Key management system based on continuous variable quantum key distribution and group key distribution method

By introducing a group key management system and adopting continuous variable quantum key distribution technology, the number of key synchronizations is reduced, solving the problem of low key application efficiency in large-scale communication networks, and achieving efficient and secure key distribution and management.

CN121770741APending Publication Date: 2026-03-31SHANGHAI CIRCULATION QUANTUM TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-09
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In large-scale communication network scenarios, the number of key requests for existing quantum key management systems increases exponentially with the number of users, resulting in high network bandwidth consumption and increased response latency, which cannot meet the requirements for efficient key distribution. In addition, the key synchronization times in the traditional end-to-end mode are N×(N-1)/2, which is inefficient.

Method used

A group key management system based on continuous variable quantum key distribution is introduced. Through the quantum key receiving service provider layer, application service layer, data management layer and routing calculation controller module, group collaborative key distribution is realized, the number of key synchronizations is reduced, group key and end-to-end key synchronization are supported, and security is ensured by encrypted storage and relay synchronization.

Benefits of technology

It significantly reduces the number of key synchronizations, improves system throughput and response efficiency, reduces network bandwidth usage and key application delay, enhances the overall performance of the system in high-concurrency, large-scale networking scenarios, and provides end-to-end security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770741A_ABST
    Figure CN121770741A_ABST
Patent Text Reader

Abstract

The invention provides a key management system based on continuous variable quantum key distribution and a group key distribution method. The key management system comprises a quantum key receiving service providing layer module, a quantum key application service layer module, a data management layer module and a routing calculation controller module. The quantum key receiving service providing layer module is set to receive a quantum key generated by a CVQKD terminal and execute a warehousing management process of the quantum key; the quantum key application service layer module is set to receive and authenticate a key application of a user side so as to trigger a key distribution process; the data management layer module is set to safely store the quantum key and all related data in an encryption form; and the routing calculation controller module is responsible for calculating an optimal path for key distribution and authenticating participating equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum communication technology, and more specifically, to a key management system and a group key distribution method based on continuous variable quantum key distribution. Background Technology

[0002] Quantum key distribution (QKD) technology, based on the fundamental principles of quantum mechanics, enables secure key negotiation between communicating parties. The generated keys possess unconditional "one-time pad" security, making it one of the core technologies for addressing the security threats faced by traditional cryptography in the quantum computing era. With the industrialization of QKD technology, its application scenarios have gradually expanded from early point-to-point communication to multi-node network scenarios such as metropolitan and intercity networks. This has placed higher demands on the full lifecycle management of keys, key distribution efficiency in multi-user group scenarios, and relay technologies for long-distance transmission.

[0003] In a multi-node quantum key distribution network, in an end-to-end key application scenario, each node needs to apply for keys from other nodes separately, forming a "fully connected" key distribution relationship. When the number of nodes exceeds 10, the number of key synchronizations increases quadratically (when the number of nodes is N, the number of key synchronizations is N×(N-1) / 2), resulting in excessive network bandwidth consumption and decreased key distribution efficiency, which cannot meet the needs of large-scale networking.

[0004] Existing quantum key management systems still suffer from significant efficiency bottlenecks in practical applications, especially in large-scale communication network scenarios, where the traditional end-to-end key request and distribution model faces severe challenges. These systems typically require each pair of communication terminals to independently initiate a key request and complete bidirectional synchronization, leading to an exponential increase in the number of key requests with the number of users. This not only consumes a large amount of quantum key resources but also significantly increases key request response latency, severely impacting communication efficiency in high-concurrency scenarios. Furthermore, frequent end-to-end key negotiation processes also increase the processing load on the system's service and data layers, causing key synchronization efficiency to drop sharply as the network scales up, making it difficult to meet the urgent needs of modern communication networks for efficient key supply and distribution.

