Cloud mobile phone encryption communication method and device, equipment, storage medium and program product

By introducing quantum cryptography technology into cloud phone services and using quantum session keys for multi-layer encryption and decryption, the security issues of traditional encryption schemes in the face of quantum computer attacks are solved, thereby improving the security and reliability of cloud phone communication.

CN121508883APending Publication Date: 2026-02-10CHINA MOBILE INTERNET CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511198519.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing cloud phone encryption solutions rely on traditional cryptographic techniques, which cannot provide theoretically unconditional security against attacks from quantum computers and are at risk of being cracked.

Method used

By introducing quantum cryptography technology, quantum session keys are generated and managed through a quantum security service platform. The quantum cryptography service platform is then used to perform multi-layered encryption and decryption operations to ensure the security of data transmission between the cloud mobile client and the server.

Benefits of technology

This effectively reduces the risk of cloud phone services being cracked and improves the security and reliability between the client and the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508883A_ABST
    Figure CN121508883A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud mobile phone encryption communication method, device and equipment, a storage medium and a program product. The method comprises the following steps: sending first information carrying first encryption data to a cloud mobile phone client through a signaling server; the first encrypted data is obtained by encrypting session connection proposal data based on the first quantum session key and the second quantum session key; sending second information carrying second encrypted data to the cloud mobile phone server through the signaling server; the second encrypted data is obtained by encrypting session connection response data based on the first quantum session key and the second quantum session key; the encrypted session connection response data is obtained through media negotiation based on the session connection proposal data; according to the first quantum session key and the second quantum session key, decrypting the second encrypted data, obtaining session connection response data, and completing connection preparation; according to the invention, the quantum password is introduced in the service communication process of the cloud mobile phone, so that the security and reliability between the client / server of the cloud mobile phone are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a cloud phone encrypted communication method, apparatus, device, storage medium, and program product. Background Technology

[0002] Currently, cloud phone products generally use a signaling server based on the WebSocket protocol to transmit ICECandidate (Interactive Connectivity Establishment Candidate) and RTC Session Description (Real-Time Communication Session Description).

[0003] Existing cloud phone encryption solutions primarily rely on traditional cryptographic techniques such as HTTPS, DTLS (Datagram Transport Layer Security), and AES (Advanced Encryption Standard). While these traditional encryption methods are considered secure in the current environment, with the continuous improvement of computing power, especially the development of quantum computers, these methods cannot provide theoretically unconditionally secure communication guarantees. They may be vulnerable to complex attacks such as advanced persistent threats and are at risk of being cracked in the future. Summary of the Invention

[0004] To address the problems existing in the prior art, embodiments of the present invention provide a cloud phone encrypted communication method, apparatus, device, storage medium, and program product, which can effectively improve the security and reliability between the cloud phone client and the server.

[0005] In a first aspect, embodiments of the present invention provide a cloud phone encrypted communication method, which applies a cloud phone server and includes:

[0006] The first information is sent to the cloud mobile client through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0007] The system receives second information sent by the cloud mobile client through the signaling server; wherein the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on a third quantum session key and a second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0008] Based on the third quantum session key and the second quantum session key, the second encrypted data is decrypted to obtain session connection response data, thereby completing the connection preparation.

[0009] As an improvement to the above solution, the step of sending the first information to the cloud mobile client via the signaling server includes:

[0010] The quantum security service platform requests the first quantum session key and the first quantum identity identifier.

[0011] Based on the first quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection proposal data, thereby obtaining encrypted session connection proposal data;

[0012] Request the fourth quantum session key and the fourth quantum identity identifier from the quantum security service platform;

[0013] Based on the fourth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data packet;

[0014] The third information carrying the first encrypted data packet and the fourth quantum identity is sent to the signaling server, so that the signaling server decrypts the first encrypted data packet to obtain session connection proposal data, encrypts the session connection proposal data based on the first quantum session key and the second quantum session key to obtain first encrypted data, and sends the first information carrying the first encrypted data and the second quantum identity to the cloud mobile client.

[0015] As an improvement to the above scheme, the process of encrypting session connection proposal data based on the first quantum session key and the second quantum session key includes:

[0016] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0017] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data;

[0018] The first information includes the first encrypted data and the second quantum identity identifier.

[0019] As an improvement to the above scheme, the second information also includes a second quantum identity identifier;

[0020] The step of decrypting the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data, thereby completing the connection preparation, includes:

[0021] The quantum security service platform requests the second quantum session key indicated by the second quantum identity in the second information;

[0022] Based on the second quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data, thereby obtaining the third quantum identity and encrypted session connection response data;

[0023] Request the third quantum session key indicated by the third quantum encryption identifier from the quantum security service platform;

[0024] Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the decrypted session connection response data;

[0025] The connection preparation is completed based on the session description response in the session connection response data.

[0026] As an improvement to the above solution, the method further includes:

[0027] After establishing a P2P connection, the first encryption algorithm is used to encrypt the data according to the first quantum session key.

[0028] Based on the fourth quantum session key, the encrypted first encryption algorithm and the first quantum identity corresponding to the first quantum session key are encrypted to obtain the final first encryption algorithm data.

[0029] The first encryption algorithm data is sent to the cloud mobile client, so that the cloud mobile client can decrypt the first encryption algorithm data to obtain the first encryption algorithm and the first quantum session key, and then perform the following SRTP encryption authentication operation:

[0030] Using the first quantum session key as the master key, derive the first session encryption key and the first authentication key;

[0031] SRTP data is encrypted and authenticated based on the first session encryption key and the first authentication key.

[0032] As an improvement to the above solution, the method further includes:

[0033] Based on the fourth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the first quantum session key are encrypted and transmitted.

[0034] As an improvement to the above solution, the method further includes:

[0035] The quantum secure channel periodically requests the quantum security service platform to update the first quantum session key and the first quantum identity identifier corresponding to the first quantum session key.

[0036] Secondly, embodiments of the present invention provide a cloud phone encrypted communication method, applied to a cloud phone client, comprising:

[0037] The cloud phone server receives first information sent through a signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0038] Based on the first quantum session key and the second quantum session key, the first encrypted data is decrypted to obtain session connection proposal data;

[0039] Based on the session connection proposal data, media negotiation is performed to obtain the session connection response data;

[0040] The signaling server sends a second message to the cloud phone server; wherein the second message includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on a third quantum session key and a second quantum session key; the second message is used to instruct the cloud phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

[0041] As an improvement to the above scheme, the step of decrypting the first encrypted data based on the first quantum session key and the second quantum session key to obtain session connection proposal data includes:

[0042] Based on the locally pre-set fifth quantum identity, the quantum security service platform requests the second quantum session key corresponding to the second quantum identity carried in the first information;

[0043] Based on the second quantum session key, the first encrypted data in the first information is decrypted to obtain the first quantum identity and encrypted session connection proposal data;

[0044] Based on the locally pre-set fifth quantum identity, request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0045] Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

[0046] As an improvement to the above solution, the step of sending the second information to the cloud mobile phone server through the signaling server includes:

[0047] Based on the locally pre-configured fifth quantum identity, request the third quantum identity and third quantum session key from the quantum security service platform;

[0048] Based on the third quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection response data, thereby obtaining encrypted session connection response data;

[0049] Based on the locally pre-set fifth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain a second encrypted data packet;

[0050] The fourth information carrying the second encrypted data packet and the fifth quantum identity is sent to the signaling server, so that the signaling server decrypts the second encrypted data packet to obtain session connection response data, encrypts the session connection response data based on the third quantum session key and the second quantum session key to obtain second encrypted data, and sends the second information carrying the second encrypted data and the second quantum identity to the cloud mobile phone server.

[0051] As an improvement to the above scheme, the process of encrypting session connection response data based on the third quantum session key and the second quantum session key includes:

[0052] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0053] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0054] The second information includes the second encrypted data and the second quantum identity identifier.

[0055] As an improvement to the above solution, the method further includes:

[0056] After establishing a P2P connection, the second encryption algorithm is encrypted using the third quantum session key.

[0057] Based on the fifth quantum session key, the encrypted second encryption algorithm and the third quantum identity corresponding to the third quantum session key are encrypted to obtain the final second encryption algorithm data;

[0058] The second encryption algorithm data is sent to the cloud phone server, so that the cloud phone server can decrypt the second encryption algorithm data to obtain the second encryption algorithm and the third quantum session key, and then perform the following SRTP encryption authentication operation:

[0059] The third quantum session key is used as the master key to derive a second session encryption key and a second authentication key;

[0060] SRTP data is encrypted and authenticated based on the second session encryption key and the second authentication key.

[0061] As an improvement to the above solution, the method further includes:

[0062] Based on the fifth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the third quantum session key are encrypted and transmitted.

[0063] As an improvement to the above solution, the method further includes:

[0064] The third quantum session key and the corresponding third quantum identity identifier are periodically requested from the quantum security service platform through a quantum secure channel.

