Key management method and device based on quantum security chip carrier
By using a key management method based on a quantum-safe chip carrier, a root key is generated and subkeys are derived hierarchically. Combined with hash algorithms and two-way authentication, this method solves the security deficiencies of existing solutions under the threat of quantum computing, achieves high-security key management, supports hybrid cryptography, and ensures the security of future digital infrastructure.
Patent Information
- Application Number
- CN202610123341.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-29
- Publication Date
- 2026-03-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing key management schemes lack hardware optimization support in the face of quantum computing threats, cannot effectively resist quantum attacks, and do not fully consider deep integration with quantum key distribution networks, resulting in insufficient resistance to physical attacks and inadequate construction of trusted execution environments.
A key management method based on a quantum-safe chip carrier is adopted. A root key is generated by a quantum random number generator and mapped to a unique identity. Device keys, application keys and session keys are derived hierarchically. A hash algorithm is used for integrity verification and two-way identity authentication. A quantum-safe transmission channel is used for key transmission, and a three-element binding mechanism of chip unique identity, quantum random entropy source and storage environment fingerprint is constructed.
It effectively defends against the threat of quantum computing, enhances the security, trustworthiness, and traceability of key management, supports hybrid cryptography, and ensures the long-term security of future digital infrastructure.
Smart Images

Figure CN121690571A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of quantum computing, in particular to a key management method and device based on a quantum security chip carrier. BACKGROUND
[0002] With the rapid development of quantum computing technology, the traditional encryption system based on classical computing complexity (such as RSA, ECC, etc.) is facing a severe survival threat. Quantum computers can theoretically break the widely used asymmetric encryption algorithm in polynomial time. Once a large-scale practical quantum computer appears, the existing information security system will face the risk of systematic collapse. To cope with this post-quantum crisis, quantum secure cryptography technology has emerged, mainly including anti-quantum cryptographic algorithms based on mathematical problems and quantum key distribution technology based on physical principles. However, in the transition period of post-quantum cryptography migration, the whole life cycle management of key generation, storage, distribution, use and destruction faces new challenges: on the one hand, anti-quantum cryptographic algorithms (such as lattice-based algorithms) usually generate longer key sizes and require higher storage and computing resources; on the other hand, pure software- implemented key management systems are vulnerable to side-channel attacks, malicious software intrusion, etc. Although traditional key management schemes based on hardware security modules provide some protection, their core chips may still be attacked by future quantum computers. In the existing technology, there are schemes that use security chips for key management, but most of them are not designed specifically for quantum threats, lack hardware optimization support for post-quantum cryptographic algorithms, and do not fully consider deep integration with quantum key distribution networks. At the same time, existing schemes have deficiencies in terms of resistance to physical attacks, trusted execution environment construction, and smooth transition with traditional cryptographic systems. Therefore, there is an urgent need for a hardware-level key management scheme that can resist quantum computing threats, support hybrid cryptographic systems, and have high security levels to ensure the long-term security of future digital infrastructure. SUMMARY
[0003] Therefore, it is necessary to provide a hardware-level key management scheme that can resist quantum computing threats, support hybrid cryptographic systems, and have high security levels to ensure the long-term security of future digital infrastructure based on a quantum security chip carrier to solve the above technical problems.
[0004] In a first aspect, a key management method based on a quantum security chip carrier is provided, the method comprising: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing it in a secure storage area of the quantum security chip carrier; According to the preset key derivation algorithm, different levels of sub-keys are generated from the root key, the different levels correspond to the secure storage area one by one, and the sub-keys include device keys, application keys and session keys; In response to the generation of the root key and the sub-keys being completed, integrity verification is performed on the root key and the sub-keys, in response to the verification being successful, a key digest corresponding to the root key and the sub-keys is calculated through a hash algorithm, and the key digest is stored in an audit log area of the quantum security chip carrier, and the generation time, generation path and associated device information of the root key and the sub-keys are recorded; In response to receiving a key service request sent by an external device, the identity information of the external device is verified based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to the verification being successful, the corresponding level key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum security transmission channel.
[0005] Optionally, initializing the quantum security chip carrier to generate a unique identity of the quantum security chip carrier includes: In response to the quantum security chip carrier being powered on, PUF feature information of the quantum security chip carrier is obtained; A quantum random number generator in the quantum security chip carrier is called to generate a first auxiliary random entropy source; The PUF feature information and the first auxiliary random entropy source are combined and input to a hash operation circuit of the quantum security chip carrier to generate the unique identity of the quantum security chip carrier, and the unique identity is written into a read-only storage area of the quantum security chip carrier.
[0006] Optionally, the root key is generated by a quantum random number generator, a mapping relationship between the root key and the unique identity is generated and stored in a secure storage area of the quantum security chip carrier, including: The secure storage area of the quantum security chip carrier, and the partition attribute information and associated features of the secure storage area are determined; Based on the partition attribute information and the associated features, an initial secure storage fingerprint is determined; Based on a preset order, a target secure storage fingerprint corresponding to the initial secure storage fingerprint is determined; Based on the quantum random number generator, a second auxiliary random entropy source is generated, and the unique identity and the target secure storage fingerprint are obtained; Based on the second auxiliary random entropy source, the unique identity and the target secure storage fingerprint, the root key is generated through a preset key generation algorithm; Based on the root key and the unique identity, a mapping relationship, a mapping verification code corresponding to the mapping relationship, and a partition feature digest are generated, the root key is stored in a secure storage area of the quantum security chip carrier, and the mapping verification code and the partition feature digest are written into a log in an audit log area.