[0005] Therefore, current quantum key management schemes urgently need breakthroughs at the key distribution mechanism level to address the problem of efficient key distribution in large-scale, dynamic networking environments. Against this backdrop, this invention proposes the introduction of a group key management mechanism. By upgrading the traditional point-to-point key distribution mode to a group collaborative distribution mode, the number of key requests and synchronization overhead are significantly reduced, thereby improving the overall system throughput and response efficiency. This provides key technical support for building an efficient and scalable quantum key management infrastructure.

[0006] Patent application CN116980122A discloses a quantum key distribution management system, comprising: a cloud quantum key center, an edge security domain, and terminal devices. The cloud quantum key center is used to acquire and store multiple quantum keys from a quantum key distribution network and distribute these quantum keys to the edge security domain. The edge security domain is used to acquire and store multiple quantum keys from the cloud quantum key center, allocate quantum keys to terminal devices within its jurisdiction, and provide cryptographic services. The cryptographic services include encryption and decryption. The terminal devices are used to request quantum keys from the edge security domain and invoke the edge security domain to complete the corresponding cryptographic services. However, this patent cannot completely solve the existing technical problems, nor can it meet the needs of this invention. Summary of the Invention

[0007] To address the shortcomings of existing technologies, the purpose of this invention is to provide a key management system and a group key distribution method based on continuous variable quantum key distribution.

[0008] The key management system based on continuous variable quantum key distribution provided by the present invention includes: a quantum key receiving service providing layer module, a quantum key request service layer module, a data management layer module, and a routing calculation controller module; The quantum key receiving service layer module is connected to the continuous variable quantum key distribution terminal, and is used to receive the quantum key generated by the continuous variable quantum key distribution terminal, and after encrypting the received quantum key and its related data, send the encrypted quantum key ciphertext to the data management layer module for storage. The quantum key request service layer module is connected to the user terminal and is used to receive and authenticate key request requests sent by the user terminal, and trigger the corresponding key distribution process according to the key type of the key request request; the key type includes group keys and end-to-end keys; The data management layer module is connected to the quantum key receiving service providing layer module and the quantum key requesting service layer module respectively, and is used to securely store the quantum key ciphertext and related data sent by the quantum key receiving service providing layer module in encrypted form, and respond to the query or read requests of the quantum key requesting service layer module. The routing calculation controller module is connected to the quantum key request service layer module and is used to receive path calculation requests from the quantum key request service layer module, calculate the synchronization path for the key distribution process, and authenticate the source device, destination device and relay device participating in the key distribution process. When the quantum key application service layer module triggers the group key distribution process, it obtains the optimal path to multiple group member devices through the routing calculation controller module, and distributes the ciphertext of the same group key to the multiple group member devices through the calculated synchronization path based on the optimal path.

[0009] Preferably, the quantum key receiving service providing layer module includes an encryption / decryption module and a key storage module; The encryption / decryption module is used to immediately encrypt the quantum key and its related data after the quantum key enters the quantum key receiving service providing layer module, and generate quantum key ciphertext. The key storage module is connected to the encryption / decryption module and the data management layer module, and is used to send the quantum key ciphertext generated by the encryption / decryption module to the data management layer module for storage.

[0010] Preferably, the quantum key request service layer module includes a data access interface and a request processing / data synchronization module; The data access interface is used to receive service requests from the user terminal and to authenticate the user terminal device that initiates the service request. The request processing / data synchronization module, connected to the data access interface and the routing calculation controller module, is used to parse the business request after successful authentication and trigger a data synchronization operation based on the parsed key type. The data synchronization operation includes group key synchronization and end-to-end key synchronization. When performing group key synchronization, the request processing / data synchronization module requests and obtains the synchronization path to multiple destination devices from the routing calculation controller module, and distributes the key ciphertext according to the synchronization path.

[0011] Preferably, the request processing / data synchronization module includes a request parsing unit and a synchronization strategy unit; The request parsing unit is used to parse the target device ID, request key quantity, key type and service priority parameters contained in the service request; The synchronization strategy unit is connected to the request parsing unit and is used to select a point-to-point direct connection synchronization strategy or a relay synchronization strategy via a relay node based on the key type parsed by the request parsing unit and the real-time network topology.