[0065] Thirdly, embodiments of the present invention provide a cloud phone encrypted communication method, applied to a signaling server, comprising:

[0066] The session connection proposal data of the cloud phone server is encrypted using the first quantum session key and the second quantum session key to obtain the first encrypted data;

[0067] Send a first message to the cloud mobile client; wherein the first message includes the first encrypted data;

[0068] The session connection response data of the cloud mobile client is encrypted using the third quantum session key and the second quantum session key to obtain second encrypted data; wherein, the encrypted session connection response data is obtained through media negotiation based on the session connection proposal data;

[0069] Send a second message to the cloud phone server; wherein the second message includes second encrypted data, so that the cloud phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key, obtain session connection response data, and complete the connection preparation.

[0070] As an improvement to the above solution, the method further includes:

[0071] Receive third information sent by the cloud mobile phone server; wherein, the third information includes a first encrypted data packet and a fourth quantum identity identifier;

[0072] The quantum security service platform requests the fourth quantum session key corresponding to the fourth quantum identity.

[0073] Based on the fourth quantum session key, the quantum cryptography service platform is invoked to decrypt the first encrypted data packet, thereby obtaining the first quantum identity and encrypted session connection proposal data;

[0074] Request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0075] Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

[0076] As an improvement to the above scheme, the step of encrypting the session connection proposal data of the cloud phone server based on the first quantum session key and the second quantum session key to obtain the first encrypted data includes:

[0077] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0078] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data;

[0079] The first information includes the first encrypted data and the second quantum identity identifier.

[0080] As an improvement to the above scheme, the step of encrypting the session connection response data of the cloud mobile client based on the third quantum session key and the second quantum session key to obtain the second encrypted data includes:

[0081] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0082] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0083] The second information includes the second encrypted data and the second quantum identity identifier.

[0084] As an improvement to the above solution, the method further includes:

[0085] The system receives a fourth message sent by the cloud mobile client; wherein the fourth message includes a second encrypted data packet and a fifth quantum identity identifier.

[0086] The quantum security service platform requests the fifth quantum session key corresponding to the fifth quantum identity.

[0087] Based on the fifth quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data packet, thereby obtaining the third quantum identity identifier and encrypted session connection response data;

[0088] Request the third quantum session key corresponding to the third quantum identity from the quantum security service platform;

[0089] Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the session connection response data.

[0090] Fourthly, embodiments of the present invention provide a cloud phone encrypted communication device, which applies a cloud phone server, including:

[0091] The first information sending module is used to send first information to the cloud mobile client through a signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0092] The first information receiving module is used to receive second information sent by the cloud mobile client through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0093] The response data acquisition module is used to decrypt the second encrypted data according to the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

[0094] Fifthly, embodiments of the present invention provide a cloud phone encrypted communication method, applied to a cloud phone client, comprising:

[0095] The second information receiving module is used to receive first information sent by the cloud mobile phone server through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0096] The first decryption module is used to decrypt the first encrypted data based on the first quantum session key and the second quantum session key to obtain session connection proposal data;

[0097] The media negotiation module is used to perform media negotiation based on the session connection proposal data to obtain session connection response data;

[0098] The second information sending module is used to send second information to the cloud mobile phone server through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the second information is used to instruct the cloud mobile phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

[0099] Sixthly, embodiments of the present invention provide a cloud phone encrypted communication method, applied to a signaling server, comprising:

[0100] The first encryption module is used to encrypt the session connection proposal data of the cloud phone server according to the first quantum session key and the second quantum session key to obtain the first encrypted data;

[0101] The third information sending module is used to send first information to the cloud mobile client; wherein, the first information includes the first encrypted data;

[0102] The second encryption module is used to encrypt the session connection response data of the cloud mobile client according to the third quantum session key and the second quantum session key to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0103] The fourth information sending module is used to send second information to the cloud phone server; wherein the second information includes second encrypted data, so that the cloud phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data to complete the connection preparation.

[0104] In a seventh aspect, embodiments of the present invention provide a cloud phone encrypted communication device, comprising: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the cloud phone encrypted communication method as described in any of the first aspects, or the cloud phone encrypted communication method as described in any of the second aspects, or the cloud phone encrypted communication method as described in any of the third aspects.

[0105] Eighthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the cloud phone encrypted communication method as described in any one of the first aspects, or the cloud phone encrypted communication method as described in any one of the second aspects, or the cloud phone encrypted communication method as described in any one of the third aspects.

[0106] Ninthly, embodiments of the present invention provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the cloud phone encrypted communication method as described in any of the first aspects, the second aspects, or the third aspects.

[0107] Compared to existing technologies, this invention provides a cloud phone encrypted communication method, apparatus, device, storage medium, and program product. The cloud phone server sends first information to the cloud phone client via a signaling server; wherein the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key. The cloud phone client sends second information to the cloud phone server via the signaling server; wherein the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on a first quantum session key and a second quantum session key; the encrypted session connection response data is obtained through media negotiation based on the session connection proposal data. Then, the cloud phone server decrypts the second encrypted data according to the first quantum session key and the second quantum session key to obtain the session connection response data, thus completing the connection preparation. This invention introduces quantum cryptography into the cloud phone business communication process, which can effectively reduce the risk of future cracking and improve the security and reliability between the cloud phone client and the server. Attached Figure Description

[0108] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0109] Figure 1 This is a schematic diagram of the communication framework for cloud mobile phone services that incorporate quantum cryptography technology, provided in an embodiment of the present invention.

[0110] Figure 2 This is the first flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention;

[0111] Figure 3 This is a flowchart of quantum-encrypted communication between a cloud mobile client and a cloud mobile server provided in an embodiment of the present invention;

[0112] Figure 4 This is the second flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention;

[0113] Figure 5 This is the third flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention;

[0114] Figure 6 This is the first structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention;

[0115] Figure 7This is a second structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention;

[0116] Figure 8 This is the third structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention;

[0117] Figure 9 This is a structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention. Detailed Implementation

[0118] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0119] It is understood that the various numerical designations used in the embodiments of this invention are merely for descriptive convenience and are not intended to limit the scope of this application. The order of the process numbers does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.

[0120] In embodiments of the invention, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, without necessarily requiring or implying any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The terms "multiple or several" refer to two or more, and the same applies to "multiple / items or several kinds / items." "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.

[0121] This invention introduces a quantum cryptography resource pool into the cloud phone business communication process. By using the quantum session key provided by the quantum security service platform of the quantum cryptography resource pool and the encryption and decryption operations based on the quantum session key provided by the cryptography service platform, the confidentiality of data transmitted between the cloud phone server and client is ensured, which can effectively reduce the risk of future cracking and improve the security and reliability between the cloud phone client and server.

[0122] For example, this invention proposes a communication framework for cloud mobile phone services that incorporates quantum cryptography technology; such as... Figure 1 As shown, the communication framework of this cloud phone service includes:

[0123] The quantum security service platform is primarily responsible for generating and managing quantum session keys, providing various levels of quantum identification (QID, also known as quantum key identifier) ​​and quantum session keys (QSK, including level-two and level-three quantum session keys) for the communication process. The quantum security service platform is the core security component of the entire system, ensuring that the keys used during communication have quantum-level security. Specifically, a level-two quantum session key corresponds to a level-two quantum identification, and a level-three quantum session key corresponds to a level-three quantum identification.

[0124] Cryptographic Service Platform: Primarily responsible for providing encryption and decryption services, using quantum session keys provided by the quantum security service platform to encrypt and decrypt data. The cryptographic service platform acts as a bridge connecting quantum security and traditional encryption systems, ensuring the confidentiality of data during transmission.

[0125] The cloud phone client is the terminal for users to access cloud phone services. The cloud phone client is responsible for interacting with the STUN (Session Traversal Utilities for NAT) server to obtain ICE candidates (also known as ICE candidate addresses or network candidate addresses), establishing PeerConnections (peer-to-peer connections, also known as point-to-point connections or P2P connections), creating answers, and using quantum encryption to securely communicate with the server and signaling server. The cloud phone client also handles local encryption and decryption operations to ensure end-to-end communication security.

[0126] The cloud phone server is the core component providing cloud phone services. It is responsible for initializing the connection process, including interacting with the STUN server, creating offers, and protecting communication data using quantum encryption. The cloud phone server also manages cloud phone resources, handles connection requests from cloud phone clients, and participates in the SRTP (Secure Real-time Transport Protocol) quantumization process to ensure secure transmission of audio and video streams.

[0127] Signaling server: Implements the transmission of ICE Candidate and RTC SessionDescription based on the WebSocket protocol, including offer or answer and SDP (Session Description Protocol); among them, the WebSocket connection is encrypted through standard HTTPS to ensure the security of signaling data.