[0007] Optionally, based on a preset key derivation algorithm, different levels of sub-keys are generated according to the root key, including: Based on a hierarchical storage mechanism of the secure storage area, an associated attribute feature of a level is obtained, and based on the associated attribute feature of the level, a sub-key encryption strength parameter and a level associated feature matrix are determined; The root key and a level random factor are obtained, and based on the root key, the level random factor, the sub-key encryption strength parameter, and the level associated feature matrix, a sub-key corresponding to a level is determined; Based on a level attribute of the level, the sub-key is stored in a corresponding level of the secure storage area, and the key encryption strength parameter, the life cycle information, and the level associated feature of the sub-key are written into a log in the audit log area.
[0008] Optionally, in response to completion of generation of the root key and the sub-key, integrity verification of the root key and the sub-key includes: Reference key integrity credentials generated when the root key and the sub-key are stored are read respectively, and current key integrity credentials are determined; The current key integrity credentials of the target key are compared with the reference key integrity credentials; In response to consistency in comparison, it is determined that the integrity verification of the target key is successful, the current key integrity credentials are stored in the audit log area, and the reference key integrity credentials are deleted; In response to inconsistency in comparison, it is determined that the integrity verification of the target key is unsuccessful, and an exception handling process is triggered.
[0009] Optionally, in response to successful verification, a key digest corresponding to the root key and the sub-key is calculated by a hash algorithm, and the key digest is stored in the audit log area of the quantum security chip carrier, and the generation time, the generation path, and the associated device information of the root key and the sub-key are recorded, including: A preset hash algorithm is used to operate on the root key and the sub-key respectively to generate a unique corresponding key digest; The generation time, the generation path, and the associated device information of each key temporarily stored in the audit log area are extracted, and a corresponding associated data set is constructed in combination with the key digest; The associated data set is encrypted and transmitted to the audit log area for classified storage. In response to the completion of the classified storage, a data archiving credential is generated and temporarily stored in a temporary buffer area.
[0010] Optionally, in response to receiving a key service request sent by an external device, the identity information of the external device is verified based on a two-way identity authentication mechanism through the quantum security chip carrier, and in response to successful verification, a corresponding hierarchical key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum security transmission channel, including: The key service request is parsed to obtain the identity credential of the external device, the request type, and the target key identifier; Based on the identity credential of the quantum security chip carrier and the identity credential of the external device, two-way identity authentication and key negotiation are completed through a post-quantum cryptographic algorithm to establish a shared session master key; According to the identity credential, the request type, and the target key identifier, and in combination with the audit state of the target key, it is determined whether access is allowed; In response to allowing access, the target key of the corresponding partition is called according to the request type; In response to the request type being a computing service request, the target key is used to process input data and output a processing result; In response to the request type being a key distribution request, the target key is key-encapsulated in the quantum security chip carrier using the session temporary public key of the external device to generate a key capsule; The processing result or the key capsule is transmitted to the external device through a quantum security transmission channel.
[0011] In a second aspect, a key management device based on a quantum security chip carrier is provided, and the device includes: A first processing module is configured to initialize the quantum security chip carrier, generate a unique identity of the quantum security chip carrier, and generate a root key through a quantum random number generator. The root key and the unique identity are mapped and stored in a secure storage area of the quantum security chip carrier; A second processing module is configured to generate different levels of sub-keys based on a preset key derivation algorithm according to the root key, the different levels corresponding one-to-one to the secure storage area, and the sub-keys including a device key, an application key, and a session key; The third processing module is configured to, in response to completion of generation of the root key and the sub-key, perform integrity verification on the root key and the sub-key, in response to successful verification, calculate a key digest corresponding to the root key and the sub-key by using a hash algorithm, and store the key digest in an audit log area of the quantum security chip carrier, while recording generation time, a generation path and associated device information of the root key and the sub-key; The fourth processing module is configured to, in response to receiving a key service request sent by an external device, verify identity information of the external device based on a two-way identity authentication mechanism by using the quantum security chip carrier, in response to successful verification, call a corresponding hierarchical key according to a type of the key service request, and encrypt the key and transmit the key to the external device through a quantum security transmission channel.
[0012] In a third aspect, a computer device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the following steps when executing the computer program: The quantum security chip carrier is initialized, a unique identity of the quantum security chip carrier is generated, and a root key is generated by using a quantum random number generator, a mapping relationship between the root key and the unique identity is generated and stored in a secure storage area of the quantum security chip carrier; Based on a preset key derivation algorithm, different hierarchical sub-keys are generated according to the root key, the different hierarchical sub-keys correspond to the secure storage area one by one, and the sub-keys include a device key, an application key and a session key; The third processing module is configured to, in response to completion of generation of the root key and the sub-key, perform integrity verification on the root key and the sub-key, in response to successful verification, calculate a key digest corresponding to the root key and the sub-key by using a hash algorithm, and store the key digest in an audit log area of the quantum security chip carrier, while recording generation time, a generation path and associated device information of the root key and the sub-key; The fourth processing module is configured to, in response to receiving a key service request sent by an external device, verify identity information of the external device based on a two-way identity authentication mechanism by using the quantum security chip carrier, in response to successful verification, call a corresponding hierarchical key according to a type of the key service request, and encrypt the key and transmit the key to the external device through a quantum security transmission channel.
[0013] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program is executable on a processor to implement the following steps: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing the mapping relationship in a secure storage area of the quantum security chip carrier; generating different levels of sub-keys according to the root key based on a preset key derivation algorithm, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; in response to completion of generation of the root key and the sub-keys, performing integrity verification on the root key and the sub-keys, in response to successful verification, calculating a key digest corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, while recording generation time, generation path, and associated device information of the root key and the sub-keys; in response to receiving a key service request sent by an external device, verifying identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to successful verification, calling a corresponding level key according to a type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel.