[0012] Preferably, the routing calculation controller module includes a device authentication unit and a routing calculation unit; The device authentication unit is used to maintain a trusted device whitelist and, before the routing calculation begins, to perform identity authentication and authorization checks on the source device, destination device and relay device participating in key synchronization based on the whitelist. The routing calculation unit is connected to the device authentication unit and is used to dynamically calculate the optimal synchronization path based on one or more factors among network topology, relay node load, link security level and service priority after the device is authenticated. The synchronization path includes direct routes and relay routes.

[0013] Preferably, the data management layer module includes a database system unit, which is used to centrally store all encrypted quantum key ciphertext data and metadata associated with the quantum key ciphertext data; the metadata includes globally unique key accounts and one or more key indexes, which are used to locate specific key segments stored in the database system unit.

[0014] Preferably, the data synchronization process executed by the request processing / data synchronization module includes: Receive a synchronization request containing the destination address and key index from the quantum key request service layer module; The routing calculation controller module is queried for the optimized synchronization path to the destination address; Based on the returned path information, the quantum key ciphertext data packet is sent to the destination device through one or more forwarding operations; The system receives confirmation information from the destination device and updates the status of the corresponding key to "distributed" through the data management layer module.

[0015] Preferably, in the distribution process of the group key, when it is necessary to pass through one or more relay nodes for relay synchronization, the relay node receives encrypted quantum key ciphertext, and the relay node forwards the ciphertext according to the routing information and cannot obtain the quantum key plaintext.

[0016] Preferably, when there are N nodes in the network that need to communicate with each other, the group key distribution process is used to securely distribute a single key to multiple pre-authenticated group members, thereby significantly reducing the number of key synchronizations compared to the N×(N-1) / 2 times required by traditional end-to-end key negotiation.

[0017] The group key distribution method based on continuous variable quantum key distribution provided by the present invention includes: Step 1: Generate the original quantum key in the continuous variable quantum key distribution terminal and push it to the connected key manager; after encrypting the original quantum key, the key manager stores the ciphertext and its associated metadata in the database; Step 2: The initiating application sends a group key request to its key manager; the key manager parses the request message, extracts the application identifier, and sends an authentication request to the central controller; after verifying the validity of the application identifier, the central controller returns an acknowledgment message and a path containing group member routing information. Step 3: The key manager selects the stored specific link key as the group key according to the path and performs a synchronization operation according to the path type. If it is a non-relay path, the key index or encrypted group key is directly synchronized with other key managers with the same link. If it is a relay path, the group key is forwarded hop by hop in encrypted form through one or more relay nodes according to the path issued by the central controller until it is delivered to the key manager to which all group members belong. Step 4: Obtain the group key and group key identifier through the initiator application, and distribute the group key identifier to the group member applications; the group member applications use the group key identifier to apply for and obtain the group key from their respective key managers for encrypted communication.

[0018] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention upgrades the traditional point-to-point key distribution mode to a group collaborative distribution mode by introducing a group key management mechanism. In large-scale multi-node networks, the number of key synchronizations can be significantly reduced from N×(N-1) / 2 times (where N is the number of nodes) required by the traditional end-to-end mode, effectively reducing network bandwidth usage and key application response delay, and significantly improving the overall throughput and response efficiency of the system in high-concurrency, large-scale networking scenarios.

[0019] (2) This invention integrates encryption / decryption modules into each core module (such as the receiving service provision layer and the data management layer) to ensure that the quantum key exists in ciphertext form throughout the entire process of storage, internal transmission, and processing from the moment it enters the system. Combining the characteristic that relay nodes can only forward ciphertext and cannot obtain plaintext during relay synchronization, an end-to-end security protection system is constructed from generation, storage, distribution to use, fundamentally eliminating potential security threats within the system.

