AMF key generation method and device and storage medium
By using quantum key distribution technology to generate AMF keys in 5G communication, the problem of AMF keys being easily cracked is solved, thus improving the security of the communication system.
Patent Information
- Application Number
- CN202510103407.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2026-02-06
AI Technical Summary
In existing 5G communications, the AMF key is at risk of being cracked or leaked, which makes it impossible to guarantee communication security.
By combining quantum key distribution technology with 5G technology standards, AMF keys are generated through the interaction of quantum and classical channels between terminals and core network equipment, replacing the AMF key derivation in the original standard key system.
It improves the security of the AMF key generation process, enhances the overall security of the 5G communication system, and resists the impact of quantum computers on traditional security mechanisms.
Smart Images

Figure CN121485908A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of mobile communication and quantum key distribution, and focuses on an AMF key generation method, device and storage medium. BACKGROUND
[0002] The 5th Generation Mobile Communication Technology (5G) mobile communication security system defines a key system, key derivation and key distribution process. The key system adopts a multi-level derivation manner, and the keys for confidentiality and integrity protection of Non-Access Stratum (NAS) signaling, Radio Resource Control (RRC) signaling and User Plane (UP) service data are directly or indirectly derived from the Authentication Management Function (AMF) key (K AMF ).
[0003] In the related art, the generation of K AMF uses modern key technology, which can ensure relative security, but there is no absolute security. With the improvement of computing power, K AMF exists the risk of being cracked or leaked. Once K AMF is cracked or leaked, the security of 5G communication cannot be guaranteed. SUMMARY
[0004] In view of the problems in the prior art, the present application provides an AMF key generation method, device and storage medium to improve the security of the AMF key generation process and thus improve the overall security of the communication system.
[0005] In a first aspect, the present application provides an AMF key generation method applied to a terminal, wherein the terminal is connected with a first quantum key distribution module, and the method comprises: receiving a measurement basis sequence sent by the first quantum key distribution module, and sending the measurement basis sequence to a core network device; receiving a measurement basis result sequence sent by the core network device, and sending the measurement basis result sequence to the first quantum key distribution module; the measurement basis result sequence is used to indicate a correct measurement basis contained in the measurement basis sequence; receiving a first AMF key sent by the first quantum key distribution module; the first AMF key is generated based on the measurement basis result sequence, the measurement basis sequence and a second group of binary strings; The measurement base sequence and the second group of binary strings are obtained by receiving a quantum messenger sent by a second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding base sequence; and the second quantum key distribution module is connected with the core network device.
[0006] In a second aspect, the application further provides an AMF key generation method, applied to a first quantum key distribution module, the first quantum key distribution module being connected with a terminal, and the method comprising: receiving a quantum messenger sent by a second quantum key distribution module and measuring the quantum messenger to obtain a measurement base sequence and a second group of binary strings; the quantum messenger being obtained based on a first group of binary strings and a randomly selected encoding base sequence; and the second quantum key distribution module being connected with a core network device sending the measurement base sequence to the terminal; receiving a measurement base result sequence sent by the terminal; the measurement base result sequence being used to indicate a correct measurement base contained in the measurement base sequence; generating a first AMF key based on the measurement base result sequence, the measurement base sequence and the second group of binary strings; sending the first AMF key to the terminal.
[0007] In a third aspect, the application further provides an AMF key generation method, applied to a core network device, the core network device being connected with a second quantum key distribution module, and the method comprising: receiving a measurement base sequence sent by a terminal and sending the measurement base sequence to the second quantum key distribution module; receiving a measurement base result sequence sent by the second quantum key distribution module and sending the measurement base result sequence to the terminal; the measurement base result sequence being used to indicate a correct measurement base contained in the measurement base sequence; receiving a sampling set sent by the terminal and sending the sampling set to the second quantum key distribution module; the sampling set being composed of a sampling result sequence and a sampling position sequence; receiving a second AMF key sent by the second quantum key distribution module; the second AMF key being obtained based on the measurement base result sequence, the measurement base sequence, the sampling set and a first group of binary strings; The measurement base sequence and the second group of binary strings are obtained by receiving a quantum messenger sent by the second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on the first group of binary strings and a randomly selected encoding base sequence; and the first quantum key distribution module is connected with the terminal.
[0008] In a fourth aspect, the application further provides an AMF key generation method, applied to a second quantum key distribution module, the second quantum key distribution module being connected with a core network device, and the method comprising: sending a quantum messenger to a first quantum key distribution module, the quantum messenger being obtained based on a first group of binary strings and a randomly selected encoding base sequence; the first quantum key distribution module being connected with a terminal; receiving a measurement base sequence sent by the core network device, the measurement base sequence being composed of randomly selected measurement bases used for measuring the quantum messenger; sending a measurement base result sequence to the core network device, the measurement base result sequence being used for indicating correct measurement bases contained in the measurement base sequence; receiving a sampling set sent by the core network device, the sampling set being composed of a sampling result sequence and a sampling position sequence; generating a second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings; sending the second AMF key to the core network device.
[0009] In a fifth aspect, the application further provides a terminal, comprising a memory, a transceiver and a processor; the memory is used for storing a computer program; the transceiver is used for transceiving data under the control of the processor; and the processor is used for reading the computer program in the memory and executing the method of the first aspect.
[0010] In a sixth aspect, the application further provides a first quantum key distribution module, comprising a memory, a transceiver and a processor; the memory is used for storing a computer program; the transceiver is used for transceiving data under the control of the processor; and the processor is used for reading the computer program in the memory and executing the method of the second aspect.
[0011] In a seventh aspect, the application further provides a core network device, comprising a memory, a transceiver and a processor; the memory is used for storing a computer program; the transceiver is used for transceiving data under the control of the processor; and the processor is used for reading the computer program in the memory and executing the method of the third aspect.
[0012] In an eighth aspect, the present application also provides a second quantum key distribution module, comprising a memory, a transceiver, and a processor. The memory is configured to store a computer program; the transceiver is configured to transceive data under control of the processor; and the processor is configured to read the computer program in the memory and perform the method of the fourth aspect.
[0013] In a ninth aspect, the present application also provides a non-transitory readable storage medium, which stores a program for causing a processor to perform the method of the first aspect, or perform the method of the second aspect, or perform the method of the third aspect, or perform the method of the fourth aspect.
[0014] In a tenth aspect, the present application also provides a computer readable storage medium, which stores a program for causing a processor to perform the method of the first aspect, or perform the method of the second aspect, or perform the method of the third aspect, or perform the method of the fourth aspect.
[0015] In an eleventh aspect, the present application also provides a chip product, which stores a program for causing the chip product to perform the method of the first aspect, or perform the method of the second aspect, or perform the method of the third aspect, or perform the method of the fourth aspect.
[0016] The AMF key generation method, device and storage medium provided by the present application are characterized in that the terminal sends a measurement base result sequence sent by a first quantum key distribution module to a core network device, sends a measurement base result sequence sent by the core network device to the first quantum key distribution module, receives an AMF key generated by the first quantum key distribution module based on the measurement base result sequence, a measurement base sequence and a second group of binary strings, the first quantum key distribution module relies on the terminal to deliver classical information, and the terminal relies on the first quantum key distribution module to complete quantum key distribution, so that the quantum key distribution technology is applied to the 5G communication security mechanism, the AMF key is negotiated through the quantum key distribution technology, the AMF key derivation in the original standard key system is replaced, the security in the AMF key generation process is improved, and the overall security of the communication system is improved. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings required by the embodiments or the related art description. Obviously, the drawings in the following description are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0018] Figure 1 is a key hierarchy diagram in 5G system.
[0019] Figure 2 is a quantum messenger and bit corresponding relationship diagram.
[0020] Figure 3 is one of the flowcharts of the AMF key generation method provided by the embodiments of the present application.
[0021] Figure 4 is a system architecture diagram provided by the embodiments of the present application.
[0022] Figure 5 is the second flowchart of the AMF key generation method provided by the embodiments of the present application.
[0023] Figure 6 is the third flowchart of the AMF key generation method provided by the embodiments of the present application.
[0024] Figure 7 is the fourth flowchart of the AMF key generation method provided by the embodiments of the present application.
[0025] Figure 8 is the fifth flowchart of the AMF key generation method provided by the embodiments of the present application.
[0026] Figure 9 is a terminal structure diagram provided by the embodiments of the present application.
[0027] Figure 10 is a first quantum key distribution module structure diagram provided by the embodiments of the present application.
[0028] Figure 11 is a core network device structure diagram provided by the embodiments of the present application.
[0029] Figure 12 is a second quantum key distribution module structure diagram provided by the embodiments of the present application. DETAILED DESCRIPTION
[0030] The key hierarchy in the 5G system is a hierarchical key system for supporting different security requirement scenarios. In the system, keys are divided into different levels for effective management and control. The topmost key is also called the root key, which is a long-term valid key, usually generated and protected by a trusted third party.
[0031] Figure 1 is a key hierarchy diagram in the 5G system, as shown in Figure 1 K NASenc and K NASint , and K RRCenc , K RRCint , K UPenc , K UPint are all derived directly or indirectly from K AMF . It can be seen that K AMF plays a crucial role in the existing 5G standard key system.
[0032] In the related art, the generation of K AMF uses modern key technology, which can ensure relative security, but there is no theoretical support for absolute security. With the improvement of computing power, K AMF exists the risk of being cracked or leaked. Once K AMF is cracked or leaked, the security of 5G communication cannot be guaranteed.
[0033] To solve the above problems, the present application provides an AMF key generation method, which combines quantum key distribution technology with 5G technology standards to improve the security of the AMF key generation process, realizes the standardization of quantum key distribution, and enhances the security of 5G users to cope with the dimension reduction impact of future quantum computers on traditional security mechanisms.
[0034] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.
[0035] In order to better understand the technical content of each embodiment of the present application, first introduce the related art as follows.
[0036] Quantum state: The quantum state is the state of a quantum system, which is a complete description of all information of the quantum system, with superposition, entanglement and uncertainty.
[0037] Quantum channel: A term in quantum communication technology, mainly used for transmitting quantum information.
[0038] Classical channel: A term opposite to quantum channel, mainly used for transmitting classical information, i.e., common information based on binary coding (0 and 1).
[0039] Quantum messenger: A carrier of quantum information, such as a photon.
[0040] Encoding basis: A set of basis vectors representing quantum states, such as the "horizontal-vertical polarization state" of a photon (denoted as "+" basis) and the "angle polarization state" (denoted as "x" basis).
[0041] Measurement basis: A set of basis vectors representing the quantum measurement process relative to the encoding basis.
[0042] "+" basis: An encoding basis or measurement basis, each set of basis has two orthogonal states, representing 0 or 1.
[0043] "×" basis: An encoding basis or measurement basis, each set of basis has two orthogonal states, representing 0 or 1.
[0044] Figure 2 is a correspondence diagram between quantum messengers and bit positions, as shown in Figure 2 For the "+" group quantum, "--" represents bit "0" and "|" represents bit "1", which needs to be received by a "+" shaped receiver; for the "×" group quantum, "\" represents bit "0" and " / " represents bit "1", which needs to be received by a "×" shaped receiver.
[0045] Preparation of quantum state: Physically (such as optically) making quantum messengers have certain states (such as polarization states of photons) The characteristics of quantum key distribution technology are as follows: Characteristic one: In the process of quantum key distribution, the sender prepares quantum states in a certain encoding basis and sends them out, and the receiver needs to use the same measurement basis to measure to correctly obtain information, otherwise it will lead to uncertainty of measurement results. For example, if the "+" basis is used as the encoding basis to prepare quantum states, the "+" basis is used to measure to obtain correct information, and if the "×" basis is used to measure, the measurement results are uncertain; the same is true in reverse.
[0046] Characteristic two: Based on the non-cloning theorem of quantum states, unknown quantum states cannot be accurately copied, so it can be detected whether there is eavesdropping. For example, when the eavesdropper measures (eavesdrops) in the middle, the eavesdropper's measurement will inevitably change the quantum state because the eavesdropper does not know the encoding basis chosen by the sender.