[0014] In a fifth aspect, a computer program product is provided, which includes a computer program, and the computer program, when executed by a processor, implements the following steps: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing the mapping relationship in a secure storage area of the quantum security chip carrier; generating different levels of sub-keys according to the root key based on a preset key derivation algorithm, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; in response to completion of generation of the root key and the sub-keys, performing integrity verification on the root key and the sub-keys, in response to successful verification, calculating a key digest corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, while recording generation time, generation path, and associated device information of the root key and the sub-keys; in response to receiving a key service request sent by an external device, verifying identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to successful verification, calling a corresponding level key according to a type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel.
[0015] The key management method and device based on the quantum security chip carrier, the method comprises: initializing the quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing the mapping relationship in a secure storage area of the quantum security chip carrier; based on a preset key derivation algorithm, generating different levels of sub-keys according to the root key, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key and a session key; in response to the completion of the generation of the root key and the sub-keys, performing integrity verification on the root key and the sub-keys, in response to the successful verification, calculating a key digest corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, while recording the generation time, the generation path and the associated device information of the root key and the sub-keys; in response to receiving a key service request sent by an external device, verifying the identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to the successful verification, calling the corresponding level key according to the type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel, the application generates a unique UID and establishes a mapping relationship through a quantum random number generator combined with a PUF technology, and performs hierarchical derivation and partition storage on the sub-keys, thereby constructing a ternary binding mechanism of chip unique identity, quantum random entropy source and storage environment fingerprint, and realizing the safe management and control of the whole life cycle of the key through integrity verification, two-way identity authentication and quantum security transmission channel, effectively resisting quantum attacks and security threats, and improving the security, credibility, traceability and adaptability of the key management. BRIEF DESCRIPTION OF DRAWINGS
[0016] Figure 1 An application environment diagram of the key management method based on the quantum security chip carrier in one embodiment; Figure 2 A flowchart of the key management method based on the quantum security chip carrier in one embodiment; Figure 3 A structural block diagram of the key management device based on the quantum security chip carrier in one embodiment; Figure 4 An internal structure diagram of a computer device in one embodiment. DETAILED DESCRIPTION
[0017] In order to make the purposes, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0018] It should be understood that in the description of the present application, unless the context clearly requires otherwise, the terms "comprise", "comprise", and the like in the entire specification mean the inclusive meaning rather than the exclusive or exhaustive meaning; that is, the meaning of "including but not limited to".
[0019] It should also be understood that the terms "first", "second", and the like are only for the purpose of description, and cannot be understood as indicating or implying relative importance. In addition, in the description of the present application, unless otherwise stated, the meaning of "multiple" is two or more.
[0020] It should be noted that the terms "S1", "S2" and the like are only for the purpose of describing the steps, and do not specifically refer to the order or position, nor are they used to limit the present application. They are only for the convenience of describing the method of the present application, and cannot be understood as indicating the order of the steps. In addition, the technical solutions of various embodiments can be combined with each other, but must be based on the fact that a person of ordinary skill in the art can realize it. When the combination of technical solutions contradicts each other or cannot be realized, it should be considered that the combination of technical solutions does not exist, nor is it within the scope of protection required by the present application.
[0021] The key management method based on quantum security chip carrier provided by the present application can be applied to the application environment as shown in Figure 1 . Among them, the terminal 102 communicates with the data processing platform set on the server 104 through the network, wherein the terminal 102 can be but not limited to various personal computers, notebook computers, smart phones, tablet computers and portable wearable devices, and the server 104 can be realized by an independent server or a server cluster composed of multiple servers.
[0022] In one embodiment, as shown in Figure 2 , a key management method based on quantum security chip carrier is provided. Taking the terminal in Figure 1 as an example, the method includes the following steps: S1: initializing the quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing it in the secure storage area of the quantum security chip carrier.
[0023] It should be noted that the quantum security chip carrier is a hardware security module integrating QRNG (quantum random number generator), PUF and post-quantum cryptographic coprocessor, providing a quantum computing and physical attack resistant root of trust for key management, the unique identity refers to UID, the root key is a top-level key generated by a quantum random entropy source and stored in the most secure area of the chip, is a trust source for deriving all sub-keys, never leaves the chip, the sub-key is a key derived from the root key, including long-term device key, medium-term application key and temporary session key, realizing the permission separation and life cycle management of key use, the quantum random number generator is a true random number generator based on quantum physical process (such as photon randomness), which provides an unpredictable high-quality entropy source for cryptographic applications.
[0024] S2: Based on the preset key derivation algorithm, different levels of sub-keys are generated according to the root key, the different levels correspond one-to-one to the secure storage area, and the sub-keys include device keys, application keys and session keys.
[0025] S3: In response to the completion of the root key and the sub-key generation, the integrity of the root key and the sub-key is checked, in response to the successful checking, the key digest corresponding to the root key and the sub-key is calculated through a hash algorithm, and the key digest is stored in the audit log area of the quantum security chip carrier, and the generation time, generation path and associated device information of the root key and the sub-key are recorded.
[0026] It should be noted that the integrity check is a security detection mechanism for verifying whether the key data is tampered with during storage or transmission through cryptographic hash or message authentication code, the audit log area is a tamper-proof storage area in the chip, used to record the operation events in the whole life cycle of the key, supporting security audit and traceability analysis.
