[0058] Furthermore, the cross-domain intelligent security gateway includes:

[0059] The identity authentication module, under the constraints of the session security policy package, uses random numbers provided by a quantum random number source cluster as the challenge value and employs a zero-knowledge proof-based identity authentication mechanism for dynamic identity authentication of cross-domain communication requesters. Specifically, when trusted domain gateway A requests communication with trusted domain gateway B, the identity authentication module does not directly transmit A's certificate. Instead, it requires A to provide a zero-knowledge proof of its claim that "I am a legally registered identity X on the blockchain." The identity authentication module uses quantum random numbers to generate a challenge value and verifies the validity of this proof. This process achieves "proof of ownership" rather than "transmission of credentials," effectively preventing the intermediate leakage of identity information.

[0060] The on-demand key generation module, under the constraints of the session security policy package, requests the consumption of pre-stored quantum entangled pairs between the two parties in cross-domain communication via the quantum entangled state pre-distribution network. It then generates the real-time quantum key for the current communication session synchronously between the two parties by performing Bell state measurements on the entangled pairs. Specifically, the number of quantum entangled pairs to be requested and the encryption level can be determined based on the key quantity and key length requirements in the session security policy package. The key length, in particular, is positively correlated with the real-time trust score and data security level. Bell state measurement refers to determining the overall quantum state of the quantum entangled pair using measurement methods conforming to Bell basis vectors. Its purpose is to obtain the quantum state information of the entangled pair, thereby providing crucial data support for downstream quantum communication processes such as quantum key generation, distribution, and quantum teleportation.

[0061] The attribute-based encryption adapter is used by the requester in cross-domain communication to use a real-time quantum key as the master key for encrypting communication data. It also combines data attributes to perform fine-grained encryption control on the communication data. Finally, the encrypted communication data, along with the context identifier of the current communication session, is transmitted to the receiver in cross-domain communication. After the receiver decrypts the communication data based on the same real-time quantum key and session security policy package, cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, used to verify the integrity and consistency of the session security policy package.

[0062] Furthermore, the complete context of each communication session recorded by the authentication audit blockchain includes: the cross-domain communication requester, real-time trust score, data security profile obtained by parsing the attributes of the communication data to be transmitted, session security policy package, quantum entanglement pair ID consumed during key generation, and hash value of the generated real-time quantum key.

[0063] In one embodiment, such as Figure 2 As shown, a method for cross-trust domain data security aggregation is provided. This method is based on the aforementioned cross-trust domain data security aggregation system and includes the following steps:

[0064] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and a quantum random number source cluster as a random source guarantee for identity authentication. This process is unrelated to the specific business request and belongs to the preparatory stage.

[0065] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment, outputting the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, which is then sent to the cross-domain communication receiver. Specifically, the session security policy package S_policy can be represented as S_policy={key length: 256 bits, authentication level: intermediate, key amount to be generated: 1MB}.

[0066] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0067] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0068] Furthermore, step 3 includes:

[0069] Under the constraints of the session security policy package, random numbers provided by the quantum random number source cluster are used as challenge values, and a zero-knowledge proof-based identity authentication mechanism is adopted to perform dynamic identity authentication of cross-domain communication requesters.

[0070] Under the constraints of the session security policy package, the quantum entangled state pre-distribution network requests the quantum entangled pairs pre-stored by both parties in the cross-domain communication, and generates the real-time quantum key for this communication session synchronously by performing Bell state measurement on the quantum entangled pairs.

[0071] On the cross-domain communication requester, a real-time quantum key is used as the master key for encrypting communication data. At the same time, fine-grained encryption control is applied to the communication data in conjunction with data attributes. Finally, the encrypted communication data and the context identifier of this communication session are transmitted to the cross-domain communication receiver. After the cross-domain communication receiver decrypts the communication data based on the same real-time quantum key and session security policy package, the cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, which is used to verify the integrity and consistency of the session security policy package.

[0072] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 3 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data. The network interface communicates with external terminals via a network connection. When the computer program is executed by the processor, it implements a cross-trust domain data security aggregation method.

[0073] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0074] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to perform the following steps:

[0075] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication;

[0076] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver;

[0077] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0078] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0079] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0080] Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication;

[0081] Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver;

[0082] Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data.

[0083] Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

[0084] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0085] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0086] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application.

Claims

1. A cross-trust domain data security aggregation system, characterized in that, The system includes: The quantum-enabled resource layer includes a quantum entangled state pre-distribution network as a key generation raw material library, and a quantum random number source cluster as a guarantee of random source for identity authentication; The intelligent security control layer includes a dynamic trust assessment engine and a policy orchestration center deployed on each trust domain gateway. The dynamic trust assessment engine is used to collect multi-source trust data related to the cross-domain communication requester, perform dynamic trust assessment, and output a real-time trust score for the cross-domain communication requester. The policy orchestration center is used to parse the attributes of the communication data to be transmitted and fuse them with the real-time trust score to form a session security policy package for this communication session, and send it to the cross-domain communication receiver. The security execution layer includes a cross-domain intelligent security gateway deployed on each trust domain gateway and an authentication audit blockchain. The cross-domain intelligent security gateway, under the constraints of the session security policy package, performs identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and performs key generation for both parties in the cross-domain communication based on the quantum entangled state pre-distribution network, obtaining real-time quantum keys and performing cross-trust domain transmission and secure aggregation of communication data. The authentication audit blockchain records the complete context of each communication session, forming an immutable security narrative chain, providing a full-process, verifiable support basis for auditing, tracing, and authentication of each communication session.