[0047] For example, the sender prepares a quantum state in the "+" basis, and the eavesdropper measures in the "x" basis, which causes the quantum state to collapse into a state in the "x" basis, and then the eavesdropper forwards it to the receiver. The receiver and the sender compare the measurement results corresponding to part of the quantum state, and if the error rate exceeds the normal range, the eavesdropping behavior can be detected.
[0048] Property three: The ingenious part of the quantum key distribution technology is that even if the classical channel is eavesdropped, the eavesdropper cannot obtain the key only through the classical channel, and even if the quantum channel is eavesdropped, the communication parties can detect it.
[0049] Because there are two sets of encoding bases (or measurement bases), bit "0" or "1" can be used to represent them. For example, it is agreed that "0" represents the "+" basis and "1" represents the "x" basis, which is convenient for machine processing and information transmission.
[0050] Figure 3 is one of the flowcharts of the AMF key generation method provided by the embodiments of the present application, as shown in Figure 3 The embodiments of the present application provide an AMF key generation method, and the execution subject of the method can be a terminal, such as a mobile phone, etc. The terminal is connected with a first quantum key distribution module, and the method comprises the following steps: Step 310: receiving a measurement base sequence sent by the first quantum key distribution module, and sending the measurement base sequence to a core network device.
[0051] Step 320: receiving a measurement base result sequence sent by the core network device, and sending the measurement base result sequence to the first quantum key distribution module; the measurement base result sequence is used to indicate the correct measurement base contained in the measurement base sequence.
[0052] Step 330: receiving a first AMF key sent by the first quantum key distribution module; the first AMF key is generated based on the measurement base result sequence, the measurement base sequence and a second set of binary strings; The measurement base sequence and the second set of binary strings are obtained by the first quantum key distribution module receiving a quantum messenger sent by a second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on a first set of binary strings and a randomly selected encoding base sequence; the second quantum key distribution module is connected with the core network device.
[0053] Specifically, the first quantum key distribution module is a communication device with quantum transceiving function and capable of interacting with the terminal. The second quantum key distribution module is a communication device with quantum transceiving function and capable of interacting with the core network device.
[0054] Figure 4 is a system architecture schematic diagram provided by the embodiments of the present application, as shown in Figure 4As shown, the terminal and the base station interact through a radio resource control (RRC) air interface, and the base station and the core network device interact through an NG interface.
[0055] The classical channel transmits classical information, and the quantum channel transmits quantum information. The entire link of the classical channel includes: an interaction link between the terminal and the first quantum key distribution module, a NAS link between the terminal and the core network device, and an interaction link between the core network device and the second quantum key distribution module. The link of the quantum channel includes: an interaction link between the first quantum key distribution module and the second quantum key distribution module.
[0056] The main role of the terminal and the core network is to forward classical information and transmit control information; the main role of the second quantum key distribution module relative to the core network is to prepare and send quantum states, which carries the encoding mission of information; and the main role of the first quantum key distribution module relative to the terminal is to receive and measure quantum states, which carries the decoding mission of information.
[0057] The first group of binary strings B is a binary code stream composed of random “0” and “1”. The encoding basis sequence E is a sequence composed of randomly selected encoding bases (“+” bases and “×” bases). Each binary value in the first group of binary strings B corresponds to an encoding base in the encoding basis sequence E. The second quantum key distribution module encodes the first group of binary strings B using the encoding basis sequence E to obtain the quantum messenger Q.
[0058] The first quantum key distribution module receives the quantum messenger Q sent by the second quantum key distribution module, and measures the quantum messenger Q to obtain a measurement basis sequence D and a second group of binary strings B'. The terminal receives the measurement basis sequence D sent by the first quantum key distribution module, and sends the measurement basis sequence D to the core network device. The core network device forwards the measurement basis sequence D to the second quantum key distribution module.
[0059] The second quantum key distribution module compares the encoding basis sequence E with the measurement basis sequence D, judges whether the measurement bases contained in the measurement basis sequence D are correct according to the encoding basis sequence E, and thus obtains a measurement basis result sequence R. The measurement basis result sequence R is used to indicate whether the measurement bases contained in the measurement basis sequence D are correct, for example, using a binary value “1” to indicate that the corresponding measurement base is correct, and using a binary value “0” to indicate that the corresponding measurement base is incorrect. The second quantum key distribution module sends the measurement basis result sequence R to the core network device. The terminal receives the measurement basis result sequence R sent by the core network device, and sends the measurement basis result sequence R to the first quantum key distribution module.
[0060] The first quantum key distribution module generates a first AMF key based on the measurement basis result sequence R, the measurement basis sequence D and the second group of binary strings B' after obtaining the measurement basis result sequence R, the measurement basis sequence D and the second group of binary strings B'. The terminal receives the first AMF key sent by the first quantum key distribution module.
[0061] The AMF key generation method provided by the embodiment of the application, the terminal sends the measurement basis result sequence sent by the first quantum key distribution module to the core network device, sends the measurement basis result sequence sent by the core network device to the first quantum key distribution module, and receives the AMF key generated by the first quantum key distribution module based on the measurement basis result sequence, the measurement basis sequence and the second group of binary strings. The first quantum key distribution module relies on the terminal to deliver classical information, and the terminal relies on the first quantum key distribution module to complete quantum key distribution. The quantum key distribution technology is applied to the 5G communication security mechanism, the AMF key is negotiated through the quantum key distribution technology, the AMF key derivation in the original standard key system is replaced, and the security in the AMF key generation process is improved, so that the security of the whole communication system is improved.
[0062] In some embodiments, the sampling result sequence is obtained in the following manner: The first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence D according to the measurement basis result sequence R, takes corresponding binary values from the second group of binary strings according to the positions of the all correct measurement bases, composes a first binary string subset, randomly samples the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained in the following manner: The first quantum key distribution module composes the sampling position sequence by taking each binary value in the sampling result sequence to the corresponding sampling position in the first binary string subset.
[0063] Specifically, the first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence D according to the indication of the measurement basis result sequence R.
[0064] Since the binary value obtained by the correct measurement basis is necessarily correct, that is, the binary value obtained by the first quantum key distribution module is necessarily the same as the binary value encoded by the second quantum key distribution module, and the binary value obtained by the incorrect measurement basis has uncertainty, that is, it cannot be determined whether the binary value obtained by the first quantum key distribution module is the same as the binary value encoded by the second quantum key distribution module, that is, the incorrect measurement basis does not contain useful information.
[0065] Therefore, the first quantum key distribution module extracts binary values corresponding to positions of all correct measurement bases contained in the measurement base sequence D from the second group of binary strings B' to form a first binary string subset V'.
[0066] The first quantum key distribution module randomly samples the first binary string subset V' to obtain a sampling result sequence V', that is, the first quantum key distribution module randomly selects part of binary values in the first binary string subset V' to form the sampling result sequence V'.
[0067] After obtaining the sampling result sequence V', the first quantum key distribution module forms a sampling position sequence P by using sampling positions in the first binary string subset V' corresponding to each binary value in the sampling result sequence V'.
[0068] In some embodiments, the AMF key generation method provided by the embodiments of the present application further includes: receiving the sampling set sent by the first quantum key distribution module, and sending the sampling set to the core network device; The sampling set is composed of the sampling result sequence and the sampling position sequence.
[0069] Specifically, the first quantum key distribution module forms a sampling set S by using the sampling result sequence V' and the sampling position sequence P. The terminal receives the sampling set S sent by the first quantum key distribution module, and then sends the sampling set S to the core network device.
[0070] The AMF key generation method provided by the embodiments of the present application can avoid that the first binary string subset contains incorrect binary values, and then randomly sample the first binary string subset to obtain a sampling result sequence, form a sampling position sequence by using sampling positions in the first binary string subset corresponding to each binary value in the sampling result sequence, and finally send the sampling result sequence and the sampling position sequence to the core network device to confirm whether there is an eavesdropper based on the sampling set by the second quantum key distribution module. In the case that there is no eavesdropper, the AMF key generated is the same as the AMF key generated by the first quantum key distribution module.
[0071] In some embodiments, before receiving the first AMF key sent by the first quantum key distribution module, the method further includes: After receiving the security mode command message sent by the core network device, a first quantum key distribution request message is sent to the first quantum key distribution module, and the first quantum key distribution request message is used to request generation and return of the AMF key; The first AMF key sent by the first quantum key distribution module is received, including: The first quantum key distribution response message sent by the first quantum key distribution module is received, and the first quantum key distribution response message carries the first AMF key.
[0072] Specifically, after obtaining the second AMF key, the core network device derives the NAS key (for example, K NASenc and K NASint ) from the second AMF key, and sends the security mode command message to the terminal through the downlink direct transmission message after performing integrity protection on the security mode command (SecurityModeCommand) message using K NASint derived from the second AMF key.
[0073] After receiving the security mode command message sent by the core network device, a first quantum key distribution request message is sent to the first quantum key distribution module, and the first quantum key distribution request message is used to request generation and return of the AMF key.
[0074] After receiving the first quantum key distribution request message, the first quantum key distribution module generates the first AMF key based on the measurement base sequence R, the measurement base sequence D, and the second group of binary strings B'. The terminal receives the first quantum key distribution response message sent by the first quantum key distribution module, and the first quantum key distribution response message carries the first AMF key.
[0075] After obtaining the first AMF key, the terminal derives the NAS key (for example, K NASenc and K NASint ) from the first AMF key, and performs integrity verification on the security mode command (SecurityModeCommand) message using K NASint derived from the first AMF key, and if the verification is passed, returns the security mode complete (SecurityModeComplete) message to the core network device through the uplink direct transmission message.
[0076] The AMF key generation method provided by the embodiment of the application realizes indication of the first quantum key distribution module to generate the AMF key and return the generated AMF key through the first quantum key distribution request message and the first quantum key distribution response message.
[0077] In some embodiments, before receiving the measurement base sequence sent by the first quantum key distribution module, the method further includes: The receiving quantum state request message is used for requesting to enter the quantum receiving state before the core network device replies to the authentication response message. The receiving quantum state response message sent by the first quantum key distribution module carries indication information used for indicating that the transition from the working state to the quantum receiving state is successful.
[0078] Specifically, in the terminal access process, the core network device sends an authentication request (Authentication Request) message to the terminal, and the terminal sends a receiving quantum state request message to the first quantum key distribution module before replying to the core network device with an authentication response (Authentication Response) message after completing the authentication process. The receiving quantum state request message is used for requesting to enter the quantum receiving state.
[0079] After receiving the receiving quantum state request message, the first quantum key distribution module is transitioned from the working state to the quantum receiving state. The terminal receives the receiving quantum state response message sent by the first quantum key distribution module.
[0080] If the receiving quantum state response message received by the terminal carries indication information used for indicating that the transition from the working state to the quantum receiving state is successful, the terminal continues the access process and returns the authentication response message to the core network device; if the receiving quantum state response message received by the terminal carries indication information used for indicating that the transition from the working state to the quantum receiving state is not successful, the terminal terminates the current access process.
[0081] The AMF key generation method provided in the embodiments of the application makes the first quantum key distribution module transition from the working state to the quantum receiving state through the receiving quantum state request message and the receiving quantum state response message before the terminal replies to the core network device with the authentication response message, and prepares for subsequent receiving of the quantum messenger.
[0082] In some embodiments, the first quantum key distribution module receives the quantum messenger sent by the second quantum key distribution module through the quantum channel.
[0083] In some embodiments, the measurement basis sequence and the sampling set are sent through the uplink direct transmission message, and the measurement basis result sequence is received through the downlink direct transmission message.
[0084] In some embodiments, the uplink direct transmission message is transmitted through the uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through the downlink NAS direct transmission link.
[0085] Specifically, the first quantum key distribution module and the second quantum key distribution module transmit a quantum messenger through a quantum channel, the terminal and the core network device transmit a measurement basis sequence and a sampling set through an uplink direct transmission message, and transmit a measurement basis result sequence through a downlink direct transmission message.
[0086] For example, the uplink direct transmission message can be an UpLinkNASTransport message, and the downlink direct transmission message can be a DownLinkNASTransport message. The uplink and downlink direct transmission messages can ensure that the information is not tampered with or modified during transmission, thereby ensuring the integrity and reliability of the information.