[0027] S4: In response to receiving a key service request sent by an external device, the identity information of the external device is verified through the quantum security chip carrier based on a two-way identity authentication mechanism, in response to the successful verification, the corresponding level key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum secure transmission channel.
[0028] It should be noted that the two-way identity authentication mechanism is a process of mutual authentication of the chip and the external device based on digital certificate or pre-shared key, ensuring the authenticity and credibility of both parties in communication, the quantum secure transmission channel is an encrypted communication link established based on post-quantum cryptographic algorithm, which can resist quantum computing attacks and ensure the security of the key distribution process.
[0029] In some embodiments, initializing a quantum secure chip carrier, generating a unique identity of the quantum secure chip carrier comprises: In response to the quantum secure chip carrier being powered on, acquiring PUF feature information of the quantum secure chip carrier, wherein PUF feature refers to physical unclonable function collecting inherent physical features of a chip, which can include, for example, transistor threshold voltage fluctuation, metal line delay difference, etc. Calling a quantum random number generator in the quantum secure chip carrier to generate a first auxiliary random entropy source; Combining the PUF feature information and the first auxiliary random entropy source, and inputting them to a hash operation circuit of the quantum secure chip carrier to generate a unique identity of the quantum secure chip carrier, and writing the unique identity into a read-only storage area of the quantum secure chip carrier, i.e. through hash calculation of the PUF feature information and the first auxiliary random entropy source by a hash algorithm, a fixed-length digital string (such as a 256-bit hash value) is generated, which is defined as the unique identity of the quantum secure chip carrier.
[0030] In some embodiments, generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing it in a secure storage area of the quantum secure chip carrier comprises: The secure storage area of the quantum-safe chip carrier is determined, along with its partition attributes and associated characteristics. The secure storage area is divided into a root key area, sub-key areas, an identity identification area, an audit log area, and a temporary cache area. Partition attribute information may include the physical address range of each partition, storage type (e.g., OTP, EEPROM, SRAM), a unique identifier for the access control circuit, and slight electrical characteristics of the storage cells in that partition measured by a lightweight PUF mechanism. Associated characteristics may include independent characteristics and associated characteristics between every two partitions. Independent characteristics may include the read-only characteristic of the root key area, the hierarchical storage characteristics of the sub-key area, the unique binding characteristic of the identity identification area, the immutability characteristic of the audit log area, and the power-off clearing characteristic of the temporary cache area. Associated characteristics may include access path association, storage verification association, lifecycle linkage, physical isolation characteristics, and resource contention characteristics. For example, access path association means that reading the key from the root key area is a prerequisite for accessing the sub-key area, forming a hardware-mandated access dependency chain. Storage verification association may include the audit log area recording operation events in the sub-key area, with the two forming a cryptographic binding through structures such as Merkle trees. Physical isolation characteristics may include hardware isolation walls (e.g., Guard) between partitions. The impedance characteristics or signal delay parameters of the Ring, and the resource contention characteristics can be the timing characteristics when multiple partitions access the shared bus at the same time, forming a dynamic behavior association pattern. In this pattern, any anomaly of a single partition (such as being attacked) will be detected through changes in the association characteristics, thereby achieving system-level security awareness. Based on the partition attribute information and the associated features, an initial secure storage fingerprint is determined. Specifically, a secure storage coefficient between the partition attribute information and the associated features is calculated using a first objective function, which includes: in, For safe storage factor, , , , , and All are weighting coefficients. This represents the quantized value of the partition attribute information. This represents the quantified value of the associated feature. This represents the quantified values of the remaining influencing factors. Indicates the number of partition attribute information. Indicates the number of associated features. Indicates the number of other influencing factors. Indicates the first Partition attribute information, Indicates the first One related feature, Indicates the first The rest of the influencing factors, wherein the partition attribute information quantization value, the correlation feature quantization value and the rest of the influencing factor quantization value are all generated through a mapping relationship list corresponding to the initial quantization value, and the final quantization value is obtained through standardization processing. The mapping relationship is generated by model training or expert assignment method in advance. For example, the partition attribute information is the storage type such as OTP, EEPROM, SRAM, the OTP is high physical security, the assignment value is 3, the SRAM security is low, the assignment value is 1, the EEPROM security is medium, the assignment value is 2, the root key area in the correlation feature is read-only feature security level, the assignment value is 3, and so on. The access path association is to read the key from the root key area, which is the premise of accessing the sub-key area, so the root key area and the three sub-key areas are all associated, the number of associations is 3, and the assignment value is 3. It is defined as the correlation feature quantization value. It is not repeated here. After obtaining the security storage coefficient, the operation result is determined as the final initial security storage fingerprint through lightweight hash operation; Based on the preset order, the target security storage fingerprint corresponding to the initial security storage fingerprint is determined, wherein the preset order can be set according to actual needs, such as address order. Based on the order, the initial security storage fingerprints of all partitions are subjected to hash operation again to obtain the final target security storage fingerprint; Based on the quantum random number generator, a second auxiliary random entropy source is generated, and the unique identity and the target security storage fingerprint are obtained, wherein a high-entropy true random number sequence is output by the quantum random number generator, that is, the second auxiliary random entropy source; Based on the second auxiliary random entropy source, the unique identity and the target security storage fingerprint, the root key is generated through a preset key generation algorithm. Specifically, the target security storage fingerprint is taken as a salt value, the second auxiliary random entropy source and the unique identity are combined (such as the second auxiliary random entropy source || unique identity) as input key material, and a preset KDF (such as HMAC-SHA256 based HKDF) is calculated to output a bit sequence of a specified length L (such as 256 bits), that is, the final root key K root ; Based on the root key and the unique identity, a mapping relationship and a mapping verification code and a partition feature digest corresponding to the mapping relationship are generated. The root key is stored in the secure storage area of the quantum security chip carrier, and the mapping verification code and the partition feature digest are written into the log of the audit log area. The mapping verification code generates the corresponding mapping relationship, and the partition feature digest is generated by inputting the collected features into a cryptographic hash function. The features can include the above-mentioned partition attribute features.