[0128] By introducing quantum keys between the cloud phone client and server within the aforementioned communication framework, the entire process from signaling exchange to P2P connection establishment and SRTP communication can be quantumized, enhancing the security and resistance to quantum computing attacks of the cloud phone service. Based on this communication framework, this invention proposes a cloud phone encrypted communication method incorporating quantum keys, which will be described in detail below with reference to the accompanying drawings.

[0129] Please see Figure 2 , Figure 2 This is the first flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention. The cloud phone encrypted communication method, using a cloud phone server, includes:

[0130] S11: Send first information to the cloud mobile client through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on the first quantum session key and the second quantum session key;

[0131] Specifically, sending the first information to the cloud mobile client via the signaling server includes:

[0132] The quantum security service platform requests the first quantum session key and the first quantum identity identifier.

[0133] Based on the first quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection proposal data, thereby obtaining encrypted session connection proposal data;

[0134] Request the fourth quantum session key and the fourth quantum identity identifier from the quantum security service platform;

[0135] Based on the fourth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data packet;

[0136] The third information carrying the first encrypted data packet and the fourth quantum identity is sent to the signaling server, so that the signaling server decrypts the first encrypted data packet to obtain session connection proposal data, encrypts the session connection proposal data based on the first quantum session key and the second quantum session key to obtain first encrypted data, and sends the first information carrying the first encrypted data and the second quantum identity to the cloud mobile client.

[0137] For example, taking the quantumized process of signaling exchange as an example, the interaction process of each component is described in detail, and the specific process is as follows:

[0138] The cloud phone server initiates the first request to the STUN server to continuously obtain ICE candidates from the cloud phone server, and completes the construction of peerConnection locally, creates session description proposal offer, prepares quantum encryption and sends it to the signaling server.

[0139] The cloud phone server requests a Level 3 quantum session key (QSK) and quantum identity identifier (QID) from the quantum security service platform (i.e., the aforementioned first quantum session key and first quantum identity identifier). Using the Level 3 quantum session key (QSK) returned by the quantum security service platform, it calls the cryptographic service platform to encrypt the room ID, ICE candidates, and session description offer, obtaining encrypted session connection proposal data. Then, it requests a Level 2 quantum session key (QSK) and quantum identity identifier (QID) from the quantum security service platform (i.e., the aforementioned fourth quantum session key and fourth quantum identity identifier). Using the Level 2 quantum session key (QSK) returned by the quantum security service platform, it calls the cryptographic service platform to fully encrypt the encrypted session connection proposal data and the Level 3 quantum identity identifier (QID), obtaining a first encrypted data packet. This third information, carrying the first encrypted data packet and the Level 2 quantum identity identifier (QID) (i.e., the fourth quantum identity identifier), is pushed to the signaling server.

[0140] In this embodiment of the invention, a three-level and a two-level quantum session key (QSK) is introduced during the instruction data interaction between the cloud mobile phone server and the signaling server. This QSK performs multi-layer quantum encryption on instruction data such as room ID, ICE candidates, and session description offer, which can effectively improve the security of instruction data transmission.

[0141] Furthermore, after receiving the first encrypted data packet, the signaling server needs to decrypt it. The specific process is as follows:

[0142] The signaling server requests the fourth quantum session key corresponding to the fourth quantum identity carried in the third information from the quantum security service platform;

[0143] The signaling server, based on the fourth quantum session key, calls the quantum cryptography service platform to decrypt the first encrypted data packet, obtaining the first quantum identity and encrypted session connection proposal data;

[0144] The signaling server requests the third quantum session key corresponding to the third quantum identity obtained after decryption from the quantum security service platform;

[0145] The signaling server, based on the third quantum session key, invokes the quantum cryptography service platform to decrypt the encrypted session connection proposal data, thereby obtaining the session connection proposal data.

[0146] For example, after receiving the first encrypted data packet and the second-level quantum identity QID (i.e., the fourth quantum identity) sent by the cloud mobile phone server, the signaling server goes to the quantum security service platform to obtain the corresponding second-level quantum session key QSK (i.e., the fourth quantum session key) based on the second-level quantum identity QID (i.e., the fourth quantum identity) sent by the cloud mobile phone server. Then, it uses the second-level quantum session key QSK (i.e., the fourth quantum session key) returned by the quantum security service platform to call the cryptographic service platform to decrypt the first encrypted data packet, thereby obtaining the third-level quantum identity QID (i.e., the first quantum identity) and the encrypted session connection proposal data. Using the decrypted Level 3 Quantum Identity (QID, i.e., the first Quantum Identity), the user retrieves the corresponding Level 3 Quantum Session Key (QSK, i.e., the first Quantum Session Key) from the quantum security service platform. Based on the QSK returned by the quantum security service platform, the user then calls the cryptographic service platform to decrypt the encrypted session connection proposal data, obtaining the room ID, ICE candidates, and session description offer provided by the cloud phone server. Finally, the user creates the corresponding room based on the cloud phone server's settings and awaits connection from the cloud phone client.

[0147] Users of the cloud phone client can connect to the cloud phone management platform by clicking the corresponding application icon, obtain the cloud phone corresponding to their user permissions, associate it with the corresponding room ID, and then the cloud phone client initiates a connection to the signaling server.

[0148] When the signaling server discovers a new connection in an established room, it triggers an event to forward the Level 3 Quantum Identity (QID) and data provided by the cloud phone server (including roomID, ICE candidates, and offer). Specifically, the signaling server encrypts the session connection proposal data based on the first and second quantum session keys. The specific process includes:

[0149] The signaling server requests the second quantum session key and the second quantum identity from the quantum security service platform;

[0150] The signaling server, based on the second quantum session key, calls the quantum cryptography service platform to encrypt the encrypted session connection proposal data and the first quantum identity to obtain the first encrypted data;

[0151] The first information includes the first encrypted data and the second quantum identity identifier.

[0152] For example, the signaling server requests a secondary quantum identity QID and a quantum session key QSK (i.e., the aforementioned second quantum session key and second quantum identity) from the quantum security service platform. Using the secondary quantum session key QSK (i.e., the aforementioned second quantum session key), the server calls the cryptographic service platform to fully encrypt the encrypted session connection proposal data and the tertiary quantum identity QID (i.e., the aforementioned first quantum identity) to obtain the first encrypted data. The server then forwards the first information carrying the first encrypted data and the secondary quantum identity QID (i.e., the aforementioned second quantum identity) to the cloud mobile client.

[0153] In this embodiment of the invention, a three-level and a two-level quantum session key (QSK) is introduced during the instruction data interaction between the cloud mobile client and the signaling server. This QSK performs multi-layer quantum encryption on instruction data such as room ID, ICE candidates, and session description offer, which can effectively improve the security of instruction data transmission.

[0154] S12: Receive the second information sent by the cloud mobile client through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0155] In this embodiment of the invention, after receiving the first encrypted data and the second-level quantum identity identifier (QID) forwarded by the signaling service, the cloud mobile client performs the following decryption and media negotiation operations, the specific process of which is as follows:

[0156] Based on the locally pre-set fifth quantum identity, the quantum security service platform requests the second quantum session key corresponding to the second quantum identity carried in the first information;

[0157] Based on the second quantum session key, the first encrypted data in the first information is decrypted to obtain the first quantum identity and encrypted session connection proposal data;

[0158] Based on the locally pre-set fifth quantum identity, request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0159] Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data;

[0160] The session connection response data is obtained by media negotiation based on the session connection proposal data.

[0161] Furthermore, after receiving the session connection response data, the cloud mobile client performs the following data encryption transmission operations:

[0162] Based on the locally pre-configured fifth quantum identity, request the third quantum identity and third quantum session key from the quantum security service platform;

[0163] Based on the third quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection response data, thereby obtaining encrypted session connection response data;

[0164] Based on the locally pre-set fifth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain a second encrypted data packet;

[0165] The fourth information carrying the second encrypted data packet and the fifth quantum identity is sent to the signaling server, so that the signaling server decrypts the second encrypted data packet to obtain session connection response data, encrypts the session connection response data based on the third quantum session key and the second quantum session key to obtain second encrypted data, and sends the second information carrying the second encrypted data and the second quantum identity to the cloud mobile phone server.

[0166] Specifically, after receiving the second encrypted data packet, the signaling server needs to decrypt it; the process of decrypting the second encrypted data packet by the signaling server is as follows:

[0167] The quantum security service platform requests the fifth quantum session key corresponding to the fifth quantum identity identifier in the fourth information.

[0168] Based on the fifth quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data packet, thereby obtaining the third quantum identity identifier and encrypted session connection response data;

[0169] Request the third quantum session key corresponding to the third quantum identity from the quantum security service platform;

[0170] Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the session connection response data.

[0171] Subsequently, the signaling server encrypts the session connection response data based on the third quantum session key and the second quantum session key. The specific process includes:

[0172] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0173] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0174] Furthermore, the second information also includes a second quantum identity identifier.