[0087] The uplink and downlink NAS direct transmission links between the terminal and the core network device are used as classical channels, and the uplink and downlink direct transmission messages are transmitted through the uplink and downlink NAS direct transmission links, thereby realizing the transmission of the measurement basis sequence, the measurement basis result sequence, and the sampling set.
[0088] Figure 5 is a flowchart of the AMF key generation method provided by the embodiment of the application, as shown in Figure 5 The embodiment of the application provides an AMF key generation method, and the execution subject of the method can be a first quantum key distribution module. The first quantum key distribution module is connected with a terminal. The method comprises the following steps. In step 510, a quantum messenger sent by a second quantum key distribution module is received, and the quantum messenger is measured to obtain a measurement basis sequence and a second group of binary strings. The quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding basis sequence. The second quantum key distribution module is connected with a core network device. In step 520, the measurement basis sequence is sent to the terminal. In step 530, a measurement basis result sequence sent by the terminal is received. The measurement basis result sequence is used to indicate correct measurement bases contained in the measurement basis sequence. In step 540, a first AMF key is generated based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings. In step 550, the first AMF key is sent to the terminal.
[0089] Specifically, the second quantum key distribution module encodes the first group of binary strings B by using an encoding basis sequence E to obtain a quantum messenger Q. The first quantum key distribution module receives the quantum messenger Q sent by the second quantum key distribution module, and measures the quantum messenger Q to obtain a measurement basis sequence D and a second group of binary strings B'. The measurement basis sequence D is composed of randomly selected measurement bases (a "+" basis and a "x" basis).
[0090] If the measurement basis selected by the first quantum key distribution module is consistent with the corresponding encoding basis selected by the second quantum key distribution module, the measurement basis is used to measure the quantum messenger, and the obtained binary value is determined. For example, the measurement basis "+" is used to measure the quantum messenger "|", and the obtained binary value is "1"; the measurement basis "+" is used to measure the quantum messenger "--", and the obtained binary value is "0"; the measurement basis "x" is used to measure the quantum messenger "\", and the obtained binary value is "0"; and the measurement basis "x" is used to measure the quantum messenger " / ", and the obtained binary value is "1".
[0091] If the measurement basis selected by the first quantum key distribution module is inconsistent with the corresponding encoding basis selected by the second quantum key distribution module, the measurement basis is used to measure the quantum messenger, and the obtained binary value is uncertain. For example, the measurement basis "+" is used to measure the quantum messenger " / ", and the measurement basis "+" is used to measure the quantum messenger "\", the measurement basis "x" is used to measure the quantum messenger "|", and the measurement basis "x" is used to measure the quantum messenger "--", and the obtained binary value can be 0 or 1.
[0092] The first quantum key distribution module sends the measurement basis sequence D to the terminal, the terminal sends the measurement basis sequence D to the core network device through the uplink direct transmission message, and the core network device forwards the measurement basis sequence D to the second quantum key distribution module.
[0093] The second quantum key distribution module compares the encoding basis sequence E with the measurement basis sequence D, judges whether the measurement basis contained in the measurement basis sequence D is correct according to the encoding basis sequence E, and obtains the measurement basis result sequence R. The measurement basis result sequence R is used to indicate whether the measurement basis contained in the measurement basis sequence D is correct, for example, the binary value "1" is used to indicate that the corresponding measurement basis is correct, and the binary value "0" is used to indicate that the corresponding measurement basis is incorrect. The second quantum key distribution module sends the measurement basis result sequence R to the core network device, the core network device sends the measurement basis result sequence R to the terminal through the downlink direct transmission message, and the first quantum key distribution module receives the measurement basis result sequence R sent by the terminal.
[0094] Table 1 is a schematic table of the first group of binary strings B, the encoding basis sequence E, the quantum messenger Q, the measurement basis sequence D, the second group of binary strings B', and the measurement basis result sequence R. Table 1 schematically shows the constitution of the first group of binary strings B, the encoding basis sequence E, the quantum messenger Q, the measurement basis sequence D, the second group of binary strings B', and the measurement basis result sequence R.
[0095] Table 1 is a schematic table of the first group of binary strings B, the encoding basis sequence E, the quantum messenger Q, the measurement basis sequence D, the second group of binary strings B', and the measurement basis result sequence R
[0096] It should be noted that Table 1 only shows the beginning part of each sequence and binary string to illustrate the principle, and the length information is omitted. The current 5G system K AMF is 32 bytes 256 bits. This value is based on the current computing power level and efficiency, and will gradually increase with the progress of technology, so the length K AMF is not defined. The length determines the difficulty of brute force cracking. In addition, due to the randomness of the selection of the encoding base and the measurement base in the process, statistically, one-half of the quantum information is invalid, so the length of the first binary string B should be greater than twice the length of K AMF .
[0097] After obtaining the measurement base result sequence R, the measurement base sequence D and the second binary string B', the first quantum key distribution module first determines all correct measurement bases contained in the measurement base sequence D according to the indication of the measurement base result sequence R, then takes out the corresponding binary values from the second binary string B' according to the positions of all correct measurement bases contained in the measurement base sequence D, to form a first binary string subset V', and then randomly samples the first binary string subset V', and finally generates a first AMF key according to the binary values remaining in the first binary string subset V' after random sampling. The first quantum key distribution module sends the first AMF key to the terminal.
[0098] The AMF key generation method provided by the embodiments of the present application, the first quantum key distribution module measures the quantum messenger sent by the second quantum key distribution module, obtains the measurement base sequence and the second binary string, sends the measurement base sequence to the core network device through the terminal, receives the measurement base result sequence sent by the core network device through the terminal, and sends the AMF key generated based on the measurement base result sequence, the measurement base sequence and the second binary string to the terminal. The first quantum key distribution module relies on the terminal to deliver classical information, and the terminal relies on the first quantum key distribution module to complete quantum key distribution, realizes the application of quantum key distribution technology in the 5G communication security mechanism, negotiates the AMF key through the quantum key distribution technology, replaces the AMF key derivation in the original standard key system, and improves the security in the AMF key generation process, thereby improving the overall security of the communication system.
[0099] In some embodiments, based on the measurement base result sequence, the measurement base sequence and the second binary string, a first AMF key is generated, including: determining all correct measurement bases contained in the measurement base sequence according to the measurement base result sequence; taking out corresponding binary values from the second binary string according to the positions of all correct measurement bases contained in the measurement base sequence to form a first binary string subset; randomly sampling the first binary string subset to obtain a sampling result sequence; generating the first AMF key according to the binary values in the first binary string subset except the sampling result sequence.
[0100] Specifically, the first quantum key distribution module determines all correct measurement bases contained in the measurement base sequence D according to the indication of the measurement base result sequence R.
[0101] Since the binary value obtained by the correct measurement base is necessarily correct, that is, the binary value obtained by the first quantum key distribution module is necessarily the same as the binary value encoded by the second quantum key distribution module, while the binary value obtained by the incorrect measurement base is uncertain, that is, it cannot be determined whether the binary value obtained by the first quantum key distribution module is the same as the binary value encoded by the second quantum key distribution module, that is, the incorrect measurement base does not contain useful information.
[0102] Therefore, the first quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement base sequence D from the second group of binary strings B' to form a first binary string subset V'.
[0103] Table 2 is a schematic table of the second group of binary strings B', the measurement base sequence D, the measurement base result sequence R and the first binary string subset V', which schematically shows the constitution of the second group of binary strings B', the measurement base sequence D, the measurement base result sequence R and the first binary string subset V'.
[0104] Table 2 Schematic table of the second group of binary strings B', the measurement base sequence D, the measurement base result sequence R and the first binary string subset V'
[0105] The first quantum key distribution module randomly samples the first binary string subset V' to obtain a sampling result sequence V', that is, the terminal randomly selects part of the binary values in the first binary string subset V' to form the sampling result sequence V'.
[0106] The first quantum key distribution module takes the binary values in the first binary string subset V' except the sampling result sequence V' to form a sequence K', and generates the first AMF key according to the sequence K'.
[0107] The first quantum key distribution module can have the following ways to generate the first AMF key according to the sequence K': Mode one, directly taking the sequence K' as the first AMF key, which is the simplest; The second method, since the length of the AMF key is generally fixed, the data of the corresponding length can be cut from the sequence K' as the first AMF key; The third method, the sequence K' is converted by an algorithm (for example, a hash algorithm) to generate a first AMF key of fixed length.
[0108] The AMF key generation method provided by the embodiment of the application can avoid that the first binary string subset contains incorrect binary values, by determining all correct measurement bases contained in the measurement base sequence according to the measurement base sequence, taking the corresponding binary values from the second group of binary strings according to the positions of the all correct measurement bases contained in the measurement base sequence, to form a first binary string subset, randomly sampling the first binary string subset to obtain a sampling result sequence, and generating the first AMF key according to the binary values in the first binary string subset except the sampling result sequence, so as to realize the acquisition of the terminal side AMF key.
[0109] In some embodiments, after the first binary string subset is randomly sampled to obtain the sampling result sequence, the method further includes: Each binary value in the sampling result sequence is arranged in the corresponding sampling position in the first binary string subset to form a sampling position sequence; The sampling result sequence and the sampling position sequence are combined to form a sampling set; The sampling set is sent to the terminal.
[0110] Specifically, after obtaining the sampling result sequence V'_, the first quantum key distribution module arranges each binary value in the sampling result sequence V'_ in the corresponding sampling position in the first binary string subset V' to form a sampling position sequence P.
[0111] Table 3 is a schematic table of the first binary string subset V', the sampling result sequence V'_ and the sampling position sequence P, which schematically shows the formation of the first binary string subset V', the sampling result sequence V'_ and the sampling position sequence P.
[0112] Table 3 is a schematic table of the first binary string subset V', the sampling result sequence V'_ and the sampling position sequence P
[0113] The first quantum key distribution module combines the sampling result sequence V'_ and the sampling position sequence P to form a sampling set S, and then sends the sampling set S to the terminal. The terminal sends the sampling set S to the core network device through the uplink direct transmission message, and the core network device forwards the sampling set S to the second quantum key distribution module.
[0114] The AMF key generation method provided by the embodiment of the application comprises the following steps: sending a sampling set composed of a sampling result sequence and a sampling position sequence to a terminal, so that the terminal sends the sampling set to a second quantum key distribution module through a core network device, and the second quantum key distribution module confirms whether there is an eavesdropper based on the sampling set; and in the case that there is no eavesdropper, the AMF key is generated, which is the same as the AMF key generated by the first quantum key distribution module.
[0115] In some embodiments, before the first AMF key is generated based on the measurement base result sequence, the measurement base sequence and the second group of binary strings, the method further comprises the following steps of: receiving a first quantum key distribution request message sent by the terminal, the first quantum key distribution request message being used for requesting generation and return of the AMF key; After the first AMF key is generated based on the measurement base result sequence, the measurement base sequence and the second group of binary strings, the method further comprises the following steps of: sending a first quantum key distribution response message to the terminal, the first quantum key distribution response message carrying the first AMF key.
[0116] Specifically, after obtaining the second AMF key, the core network device derives a NAS key (for example, K NASenc and K NASint ) from the second AMF key, and sends a security mode command (SecurityModeCommand) message to the terminal after performing integrity protection on the security mode command message by using K NASint .
[0117] After the terminal receives the security mode command message sent by the core network device, the first quantum key distribution module receives a first quantum key distribution request message sent by the terminal, the first quantum key distribution request message being used for requesting generation and return of the AMF key.
[0118] After receiving the first quantum key distribution request message, the first quantum key distribution module generates a first AMF key based on the measurement base result sequence, the measurement base sequence and the second group of binary strings, and sends a first quantum key distribution response message to the terminal, the first quantum key distribution response message carrying the first AMF key.
[0119] After obtaining the first AMF key, the terminal derives a NAS key (for example, K NASenc and K NASint ) from the first AMF key, and uses K NASintThe security mode command (SecurityModeCommand) message is subjected to integrity verification, and if the verification is passed, a security mode complete (SecurityModeComplete) message is returned to the core network device through an uplink direct transmission message.