[0031] In some embodiments, generating different levels of sub-keys from the root key based on a preset key derivation algorithm comprises: Based on the hierarchical storage mechanism of the secure storage area, the associated attribute characteristics of the level are obtained, and based on the associated attribute characteristics of the level, the sub-key encryption strength parameter and the level association feature matrix are determined. Specifically, the associated attribute characteristics can include the binding association characteristics of the device key and the application key, the session subordinate association characteristics of the application key and the session key, etc. The specific expression of the level association feature matrix M is: M=[M1;M2;M3], wherein M1 is the level association feature sub-matrix corresponding to the device key, M1=[root key association weight, device identification feature, sub-key area device partition access permission feature], M2 is the device-application association feature sub-matrix, M2=[device key association weight, application unique identifier ID, application scenario security level, sub-key area application partition access permission feature], and M3 is the application-session association feature sub-matrix M3=[application key association weight, session timestamp T, session validity period, sub-key area session partition access permission feature]. In each sub-matrix, the feature parameters are standardized by 0-1, and the weight values are dynamically allocated according to the key level security priority, such as root key association weight>device key association weight>application key association weight. The second objective function is used to calculate the sub-key encryption strength parameter, and the second objective function includes: wherein, represents the device key encryption strength parameter, represents the application key encryption strength parameter, represents the session key encryption strength parameter, represents the integer function, represents the basic security strength, which is determined by the root key strength, such as AES-256 corresponding strength value 256, etc. , , respectively represent the level of the sub-key, such as device key 1, application key 2, etc. , , all represent the business criticality coefficient, such as device authentication=1.2, user data encryption=1, etc. represents the device identification credibility weight, represents the application scenario security level, represents the session validity period weight, represents the partition access permission level, represents the device key association weight, representing an application key association weight; obtaining the root key and the hierarchical random factor, determining the sub-key of the corresponding level based on the root key, the hierarchical random factor, the sub-key encryption strength parameter and the hierarchical association feature matrix, specifically, generating the device key P1 through the formula P1=LHF(K root , M1, Q1), generating the application key P2 through P2=LHF(K root , M2, ID, Q2), and generating the session key P3 through P3=LHF(K root , M3, T, Q3), wherein LHF represents a lattice-based hash function; based on the level attribute of the level, storing the sub-key to the corresponding level of the secure storage area, and synchronously writing the key encryption strength parameter, the life cycle information and the hierarchical association feature of the sub-key into the log of the audit log area, that is, storing the device key, the application key and the session key in the device key partition, the application key partition and the session key partition of the sub-key area of the secure storage area respectively, and synchronously recording the encryption strength parameter, the life cycle information and the hierarchical association feature of each sub-key to the audit log area.
[0032] In some embodiments, in response to the root key and the sub-key generation being completed, the integrity check of the root key and the sub-key comprises: respectively reading the reference key integrity credential generated when the root key and the sub-key are stored, and determining the current key integrity credential, wherein the key integrity credential can be an original digest value calculated through a hash algorithm (such as SHA-3) according to the root key of the root key area of the secure storage area, the sub-key (device key, application key, session key) of each partition of the sub-key area, the key generation time, the derivation path and the associated device information recorded in the audit log area, or for the root key, the integrity credential thereof is obtained through message authentication code calculation by the local key derived by the hash operation of the key ciphertext, the storage environment fingerprint and the unique identity, and for any level of sub-key, the integrity credential thereof is obtained through message authentication code calculation by the local key after the hash operation of the sub-key ciphertext, the identification information of the parent key thereof and the derivation parameter at the time of generation, which can be selected according to actual needs, the reference key integrity credential is generated when stored, and stored in the temporary storage area, and the current key integrity credential is generated when a certain key needs to be accessed or used or according to a preset period; comparing the current key integrity credential of the target key with the reference key integrity credential; in response to the comparison being consistent, determining that the integrity check of the target key is successful, storing the current key integrity credential to the audit log area, and deleting the reference key integrity credential; In response to the inconsistency, it is determined that the integrity check of the target key is unsuccessful, an exception handling process is triggered, such as clearing the abnormal key, re-executing the key generation process, and recording the exception information to the audit log area.
[0033] In some embodiments, in response to the successful check, a key digest corresponding to the root key and the sub-key is calculated by a hash algorithm, and the key digest is stored in the audit log area of the quantum security chip carrier, while recording the generation time, generation path and associated device information of the root key and the sub-key, including: The preset hash algorithm (such as SHA-3) is used to operate the root key and the sub-key respectively to generate a unique corresponding key digest, wherein the exclusive features of each key (the mapping relationship feature of the root key associated with the UID, the hierarchical association attribute feature of the sub-key, etc.) are integrated in the calculation process; The generation time, generation path and associated device information of each key temporarily stored in the audit log area are extracted, and a corresponding associated data set is constructed by combining the key digest, that is, a corresponding mapping set is generated; After the associated data set is encrypted and transmitted to the audit log area for classified storage, that is, after being encrypted by the built-in encryption algorithm of the chip, it is transmitted to the audit log area of the secure storage area for storage, and when stored, it is sequentially archived according to the classification rule of root key related data-sub-key related data; In response to the completion of the classified storage, a data archive credential is generated and temporarily stored in a temporary cache area for subsequent audit verification, and the temporary cache area data is automatically cleared after the storage operation is completed.