[0020] (3) The key management system provided by this invention supports both group key synchronization and end-to-end key synchronization modes, as well as point-to-point direct synchronization and secure relay synchronization paths. The routing calculation controller can dynamically calculate the optimal path based on real-time network topology, node load, link security level, and service priority. This design enables the system to flexibly adapt to network topologies of different sizes and diverse service requirements, ensuring the reachability and reliability of key distribution in complex or restricted network environments.

[0021] (4) Through group key distribution, a single key can securely serve multiple pre-authenticated communication parties, avoiding the waste of resources caused by repeatedly generating and synchronizing keys for each communication pair. This mechanism reduces the consumption of quantum key resources themselves, and also reduces the processing load of the system service layer and data layer, enabling the system to support the growth of the number of nodes more efficiently, with good scalability, laying the foundation for building a large-scale quantum key distribution network.

[0022] (5) This invention achieves refined management and full-process traceability of massive quantum keys by defining complete key metadata (such as globally unique key accounts and key indexes), strict identity authentication processes (such as two-factor authentication and device whitelists), and verifiable key status management (such as "distributed" status updates). This improves the controllability and auditability of key management and meets the standardized and normalized management requirements of modern secure communication networks for key supply. Attached Figure Description

[0023] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 The key management system structure of this invention is shown below; Figure 2 The key management system of this invention stores the key process; Figure 3 The key management system of this invention applies for group keys and relay processes. Detailed Implementation

[0024] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.

[0025] Example 1 In the key management system and method of the present invention, a security control mechanism is designed that runs through the entire process of key storage, transmission and distribution. It also innovatively introduces a group key distribution mode and an intelligent relay routing strategy. By organically integrating CVQKD technology, group management and encrypted storage, it effectively solves the problems of low key application efficiency, excessive end-to-end synchronization load and high internal transmission security risks in large-scale network scenarios, and significantly improves the overall efficiency and security of quantum key management.

[0026] In one aspect of the present invention, a key management system based on continuous variable quantum key distribution (CVQKD) is disclosed, comprising a quantum key receiving service providing layer module, a quantum key request service layer module, a data management layer module, and a routing calculation controller module. The quantum key receiving service providing layer module is configured to receive quantum keys generated by a CVQKD terminal and execute a quantum key storage management process; the quantum key request service layer module is configured to receive and authenticate key requests from user terminals, thereby triggering the key distribution process; the data management layer module is configured to securely store the quantum keys and all related data in encrypted form; and the routing calculation controller module is responsible for calculating the optimal path for key distribution and authenticating participating devices.

[0027] In this invention, the quantum key receiving service providing layer module includes an encryption / decryption module. This module encrypts the key itself and its related data immediately after the quantum key enters the system, and decrypts it only during necessary distribution. This ensures that the quantum key remains encrypted throughout its storage, flow, and processing within the system, fundamentally eliminating potential internal security threats and significantly improving the overall security of the quantum key.

[0028] In this invention, the quantum key request service module integrates core functions of request processing and data synchronization. This module has a built-in request processing / data synchronization module specifically designed to receive quantum key request requests, parse the key information contained within them, such as the target device, key quantity, type (group or end-to-end), and service priority, and initiate corresponding key distribution and data synchronization operations accordingly. Its core innovation lies in supporting two synchronization modes: efficient group key synchronization, which can securely distribute a single key to multiple pre-authenticated group members, greatly reducing the overhead of large-scale distribution; and traditional end-to-end key synchronization, used for key negotiation between two specific devices. Simultaneously, this module supports two synchronization paths: direct point-to-point synchronization without relays, and secure relay synchronization via one or more relay nodes for encrypted forwarding when direct links are unavailable, ensuring reachability and reliability in complex network topologies.

[0029] The data layer module forms the cornerstone of the system's secure storage, with the database system unit at its core. This unit is specifically designed for the centralized storage of all encrypted quantum key data. By persistently storing the encrypted keys in ciphertext form within the database, this module ensures a high level of security for the keys in their static storage state. Even if the storage medium faces unauthorized access, the plaintext key cannot be obtained. Combined with the service layer's transmission encryption, this achieves secure management of the key throughout its entire lifecycle.