[0120] The AMF key generation method provided in the embodiments of the present application realizes the indication of the first quantum key distribution module to generate the AMF key and the return of the generated AMF key through the first quantum key distribution request message and the first quantum key distribution response message.
[0121] In some embodiments, before receiving the quantum messenger sent by the second quantum key distribution module, the method further comprises: receiving a receiving quantum state request message sent by the terminal, the receiving quantum state request message being used to request to enter a quantum receiving state; sending a receiving quantum state response message to the terminal, the receiving quantum state response message carrying indication information used to indicate that the transition from the working state to the quantum receiving state is successful.
[0122] Specifically, in the terminal access process, the core network device sends an authentication request (AuthenticationRequest) message to the terminal, and before the terminal replies an authentication response (AuthenticationResponse) message to the core network device after completing the authentication process, the first quantum key distribution module receives a receiving quantum state request message sent by the terminal, the receiving quantum state request message being used to request to enter a quantum receiving state.
[0123] After receiving the receiving quantum state request message, the first quantum key distribution module is transitioned from the working state to the quantum receiving state, and sends a receiving quantum state response message to the terminal. If the receiving quantum state response message carries indication information used to indicate that the transition from the working state to the quantum receiving state is successful, the terminal continues the access process and returns the authentication response message to the core network device. If the receiving quantum state response message carries indication information used to indicate that the transition from the working state to the quantum receiving state is not successful, the terminal terminates the current access process.
[0124] The AMF key generation method provided in the embodiments of the present application realizes the indication of the first quantum key distribution module to generate the AMF key and the return of the generated AMF key through the first quantum key distribution request message and the first quantum key distribution response message.
[0125] Figure 6 is a third flowchart of the AMF key generation method provided in the embodiments of the present application, as shown in Figure 6As shown, the embodiment of the present application provides an AMF key generation method, the execution subject of which can be a core network device, for example, an AMF network element device, and the core network device is connected with a second quantum key distribution module, and the method comprises the following steps: In step 610, the measurement base sequence sent by the terminal is received, and the measurement base sequence is sent to the second quantum key distribution module. In step 620, the measurement base result sequence sent by the second quantum key distribution module is received, and the measurement base result sequence is sent to the terminal; the measurement base result sequence is used to indicate the correct measurement base contained in the measurement base sequence. In step 630, the sampling set sent by the terminal is received, and the sampling set is sent to the second quantum key distribution module; the sampling set is composed of the sampling result sequence and the sampling position sequence. In step 640, the second AMF key sent by the second quantum key distribution module is received; the second AMF key is obtained based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings. Wherein, the measurement base sequence and the second group of binary strings are obtained by the first quantum key distribution module receiving the quantum messenger sent by the second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on the first group of binary strings and the randomly selected encoding base sequence; the first quantum key distribution module is connected with the terminal.
[0126] Specifically, the second quantum key distribution module encodes the first group of binary strings B by using the encoding base sequence E to prepare the quantum messenger Q. The first quantum key distribution module receives the quantum messenger sent by the second quantum key distribution module and measures the quantum messenger to obtain the measurement base sequence D and the second group of binary strings B'. The first quantum key distribution module sends the measurement base sequence D to the terminal.
[0127] The core network device receives the measurement base sequence D sent by the terminal and sends the measurement base sequence D to the second quantum key distribution module.
[0128] The second quantum key distribution module compares the measurement base sequence D with the encoding base sequence E to determine whether the measurement base contained in the measurement base sequence D is correct according to the encoding base sequence E, thereby obtaining the measurement base result sequence R, which is used to indicate whether the measurement base contained in the measurement base sequence D is correct, for example, indicating that the corresponding measurement base is correct by using the binary value "1" and indicating that the corresponding measurement base is incorrect by using the binary value "0".
[0129] The core network device receives the measurement base result sequence R sent by the second quantum key distribution module and sends the measurement base result sequence R to the terminal, and the terminal forwards the measurement base result sequence R to the first quantum key distribution module.
[0130] The first quantum key distribution module obtains a sampling result sequence V'_ and a sampling position sequence P based on the measurement basis result sequence R, the measurement basis sequence D and the second group of binary strings B', groups the sampling result sequence V'_ and the sampling position sequence P into a sampling set S, and sends the sampling set S to the terminal. The core network device receives the sampling set S sent by the terminal, and sends the sampling set S to the second quantum key distribution module.
[0131] The second quantum key distribution module generates a second AMF key based on the measurement basis result sequence R, the measurement basis sequence D, the sampling set S and the first group of binary strings B. The core network device receives the second AMF key sent by the second quantum key distribution module.
[0132] The AMF key generation method provided by the embodiment of the application, the core network device forwards the measurement basis sequence sent by the terminal to the second quantum key distribution module, forwards the measurement basis result sequence sent by the second quantum key distribution module to the terminal, receives the second AMF key generated by the second quantum key distribution module based on the measurement basis result sequence, the measurement basis sequence, the sampling set and the first group of binary strings, the second quantum key distribution module relies on the core network device to transfer classical information, and the core network device relies on the second quantum key distribution module to complete quantum key distribution, so that the quantum key distribution technology is applied to the 5G communication security mechanism, the AMF key is negotiated through the quantum key distribution technology, the AMF key derivation in the original standard key system is replaced, the security in the AMF key generation process is improved, and therefore the security of the whole communication system is improved.
[0133] In some embodiments, the sampling result sequence is obtained in the following manner: The first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence, takes corresponding binary values from the second group of binary strings according to the positions of the all correct measurement bases contained in the measurement basis sequence, groups the first binary string subset, performs random sampling on the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained in the following manner: The first quantum key distribution module groups the sampling position sequence of each binary value in the sampling result sequence in the corresponding sampling position in the first binary string subset.
[0134] Specifically, the first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence D according to the indication of the measurement basis result sequence R.
[0135] Since the binary value obtained by correct measurement basis is necessarily correct, that is, the binary value obtained by the first quantum key distribution module is necessarily the same as the binary value encoded by the second quantum key distribution module, and the binary value obtained by incorrect measurement basis has uncertainty, that is, it cannot be determined whether the binary value obtained by the first quantum key distribution module is the same as the binary value encoded by the second quantum key distribution module, that is, the incorrect measurement basis does not contain useful information.
[0136] Therefore, the first quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement basis sequence D from the second group of binary strings B' to form a first binary string subset V'.
[0137] The first quantum key distribution module randomly samples the first binary string subset V' to obtain a sampling result sequence V'.
[0138] After obtaining the sampling result sequence V', the first quantum key distribution module forms a sampling position sequence P by taking the sampling positions corresponding to each binary value in the sampling result sequence V' in the first binary string subset V'.
[0139] The AMF key generation method provided in the embodiments of the application can avoid the first binary string subset containing incorrect binary values by determining all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence, taking out the corresponding binary values from the second group of binary strings according to the positions of all correct measurement bases contained in the measurement basis sequence to form a first binary string subset, and then randomly sampling the first binary string subset to obtain a sampling result sequence, forming a sampling position sequence by taking the sampling positions corresponding to each binary value in the sampling result sequence in the first binary string subset, and finally sending the sampling result sequence and the sampling position sequence to the core network device to enable the second quantum key distribution module to confirm whether there is an eavesdropper based on the sampling set, so that the AMF key generated in the case where there is no eavesdropper is the same as the AMF key generated by the first quantum key distribution module.
[0140] In some embodiments, before receiving the second AMF key sent by the second quantum key distribution module, the method further includes: After receiving the authentication response message replied by the terminal, a second quantum key distribution request message is sent to the second quantum key distribution module, and the second quantum key distribution request message is used to request generation and return of an AMF key; The second AMF key sent by the second quantum key distribution module is received, including: The second quantum key distribution module sends a second quantum key distribution response message to the first quantum key distribution module, and the second quantum key distribution response message carries the second AMF key.
[0141] Specifically, in the terminal access process, the core network device sends an Authentication Request message to the terminal, and after receiving an Authentication Response message returned by the terminal, the core network device sends a second quantum key distribution request message to the second quantum key distribution module, and the second quantum key distribution request message is used to request generation and return of the AMF key.
[0142] After receiving the second quantum key distribution request message, the second quantum key distribution module encodes the first group of binary strings B by using an encoding base sequence E to obtain a quantum messenger Q, sends the quantum messenger Q to the first quantum key distribution module, receives a measurement base sequence D and a sampling set S forwarded by the first quantum key distribution module through the terminal and the core network device, and generates the second AMF key based on a measurement base result sequence R, the measurement base sequence D, the sampling set S and the first group of binary strings B.
[0143] The core network device receives a second quantum key distribution response message sent by the second quantum key distribution module, and the second quantum key distribution response message carries the second AMF key. The core network device derives a NAS key (for example, K NASenc and K NASint ) from the second AMF key, and performs integrity protection on a SecurityModeCommand message by using K NASint derived from the second AMF key.
[0144] The AMF key generation method provided in the embodiments of the application realizes indication of AMF key generation by the second quantum key distribution module and return of the generated AMF key through the second quantum key distribution request message and the second quantum key distribution response message.
[0145] In some embodiments, the first quantum key distribution module receives the quantum messenger sent by the second quantum key distribution module through a quantum channel.
[0146] In some embodiments, the measurement base sequence and the sampling set are received through an uplink direct transmission message, and the measurement base result sequence is sent through a downlink direct transmission message.
[0147] In some embodiments, the uplink direct transmission message is transmitted through an uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through a downlink NAS direct transmission link.
[0148] Specifically, the first quantum key distribution module and the second quantum key distribution module transmit a quantum messenger through a quantum channel, the terminal and the core network device transmit a measurement base sequence and a sampling set through an uplink direct transmission message, and transmit a measurement base result sequence through a downlink direct transmission message.
[0149] For example, the uplink direct transmission message can be an UpLinkNASTransport message, and the downlink direct transmission message can be a DownLinkNASTransport message. The uplink and downlink direct transmission messages can ensure that the information is not tampered with or modified during transmission, thereby ensuring the integrity and reliability of the information.
[0150] The uplink and downlink NAS direct transmission links between the terminal and the core network device are used as classical channels, and the uplink and downlink direct transmission messages are transmitted through the uplink and downlink NAS direct transmission links, thereby realizing the transmission of the measurement base sequence, the measurement base result sequence and the sampling set.
[0151] Figure 7 Figure 4 is a flowchart of an AMF key generation method provided by the present application, as shown in Figure 7 The execution subject of the AMF key generation method provided by the present application can be a second quantum key distribution module, and the second quantum key distribution module is connected with a core network device. The method comprises the following steps. In step 710, a quantum messenger is sent to a first quantum key distribution module, and the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding base sequence; the first quantum key distribution module is connected with a terminal; In step 720, a measurement base sequence sent by the core network device is received, and the measurement base sequence is composed of randomly selected measurement bases used for measuring the quantum messenger; In step 730, a measurement base result sequence is sent to the core network device, and the measurement base result sequence is used to indicate the correct measurement base contained in the measurement base sequence; In step 740, a sampling set sent by the core network device is received, and the sampling set is composed of a sampling result sequence and a sampling position sequence; In step 750, a second AMF key is generated based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings; In step 760, the second AMF key is sent to the core network device.
[0152] Specifically, the first group of binary strings B is a binary code stream randomly generated by “0” and “1”. The encoding base sequence E is a sequence composed of randomly selected encoding bases (“+” base and “×” base). The length of the encoding base sequence E is the same as that of the first group of binary strings B, and each binary value in the first group of binary strings B corresponds to an encoding base in the encoding base sequence E.
[0153] The second quantum key distribution module encodes the first set of binary strings B using the encoding basis sequence E to obtain a quantum messenger Q. For example, the encoding basis "+" encodes the binary value "0" to obtain the quantum messenger "--"; the encoding basis "+" encodes the binary value "1" to obtain the quantum messenger "|"; the encoding basis "x" encodes the binary value "0" to obtain the quantum messenger "\"; and the encoding basis "x" encodes the binary value "1" to obtain the quantum messenger " / ". The second quantum key distribution module sends the quantum messenger Q to the first quantum key distribution module through a quantum channel.