[0175] For example, the cloud phone client receives the first encrypted data and the second-level quantum identity QID (i.e., the second quantum identity) sent by the signaling server. It uses the locally preset second-level quantum identity QID (i.e., the fifth quantum identity) to obtain the second-level quantum session key QSK (i.e., the second quantum session key) corresponding to the second-level quantum identity QID (i.e., the second quantum identity) sent by the signaling server from the quantum security service platform. Based on the second-level quantum session key QSK (i.e., the second quantum session key) returned by the quantum security service platform, it calls the local SDK (Software Development Kit) to decrypt the first encrypted data packet and obtain the third-level quantum identity QID (i.e., the first quantum identity requested by the cloud phone server) and encrypted session connection proposal data. Then, the locally pre-set Level 2 quantum identity QID (i.e., the fifth quantum identity) is used again to obtain the Level 3 quantum identity QID (i.e., the first quantum identity requested by the cloud phone server) from the quantum security service platform. After decryption, the Level 3 quantum session key QSK (i.e., the first quantum session key requested by the cloud phone server) corresponding to the Level 3 quantum identity QID (i.e., the first quantum session key requested by the cloud phone server) is obtained. Based on the Level 3 quantum session key QSK returned by the quantum security service platform (i.e., the first quantum session key requested by the cloud phone server), the local SDK is called to decrypt the encrypted session connection proposal data to obtain the roomID, ICE candidate, and offer provided by the cloud phone server.

[0176] Then, the cloud phone client sends a second request to the STUN server to continuously obtain ICE candidates from the cloud phone server, and completes the construction of peerConnection locally, adds the received session description offer provided by the cloud phone server, creates a session description response, and completes media negotiation of ICE candidates.

[0177] Subsequently, the cloud phone client uses its locally pre-configured Level 2 quantum identity QID (i.e., the fifth quantum identity) to obtain a Level 3 quantum identity QID and a quantum key session QSK (i.e., the third quantum identity key and the third quantum session key) from the quantum security service platform. Using the Level 3 quantum key session QSK (i.e., the third quantum session key) returned by the quantum security service platform, it calls the quantum cryptography service platform to encrypt the session connection response data (including the aforementioned roomID, ICE candidates, and session description response answer). Then, using the locally pre-configured Level 2 quantum identity QSK (i.e., the aforementioned fifth quantum session key), it encrypts the Level 3 quantum key session QSK (i.e., the third quantum session key) and the encrypted session connection response data to obtain a second encrypted data packet. Finally, the second encrypted data packet and the Level 2 quantum identity QID (i.e., the fifth quantum identity) are sent back to the signaling server.

[0178] The signaling server receives the second encrypted data packet and the second-level quantum identity QID (i.e., the fifth quantum identity) from the cloud mobile client. Based on the second-level quantum identity QID (i.e., the fifth quantum identity) from the cloud mobile client, it obtains the corresponding second-level quantum session key QSK (i.e., the fifth quantum session key) from the quantum security service platform. Using the second-level quantum session key QSK (i.e., the fifth quantum session key) returned by the quantum security service platform, it calls the cryptographic service platform to decrypt the second encrypted data packet, obtaining the third-level quantum identity QID (i.e., the third quantum identity) and encrypted session connection response data. Then, using the decrypted third-level quantum identity QID (i.e., the third quantum identity), it obtains the third-level quantum session key QSK (i.e., the third quantum session key) from the quantum security service platform. Based on the third-level quantum session key QSK (i.e., the third quantum session key) returned by the quantum security service platform, it calls the cryptographic service platform to decrypt the encrypted session connection response data, obtaining the session connection response data, including the roomID, ICE candidate, and answer provided by the cloud mobile client.

[0179] Based on the roomID obtained through decryption, the signaling server triggers the forwarding of session connection response data to the cloud phone server in the room. The specific process is as follows: The signaling server requests the secondary quantum identity QID and quantum session key QSK (i.e., the second quantum session key and the second quantum identity) from the quantum security service platform. Using the secondary quantum session key QSK (i.e., the second quantum session key), the signaling server calls the cryptographic service platform to completely encrypt the session connection response data provided by the cloud phone client and the tertiary quantum identity QID (i.e., the third quantum identity), obtaining the second encrypted data. The second information carrying the second encrypted data and the secondary quantum identity QID (i.e., the second quantum identity) is then forwarded to the cloud phone server.

[0180] In this embodiment of the invention, a three-level and a two-level quantum session key (QSK) is introduced during the instruction data interaction between the cloud mobile client and the signaling server. This QSK performs multi-layer quantum encryption on instruction data such as room ID, ICE candidates, session description offer, and session description answer, which can effectively improve the security of instruction data transmission.

[0181] S13: Decrypt the second encrypted data according to the third quantum session key and the second quantum session key to obtain session connection response data, so as to complete the connection preparation.

[0182] Specifically, the step of decrypting the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data, thereby completing the connection preparation, includes:

[0183] The quantum security service platform requests the second quantum session key indicated by the second quantum identity in the second information;

[0184] Based on the second quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data, thereby obtaining the third quantum identity and encrypted session connection response data;

[0185] Request the third quantum session key indicated by the third quantum encryption identifier from the quantum security service platform;

[0186] Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the decrypted session connection response data;

[0187] The connection preparation is completed based on the session description response in the session connection response data.

[0188] For example, after the cloud phone server receives the second encrypted data and the second-level quantum identity QID (i.e., the second quantum identity of the signaling server) from the signaling server, it obtains the second-level quantum session key QSK (i.e., the second quantum session key of the signaling server) corresponding to the second-level quantum identity QID (i.e., the second quantum identity) provided by the signaling server from the quantum security service platform. Then, using the second-level quantum session key QSK (i.e., the second quantum session key) returned by the quantum security service platform, it calls the cryptographic service platform to decrypt the second encrypted data, thereby obtaining the third-level quantum identity QID (i.e., the third quantum identity) and the encrypted session connection response data provided by the cloud phone client. Then, the quantum security service platform obtains the level 3 quantum identity QID (i.e., the third quantum identity) and the corresponding level 3 quantum session key QSK (i.e., the third quantum session key provided by the cloud mobile client). Using the level 3 quantum session key QSK returned by the quantum security service platform (i.e., the third quantum session key provided by the cloud mobile client), the cryptographic service platform is called to decrypt the encrypted session connection response data to obtain the session connection response data, including the roomID, ICE candidate, and answer provided by the cloud mobile client.

[0189] The cloud phone server completes the answer in the local peerConnection, and the P2P connection is now ready.

[0190] This invention employs a two-level and three-level QID (Quantum Identity Authentication) and QSK (Quantum Session Key) system during the command and data interaction process between the cloud mobile client, signaling server, and cloud mobile server. Figure 3 As shown, multi-layer quantum encryption protection is implemented for instruction data throughout the entire P2P connection establishment process, which can effectively improve the security of instruction data transmission, reduce the risk of future cracking, and ensure the quantum security and reliability of the entire communication process of cloud phone services.

[0191] It should be noted that, in this embodiment of the invention, the first quantum session key and its corresponding first quantum identity identifier, the third quantum session key and its corresponding third quantum identity identifier requested by the cloud phone server and the cloud phone client from the quantum security service platform are all level 3 quantum session keys (QSK) and their corresponding level 3 quantum identity identifiers (QID); the second quantum session key and its corresponding second quantum identity identifier, the fourth quantum session key and its corresponding fourth quantum identity identifier, the fifth quantum session key and its corresponding fifth quantum identity identifier requested by the signaling server, the cloud phone server, and the cloud phone client from the quantum security service platform are all level 2 quantum session keys (QSK) and their corresponding level 2 quantum identity identifiers (QID). The level 3 quantum session key (QSK) and quantum identity identifier (QID) requested by the cloud phone server and the cloud phone client can be the same or the same, and the level 2 quantum session key (QSK) and quantum identity identifier (QID) requested by the signaling server, the cloud phone server, and the cloud phone client can be the same or the same. This embodiment of the invention does not impose specific limitations.

[0192] Furthermore, the method also includes:

[0193] After establishing a P2P connection, the first encryption algorithm is used to encrypt the data according to the first quantum session key.

[0194] Based on the fourth quantum session key, the encrypted first encryption algorithm and the first quantum identity corresponding to the first quantum session key are encrypted to obtain the final first encryption algorithm data.

[0195] The first encryption algorithm data is sent to the cloud mobile client, so that the cloud mobile client can decrypt the first encryption algorithm data to obtain the first encryption algorithm and the first quantum session key, and then perform the following SRTP encryption authentication operation:

[0196] Using the first quantum session key as the master key, derive the first session encryption key and the first authentication key;

[0197] SRTP data is encrypted and authenticated based on the first session encryption key and the first authentication key.

[0198] Furthermore, the method also includes:

[0199] Based on the fourth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the first quantum session key are encrypted and transmitted.

[0200] Furthermore, the method also includes:

[0201] The quantum secure channel periodically requests the quantum security service platform to update the first quantum session key and the first quantum identity identifier corresponding to the first quantum session key.