2. The cross-trust domain data security aggregation system according to claim 1, characterized in that, The quantum entangled state pre-distribution network consists of entangled sources and quantum memories deployed in each trust domain gateway. It is used to periodically establish and store quantum entangled pairs between any two trust domain gateways that need to communicate, forming a distributed entanglement resource pool as a key generation raw material library.

3. The cross-trust domain data security aggregation system according to claim 1, characterized in that, The dynamic trust assessment engine includes: The multi-source trust data collector is used to collect multi-source trust data related to the cross-domain communication requester in the current communication session in real time after each trust domain gateway participates in the blockchain consensus. The multi-source trust data includes the cross-domain communication requester's historical behavior records on the blockchain, the response time and complexity of historical identity authentication, communication environment situation awareness information, and third-party reputation scores. The trust quantification model is used to perform fusion analysis on the multi-source trust data using a machine learning model, and output the real-time trust score of the cross-domain communication requester to the policy orchestration center.

4. A cross-trust domain data security aggregation system according to claim 3, characterized in that, The strategy orchestration center includes: A data attribute sensor is used to parse the data attributes of the communication data to be transmitted in the current communication session on the cross-domain communication requester, forming a data security profile; the data attributes include the tag, format, and size of the communication data to be transmitted; The security policy fusion unit is used to merge real-time trust scores and data security profiles to form a session security policy package for the current communication session and send it to the cross-domain communication recipient to ensure that both parties in the cross-domain communication reach an agreement on the security parameters transmitted in this communication session.

5. A cross-trust domain data security aggregation system according to claim 1, characterized in that, The cross-domain intelligent security gateway includes: The identity authentication module is used to perform dynamic identity authentication of the cross-domain communication requester under the constraints of the session security policy package, using the random number provided by the quantum random number source cluster as the challenge value, and adopting an identity authentication mechanism based on zero-knowledge proof. The key on-demand generation module is used to request the quantum entangled pairs pre-stored by both parties in the cross-domain communication from the quantum entangled state pre-distribution network under the constraints of the session security policy package, and to generate the real-time quantum key for this communication session synchronously between the two parties in the cross-domain communication by performing Bell state measurement on the quantum entangled pairs. An attribute-based encryption adapter is used by the requesting party in cross-domain communication to use the real-time quantum key as the master key for encrypting communication data, and to combine data attributes to perform fine-grained encryption control on the communication data. Finally, the encrypted communication data and the context identifier of this communication session are transmitted to the receiving party in cross-domain communication. After the receiving party decrypts the communication data based on the same real-time quantum key and session security policy package, cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, which is used to verify the integrity and consistency of the session security policy package.

6. A cross-trust domain data security aggregation system according to claim 1, characterized in that, The complete context of each communication session recorded by the authentication audit blockchain includes: the cross-domain communication requester, the real-time trust score, the data security profile obtained by parsing the attributes of the communication data to be transmitted, the session security policy package, the quantum entanglement pair ID consumed during key generation, and the hash value of the generated real-time quantum key.

7. A cross-trust domain data security aggregation method implemented based on the system described in any one of claims 1-6, characterized in that, The method includes: Step 1, Resource Preparation: Before the communication request, deploy a quantum entangled state pre-distribution network as the raw material library for key generation, and deploy a quantum random number source cluster as a random source guarantee for identity authentication; Step 2, Dynamic Trust Assessment and Policy Generation: After the cross-domain communication requester receives the instruction to send communication data to the cross-domain communication receiver, the dynamic trust assessment engine is triggered to collect multi-source trust data related to the cross-domain communication requester for dynamic trust assessment and output the real-time trust score of the cross-domain communication requester; and the policy orchestration center is triggered to parse the attributes of the communication data to be transmitted and merge it with the real-time trust score to form the session security policy package for this communication session, and send it to the cross-domain communication receiver; Step 3, Policy-based on-demand quantum key generation and secure data aggregation: Under the constraints of the session security policy package, the cross-domain intelligent security gateway deployed on both parties of the cross-domain communication is triggered to perform identity authentication of the cross-domain communication requester based on the quantum random number source cluster, and to perform key generation of both parties of the cross-domain communication based on the quantum entangled state pre-distribution network, to obtain the real-time quantum key of this communication session and to perform cross-trust domain transmission and secure aggregation of communication data; Step 4, Evidence Closure and Audit: Trigger the deployment of the authentication and audit blockchain on both parties in the cross-domain communication to record the complete context of this communication session, forming an immutable security narrative chain, providing full-process and verifiable support for the audit tracing and authentication of this communication session.

8. The cross-trust domain data security aggregation method according to claim 7, characterized in that, Step 3 includes: Under the constraints of the session security policy package, the random number provided by the quantum random number source cluster is used as the challenge value, and a zero-knowledge proof-based identity authentication mechanism is adopted to perform dynamic identity authentication of the cross-domain communication requester. Under the constraints of the session security policy package, the quantum entangled state pre-distribution network requests and consumes the quantum entangled pairs pre-stored by both parties in the cross-domain communication, and generates the real-time quantum key for this communication session synchronously by performing Bell state measurement on the quantum entangled pairs. On the cross-domain communication requesting party, the real-time quantum key is used as the master key for encrypting the communication data. At the same time, the communication data is subjected to fine-grained encryption control in combination with data attributes. Finally, the encrypted communication data and the context identifier of this communication session are transmitted to the cross-domain communication receiving party. After the cross-domain communication receiving party decrypts the communication data based on the same real-time quantum key and session security policy package, the cross-trust domain data security aggregation is completed. The context identifier contains the hash value of the session security policy package, which is used to verify the integrity and consistency of the session security policy package.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method of claim 7 or 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 7 or 8.

Citation Information

Patent Citations

  • Political and law data cross-domain secure transmission model based on quantum technology

    CN116846547A

  • Remote attestation method for trusted data space

    CN120498700A