[0154] After receiving the quantum messenger Q sent by the core network device, the first quantum key distribution module randomly selects a measurement basis ("+" basis and "x" basis) to measure the quantum messenger Q to obtain a measurement basis sequence D and a second set of binary strings B'. The first quantum key distribution module sends the measurement basis sequence D to the terminal, and the terminal sends the measurement basis sequence D to the core network device through an uplink direct transmission message.
[0155] The second quantum key distribution module receives the measurement basis sequence D sent by the core network device, compares the measurement basis sequence D with the encoding basis sequence E, and determines whether the measurement basis contained in the measurement basis sequence D is correct according to the encoding basis sequence E to obtain a measurement basis result sequence R. The measurement basis result sequence R is used to indicate whether the measurement basis contained in the measurement basis sequence D is correct. The length of the measurement basis result sequence R is the same as that of the measurement basis sequence D.
[0156] If the measurement basis is consistent with the corresponding encoding basis, it is considered that the measurement basis is correct, and if the measurement basis is inconsistent with the corresponding encoding basis, it is considered that the measurement basis is incorrect. For example, in the measurement basis result sequence R, the binary value "1" indicates that the corresponding measurement basis is correct, and the binary value "0" indicates that the corresponding measurement basis is incorrect.
[0157] The second quantum key distribution module sends the measurement basis result sequence R to the core network device, and the core network device sends the measurement basis result sequence R to the terminal through a downlink direct transmission message. The terminal forwards the measurement basis result sequence R to the first quantum key distribution module.
[0158] According to the indication of the measurement basis result sequence R, the first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence D, and takes out the binary values corresponding to the positions of the correct measurement bases contained in the measurement basis sequence D from the second set of binary strings B' to form a first binary string subset V'.
[0159] The first quantum key distribution module randomly samples the first binary string subset V' to obtain a sampling result sequence V', then groups each binary value in the sampling result sequence V' with a corresponding sampling position in the first binary string subset V' to form a sampling position sequence P, and finally groups the sampling result sequence V' and the sampling position sequence P to form a sampling set S. The first quantum key distribution module sends the sampling set S to the terminal, and the terminal sends the sampling set S to the core network device through an uplink direct transmission message. The second quantum key distribution module receives the sampling set S sent by the core network device.
[0160] After obtaining the measurement basis result sequence R, the measurement basis sequence D, the sampling set S and the first group of binary strings B, the second quantum key distribution module first determines all correct measurement bases contained in the measurement basis sequence D according to the indication of the measurement basis result sequence R, then takes out corresponding binary values from the first group of binary strings B according to the positions of all correct measurement bases contained in the measurement basis sequence D to form a second binary string subset V, and finally generates a second AMF key according to the binary values remaining in the second binary string subset V after taking out. The second quantum key distribution module sends the second AMF key to the core network device.
[0161] The AMF key generation method provided by the embodiments of the present application, the second quantum key distribution module receives the measurement basis sequence and the sampling set sent by the terminal forwarded by the core network device, sends the measurement basis result sequence to the terminal through the core network device, and sends a second AMF key generated based on the measurement basis result sequence, the measurement basis sequence, the sampling set and the first group of binary strings to the core network device. The second quantum key distribution module relies on the core network device to transfer classical information, and the core network device relies on the second quantum key distribution module to complete quantum key distribution, so as to apply quantum key distribution technology to the 5G communication security mechanism, negotiate an AMF key through the quantum key distribution technology, replace the AMF key derivation in the original standard key system, and improve the security of the AMF key generation process, thereby improving the overall security of the communication system.
[0162] In some embodiments, the second AMF key is generated based on the measurement basis result sequence, the measurement basis sequence, the sampling set and the first group of binary strings, including: determining all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence; taking out corresponding binary values from the first group of binary strings according to the positions of all correct measurement bases contained in the measurement basis sequence to form a second binary string subset; According to the sampling positions contained in the sampling position sequence in the sampling set, the corresponding binary values in the second binary string subset are taken out to form a binary sequence; According to the binary values in the second binary string subset except the binary sequence, a second AMF key is generated.
[0163] Specifically, the second quantum key distribution module determines all correct measurement bases contained in the measurement base sequence D according to the indication of the measurement base result sequence R.
[0164] The second quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement base sequence D from the first group of binary strings B to form a second binary string subset V.
[0165] Table 4 is a schematic table of the first group of binary strings B, the measurement base sequence D, the measurement base result sequence R and the second binary string subset V, which schematically shows the formation of the first group of binary strings B, the measurement base sequence D, the measurement base result sequence R and the second binary string subset V. As can be seen from Table 2 and Table 4, in theory, the first binary string subset V’ and the second binary string subset V should be the same.
[0166] Table 4 is a schematic table of the first group of binary strings B, the measurement base sequence D, the measurement base result sequence R and the second binary string subset V, which schematically shows the formation of the first group of binary strings B, the measurement base sequence D, the measurement base result sequence R and the second binary string subset V. As can be seen from Table 2 and Table 4, in theory, the first binary string subset V’ and the second binary string subset V should be the same.
[0167] The second quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement base sequence D from the first group of binary strings B to form a second binary string subset V.
[0168] Table 5 is a schematic table of the second binary string subset V, the sampling position sequence P and the binary sequence V_, which schematically shows the formation of the second binary string subset V, the sampling position sequence P and the binary sequence V_. As can be seen from Table 3 and Table 5, in theory, the sampling result sequence V’_ and the binary sequence V_ should be the same.
[0169] Table 5 is a schematic table of the second binary string subset V, the sampling position sequence P and the binary sequence V_, which schematically shows the formation of the second binary string subset V, the sampling position sequence P and the binary sequence V_. As can be seen from Table 3 and Table 5, in theory, the sampling result sequence V’_ and the binary sequence V_ should be the same.
[0170] The second quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement base sequence D from the first group of binary strings B to form a second binary string subset V.
[0171] The second quantum key distribution module generates a second AMF key according to the sequence K, and the following methods can be used: Method one: directly taking the sequence K as the second AMF key, which is the simplest; Method two: since the length of the AMF key is generally fixed, data of a corresponding length can be intercepted from the sequence K as the second AMF key; Method three: converting the sequence K through an algorithm (for example, a hash algorithm) to generate a second AMF key of a fixed length.
[0172] Since the sequence K' and the sequence K are the same, the AMF keys obtained by the same processing on the sequence K' and the sequence K are also necessarily the same, which guarantees that the AMF keys generated by the terminal and the core network device through the same processing are consistent, that is, the first AMF key and the second AMF key are the same.
[0173] The AMF key generation method provided by the embodiment of the application includes the following steps: the second quantum key distribution module first determines all correct measurement bases contained in the measurement base sequence according to the measurement base sequence, takes corresponding binary values from the first group of binary strings according to positions of the all correct measurement bases contained in the measurement base sequence, and composes a second binary string subset, so that the first binary string subset and the second binary string subset are the same; then the second quantum key distribution module takes corresponding binary values from the second binary string subset according to sampling positions contained in the sampling position sequence in the sampling set, and composes a binary sequence, so that the sampling result sequence and the binary sequence are the same; finally, the second quantum key distribution module generates a second AMF key according to binary values in the second binary string subset except the binary sequence, so that the AMF keys generated by the first quantum key distribution module and the second quantum key distribution module are the same.
[0174] In some embodiments, before the second quantum key distribution module generates the second AMF key according to the binary values in the second binary string subset except the binary sequence, the following steps are further included: The second quantum key distribution module performs consistency comparison on the sampling result sequence in the sampling set and the binary sequence, and obtains a consistency comparison result; In the case that the consistency comparison result is greater than a verification threshold, it is confirmed that the sampling set passes the verification.
[0175] Specifically, the comparison between the second binary string subset V and the first binary string subset V' can know whether there is eavesdropping in the key distribution process, but the classical channel cannot directly transmit the second binary string subset V and the first binary string subset V' (if there is eavesdropping, it is easy to leak), so the first binary string subset V' is sampled, the sampling set S is transmitted, and the same effect is achieved through sampling, so even if the sampling set S is leaked, the eavesdropper cannot obtain the remaining information (that is, the sequence K' and the sequence K).
[0176] Before generating the second AMF key based on the sampling set S, the sampling result sequence V' in the sampling set S is compared with the binary sequence V for consistency, and if the consistency comparison result is greater than the verification threshold, it is considered that there is no eavesdropper in the channel, and it is confirmed that the sampling set S is verified, and the process of generating the AMF is entered. Otherwise, it is considered that there is an eavesdropper.
[0177] The AMF key generation method provided by the embodiment of the application realizes confirmation of whether there is an eavesdropper by comparing the sampling result sequence with the binary sequence.
[0178] In some embodiments, after receiving the measurement base sequence sent by the core network device, further comprising: Comparing the measurement base sequence with the encoding base sequence to obtain a measurement base result sequence.
[0179] Specifically, the second quantum key distribution module compares the measurement base sequence D and the encoding base sequence E, which can be specifically: performing bitwise XOR processing on the measurement base sequence D and the encoding base sequence E, that is, performing XOR operation on the measurement base and the encoding base at the same position, the same is true (1) and the different is false (0), if the operation result is 1, the measurement base is correct, if the operation result is 0, the measurement base is incorrect, thereby obtaining the measurement base result sequence R, the measurement base result sequence R is used to indicate whether the measurement base contained in the measurement base sequence D is correct, for example, using binary value "1" to indicate that the corresponding measurement base is correct, and using binary value "0" to indicate that the corresponding measurement base is incorrect. Bitwise XOR is a suitable and concise way.
[0180] The second quantum key distribution module compares the measurement base sequence D and the encoding base sequence E, which can be specifically: the second quantum key distribution module judges the measurement base sequence D and the encoding base sequence E, that is, judges whether the corresponding measurement base and the encoding base are the same, if the same, the measurement base is correct, if not the same, the measurement base is incorrect, thereby obtaining the measurement base result sequence R, the measurement base result sequence R is used to indicate whether the measurement base contained in the measurement base sequence D is correct, for example, using binary value "1" to indicate that the corresponding measurement base is correct, and using binary value "0" to indicate that the corresponding measurement base is incorrect.
[0181] The AMF key generation method provided by the embodiment of the application compares the measurement base sequence with the encoding base sequence to obtain the measurement base result sequence, and then determines the correct measurement base contained in the measurement base sequence according to the measurement base result sequence.
[0182] In some embodiments, before sending the quantum messenger to the first quantum key distribution module, further comprising: receive a second quantum key distribution request message sent by the core network device, the second quantum key distribution request message being used to request generation and return of the AMF key; after generating the second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set, and the first group of binary strings, comprising: send a second quantum key distribution response message to the core network device, the second quantum key distribution response message carrying the second AMF key.
[0183] Specifically, in a terminal access process, the core network device sends an authentication request (AuthenticationRequest) message to the terminal, and after receiving an authentication response (AuthenticationResponse) message returned by the terminal, the second quantum key distribution module receives a second quantum key distribution request message sent by the core network device, and the second quantum key distribution request message is used to request generation and return of the AMF key.
[0184] After receiving the second quantum key distribution request message, the second quantum key distribution module encodes the first group of binary strings B by using the encoding base sequence E to obtain a quantum messenger Q, sends the quantum messenger Q to the first quantum key distribution module through a quantum channel, receives a measurement base sequence D and a sampling set S forwarded by the first quantum key distribution module through the terminal and the core network device, and generates a second AMF key based on a measurement base result sequence R, the measurement base sequence D, the sampling set S, and the first group of binary strings B. The second quantum key distribution module sends a second quantum key distribution response message to the core network device, and the second quantum key distribution response message carries the second AMF key.
[0185] After obtaining the second AMF key, the core network device derives a NAS key (for example, K NASenc and K NASint ) from the second AMF key, and performs integrity protection on a security mode command (SecurityModeCommand) message by using K NASint .