[0034] In some embodiments, in response to receiving a key service request sent by an external device, the identity information of the external device is verified by the quantum security chip carrier based on a two-way identity authentication mechanism, and in response to the successful verification, the corresponding hierarchical key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum security transmission channel, including: The key service request is parsed to obtain the identity credential, request type and target key identifier of the external device, such as device key calling, application key calling or session key calling, calculation service request or key distribution request; Based on the identity certificate of the quantum secure chip carrier and the identity certificate of the external device, two-way identity authentication and key negotiation are completed through a post-quantum cryptographic algorithm to establish a shared session master key, that is, the chip uses an internally pre-stored or dynamically updated root certificate to verify the legitimacy and validity of the external device certificate, and the external device uses a pre-stored chip CA certificate to verify the legitimacy of the chip identity. After the certificate verification is passed, both parties perform a post-quantum key exchange protocol (such as CRYSTALS-Kyber based on lattice), and the chip uses its internal post-quantum cryptographic coprocessor to negotiate a session master key SMK with the external device to ensure that the key negotiation process of this session is secure even in the face of future quantum computers. According to the identity certificate, the request type and the target key identifier, and in combination with the audit state of the target key, it is determined whether access is allowed. Specifically, the session master key is used to ensure the confidentiality and integrity of subsequent communication, and the real-time nature of the request is verified, the internal policy engine is called, and access control decisions are made according to the external device identity, the request type and the target key identifier, and in combination with the audit state of the target key (such as non-locking, non-expiration, etc.). Thus, the external device identity (extracted from the certificate) is authorized to request such services (request type) and this specific key (target key identifier), the target key is in a usable state, and the request use case (such as associated information obtained from the audit log) meets the key life cycle policy, and only when all checks pass, the access control decision is passed. In response to the access being allowed, that is, the access control decision is passed, the target key of the corresponding partition is called according to the request type, such as calling the device key partition of the corresponding sub-key area for the device key, calling the application key partition of the corresponding sub-key area for the application key, and calling the session key partition of the corresponding sub-key area for the session key. In response to the request type being a computing service request, the target key is used to process input data and output a processing result, that is, the external device sends data to the chip, the chip performs operations (encryption / decryption / signature) using the target key internally, and only the result is output. In response to the request type being a key distribution request, the target key is encapsulated in the quantum secure chip carrier using the session temporary public key of the external device to generate a key capsule, that is, the target key is encapsulated in the chip using a post-quantum cryptographic algorithm to generate a key capsule. The processing result or the key capsule is transmitted to the external device through a quantum secure transmission channel, and the external device can use its own corresponding private key to unencapsulate, that is, the corresponding result can be obtained.
[0035] In some embodiments, the operating environment parameters of the quantum security chip carrier are monitored in real time, and the operating environment parameters include voltage Z1, frequency Z2 and temperature Z3; When any parameter is monitored to be out of the preset safe range or an abnormal fault injection mode is detected, and / or, y = f1Z1 + f2Z2 + f3Z3 > V, a protection mechanism is triggered immediately, wherein y represents a security response value, f1, f2 and f3 are weight coefficients, and V is a preset threshold. The preset safe range and the preset threshold can be set according to actual requirements. The protection mechanism includes at least one of clearing the working key in the volatile register and making the security storage area enter a locked state.
[0036] In the above key management method based on the quantum security chip carrier, the method includes: initializing the quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator; a mapping relationship between the root key and the unique identity is generated and stored in a security storage area of the quantum security chip carrier; based on a preset key derivation algorithm, different levels of sub-keys are generated according to the root key, the different levels correspond to the security storage area one by one, and the sub-keys include device keys, application keys and session keys; in response to completion of generation of the root key and the sub-keys, integrity verification is performed on the root key and the sub-keys, in response to successful verification, a key digest corresponding to the root key and the sub-keys is calculated through a hash algorithm, and the key digest is stored in an audit log area of the quantum security chip carrier, and the generation time, generation path and associated device information of the root key and the sub-keys are recorded; in response to receiving a key service request sent by an external device, identity information of the external device is verified through the quantum security chip carrier based on a two-way identity authentication mechanism, in response to successful verification, a corresponding level key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum security transmission channel. The application generates a unique UID and establishes a mapping relationship through a quantum random number generator combined with PUF technology, and sub-keys are derived and stored in different layers, a ternary binding mechanism of chip unique identity, quantum random entropy source and storage environment fingerprint is constructed, key life cycle safety control is realized through integrity verification, two-way identity authentication and quantum security transmission channel, quantum attacks and security threats are effectively resisted, and the security, credibility, traceability and adaptability of key management are improved.
[0037] It should be understood that, although Figure 2 The steps in the flowchart of FIG. 1 1 are shown in sequential order following the arrows, but these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specifically noted, the execution of these steps is not strictly limited in sequence, and these steps can be performed in other orders. Moreover,Figure 2 At least one of the steps in the above method can include a plurality of sub-steps or a plurality of stages, which are not necessarily performed at the same time, but can be performed at different times, and the order of the execution of the sub-steps or stages is not necessarily sequential, but can be performed alternately or alternately with at least one of the other steps or sub-steps or stages of the other steps.