[0202] In this embodiment of the invention, after completing the above-mentioned P2P connection establishment preparations, a P2P connection is established. Subsequently, based on the quantum cryptography resource pool, the SRTP data between the cloud mobile client and the server is transmitted using quantum encryption. The specific process is as follows:

[0203] Step 1: Three-Level Quantum Key Distribution: The cloud phone server / cloud client transmits encryption algorithms based on the secondary quantum identity identifier (QID) and quantum session key (QSK) distributed by the quantum security service platform (i.e., the fourth quantum identity identifier and its corresponding fourth quantum session key / the fifth quantum identity identifier and its corresponding fifth quantum session key), and the corresponding tertiary quantum identity identifier (QID) and quantum session key (QSK) (e.g., the first quantum identity identifier and its corresponding first quantum session key / the third quantum identity identifier and its corresponding third quantum session key). The tertiary quantum session key (QSK) serves as the master key for the actual encryption of SRTP data. For example, for encryption algorithms (such as AES-CTR algorithm, HMAC-SHA1 algorithm), the cryptographic service platform is invoked to encrypt the data based on the tertiary quantum session key (QSK), and then the encrypted algorithm and the tertiary quantum identity identifier (QID) are encrypted again based on the secondary quantum session key (QSK) to obtain the final encryption algorithm, which is then transmitted to the cloud phone client.

[0204] Step 2: SRTP Key Material Generation: The cloud mobile client uses the received Level 3 quantum session key (QSK) as the SRTP master key. Following the SRTP protocol specifications, the first session encryption key, the first authentication key, and the first salt value are derived using the Level 3 quantum session key (QSK).

[0205] Step 3: SRTP Encryption and Authentication: The cloud mobile client uses the derived first session encryption key to encrypt the RTP data packets (payload) using the AES-CTR algorithm, obtaining SRTP data packets. Using the first authentication key, an authentication tag is generated for each SRTP data packet using the HMAC-SHA1 algorithm, and the final SRTP data is generated based on the SRTP data and the authentication tags. Compared to the standard SRTP process, this embodiment of the invention derives session encryption keys, authentication keys, etc., based on a three-level quantum session key (QSK), which can enhance encryption strength and resistance to quantum computing attacks.

[0206] Step 4: Dynamic Key Update and Session Maintenance: The cloud phone server periodically updates the Level 3 quantum session key (QSK) via a quantum secure channel. The frequency can be adjusted according to security requirements. After each update, steps one through three are repeated to refresh all key materials for SRTP.

[0207] It should be noted that the SRTP quantization process of the cloud phone client is the same as that of the cloud phone server when establishing a P2P connection, and will not be repeated here.

[0208] Compared to existing technologies, this invention introduces quantum encryption technology. Quantum encryption utilizes quantum mechanics principles, such as the uncertainty principle, to achieve theoretically uneavesdroppable communication. It can generate truly random keys and detect any eavesdropping attempts, thus providing a higher level of security. This invention introduces quantum communication encryption technology into the data interaction process of cloud phones, particularly in the key generation and distribution process, achieving theoretically unbreakable security. This can resist the threats posed by future quantum computers, providing a long-term, provably secure communication channel for cloud phone services and enhancing the security and reliability of the entire system.

[0209] This invention addresses the communication solution for cloud phones by introducing a quantum cryptographic resource pool, including a quantum security service platform and a cryptographic service platform. This enables a quantum-secure communication solution comprising the quantum security service platform, the cryptographic service platform, a cloud phone client, a cloud phone server, and a signaling server. The quantum security service platform and the cryptographic service platform provide quantum key generation and distribution, as well as quantum key-based encryption and decryption functions, for each stage from signaling exchange and P2P connection establishment to real-time media transmission. By enhancing traditional encryption methods with quantum encryption technology, true end-to-end quantum security protection is achieved, filling potential security vulnerabilities in traditional communication systems and providing seamless security coverage for the entire communication process. This provides a comprehensive, future-oriented secure communication framework for cloud phone services.

[0210] The embodiments of this invention employ a multi-layered quantum encryption architecture and full-process quantization. Based on a two-level and three-level quantum identity identifier (QID) and quantum session key (QSK) system, it achieves a more refined classification of quantum key categories. This multi-layered architecture ensures the quantum security of the entire communication process.

[0211] Please see Figure 4 , Figure 4 This is the second flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention. The cloud phone encrypted communication method is applied to a cloud phone client and includes:

[0212] S21: Receive first information sent by the cloud mobile phone server through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0213] S22: Decrypt the first encrypted data according to the first quantum session key and the second quantum session key to obtain session connection proposal data;

[0214] S23: Obtain session connection response data by performing media negotiation based on the session connection proposal data;

[0215] S24: Send second information to the cloud mobile phone server through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the second information is used to instruct the cloud mobile phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key, obtain session connection response data, and complete the connection preparation.

[0216] In an optional embodiment, the step of decrypting the first encrypted data based on the first quantum session key and the second quantum session key to obtain session connection proposal data includes:

[0217] Based on the locally pre-set fifth quantum identity, the quantum security service platform requests the second quantum session key corresponding to the second quantum identity carried in the first information;

[0218] Based on the second quantum session key, the first encrypted data in the first information is decrypted to obtain the first quantum identity and encrypted session connection proposal data;

[0219] Based on the locally pre-set fifth quantum identity, request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0220] Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

[0221] In one optional embodiment, sending the second information to the cloud phone server via the signaling server includes:

[0222] Based on the locally pre-configured fifth quantum identity, request the third quantum identity and third quantum session key from the quantum security service platform;

[0223] Based on the third quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection response data, thereby obtaining encrypted session connection response data;

[0224] Based on the locally pre-set fifth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain a second encrypted data packet;

[0225] The fourth information carrying the second encrypted data packet and the fifth quantum identity is sent to the signaling server, so that the signaling server decrypts the second encrypted data packet to obtain session connection response data, encrypts the session connection response data based on the third quantum session key and the second quantum session key to obtain second encrypted data, and sends the second information carrying the second encrypted data and the second quantum identity to the cloud mobile phone server.

[0226] In one optional embodiment, the process of encrypting session connection response data based on the third quantum session key and the second quantum session key includes:

[0227] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0228] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0229] The second information includes the second encrypted data and the second quantum identity identifier.

[0230] In an optional embodiment, the method further includes:

[0231] After establishing a P2P connection, the second encryption algorithm is encrypted using the third quantum session key.

[0232] Based on the fifth quantum session key, the encrypted second encryption algorithm and the third quantum identity corresponding to the third quantum session key are encrypted to obtain the final second encryption algorithm data;

[0233] The second encryption algorithm data is sent to the cloud phone server, so that the cloud phone server can decrypt the second encryption algorithm data to obtain the second encryption algorithm and the third quantum session key, and then perform the following SRTP encryption authentication operation:

[0234] The third quantum session key is used as the master key to derive a second session encryption key and a second authentication key;

[0235] SRTP data is encrypted and authenticated based on the second session encryption key and the second authentication key.

[0236] In an optional embodiment, the method further includes:

[0237] Based on the fifth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the third quantum session key are encrypted and transmitted.

[0238] In an optional embodiment, the method further includes:

[0239] The third quantum session key and the corresponding third quantum identity identifier are periodically requested from the quantum security service platform through a quantum secure channel.

[0240] It should be noted that the working process of the cloud phone encrypted communication method described in the embodiments of the present invention can refer to the working process of the cloud phone encrypted communication method described in the above embodiments, and the technical effect achieved is the same as that of the cloud phone encrypted communication method described in the above embodiments, so it will not be repeated here.

[0241] Please see Figure 5 , Figure 5 This is the third flowchart of a cloud phone encrypted communication method provided in an embodiment of the present invention. The cloud phone encrypted communication method is applied to a signaling server and includes:

[0242] S31: Encrypt the session connection proposal data of the cloud phone server according to the first quantum session key and the second quantum session key to obtain the first encrypted data;

[0243] S32: Send first information to the cloud mobile client; wherein, the first information includes the first encrypted data;

[0244] S33: Encrypt the session connection response data of the cloud mobile client according to the third quantum session key and the second quantum session key to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0245] S34: Send second information to the cloud phone server; wherein the second information includes second encrypted data, so that the cloud phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data, so as to complete the connection preparation.

[0246] In an optional embodiment, the method further includes:

[0247] Receive third information sent by the cloud mobile phone server; wherein, the third information includes a first encrypted data packet and a fourth quantum identity identifier;

[0248] The quantum security service platform requests the fourth quantum session key corresponding to the fourth quantum identity.

[0249] Based on the fourth quantum session key, the quantum cryptography service platform is invoked to decrypt the first encrypted data packet, thereby obtaining the first quantum identity and encrypted session connection proposal data;

[0250] Request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0251] Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

[0252] In one optional embodiment, encrypting the session connection proposal data of the cloud phone server based on the first quantum session key and the second quantum session key to obtain the first encrypted data includes:

[0253] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0254] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data;

[0255] The first information includes the first encrypted data and the second quantum identity identifier.