[0186] The AMF key generation method provided in the embodiments of the application realizes indication of AMF key generation by the second quantum key distribution module and return of the generated AMF key through the second quantum key distribution request message and the second quantum key distribution response message.
[0187] Figure 8 is a flowchart of the AMF key generation method provided in the embodiments of the application, as shown in FIG. 5, the AMF key generation method provided in the embodiments of the application comprises the following steps: Figure 8 Step 801, the core network device sends an authentication request (AuthenticationRequest) message to the terminal through a downlink NAS transport (DownLinkNASTransport) message, and the terminal enters an authentication process.
[0188] Step 802, after completing the authentication process, the terminal sends a receive quantum state request message to the first quantum key distribution module before replying to an authentication response (AuthenticationResponse), the receive quantum state request message is used to request to enter a quantum receiving state, and the terminal starts a timer at the same time to wait for a receive quantum state response message returned by the first quantum key distribution module.
[0189] Step 803, the second quantum key distribution module enters a quantum receiving state from a working state after receiving the receive quantum state request message, and sends a receive quantum state response message to the terminal.
[0190] If the receive quantum state response message carries indication information that the quantum receiving state is successfully entered from the working state, the terminal continues the access process and enters step 804; if the receive quantum state response message carries indication information that the quantum receiving state is not successfully entered from the working state, or the timer is timed out when the receive quantum state response message is received, the current access process is terminated.
[0191] Step 804, the terminal sends an authentication response (AuthenticationResponse) message to the core network device through an uplink NAS transport (UpLinkNASTransport) message.
[0192] Step 805, after receiving the authentication response message sent by the terminal and completing the authentication process, the core network device sends a second quantum key distribution request message to the second quantum key distribution module, the second quantum key distribution request message is used to request to generate and return an AMF key, and the core network device starts a timer at the same time to wait for a second quantum key distribution response message returned by the second quantum key distribution module.
[0193] Step 806, after receiving the second quantum key distribution request message, the second quantum key distribution module encodes the first group of binary strings B based on a randomly selected encoding base sequence E to obtain a quantum messenger Q, and sends the quantum messenger to the first quantum key distribution module through a quantum channel.
[0194] Step 807, the first quantum key distribution module receives and measures the quantum messenger Q to obtain a measurement base sequence D and a second group of binary strings B'. The first quantum key distribution module sends the measurement base sequence D to the terminal.
[0195] Step 808, the terminal sends the measurement basis sequence D to the core network device through the uplink direct transmission message.
[0196] Step 809, the core network device forwards the measurement basis sequence D to the second quantum key distribution module.
[0197] Step 810, the second quantum key distribution module compares the measurement basis sequence D with the encoding basis sequence E to obtain a measurement result sequence R, the measurement result sequence R is used to indicate the correct measurement bases contained in the measurement basis sequence D. The second quantum key distribution module sends the measurement result sequence R to the core network device.
[0198] The second quantum key distribution module takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement basis sequence D from the first group of binary strings B to form a second binary string subset V.
[0199] Step 811, the core network device sends the measurement result sequence R to the terminal through the downlink direct transmission message.
[0200] Step 812, the terminal forwards the measurement result sequence R to the first quantum key distribution module.
[0201] Step 813, after the first quantum key distribution module obtains the measurement basis result sequence R, according to the measurement basis result sequence R, it determines all correct measurement bases contained in the measurement basis sequence D, and takes out the binary values corresponding to the positions of all correct measurement bases contained in the measurement basis sequence D from the second group of binary strings B' to form a first binary string subset V'.
[0202] The first quantum key distribution module randomly samples the first binary string subset V' to obtain a sampling result sequence V', and the sampling position sequence P is composed of the sampling positions in the first binary string subset V' corresponding to each binary value in the sampling result sequence V'.
[0203] The first quantum key distribution module forms a sampling set S by combining the sampling result sequence V' and the sampling position sequence P, and sends the sampling set S to the terminal.
[0204] Step 814, the terminal sends the sampling set S to the core network device through the uplink direct transmission message.
[0205] Step 815, the core network device forwards the sampling set S to the second quantum key distribution module.
[0206] Step 816, the second quantum key distribution module receives the sampling set S, obtains the sampling result sequence V' and the sampling position sequence P, takes out the binary values corresponding to the sampling positions contained in the sampling position sequence P from the second binary string subset V to form a binary sequence V_, and the remaining binary values in the second binary string subset V form a sequence K.
[0207] The sampling set S is verified, that is, the sampling result sequence V' in the sampling set S is compared with the binary sequence V_ for consistency, and if the consistency comparison result is greater than a verification threshold, it is considered that there is no eavesdropper in the channel, otherwise it is considered that there is an eavesdropper.
[0208] If it is considered that there is no eavesdropper, the second quantum key distribution module generates a second AMF key according to the sequence K, and sends a second quantum key distribution response message to the core network device, the second quantum key distribution response message carrying the second AMF key.
[0209] If it is considered that there is an eavesdropper, the second quantum key distribution module sends a second quantum key distribution response message to the core network device, the second quantum key distribution response message carrying an error code.
[0210] Step 817, if the core network device obtains the second AMF key, the NAS key (for example, K NASenc and K NASint ) is derived from the second AMF key, and the SMC message is integrity protected by K NASint derived from the second AMF key, that is, K NASint is used to calculate the MAC value of the SMC message, and the security mode command message is sent to the terminal through the downlink direct transmission message.
[0211] If the core network device obtains the error code, indicating that the error reason is "if an eavesdropper is detected" or the timer is timed out, the current access process is terminated, a registration rejection message is returned to the terminal and the rejection reason is carried.
[0212] Step 818, after the terminal receives the security mode command message, the terminal sends a first quantum key distribution request message to the first quantum key distribution module, the first quantum key distribution request message being used to request to generate and return an AMF key.
[0213] Step 819, after the first quantum key distribution module receives the first quantum key distribution request message, the first AMF key is generated according to the sequence K', and the first quantum key distribution response message carrying the first AMF key is sent to the terminal.
[0214] Step 820: After obtaining the first AMF key, the terminal derives a NAS key (e.g., K) from the first AMF key. NASenc and K NASint ), and K derived from the first AMF key NASint Perform integrity verification on the SecurityModeCommand message, i.e., use the K derived from the first AMF key. NASint The MAC value is calculated for the SMC message. If the MAC values calculated by the terminal and the core network device are consistent, it indicates that the verification is successful. Then, a SecurityModeComplete message is returned to the core network device through an uplink direct transmission message.
[0215] Figure 9 This is a schematic diagram of the terminal structure provided in the embodiments of this application, such as... Figure 9 As shown, the terminal includes a memory 920, a transceiver 910, and a processor 900; wherein the processor 900 and the memory 920 can also be physically arranged separately.
[0216] The memory 920 is used to store computer programs; the transceiver 910 is used to send and receive data under the control of the processor 900.
[0217] Among them, Figure 9 In this application, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 900 and memory represented by memory 920 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be further described herein. The bus interface provides an interface. The transceiver 910 can be multiple components, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, the user interface 930 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0218] The processor 900 is responsible for managing the bus architecture and general processing, while the memory 920 can store the data used by the processor 900 during operation.
[0219] The processor 900 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0220] The processor 900 invokes a computer program stored in the memory 920 to execute any of the AMF key generation methods provided in the embodiments of the present application according to the obtained executable instructions, including: receiving a measurement basis sequence sent by the first quantum key distribution module, and sending the measurement basis sequence to a core network device; receiving a measurement basis result sequence sent by the core network device, and sending the measurement basis result sequence to the first quantum key distribution module; the measurement basis result sequence is used to indicate correct measurement bases contained in the measurement basis sequence; receiving a first AMF key sent by the first quantum key distribution module; the first AMF key is generated based on the measurement basis result sequence, the measurement basis sequence and a second group of binary strings; The measurement basis sequence and the second group of binary strings are obtained by measuring a quantum messenger received by the first quantum key distribution module from a second quantum key distribution module; the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding basis sequence; the second quantum key distribution module is connected with the core network device.
[0221] In some embodiments, the method further includes: receiving a sampling set sent by the first quantum key distribution module, and sending the sampling set to the core network device; The sampling set is composed of a sampling result sequence and a sampling position sequence.
[0222] In some embodiments, the sampling result sequence is obtained by: The first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence, takes out corresponding binary values from the second group of binary strings according to the positions of all correct measurement bases contained in the measurement basis sequence, to form a first binary string subset, randomly samples the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained by the following method: The first quantum key distribution module assembles each binary value in the sampling result sequence into the sampling position sequence at the corresponding sampling position in the first binary string subset.
[0223] In some embodiments, before the receiving of the first AMF key sent by the first quantum key distribution module, the method further comprises: After receiving the security mode command message sent by the core network device, a first quantum key distribution request message is sent to the first quantum key distribution module, and the first quantum key distribution request message is used to request generation and return of an AMF key. The receiving of the first AMF key sent by the first quantum key distribution module comprises: The first quantum key distribution response message sent by the first quantum key distribution module is received, and the first quantum key distribution response message carries the first AMF key.
[0224] In some embodiments, before the receiving of the measurement basis sequence sent by the first quantum key distribution module, the method further comprises: Before the reply of the authentication response message to the core network device, a receiving quantum state request message is sent to the first quantum key distribution module, and the receiving quantum state request message is used to request entering of a quantum receiving state. The receiving quantum state response message sent by the first quantum key distribution module is received, and the receiving quantum state response message carries indication information used to indicate successful transition from a working state to a quantum receiving state.
[0225] In some embodiments, the first quantum key distribution module receives a quantum messenger sent by a second quantum key distribution module through a quantum channel.
[0226] In some embodiments, the measurement basis sequence and the sampling set are sent through an uplink direct transmission message, and the sampling result sequence is received through a downlink direct transmission message.
[0227] In some embodiments, the uplink direct transmission message is transmitted through an uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through a downlink NAS direct transmission link.
[0228] It should be noted that the terminal provided by the embodiments of the present application can realize all the method steps realized by the corresponding method embodiments described above, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments in the embodiments will not be described in detail.
[0229] Figure 10Figure 1 is a schematic diagram of a first quantum key distribution module structure provided by an embodiment of the present application, as shown in the figure, the first quantum key distribution module comprises a memory 1020, a transceiver 1010 and a processor 1000; wherein the processor 1000 and the memory 1020 can also be arranged physically separately. Figure 10
[0230] The memory 1020 is configured to store a computer program; and the transceiver 1010 is configured to transceive data under the control of the processor 1000.
[0231] In the above embodiment, the bus architecture can comprise any number of interconnected buses and bridges, which link together various circuits of one or more processors represented by the processor 1000 and the memory represented by the memory 1020. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus, the present application will not further describe them. The bus interface provides an interface. The transceiver 1010 can be a plurality of elements, i.e., comprising a transmitter and a receiver, which provide units for communicating with various other devices on transmission media, including wireless channels, wired channels, optical cables, etc. For different user equipment, the user interface 1030 can also be an interface capable of connecting to the required equipment, including but not limited to a keypad, a display, a speaker, a microphone, a joystick, etc. Figure 10
[0232] The processor 1000 is responsible for managing the bus architecture and general processing, and the memory 1020 can store data used by the processor 1000 when performing operations.
[0233] The processor 1000 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or a complex programmable logic device (CPLD), and the processor can also adopt a multi-core architecture.
[0234] The processor 1000, by invoking the computer program stored in the memory 1020, is configured to execute any of the AMF key generation methods provided by the embodiments of the present application according to the obtained executable instructions, comprising: receive a quantum messenger sent by a second quantum key distribution module, and measure the quantum messenger to obtain a measurement basis sequence and a second group of binary strings; the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding basis sequence; the second quantum key distribution module is connected with a core network device send the measurement basis sequence to the terminal; receive a measurement basis result sequence sent by the terminal; the measurement basis result sequence is used to indicate correct measurement bases contained in the measurement basis sequence; generate a first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings; send the first AMF key to the terminal.
[0235] In some embodiments, the generating the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings comprises: determine all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence; extract corresponding binary values from the second group of binary strings according to positions of all correct measurement bases contained in the measurement basis sequence to form a first binary string subset; randomly sample the first binary string subset to obtain a sampling result sequence; generate the first AMF key according to binary values in the first binary string subset except the sampling result sequence.