[0030] The routing calculation controller module is the decision-making center for the system to achieve intelligent and secure key distribution. It dynamically calculates the optimal synchronization path, intelligently decides whether to use a direct route or a relay route, and issues the determined destination address and next-hop address instructions to the data synchronization module for execution, thereby ensuring the efficiency and reliability of the key distribution process.

[0031] Furthermore, before receiving a user's key application request, the quantum key application service will authenticate the user's identity, and only legitimate users can proceed with the subsequent application process.

[0032] Furthermore, the data access interface adopts a two-factor authentication mechanism based on pre-registration and pre-set keys to ensure the legitimacy of the user terminal device initiating the service request and the security of access.

[0033] In this invention, the request processing / data synchronization module is further provided with a request parsing unit and a synchronization strategy unit: the former is responsible for parsing the target device ID, request key quantity, key type and service priority contained in the request; the latter intelligently selects the point-to-point direct connection or the relay synchronization strategy via relay nodes based on the key type and real-time network topology.

[0034] Furthermore, the system defines two modes: group key synchronization and end-to-end key synchronization. Group synchronization is used to securely distribute the same key to a group of authenticated group members, significantly improving the efficiency of group communication. End-to-end synchronization is used for key negotiation and distribution between two specific terminal devices.

[0035] Furthermore, the relay synchronization refers to the process in which a relay node participates in the forwarding of the key ciphertext when there is no direct link between the source and destination devices. During this process, the relay node cannot obtain the key plaintext, thereby ensuring the security of the key forwarding process.

[0036] Furthermore, the data synchronization process specifically includes the following steps: receiving a synchronization request, querying the optimal path, forwarding the key ciphertext to the destination device according to the path, receiving confirmation and updating the key status to "distributed", thereby achieving controllable and verifiable key distribution.

[0037] Furthermore, the path selection strategy executed by the routing calculation unit comprehensively considers one or more factors among network topology, relay node load, link security level, and service priority to achieve dynamic optimization and adaptive selection of paths.

[0038] Example 2 As attached Figure 1As shown, the key management system of the present invention mainly includes a central controller, several key managers (KM1, KM2, ..., KMn) and corresponding quantum key distribution devices (QKD1, QKD2, ..., QKDn) at the physical level.

[0039] The central controller physically integrates the core functions of the routing calculation controller module described in this invention and serves as the intelligent decision-making hub of the system.

[0040] The Key Manager (KM) physically implements the functions of the quantum key receiving service provider layer module and the quantum key application service layer module described in this invention, and is a business node that performs key storage, management and distribution operations.

[0041] The quantum key distribution device (QKD) is responsible for generating raw quantum keys based on the CVQKD protocol and pushing them to the key manager (KM) directly connected to it.

[0042] A typical operation flow of this system includes key generation, storage, application, and distribution (taking group key relay distribution as an example): 1. Key generation and secure data storage: QKD1 and QKD2 negotiate using the CVQKD protocol to generate a batch of original quantum keys.

[0043] QKD1 pushes the generated raw quantum key to the key manager KM1, which is directly connected to it.

[0044] Key storage process as follows Figure 2 As shown, the encryption / decryption module in KM1 immediately encrypts the batch of subkeys. Subsequently, its key storage module stores the encrypted quantum key ciphertext into the database system unit of the data layer module.

[0045] At the same time, the system generates metadata associated with the batch of keys, including a globally unique key account (QKD number) (used to identify this QKD link) and one or more key indexes (used to locate each key segment in the batch of keys). This related data is also encrypted and stored in the database.

[0046] 2. (Group) Key Distribution and Relay Synchronization: like Figure 3 The diagram shows two scenarios for group key distribution: distribution without relays and distribution with relays.

[0047] When application 1 needs to use a group key and acts as the initiator, it sends a group key request to its associated key manager K.

[0048] When KM1 receives a group key request from application 1, it first parses the request message, extracts the application UUID, and uses the extracted UUID to send a request to the controller to verify whether it is a valid UUID.