[0256] In an optional embodiment, encrypting the session connection response data of the cloud mobile client based on the third quantum session key and the second quantum session key to obtain the second encrypted data includes:

[0257] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0258] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0259] The second information includes the second encrypted data and the second quantum identity identifier.

[0260] In an optional embodiment, the method further includes:

[0261] The system receives a fourth message sent by the cloud mobile client; wherein the fourth message includes a second encrypted data packet and a fifth quantum identity identifier.

[0262] The quantum security service platform requests the fifth quantum session key corresponding to the fifth quantum identity.

[0263] Based on the fifth quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data packet, thereby obtaining the third quantum identity identifier and encrypted session connection response data;

[0264] Request the third quantum session key corresponding to the third quantum identity from the quantum security service platform;

[0265] Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the session connection response data.

[0266] It should be noted that the working process of the cloud phone encrypted communication method described in the embodiments of the present invention can refer to the working process of the cloud phone encrypted communication method described in the above embodiments, and the technical effect achieved is the same as that of the cloud phone encrypted communication method described in the above embodiments, so it will not be repeated here.

[0267] See Figure 6 , Figure 6 This is a first structural block diagram of a cloud phone encrypted communication device provided by an embodiment of the present invention. The cloud phone encrypted communication device, which applies a cloud phone server, includes:

[0268] The first information sending module 11 is used to send first information to the cloud mobile client through a signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0269] The first information receiving module 12 is used to receive second information sent by the cloud mobile client through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0270] The response data acquisition module 13 is used to decrypt the second encrypted data according to the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

[0271] In an optional embodiment, the first information sending module 11 includes:

[0272] The first quantum key request unit is used to request the first quantum session key and the first quantum identity from the quantum security service platform;

[0273] The first data encryption unit is used to call the quantum cryptography service platform to encrypt the session connection proposal data according to the first quantum session key, so as to obtain encrypted session connection proposal data.

[0274] The second quantum key request unit is used to request the fourth quantum session key and the fourth quantum identity identifier from the quantum security service platform;

[0275] The second data encryption unit is used to call the quantum cryptography service platform to encrypt the encrypted session connection proposal data and the first quantum identity identifier according to the fourth quantum session key, so as to obtain the first encrypted data packet;

[0276] The first encrypted data sending unit is used to send third information carrying the first encrypted data packet and the fourth quantum identity to the signaling server, so that the signaling server decrypts the first encrypted data packet to obtain session connection proposal data, encrypts the session connection proposal data based on the first quantum session key and the second quantum session key to obtain the first encrypted data, and sends the first information carrying the first encrypted data and the second quantum identity to the cloud mobile client.

[0277] In one alternative embodiment, the process of encrypting session connection proposal data based on a first quantum session key and a second quantum session key includes:

[0278] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0279] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data;

[0280] The first information includes the first encrypted data and the second quantum identity identifier.

[0281] In one optional embodiment, the second information further includes a second quantum identity identifier;

[0282] The response data acquisition module 13 includes:

[0283] The third quantum key request unit is used to request the second quantum session key indicated by the second quantum identity in the second information from the quantum security service platform;

[0284] The first data decryption unit is used to call the quantum cryptography service platform to decrypt the second encrypted data according to the second quantum session key, and obtain the third quantum identity and encrypted session connection response data;

[0285] The fourth quantum key request unit is used to request the third quantum session key indicated by the third quantum encryption identifier from the quantum security service platform;

[0286] The second data decryption unit is used to call the quantum cryptography service platform to decrypt the encrypted session connection response data according to the third quantum session key, so as to obtain the decrypted session connection response data.

[0287] The connection preparation unit is used to complete the connection preparation based on the session description response in the session connection response data.

[0288] In an optional embodiment, the device further includes:

[0289] The first algorithm encryption module is used to encrypt the preset first encryption algorithm according to the first quantum session key after the P2P connection is established.

[0290] The second algorithm encryption module is used to encrypt the encrypted first encryption algorithm and the first quantum identity corresponding to the first quantum session key according to the fourth quantum session key, so as to obtain the final first encryption algorithm data.

[0291] The first encrypted data sending module is used to send the first encryption algorithm data to the cloud mobile client, so that the cloud mobile client can decrypt the first encryption algorithm data to obtain the first encryption algorithm and the first quantum session key, and then perform the following SRTP encryption authentication operation:

[0292] Using the first quantum session key as the master key, derive the first session encryption key and the first authentication key;

[0293] SRTP data is encrypted and authenticated based on the first session encryption key and the first authentication key.

[0294] In an optional embodiment, the device further includes:

[0295] The first data encryption transmission module is used to encrypt and transmit the encrypted and authenticated SRTP data and the third quantum identity identifier corresponding to the first quantum session key according to the fourth quantum session key.

[0296] In an optional embodiment, the device further includes:

[0297] The first quantum key update module is used to periodically request the quantum security service platform to update the first quantum session key and the first quantum identity identifier corresponding to the first quantum session key through a quantum secure channel.

[0298] It should be noted that the working process of each module in the cloud phone encrypted communication device described in the embodiments of the present invention can refer to the working process of the cloud phone encrypted communication method described in the above embodiments, and the technical effect achieved is the same as that of the cloud phone encrypted communication method described in the above embodiments, so it will not be repeated here.

[0299] See Figure 7 , Figure 7 This is a second structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention. The cloud phone encrypted communication device is applied to a cloud phone client and includes:

[0300] The second information receiving module 21 is used to receive first information sent by the cloud mobile phone server through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key;

[0301] The first decryption module 22 is used to decrypt the first encrypted data according to the first quantum session key and the second quantum session key to obtain session connection proposal data;

[0302] Media negotiation module 23 is used to perform media negotiation based on the session connection proposal data to obtain session connection response data;

[0303] The second information sending module 24 is used to send second information to the cloud mobile phone server through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the second information is used to instruct the cloud mobile phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key, and obtain the session connection response data to complete the connection preparation.

[0304] In an optional embodiment, the first decryption module 22 includes:

[0305] The fifth quantum key request unit is used to request the second quantum session key corresponding to the second quantum identity carried in the first information from the quantum security service platform based on the locally preset fifth quantum identity.

[0306] The third data decryption unit is used to decrypt the first encrypted data in the first information according to the second quantum session key to obtain the first quantum identity and encrypted session connection proposal data;

[0307] The sixth quantum key request unit is used to request the first quantum session key corresponding to the first quantum identity from the quantum security service platform based on the locally preset fifth quantum identity.

[0308] The fourth data decryption unit is used to decrypt the encrypted session connection proposal data according to the first quantum session key to obtain the session connection proposal data.

[0309] In an optional embodiment, the second information sending module 24 includes:

[0310] The seventh quantum key request unit is used to request the third quantum identity and the third quantum session key from the quantum security service platform based on the locally preset fifth quantum identity.

[0311] The fifth data encryption unit is used to call the quantum cryptography service platform to encrypt the session connection response data according to the third quantum session key, so as to obtain encrypted session connection response data;

[0312] The sixth data encryption unit is used to call the quantum cryptography service platform to encrypt the encrypted session connection response data and the third quantum identity identifier according to the locally preset fifth quantum session key, so as to obtain the second encrypted data packet;

[0313] The first encrypted data sending unit is used to send fourth information carrying the second encrypted data packet and the fifth quantum identity to the signaling server, so that the signaling server decrypts the second encrypted data packet to obtain session connection response data, encrypts the session connection response data based on the third quantum session key and the second quantum session key to obtain second encrypted data, and sends the second information carrying the second encrypted data and the second quantum identity to the cloud mobile phone server.

[0314] In one optional embodiment, the process of encrypting session connection response data based on the third quantum session key and the second quantum session key includes:

[0315] Request the second quantum session key and the second quantum identity from the quantum security service platform;

[0316] Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0317] The second information includes the second encrypted data and the second quantum identity identifier.

[0318] In an optional embodiment, the device further includes:

[0319] The third algorithm encryption module is used to encrypt the preset second encryption algorithm according to the third quantum session key after the P2P connection is established.

[0320] The fourth algorithm encryption module is used to encrypt the encrypted second encryption algorithm and the third quantum identity corresponding to the third quantum session key according to the fifth quantum session key, so as to obtain the final second encryption algorithm data.

[0321] The second encrypted data sending module is used to send the second encryption algorithm data to the cloud phone server, so that the cloud phone server can decrypt the second encryption algorithm data to obtain the second encryption algorithm and the third quantum session key, and then perform the following SRTP encryption authentication operation:

[0322] The third quantum session key is used as the master key to derive a second session encryption key and a second authentication key;

[0323] SRTP data is encrypted and authenticated based on the second session encryption key and the second authentication key.