[0236] In some embodiments, after the randomly sampling the first binary string subset to obtain a sampling result sequence, the method further comprises: compose a sampling position sequence by each binary value in the sampling result sequence and a corresponding sampling position in the first binary string subset; compose a sampling set by the sampling result sequence and the sampling position sequence; send the sampling set to the terminal.
[0237] In some embodiments, before the generating the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings, the method further comprises: receive a first quantum key distribution request message sent by the terminal, the first quantum key distribution request message being used to request generation and return of an AMF key; after the generating the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings, the method further comprises: The first quantum key distribution response message is sent to the terminal, and the first quantum key distribution response message carries the first AMF key.
[0238] In some embodiments, before receiving the quantum messenger sent by the second quantum key distribution module, the method further comprises: The terminal sends a receiving quantum state request message, and the receiving quantum state request message is used to request entering a quantum receiving state. The terminal sends a receiving quantum state response message, and the receiving quantum state response message carries indication information used to indicate that the terminal successfully enters the quantum receiving state from the working state.
[0239] It should be noted that the first quantum key distribution module provided by the embodiments of the present application can realize all the method steps realized by the corresponding method embodiments and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0240] Figure 11 The core network device provided by the embodiments of the present application is shown in FIG. 1, which includes a memory 1120, a transceiver 1110 and a processor 1100. Figure 11 The processor 1100 and the memory 1120 can also be arranged physically separately.
[0241] The memory 1120 is used to store a computer program; and the transceiver 1110 is used to transceive data under the control of the processor 1100.
[0242] The bus architecture can include any number of interconnecting buses and bridges, and the various circuitry represented by the processor 1100 and the memory 1120 is linked together by the bus architecture. Figure 11 The bus architecture can also link various other circuitry, such as peripheral devices, voltage regulators, and power management circuitry, which are well known in the art, and therefore will not be described further. The bus interface provides an interface to the bus architecture. The transceiver 1110 can be multiple elements, i.e., including a transmitter and a receiver, which provide units for communicating with various other devices on transmission media, including wireless channels, wired channels, optical cables, and other transmission media.
[0243] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store data used by the processor 1100 when performing operations.
[0244] The processor 1100 can be a CPU, ASIC, FPGA or CPLD, and the processor can also adopt a multi-core architecture.
[0245] The processor 1100 invokes the computer program stored in the memory 1120 to execute the AMF key generation method provided by the embodiments of the present application according to the obtained executable instructions, including: receiving a measurement base sequence sent by a terminal, and sending the measurement base sequence to the second quantum key distribution module; receiving a measurement base result sequence sent by the second quantum key distribution module, and sending the measurement base result sequence to the terminal; the measurement base result sequence is used to indicate correct measurement bases contained in the measurement base sequence; receiving a sampling set sent by the terminal, and sending the sampling set to the second quantum key distribution module; the sampling set is composed of a sampling result sequence and a sampling position sequence; receiving a second AMF key sent by the second quantum key distribution module; the second AMF key is obtained based on the measurement base result sequence, the measurement base sequence, the sampling set, and a first group of binary strings; The measurement base sequence and a second group of binary strings are obtained by the first quantum key distribution module receiving a quantum messenger sent by the second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on the first group of binary strings and a randomly selected encoding base sequence; the first quantum key distribution module is connected with the terminal.
[0246] In some embodiments, before the receiving the second AMF key sent by the second quantum key distribution module, further comprising: after receiving the authentication response message replied by the terminal, sending a second quantum key distribution request message to the second quantum key distribution module, the second quantum key distribution request message being used to request generation and return of an AMF key; The receiving the second AMF key sent by the second quantum key distribution module comprises: receiving a second quantum key distribution response message sent by the second quantum key distribution module, the second quantum key distribution response message carrying the second AMF key.
[0247] In some embodiments, the sampling result sequence is obtained by: The first quantum key distribution module determines all correct measurement bases contained in the measurement base sequence according to the measurement base result sequence, takes out corresponding binary values from the second group of binary strings according to the positions of all correct measurement bases contained in the measurement base sequence, to form a first binary string subset, randomly samples the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained by the following way: The first quantum key distribution module assembles each binary value in the sampling result sequence into the sampling position sequence at the corresponding sampling position in the first binary string subset.
[0248] In some embodiments, the first quantum key distribution module receives the quantum messenger sent by the second quantum key distribution module through a quantum channel.
[0249] In some embodiments, the measurement basis sequence and the sampling set are received through an uplink direct transmission message, and the measurement basis result sequence is sent through a downlink direct transmission message.
[0250] In some embodiments, the uplink direct transmission message is transmitted through an uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through a downlink NAS direct transmission link.
[0251] It should be noted that the core network device provided by the embodiments of the present application can realize all the method steps realized by the corresponding method embodiments described above, and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0252] Figure 12 is a structure diagram of the second quantum key distribution module provided by the embodiments of the present application, as Figure 12 shown, the second quantum key distribution module includes a memory 1220, a transceiver 1210 and a processor 1200; wherein the processor 1200 and the memory 1220 can also be arranged physically separately.
[0253] The memory 1220 is used for storing a computer program; the transceiver 1210 is used for receiving and transmitting data under the control of the processor 1200.
[0254] Wherein, in Figure 12 , the bus architecture can include any number of interconnected buses and bridges, which are variously linked by the processor 1200 representing one or more processors and the memory 1220 representing the memory of various circuits. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators and power management circuits, which are well known in the art, and therefore, the present application will not further describe them. The bus interface provides an interface. The transceiver 1210 can be a plurality of elements, i.e. including a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, including wireless channels, wired channels, optical cables and other transmission media.
[0255] The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 can store data used by the processor 1200 when performing operations.
[0256] The processor 1200 can be a CPU, ASIC, FPGA or CPLD, and the processor can also adopt a multi-core architecture.
[0257] The processor 1200 calls the computer program stored in the memory 1220 to execute the AMF key generation method provided by the embodiments of the application according to the obtained executable instructions, including: Send a quantum messenger to a first quantum key distribution module, the quantum messenger is obtained based on a first set of binary strings and a randomly selected encoding basis sequence; the first quantum key distribution module is connected with a terminal; Receive the measurement basis sequence sent by the core network device, the measurement basis sequence is composed of a randomly selected measurement basis for measuring the quantum messenger; Send a measurement basis result sequence to the core network device, the measurement basis result sequence is used to indicate the correct measurement basis contained in the measurement basis sequence; Receive the sampling set sent by the core network device, the sampling set is composed of a sampling result sequence and a sampling position sequence; Generate a second AMF key based on the measurement basis result sequence, the measurement basis sequence, the sampling set and the first set of binary strings; Send the second AMF key to the core network device.
[0258] In some embodiments, the second AMF key is generated based on the measurement basis result sequence, the measurement basis sequence, the sampling set and the first set of binary strings, including: Determine all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence; According to the positions of all correct measurement bases contained in the measurement basis sequence, take out the corresponding binary values from the first set of binary strings to form a second binary string subset; According to the sampling positions contained in the sampling position sequence in the sampling set, take out the corresponding binary values from the second binary string subset to form a binary sequence; Generate the second AMF key according to the binary values in the second binary string subset except the binary sequence.
[0259] In some embodiments, before the second AMF key is generated according to the binary values in the second binary string subset except the binary sequence, it further includes: perform a consistency comparison between the sampling result sequence in the sampling set and the binary sequence, to obtain a consistency comparison result; In a case where the consistency comparison result is greater than a verification threshold, it is confirmed that the sampling set is verified.
[0260] In some embodiments, before the sending of the quantum messenger to the first quantum key distribution module, further comprising: receiving a second quantum key distribution request message sent by the core network device, the second quantum key distribution request message being used to request generation and return of an AMF key; after the generation of the second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings, comprising: sending a second quantum key distribution response message to the core network device, the second quantum key distribution response message carrying the second AMF key.
[0261] In some embodiments, after the receiving of the measurement base sequence sent by the core network device, further comprising: comparing the measurement base sequence with the encoding base sequence to obtain the measurement base result sequence.
[0262] It should be noted that the second quantum key distribution module provided by the embodiments of the present application can realize all the method steps realized by the corresponding method embodiments described above, and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0263] In some embodiments, a computer program product is further provided. The computer program product includes a computer program, the computer program being stored in a non-transitory readable storage medium, and the computer program being executable by a processor to enable the processor to execute the AMF key generation method provided by each of the embodiments.
[0264] Specifically, the computer program product provided by the embodiments of the present application can realize all the method steps realized by the method embodiments described above, and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0265] In some embodiments, a non-transitory readable storage medium is further provided. The non-transitory readable storage medium stores a computer program, and the computer program is used to enable a processor to execute the AMF key generation method provided by each of the method embodiments whose execution subject is a terminal, or the AMF key generation method provided by each of the method embodiments whose execution subject is a network side device.
[0266] The non-transitory readable storage medium provided by the embodiments of the present application can implement all the method steps of the method embodiments whose execution subject is the terminal or the method embodiments whose execution subject is the network side device, and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the embodiments of the present application as the method embodiments will not be repeated in detail.
[0267] In some embodiments, a computer readable storage medium is also provided, which stores a computer program for causing a processor to execute the AMF key generation method provided by the method embodiments whose execution subject is the terminal or the AMF key generation method provided by the method embodiments whose execution subject is the network side device.
[0268] The computer readable storage medium provided by the embodiments of the present application can implement all the method steps of the method embodiments whose execution subject is the terminal or the method embodiments whose execution subject is the network side device, and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the embodiments of the present application as the method embodiments will not be repeated in detail.
[0269] The computer readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to a magnetic memory (such as a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), an optical memory (such as a CD, a DVD, a BD, a HVD, etc.), and a semiconductor memory (such as a ROM, an EPROM, an EEPROM, a non-volatile memory (NAND FLASH), a solid state disk (SSD)), etc.
[0270] The technical solutions provided by the embodiments of the present application can be applied to various systems. For example, the applicable systems can be a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD) system, a long term evolution advanced (LTE-A) system, a universal mobile system (UMTS), a worldwide interoperability for microwave access (WiMAX) system, a 5G New Radio (NR) system and its evolution communication system, a 6G (sixth generation mobile communication technology) system, and the like. The various systems can include terminals and network devices. The system can also include a core network part, such as an evolved packet system (EPC), a 5G core network (5GC), a 6G core network (6GC), and the like.
[0271] The terminal referred to in embodiments of the present application can be a device providing voice and / or data connectivity to a user, a handheld device having wireless connection capability, or other processing device connected to a wireless modem, etc. In different systems, the name of the terminal can also be different, for example, in a 5G system, the terminal can be referred to as a user equipment (UE). The wireless terminal can communicate with one or more core networks (CN) via a radio access network (RAN), and the wireless terminal can be a mobile terminal, such as a mobile phone (or called "cellular" phone) and a computer with a mobile terminal, for example, a portable, pocket, handheld, computer built-in or vehicle mounted mobile device, which exchanges voice and / or data with a radio access network. For example, personal communication service (PCS) phones, cordless phones, session initiated protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs) and the like. The wireless terminal can also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, which is not limited in embodiments of the present application.
[0272] In some embodiments, a communication device is also provided, and the communication device stores a computer program, and the computer program is used to make the communication device perform the AMF key generation method provided by each method embodiment whose execution subject is a terminal, or the AMF key generation method provided by each method embodiment whose execution subject is a core network device.
[0273] The above communication device provided by embodiments of the present application can implement all the method steps achieved by each method embodiment whose execution subject is a terminal, or each method embodiment whose execution subject is a core network device, and can achieve the same technical effects, and here the same parts and beneficial effects of the method embodiments in the embodiments will not be described in detail.
[0274] In some embodiments, a chip product is also provided, wherein a computer program is stored in the chip product, and the computer program is used for enabling the chip product to perform the AMF key generation method provided by each method embodiment.
[0275] Specifically, the chip product provided by the embodiments of the present application can implement all the method steps achieved by the method embodiments, and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments are not described in detail here.