[0049] After receiving the application identity verification request from the key manager, the controller will query an application identity registry to see if the received application UUID is a valid UUID. After confirming the valid application identity, it will return a confirmation message and the routing table of group members.

[0050] Figure 3 The relayless group key synchronization process shown is applicable when the applied KM1 and other KMs have the same code link stored between them and are not far apart.

[0051] When there is no relay key synchronization: KM1 parses the routing table and selects the key of a certain link as the group key for this application. KM1 first synchronizes with KM2, which has the same link 1. For KMs with the same quantum key on the same link, the synchronization message only sends the key index corresponding to the corresponding link. After KM2 receives the synchronization message and confirms compliance, it returns a synchronization confirmation to KM1.

[0052] Afterwards, KM1 uses the key from Link 2 to encrypt the group key. During synchronization, KM1 synchronizes the key index from Link 2 and the encrypted group key to KM3.

[0053] After receiving the synchronization message, KM3 requests the corresponding link key from the data module based on the received key index of link 2, then decrypts the group key, verifies it, and returns a synchronization success confirmation message.

[0054] After receiving the synchronization confirmation, KM1 returns the group key and group key ID to Application 1. Application 1 needs to synchronize the group key ID with the group members. Figure 3 Applications 2 and 3 are shown in the diagram.

[0055] Once Application 2 and Application 3 receive the group key ID, they can use the ID to request the group key from their respective key managers, enabling encrypted communication between the applications.

[0056] When Application 2 and Application 3 request keys from their respective KMs, the corresponding KMs also need to verify the request with the controller to ensure the legitimacy of the applications.

[0057] When the group key relay is synchronized: The authentication process between the application and the KM is the same as the relayless synchronization process.

[0058] After authentication, the data synchronization module of KM1, following the path issued by the central controller, first synchronizes the index of the Link 1 key to the next-hop key manager KM2, which is also another storage node for the Link 1 key.

[0059] After receiving the synchronization message, the KM2 data synchronization module will select the same index key for link 1 and select a key for link 2 to encrypt the key for link 1.

[0060] Afterwards, KM2 will send the key ciphertext and Link 2 key index to KM3 via encrypted messages. KM3 is also another storage node for the Link 2 key.

[0061] After receiving the synchronization message, the KM3 data synchronization module requests the Link 2 synchronous index key from the database, decrypts the group key ciphertext to obtain the group key, encrypts it using the encryption module, stores it in the database, and then returns a synchronization confirmation message.

[0062] The group key ID and group key are then returned to the application via encryption, and each application then decrypts and uses the key.

[0063] After receiving the confirmation message, the destination device returns an acknowledgment message. Upon receiving the acknowledgment, KM1 updates the status of the batch of keys to "distributed" through the data access interface.

[0064] When the relay process involves multiple relay KM nodes, the data synchronization module of each KM node receives the encrypted data packet. Based on the routing information, it performs an XOR encryption followed by an XOR decryption before forwarding the packet. This prevents the plaintext used to obtain the quantum key from being decrypted, thus ensuring the security of the forwarding process. This process may involve multiple hops until the packet finally reaches the group member devices.

[0065] For each group member's KM (Keeper Management Device), the requesting KM will perform the above synchronization process according to the routing table until all group member KMs have the same group key.

[0066] In summary, this invention organically integrates CVQKD key generation, encrypted storage, group key distribution, and secure relay forwarding through the collaborative work of a central controller, key manager, and QKD devices, constructing a secure and efficient quantum key management system. This system is particularly suitable for large-scale, multi-node quantum secure communication networks, allowing the number of synchronization interactions to be controlled to O(N), effectively solving the problems of low efficiency and poor scalability in traditional end-to-end key distribution modes.

[0067] Those skilled in the art will understand that, in addition to implementing the system, apparatus, and their modules provided by this invention in purely computer-readable program code, the same program can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, the system, apparatus, and their modules provided by this invention can be considered a hardware component, and the modules included therein for implementing various programs can also be considered structures within the hardware component; alternatively, modules for implementing various functions can be considered both software programs implementing the method and structures within the hardware component.