[0324] In an optional embodiment, the device further includes:

[0325] The second data encryption transmission module is used to encrypt and transmit the encrypted and authenticated SRTP data and the third quantum identity corresponding to the third quantum session key according to the fifth quantum session key.

[0326] In an optional embodiment, the device further includes:

[0327] The second quantum key update module is used to periodically request the quantum security service platform to update the third quantum session key and the third quantum identity identifier corresponding to the third quantum session key through a quantum secure channel.

[0328] It should be noted that the working process of each module in the cloud phone encrypted communication device described in the embodiments of the present invention can refer to the working process of the cloud phone encrypted communication method described in the above embodiments, and the technical effect achieved is the same as that of the cloud phone encrypted communication method described in the above embodiments, so it will not be repeated here.

[0329] See Figure 8 , Figure 8 This is a third structural block diagram of a cloud phone encrypted communication device provided in this embodiment of the invention. The cloud phone encrypted communication device is applied to a signaling server and includes:

[0330] The first encryption module 31 is used to encrypt the session connection proposal data of the cloud phone server according to the first quantum session key and the second quantum session key to obtain the first encrypted data;

[0331] The third information sending module 32 is used to send first information to the cloud mobile client; wherein, the first information includes the first encrypted data;

[0332] The second encryption module 33 is used to encrypt the session connection response data of the cloud mobile client according to the third quantum session key and the second quantum session key to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data;

[0333] The fourth information sending module 34 is used to send second information to the cloud mobile phone server; wherein the second information includes second encrypted data, so that the cloud mobile phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data to complete the connection preparation.

[0334] In an optional embodiment, the device further includes:

[0335] The third information receiving module is used to receive third information sent by the cloud mobile phone server; wherein, the third information includes a first encrypted data packet and a fourth quantum identity identifier;

[0336] The first key request module is used to request the fourth quantum session key corresponding to the fourth quantum identity from the quantum security service platform;

[0337] The second decryption module is used to call the quantum cryptography service platform to decrypt the first encrypted data packet according to the fourth quantum session key, so as to obtain the first quantum identity and encrypted session connection proposal data.

[0338] The second key request module is used to request the first quantum session key corresponding to the first quantum identity from the quantum security service platform;

[0339] The third decryption module is used to decrypt the encrypted session connection proposal data according to the first quantum session key to obtain the session connection proposal data.

[0340] In an optional embodiment, the first encryption module 31 includes:

[0341] The eighth quantum key request unit is used to request the second quantum session key and the second quantum identity from the quantum security service platform;

[0342] The seventh data encryption unit is used to call the quantum cryptography service platform to encrypt the encrypted session connection proposal data and the first quantum identity identifier according to the second quantum session key, so as to obtain the first encrypted data;

[0343] The first information includes the first encrypted data and the second quantum identity identifier.

[0344] In an optional embodiment, the second encryption module 33 includes:

[0345] The ninth quantum key request unit is used to request the second quantum session key and the second quantum identity from the quantum security service platform;

[0346] The eighth data encryption unit is used to call the quantum cryptography service platform to encrypt the encrypted session connection response data and the third quantum identity identifier according to the second quantum session key, so as to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key;

[0347] The second information includes the second encrypted data and the second quantum identity identifier.

[0348] In an optional embodiment, the device further includes:

[0349] The fourth information receiving module is used to receive the fourth information sent by the cloud mobile client; wherein the fourth information includes a second encrypted data packet and a fifth quantum identity identifier;

[0350] The third key request module is used to request the fifth quantum session key corresponding to the fifth quantum identity from the quantum security service platform;

[0351] The fourth decryption module is used to call the quantum cryptography service platform to decrypt the second encrypted data packet according to the fifth quantum session key, so as to obtain the third quantum identity and encrypted session connection response data;

[0352] The fourth key request module is used to request the third quantum session key corresponding to the third quantum identity from the quantum security service platform;

[0353] The fifth decryption module is used to call the quantum cryptography service platform to decrypt the encrypted session connection response data based on the third quantum session key, so as to obtain the session connection response data.

[0354] It should be noted that the working process of each module in the cloud phone encrypted communication device described in the embodiments of the present invention can refer to the working process of the cloud phone encrypted communication method described in the above embodiments, and the technical effect achieved is the same as that of the cloud phone encrypted communication method described in the above embodiments, so it will not be repeated here.

[0355] See Figure 9 , Figure 9 This is a structural block diagram of a cloud phone encrypted communication device provided in an embodiment of the present invention. The cloud phone encrypted communication device includes a processor 41, a memory 42, and a computer program stored in the memory 42 and executable on the processor 41. When the processor 41 executes the computer program, it implements the steps in the above-described embodiments of the cloud phone encrypted communication method, such as steps S11-S13, S21-S24, or S31-S34.

[0356] For example, the computer program can be divided into one or more modules / units, which are stored in the memory 42 and executed by the processor 41 to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the cloud phone encrypted communication device.

[0357] The cloud phone encrypted communication device may include, but is not limited to, a processor 41 and a memory 42. Those skilled in the art will understand that the schematic diagram is merely an example of a cloud phone encrypted communication device and does not constitute a limitation on the device. It may include more or fewer components than illustrated, or combine certain components, or use different components. For example, the cloud phone encrypted communication device may also include input / output devices, network access devices, buses, etc.

[0358] The processor 41 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 41 is the control center of the cloud phone encrypted communication device, connecting all parts of the device via various interfaces and lines.

[0359] The memory 42 can be used to store the computer programs and / or modules. The processor 41 implements various functions of the cloud phone encrypted communication device by running or executing the computer programs and / or modules stored in the memory 42 and calling the data stored in the memory 42. The memory 42 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 42 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0360] Wherein, if the modules / units integrated in the cloud phone encrypted communication device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor 41, it can implement the steps of the above-mentioned method embodiments. Wherein, the computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0361] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0362] The above description represents the preferred embodiments of the present invention. It should be noted that, for those skilled in the art, various improvements and modifications can be made without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A cloud phone encrypted communication method, characterized in that, Application cloud phone server, including: The first information is sent to the cloud mobile client through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key; The system receives second information sent by the cloud mobile client through the signaling server; wherein the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on a third quantum session key and a second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data; Based on the third quantum session key and the second quantum session key, the second encrypted data is decrypted to obtain session connection response data, thereby completing the connection preparation.

2. The cloud phone encrypted communication method as described in claim 1, characterized in that, The step of sending the first information to the cloud mobile client via the signaling server includes: The quantum security service platform requests the first quantum session key and the first quantum identity identifier. Based on the first quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection proposal data, thereby obtaining encrypted session connection proposal data; Request the fourth quantum session key and the fourth quantum identity identifier from the quantum security service platform; Based on the fourth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data packet; The third information carrying the first encrypted data packet and the fourth quantum identity is sent to the signaling server, so that the signaling server decrypts the first encrypted data packet to obtain session connection proposal data, encrypts the session connection proposal data based on the first quantum session key and the second quantum session key to obtain first encrypted data, and sends the first information carrying the first encrypted data and the second quantum identity to the cloud mobile client.

3. The cloud phone encrypted communication method as described in claim 1 or 2, characterized in that, The process of encrypting session connection proposal data based on the first quantum session key and the second quantum session key includes: Request the second quantum session key and the second quantum identity from the quantum security service platform; Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data; The first information includes the first encrypted data and the second quantum identity identifier.

4. The cloud phone encrypted communication method as described in claim 1, characterized in that, The second information also includes a second quantum identity identifier; The step of decrypting the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data, thereby completing the connection preparation, includes: The quantum security service platform requests the second quantum session key indicated by the second quantum identity in the second information; Based on the second quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data, thereby obtaining the third quantum identity and encrypted session connection response data; Request the third quantum session key indicated by the third quantum encryption identifier from the quantum security service platform; Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the decrypted session connection response data; The connection preparation is completed based on the session description response in the session connection response data.

5. The cloud phone encrypted communication method as described in claim 2, characterized in that, The method further includes: After establishing a P2P connection, the first encryption algorithm is used to encrypt the data according to the first quantum session key. Based on the fourth quantum session key, the encrypted first encryption algorithm and the first quantum identity corresponding to the first quantum session key are encrypted to obtain the final first encryption algorithm data. The first encryption algorithm data is sent to the cloud mobile client, so that the cloud mobile client can decrypt the first encryption algorithm data to obtain the first encryption algorithm and the first quantum session key, and then perform the following SRTP encryption authentication operation: Using the first quantum session key as the master key, derive the first session encryption key and the first authentication key; SRTP data is encrypted and authenticated based on the first session encryption key and the first authentication key.

6. The cloud phone encrypted communication method as described in claim 4, characterized in that, The method further includes: Based on the fourth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the first quantum session key are encrypted and transmitted.

7. The cloud phone encrypted communication method as described in claim 4, characterized in that, The method further includes: The quantum secure channel periodically requests the quantum security service platform to update the first quantum session key and the first quantum identity identifier corresponding to the first quantum session key.