[0038] In one embodiment, as shown in Figure 3 A quantum security chip carrier-based key management device is provided, comprising: A first processing module is configured to initialize a quantum security chip carrier, generate a unique identity of the quantum security chip carrier, and generate a root key by a quantum random number generator, generate a mapping relationship between the root key and the unique identity, and store the mapping relationship in a secure storage area of the quantum security chip carrier; A second processing module is configured to generate different levels of sub-keys based on a preset key derivation algorithm according to the root key, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; A third processing module is configured to, in response to the generation of the root key and the sub-keys being completed, perform integrity verification on the root key and the sub-keys, in response to the verification being successful, calculate a key digest corresponding to the root key and the sub-keys by a hash algorithm, and store the key digest in an audit log area of the quantum security chip carrier, and record the generation time, the generation path, and the associated device information of the root key and the sub-keys; A fourth processing module is configured to, in response to receiving a key service request sent by an external device, verify the identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to the verification being successful, call a corresponding level key according to the type of the key service request, and encrypt and transmit the key to the external device through a quantum security transmission channel.
[0039] The specific limitations of the quantum security chip carrier-based key management device can be referred to the limitations of the quantum security chip carrier-based key management method described above, which will not be repeated here. Each module in the above quantum security chip carrier-based key management device can be realized by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0040] In one embodiment, a computer device is provided, which can be a terminal, and its internal structure diagram can be as shown in Figure 4As shown in the figure. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The network interface of the computer device is used to communicate with the external terminal through the network connection. The computer program is executed by the processor to implement a quantum security chip carrier-based key management method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the shell of the computer device, or an external keyboard, touchpad or mouse, etc.
[0041] Those skilled in the art can understand that, Figure 4 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0042] In one embodiment, a computer device is provided, including a memory, a processor and a computer program stored on the memory and executable on the processor, and the processor executes the computer program to implement the following steps: S1: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing it in a secure storage area of the quantum security chip carrier; S2: generating different levels of sub-keys according to the root key based on a preset key derivation algorithm, the different levels corresponding one-to-one to the secure storage area, the sub-keys including a device key, an application key and a session key; S3: in response to the completion of the generation of the root key and the sub-keys, performing integrity verification on the root key and the sub-keys, in response to successful verification, calculating a key digest corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, while recording the generation time, the generation path and the associated device information of the root key and the sub-keys; S4: in response to receiving a key service request sent by an external device, verifying identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to successful verification, calling a corresponding level key according to a type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel.
[0043] In one embodiment, a computer readable storage medium is provided, and the computer readable storage medium has stored thereon a computer program, and the computer program is executed by a processor to implement the following steps: S1: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity, and storing the mapping relationship in a secure storage area of the quantum security chip carrier; S2: generating sub-keys of different levels based on a preset key derivation algorithm according to the root key, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; S3: in response to completion of generation of the root key and the sub-keys, performing integrity verification on the root key and the sub-keys, in response to successful verification, calculating a key digest corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, and recording generation time, generation path, and associated device information of the root key and the sub-keys; S4: in response to receiving a key service request sent by an external device, verifying identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to successful verification, calling a corresponding level key according to a type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel.
[0044] In one embodiment, a computer program product is provided, and the computer program product includes a computer program, and the computer program is executed by a processor to implement the following steps: S1: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity, and storing the mapping relationship in a secure storage area of the quantum security chip carrier; S2: generating sub-keys of different levels based on a preset key derivation algorithm according to the root key, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; S3: in response to the root key and the sub-key generation being completed, performing integrity check on the root key and the sub-key, in response to the check being successful, calculating a key digest corresponding to the root key and the sub-key through a hash algorithm, and storing the key digest in an audit log area of the quantum security chip carrier, while recording the generation time, generation path and associated device information of the root key and the sub-key; S4: in response to receiving a key service request sent by an external device, verifying the identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to the verification being successful, calling a corresponding hierarchical key according to the type of the key service request, and transmitting the key to the external device through a quantum security transmission channel.
[0045] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware, and the computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In the embodiments provided in the present application, any reference to memory, storage, database or other medium can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM) and memory bus dynamic RAM (RDRAM).
[0046] The technical features of the above embodiments can be combined in any way. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0047] The above embodiments only express several implementation ways of the present application, and the description is more specific and detailed, but it should not be understood as a limitation to the scope of the patent. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, several modifications and improvements can be made, which are all within the scope of protection of the present application.
Claims
1. A quantum secure chip carrier based key management method, characterized by, The method comprises: initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier, and generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing the root key in a secure storage area of the quantum security chip carrier; based on a preset key derivation algorithm, generating sub-keys of different levels according to the root key, the different levels corresponding to the secure storage area one by one, the sub-keys including device keys, application keys and session keys; in response to the generation of the root key and the sub-keys being completed, performing integrity verification on the root key and the sub-keys, in response to the verification being successful, calculating key digests corresponding to the root key and the sub-keys through a hash algorithm, and storing the key digests in an audit log area of the quantum security chip carrier, while recording the generation time, generation path and associated device information of the root key and the sub-keys; in response to receiving a key service request sent by an external device, verifying the identity information of the external device based on a two-way identity authentication mechanism through the quantum security chip carrier, in response to the verification being successful, calling the corresponding level key according to the type of the key service request, and encrypting and transmitting the key to the external device through a quantum security transmission channel.
2. The quantum secure chip carrier based key management method of claim 1, wherein, initializing a quantum security chip carrier, generating a unique identity of the quantum security chip carrier comprises: in response to the quantum security chip carrier being powered on, obtaining PUF feature information of the quantum security chip carrier; calling a quantum random number generator in the quantum security chip carrier to generate a first auxiliary random entropy source; combining the PUF feature information and the first auxiliary random entropy source, and inputting them into a hash operation circuit of the quantum security chip carrier to generate a unique identity of the quantum security chip carrier, and writing the unique identity into a read-only storage area of the quantum security chip carrier.