[0276] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage, etc.) containing computer-usable program code.
[0277] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer executable instructions. These computer executable instructions can be provided to a general purpose computer, a special purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that carries out the functions specified in one or more flows and / or blocks.
[0278] These processor executable instructions can also be stored in a processor readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the processor readable memory produce a manufactured product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that carries out the functions specified in one or more flows and / or blocks.
[0279] These processor executable instructions can also be loaded into a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1steps of the functions specified in the one or more blocks.
[0280] It will be apparent to those skilled in the art that various modifications and variations can be made to the present application without departing from the spirit or scope of the application. Thus, it is intended that the present application cover the modifications and variations of this application provided they come within the scope of the appended claims and their equivalents.
Claims
1. An AMF key generation method, characterized by, The application is applied to a terminal connected with a first quantum key distribution module, and the method comprises the following steps: receiving a measurement base sequence sent by the first quantum key distribution module, and sending the measurement base sequence to a core network device; receiving a measurement base result sequence sent by the core network device, and sending the measurement base result sequence to the first quantum key distribution module; the measurement base result sequence is used for indicating correct measurement bases contained in the measurement base sequence; receiving a first AMF key sent by the first quantum key distribution module; the first AMF key is generated based on the measurement base result sequence, the measurement base sequence and a second group of binary strings; wherein the measurement base sequence and the second group of binary strings are obtained by measuring a quantum messenger sent by a second quantum key distribution module and received by the first quantum key distribution module; the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding base sequence; the second quantum key distribution module is connected with the core network device.
2. The AMF key generation method of claim 1, wherein, The method further comprises the following steps: receiving a sampling set sent by the first quantum key distribution module, and sending the sampling set to the core network device; wherein the sampling set is composed of a sampling result sequence and a sampling position sequence.
3. The AMF key generation method of claim 2, wherein, The sampling result sequence is obtained by the following way: the first quantum key distribution module determines all correct measurement bases contained in the measurement base sequence according to the measurement base result sequence, takes corresponding binary values from the second group of binary strings according to positions of the all correct measurement bases contained in the measurement base sequence, composes a first binary string subset, randomly samples the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained by the following way: the first quantum key distribution module composes the sampling position sequence by taking each binary value in the sampling result sequence to corresponding sampling positions in the first binary string subset.
4. The AMF key generation method of claim 1, wherein, Before the step of receiving the first AMF key sent by the first quantum key distribution module, the method further comprises the following steps: after receiving a security mode command message sent by the core network device, sending a first quantum key distribution request message to the first quantum key distribution module, the first quantum key distribution request message being used for requesting to generate and return an AMF key; the step of receiving the first AMF key sent by the first quantum key distribution module comprises the following steps: receiving a first quantum key distribution response message sent by the first quantum key distribution module, the first quantum key distribution response message carrying the first AMF key.
5. The AMF key generation method of claim 1, wherein, Before the step of receiving the measurement base sequence sent by the first quantum key distribution module, the method further comprises the following steps: before replying an authentication response message to the core network device, sending a receive quantum state request message to the first quantum key distribution module, the receive quantum state request message being used for requesting to enter a quantum receiving state; Receiving a receiving quantum state response message sent by the first quantum key distribution module, the receiving quantum state response message carrying indication information indicating that the first quantum key distribution module successfully enters a quantum receiving state from a working state.
6. The AMF key generation method of claim 1, wherein, The first quantum key distribution module receives a quantum messenger sent by a second quantum key distribution module through a quantum channel.
7. The AMF key generation method of claim 2, wherein, The measurement basis sequence and the sampling set are sent through an uplink direct transmission message, and the measurement basis result sequence is received through a downlink direct transmission message.
8. The AMF key generation method of claim 7, wherein, The uplink direct transmission message is transmitted through an uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through a downlink NAS direct transmission link.
9. An AMF key generation method, characterized by, The method is applied to a first quantum key distribution module connected with a terminal, and includes the following steps: Receiving a quantum messenger sent by a second quantum key distribution module and measuring the quantum messenger to obtain a measurement basis sequence and a second group of binary strings; the quantum messenger is obtained based on a first group of binary strings and a randomly selected encoding basis sequence; the second quantum key distribution module is connected with a core network device Sending the measurement basis sequence to the terminal; Receiving a measurement basis result sequence sent by the terminal; the measurement basis result sequence is used to indicate correct measurement bases contained in the measurement basis sequence; Generating a first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings; Sending the first AMF key to the terminal.
10. The AMF key generation method of claim 9, wherein, The generating of the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings includes the following steps: Determining all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence; Taking out corresponding binary values from the second group of binary strings according to positions of all correct measurement bases contained in the measurement basis sequence to form a first binary string subset; Randomly sampling the first binary string subset to obtain a sampling result sequence; Generating the first AMF key according to binary values in the first binary string subset except the sampling result sequence.
11. The AMF key generation method of claim 10, wherein, After the randomly sampling of the first binary string subset to obtain the sampling result sequence, the method further includes the following steps: Forming a sampling position sequence by arranging each binary value in the sampling result sequence in a corresponding sampling position in the first binary string subset; Forming a sampling set by combining the sampling result sequence and the sampling position sequence; Sending the sampling set to the terminal.
12. The AMF key generation method of claim 10, wherein, Before the generating of the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings, the method further includes the following step: Receiving a first quantum key distribution request message sent by the terminal, the first quantum key distribution request message being used to request the generation and return of an AMF key; After the generating of the first AMF key based on the measurement basis result sequence, the measurement basis sequence, and the second group of binary strings, the method further includes the following step: Sending a first quantum key distribution response message to the terminal, the first quantum key distribution response message carrying the first AMF key.
13. The AMF key generation method of claim 10, wherein, Before receiving the quantum messenger sent by the second quantum key distribution module, further comprising: Receiving a receiving quantum state request message sent by the terminal, the receiving quantum state request message being used for requesting entering a quantum receiving state; Sending a receiving quantum state response message to the terminal, the receiving quantum state response message carrying indication information used for indicating successfully switching from a working state to a quantum receiving state.
14. An AMF key generation method, comprising: Applied to a core network device, the core network device being connected with a second quantum key distribution module, the method comprising: Receiving a measurement basis sequence sent by a terminal, and sending the measurement basis sequence to the second quantum key distribution module; Receiving a measurement basis result sequence sent by the second quantum key distribution module, and sending the measurement basis result sequence to the terminal; the measurement basis result sequence being used for indicating correct measurement bases contained in the measurement basis sequence; Receiving a sampling set sent by the terminal, and sending the sampling set to the second quantum key distribution module; the sampling set being composed of a sampling result sequence and a sampling position sequence; Receiving a second AMF key sent by the second quantum key distribution module; the second AMF key being obtained based on the measurement basis result sequence, the measurement basis sequence, the sampling set and a first group of binary strings; The measurement basis sequence and a second group of binary strings are obtained by a first quantum key distribution module receiving a quantum messenger sent by the second quantum key distribution module and measuring the quantum messenger; the quantum messenger is obtained based on the first group of binary strings and a randomly selected encoding basis sequence; the first quantum key distribution module is connected with the terminal.
15. The AMF key generation method of claim 14, wherein, Before the receiving the second AMF key sent by the second quantum key distribution module, further comprising: After receiving an authentication response message replied by the terminal, sending a second quantum key distribution request message to the second quantum key distribution module, the second quantum key distribution request message being used for requesting generating and returning an AMF key; Receiving the second AMF key sent by the second quantum key distribution module, comprising: Receiving a second quantum key distribution response message sent by the second quantum key distribution module, the second quantum key distribution response message carrying the second AMF key.
16. The AMF key generation method of claim 14, wherein, The sampling result sequence is obtained by the following way: The first quantum key distribution module determines all correct measurement bases contained in the measurement basis sequence according to the measurement basis result sequence, takes corresponding binary values from the second group of binary strings according to positions of all correct measurement bases contained in the measurement basis sequence, composes a first binary string subset, randomly samples the first binary string subset, and obtains the sampling result sequence; The sampling position sequence is obtained by the following way: The first quantum key distribution module composes the sampling position sequence by taking each binary value in the sampling result sequence to a corresponding sampling position in the first binary string subset.
17. The AMF key generation method of claim 14, wherein, The first quantum key distribution module receives the quantum messenger sent by the second quantum key distribution module through a quantum channel.
18. The AMF key generation method of claim 14, wherein, The measurement base sequence and the sampling set are received through an uplink direct transmission message, and the measurement base result sequence is sent through a downlink direct transmission message.
19. The AMF key generation method of claim 18, wherein, The uplink direct transmission message is transmitted through an uplink NAS direct transmission link, and the downlink direct transmission message is transmitted through a downlink NAS direct transmission link.
20. An AMF key generation method, comprising: The method is applied to a second quantum key distribution module connected with a core network device, and includes: sending a quantum messenger to a first quantum key distribution module, the quantum messenger being obtained based on a first group of binary strings and a randomly selected encoding base sequence; the first quantum key distribution module is connected with a terminal; receiving a measurement base sequence sent by the core network device, the measurement base sequence being composed of randomly selected measurement bases for measuring the quantum messenger; sending a measurement base result sequence to the core network device, the measurement base result sequence being used to indicate correct measurement bases contained in the measurement base sequence; receiving a sampling set sent by the core network device, the sampling set being composed of a sampling result sequence and a sampling position sequence; generating a second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings; sending the second AMF key to the core network device.
21. The AMF key generation method of claim 20, wherein, The generating of the second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings includes: determining all correct measurement bases contained in the measurement base sequence according to the measurement base result sequence; taking out corresponding binary values from the first group of binary strings according to positions of all correct measurement bases contained in the measurement base sequence to form a second binary string subset; taking out corresponding binary values from the second binary string subset according to sampling positions contained in the sampling position sequence of the sampling set to form a binary sequence; generating the second AMF key according to binary values in the second binary string subset except the binary sequence.
22. The AMF key generation method of claim 21, wherein, Before the generating of the second AMF key according to binary values in the second binary string subset except the binary sequence, the method further includes: performing consistency comparison between the sampling result sequence of the sampling set and the binary sequence to obtain a consistency comparison result; in a case where the consistency comparison result is greater than a verification threshold, confirming that the sampling set is verified.
23. The AMF key generation method of claim 20, wherein, Before the sending of the quantum messenger to the first quantum key distribution module, the method further includes: receiving a second quantum key distribution request message sent by the core network device, the second quantum key distribution request message being used to request generation and return of an AMF key; after the generating of the second AMF key based on the measurement base result sequence, the measurement base sequence, the sampling set and the first group of binary strings, the method includes: sending a second quantum key distribution response message to the core network device, the second quantum key distribution response message carrying the second AMF key.
24. The AMF key generation method of claim 20, wherein, After the receiving of the measurement base sequence sent by the core network device, the method further includes: Comparing the measurement base sequence with the encoding base sequence, obtaining the measurement base result sequence.
25. A terminal, characterized by comprising a memory, a transceiver, a processor; a memory for storing computer programs; a transceiver for transceiving data under the control of the processor; a processor for reading the computer programs in the memory and executing the AMF key generation method of any one of claims 1-8.
26. A first quantum key distribution module, comprising: comprising a memory, a transceiver, a processor; a memory for storing computer programs; a transceiver for transceiving data under the control of the processor; a processor for reading the computer programs in the memory and executing the AMF key generation method of any one of claims 9-13.
27. A core network device, comprising: comprising a memory, a transceiver, a processor; a memory for storing computer programs; a transceiver for transceiving data under the control of the processor; a processor for reading the computer programs in the memory and executing the AMF key generation method of any one of claims 14-19.
28. A second quantum key distribution module, comprising: comprising a memory, a transceiver, a processor; a memory for storing computer programs; a transceiver for transceiving data under the control of the processor; a processor for reading the computer programs in the memory and executing the AMF key generation method of any one of claims 20-24.
29. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a program for causing the processor to execute the AMF key generation method of any one of claims 1-8, or any one of claims 9-13, or any one of claims 14-19, or any one of claims 20-24.