8. A cloud phone encrypted communication method, characterized in that, Applications to cloud mobile clients include: The cloud phone server receives first information sent through a signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key; Based on the first quantum session key and the second quantum session key, the first encrypted data is decrypted to obtain session connection proposal data; Based on the session connection proposal data, media negotiation is performed to obtain the session connection response data; The signaling server sends a second message to the cloud phone server; wherein the second message includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on a third quantum session key and a second quantum session key; the second message is used to instruct the cloud phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

9. The cloud phone encrypted communication method as described in claim 8, characterized in that, The step of decrypting the first encrypted data based on the first quantum session key and the second quantum session key to obtain session connection proposal data includes: Based on the locally pre-set fifth quantum identity, the quantum security service platform requests the second quantum session key corresponding to the second quantum identity carried in the first information; Based on the second quantum session key, the first encrypted data in the first information is decrypted to obtain the first quantum identity and encrypted session connection proposal data; Based on the locally pre-set fifth quantum identity, request the first quantum session key corresponding to the first quantum identity from the quantum security service platform; Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

10. The cloud phone encrypted communication method as described in claim 8, characterized in that, Sending the second information to the cloud phone server via the signaling server includes: Based on the locally pre-configured fifth quantum identity, request the third quantum identity and third quantum session key from the quantum security service platform; Based on the third quantum session key, the quantum cryptography service platform is invoked to encrypt the session connection response data, thereby obtaining encrypted session connection response data; Based on the locally pre-set fifth quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain a second encrypted data packet; The fourth information carrying the second encrypted data packet and the fifth quantum identity is sent to the signaling server, so that the signaling server decrypts the second encrypted data packet to obtain session connection response data, encrypts the session connection response data based on the third quantum session key and the second quantum session key to obtain second encrypted data, and sends the second information carrying the second encrypted data and the second quantum identity to the cloud mobile phone server.

11. The cloud phone encrypted communication method as described in claim 8 or 10, characterized in that, The process of encrypting session connection response data based on the third quantum session key and the second quantum session key includes: Request the second quantum session key and the second quantum identity from the quantum security service platform; Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key; The second information includes the second encrypted data and the second quantum identity identifier.

12. The cloud phone encrypted communication method as described in claim 10, characterized in that, The method further includes: After establishing a P2P connection, the second encryption algorithm is encrypted using the third quantum session key. Based on the fifth quantum session key, the encrypted second encryption algorithm and the third quantum identity corresponding to the third quantum session key are encrypted to obtain the final second encryption algorithm data; The second encryption algorithm data is sent to the cloud phone server, so that the cloud phone server can decrypt the second encryption algorithm data to obtain the second encryption algorithm and the third quantum session key, and then perform the following SRTP encryption authentication operation: The third quantum session key is used as the master key to derive a second session encryption key and a second authentication key; SRTP data is encrypted and authenticated based on the second session encryption key and the second authentication key.

13. The cloud phone encrypted communication method as described in claim 12, characterized in that, The method further includes: Based on the fifth quantum session key, the encrypted and authenticated SRTP data and the third quantum identity corresponding to the third quantum session key are encrypted and transmitted.

14. The cloud phone encrypted communication method as described in claim 12, characterized in that, The method further includes: The third quantum session key and the corresponding third quantum identity identifier are periodically requested from the quantum security service platform through a quantum secure channel.

15. A cloud phone encrypted communication method, characterized in that, Applied to signaling servers, including: The session connection proposal data of the cloud phone server is encrypted using the first quantum session key and the second quantum session key to obtain the first encrypted data; Send a first message to the cloud mobile client; wherein the first message includes the first encrypted data; The session connection response data of the cloud mobile client is encrypted using the third quantum session key and the second quantum session key to obtain second encrypted data; wherein, the encrypted session connection response data is obtained through media negotiation based on the session connection proposal data; Send a second message to the cloud phone server; wherein the second message includes second encrypted data, so that the cloud phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key, obtain session connection response data, and complete the connection preparation.

16. The cloud phone encrypted communication method as described in claim 15, characterized in that, The method further includes: Receive third information sent by the cloud mobile phone server; wherein, the third information includes a first encrypted data packet and a fourth quantum identity identifier; The quantum security service platform requests the fourth quantum session key corresponding to the fourth quantum identity. Based on the fourth quantum session key, the quantum cryptography service platform is invoked to decrypt the first encrypted data packet, thereby obtaining the first quantum identity and encrypted session connection proposal data; Request the first quantum session key corresponding to the first quantum identity from the quantum security service platform; Based on the first quantum session key, the encrypted session connection proposal data is decrypted to obtain the session connection proposal data.

17. The cloud phone encrypted communication method as described in claim 15 or 16, characterized in that, The first encrypted data is obtained by encrypting the session connection proposal data of the cloud phone server according to the first quantum session key and the second quantum session key, including: Request the second quantum session key and the second quantum identity from the quantum security service platform; Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection proposal data and the first quantum identity identifier to obtain the first encrypted data; The first information includes the first encrypted data and the second quantum identity identifier.

18. The cloud phone encrypted communication method as described in claim 15, characterized in that, The encryption of the session connection response data of the cloud mobile client based on the third quantum session key and the second quantum session key to obtain the second encrypted data includes: Request the second quantum session key and the second quantum identity from the quantum security service platform; Based on the second quantum session key, the quantum cryptography service platform is invoked to encrypt the encrypted session connection response data and the third quantum identity identifier to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by the cloud mobile client encrypting the session connection response data based on the third quantum session key; The second information includes the second encrypted data and the second quantum identity identifier.

19. The cloud phone encrypted communication method as described in claim 15 or 18, characterized in that, The method further includes: The system receives a fourth message sent by the cloud mobile client; wherein the fourth message includes a second encrypted data packet and a fifth quantum identity identifier. The quantum security service platform requests the fifth quantum session key corresponding to the fifth quantum identity. Based on the fifth quantum session key, the quantum cryptography service platform is invoked to decrypt the second encrypted data packet, thereby obtaining the third quantum identity identifier and encrypted session connection response data; Request the third quantum session key corresponding to the third quantum identity from the quantum security service platform; Based on the third quantum session key, the quantum cryptography service platform is invoked to decrypt the encrypted session connection response data to obtain the session connection response data.

20. A cloud phone encrypted communication device, characterized in that, Application cloud phone server, including: The first information sending module is used to send first information to the cloud mobile client through a signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key; The first information receiving module is used to receive second information sent by the cloud mobile client through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data; The response data acquisition module is used to decrypt the second encrypted data according to the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

21. A cloud phone encrypted communication method, characterized in that, Applications to cloud mobile clients include: The second information receiving module is used to receive first information sent by the cloud mobile phone server through the signaling server; wherein, the first information includes first encrypted data; the first encrypted data is obtained by encrypting session connection proposal data based on a first quantum session key and a second quantum session key; The first decryption module is used to decrypt the first encrypted data based on the first quantum session key and the second quantum session key to obtain session connection proposal data; The media negotiation module is used to perform media negotiation based on the session connection proposal data to obtain session connection response data; The second information sending module is used to send second information to the cloud mobile phone server through the signaling server; wherein, the second information includes second encrypted data; the second encrypted data is obtained by encrypting session connection response data based on the third quantum session key and the second quantum session key; the second information is used to instruct the cloud mobile phone server to decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data in order to complete the connection preparation.

22. A cloud phone encrypted communication method, characterized in that, Applied to signaling servers, including: The first encryption module is used to encrypt the session connection proposal data of the cloud phone server according to the first quantum session key and the second quantum session key to obtain the first encrypted data; The third information sending module is used to send first information to the cloud mobile client; wherein, the first information includes the first encrypted data; The second encryption module is used to encrypt the session connection response data of the cloud mobile client according to the third quantum session key and the second quantum session key to obtain the second encrypted data; wherein, the encrypted session connection response data is obtained by media negotiation based on the session connection proposal data; The fourth information sending module is used to send second information to the cloud phone server; wherein the second information includes second encrypted data, so that the cloud phone server can decrypt the second encrypted data based on the third quantum session key and the second quantum session key to obtain session connection response data to complete the connection preparation.

23. A cloud-based encrypted communication device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the cloud phone encrypted communication method as described in any one of claims 1 to 7, or the cloud phone encrypted communication method as described in any one of claims 8 to 14, or the cloud phone encrypted communication method as described in any one of claims 15 to 19.

24. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the cloud phone encrypted communication method as described in any one of claims 1 to 7, or the cloud phone encrypted communication method as described in any one of claims 8 to 14, or the cloud phone encrypted communication method as described in any one of claims 15 to 19.

25. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the cloud phone encrypted communication method according to any one of claims 1 to 7, or the cloud phone encrypted communication method according to any one of claims 8 to 14, or the cloud phone encrypted communication method according to any one of claims 15 to 19.