3. The quantum secure chip carrier based key management method of claim 2, wherein, generating a root key through a quantum random number generator, generating a mapping relationship between the root key and the unique identity and storing the root key in a secure storage area of the quantum security chip carrier comprises: determining the secure storage area of the quantum security chip carrier, and the partition attribute information and associated features of the secure storage area; based on the partition attribute information and the associated features, determining an initial secure storage fingerprint; based on a preset order, determining a target secure storage fingerprint corresponding to the initial secure storage fingerprint; based on the quantum random number generator, generating a second auxiliary random entropy source, and obtaining the unique identity and the target secure storage fingerprint; based on the second auxiliary random entropy source, the unique identity and the target secure storage fingerprint, generating the root key through a preset key generation algorithm; based on the root key and the unique identity, generating a mapping relationship, a mapping verification code corresponding to the mapping relationship and a partition feature digest, storing the root key in the secure storage area of the quantum security chip carrier, and writing the mapping verification code and the partition feature digest into the log of the audit log area.
4. The quantum secure chip carrier based key management method of claim 3, wherein, generating different levels of sub-keys from the root key based on a preset key derivation algorithm comprises: based on the hierarchical storage mechanism of the secure storage area, obtaining the associated attribute characteristics of the level, based on the associated attribute characteristics of the level, determining the sub-key encryption strength parameter and the level association feature matrix; obtaining the root key and the level random factor, based on the root key, the level random factor, the sub-key encryption strength parameter and the level association feature matrix, determining the sub-key of the corresponding level; based on the level attribute of the level, the sub-key is stored to the corresponding level of the secure storage area, and the key encryption strength parameter, the life cycle information and the level association feature of the sub-key are written into the log of the audit log area.
5. The quantum secure chip carrier based key management method of claim 4, wherein, in response to the completion of the root key and the sub-key generation, the integrity check of the root key and the sub-key comprises: respectively reading the reference key integrity certificate generated when the root key and the sub-key are stored, and determining the current key integrity certificate; comparing the current key integrity certificate of the target key with the reference key integrity certificate; in response to the comparison being consistent, it is determined that the integrity check of the target key is successful, the current key integrity certificate is stored to the audit log area, and the reference key integrity certificate is deleted; in response to the comparison being inconsistent, it is determined that the integrity check of the target key is unsuccessful, and an exception handling process is triggered.
6. The quantum secure chip carrier based key management method of claim 5, wherein, in response to the successful check, the key digest corresponding to the root key and the sub-key is calculated through a hash algorithm, and the key digest is stored in the audit log area of the quantum security chip carrier, and the generation time, generation path and associated device information of the root key and the sub-key are recorded simultaneously, comprising: using a preset hash algorithm to operate on the root key and the sub-key respectively to generate a unique corresponding key digest; extracting the temporarily stored key generation time, generation path and associated device information in the audit log area, combining the key digest to construct a corresponding associated data set; after encryption processing of the associated data set, it is transmitted to the audit log area for classified storage; in response to the completion of the classified storage, a data archiving certificate is generated and temporarily stored in a temporary cache area.
7. The quantum secure chip carrier based key management method of claim 6, wherein, in response to receiving a key service request sent by an external device, the identity information of the external device is verified through the quantum security chip carrier based on a two-way identity authentication mechanism, and in response to the successful verification, the corresponding level key is called according to the type of the key service request, and the key is encrypted and transmitted to the external device through a quantum security transmission channel, comprising: parsing the key service request to obtain the identity certificate, request type and target key identifier of the external device; based on the identity certificate of the quantum security chip carrier and the identity certificate of the external device, two-way identity authentication and key negotiation are completed through a post-quantum cryptographic algorithm to establish a shared session master key; determine whether it can be accessed according to the identity certificate, the request type and the target key identifier, and combine the audit state of the target key; in response to the request type being a computing service request, processing input data using the target key and outputting a processing result; in response to the request type being a key distribution request, key wrapping the target key within the quantum secure chip carrier using a session ephemeral public key of the external device to generate a key capsule; transmitting the processing result or the key capsule to the external device through a quantum secure transmission channel. The apparatus comprises:
8. A quantum secure chip carrier based key management apparatus, characterized by, a first processing module configured to initialize a quantum secure chip carrier, generate a unique identity of the quantum secure chip carrier, and generate a root key through a quantum random number generator, generate a mapping relationship between the root key and the unique identity, and store the mapping relationship in a secure storage area of the quantum secure chip carrier; a second processing module configured to generate different levels of sub-keys from the root key based on a preset key derivation algorithm, the different levels corresponding to the secure storage area one by one, the sub-keys including a device key, an application key, and a session key; a third processing module configured to, in response to the root key and the sub-keys being generated, perform integrity verification on the root key and the sub-keys, in response to the verification being successful, calculate a key digest corresponding to the root key and the sub-keys through a hash algorithm, and store the key digest in an audit log area of the quantum secure chip carrier, and record a generation time, a generation path, and associated device information of the root key and the sub-keys; a fourth processing module configured to, in response to receiving a key service request sent by an external device, verify identity information of the external device based on a two-way identity authentication mechanism through the quantum secure chip carrier, in response to the verification being successful, invoke a corresponding level key according to a type of the key service request, and encrypt and transmit the key to the external device through a quantum secure transmission channel. The processor executes the computer program to implement the method in any one of claims 1 to 7.
9. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The computer program is executed by the processor to implement the method in any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that,
Citation Information
Cited By
Quantum random number-based computing power network identity authentication and permission management method and device
CN122247767A