[0068] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.

Claims

1. A key management system based on continuous variable quantum key distribution, characterized by, The application relates to a quantum key receiving service providing layer module, a quantum key application service layer module, a data management layer module and a route calculation controller module. The quantum key receiving service providing layer module is connected with a continuous variable quantum key distribution terminal, is used for receiving quantum keys generated by the continuous variable quantum key distribution terminal, and performs encryption processing on the received quantum keys and related data, and sends the encrypted quantum key ciphertext to the data management layer module for storage. The quantum key application service layer module is connected with a user terminal, is used for receiving and authenticating a key application request sent by the user terminal, triggers a corresponding key distribution process according to a key type of the key application request, and the key type includes a group key and an end-to-end key. The data management layer module is connected with the quantum key receiving service providing layer module and the quantum key application service layer module, is used for securely storing the quantum key ciphertext and related data sent by the quantum key receiving service providing layer module in an encrypted form, and responds to a query or reading request of the quantum key application service layer module. The route calculation controller module is connected with the quantum key application service layer module, is used for receiving a path calculation request from the quantum key application service layer module, calculating a synchronization path for the key distribution process, and authenticating source equipment, destination equipment and relay equipment participating in the key distribution process. When the quantum key application service layer module triggers a group key distribution process, the route calculation controller module obtains an optimal path reaching a plurality of group member devices, and distributes ciphertext of the same group key to the plurality of group member devices via the calculated synchronization path. The quantum key receiving service providing layer module includes an encryption / decryption module and a key storage module.

2. The continuous variable quantum key distribution based key management system according to claim 1, wherein, The encryption / decryption module is used for immediately performing encryption processing on the quantum key and related data after the quantum key enters the quantum key receiving service providing layer module, and generating quantum key ciphertext. The key storage module is connected with the encryption / decryption module and the data management layer module, and is used for sending the quantum key ciphertext generated by the encryption / decryption module to the data management layer module for storage. The quantum key application service layer module includes a data access interface and a request processing / data synchronization module.

3. The continuous variable quantum key distribution based key management system of claim 1, wherein, The data access interface is used for receiving a service request of a user terminal, and performing identity authentication on a user terminal device initiating the service request. The request processing / data synchronization module is connected with the data access interface and the route calculation controller module, is used for parsing the service request after identity authentication, triggering a data synchronization operation according to a parsed key type, and the data synchronization operation includes group key synchronization and end-to-end key synchronization; the request processing / data synchronization module requests and obtains a synchronization path reaching a plurality of destination equipment from the route calculation controller module when performing the group key synchronization, and distributes key ciphertext according to the synchronization path. ​ 4. The continuous variable quantum key distribution based key management system of claim 3, wherein, The request processing / data synchronization module comprises a request analysis unit and a synchronization strategy unit; The request analysis unit is configured to analyze the target device ID, request key amount, key type and service priority parameter contained in the service request; The synchronization strategy unit is connected with the request analysis unit and configured to select a point-to-point direct connection synchronization strategy or a relay synchronization strategy through a relay node according to the key type and real-time network topology analyzed by the request analysis unit. 5.The continuous variable quantum key distribution based key management system according to claim 1, wherein, The route calculation controller module comprises a device authentication unit and a route calculation unit; The device authentication unit is configured to maintain a white list of trusted devices and perform identity authentication and authorization check on the source device, destination device and relay device participating in key synchronization based on the white list before route calculation starts; The route calculation unit is connected with the device authentication unit and configured to dynamically calculate an optimal synchronization path based on one or more factors such as network topology, relay node load, link security level and service priority after device authentication passes, wherein the synchronization path comprises a direct route and a relay route.

6. The continuous variable quantum key distribution based key management system of claim 1, wherein, The data management layer module comprises a database system unit configured to centrally store all encrypted quantum key ciphertext data and metadata associated with the quantum key ciphertext data; the metadata comprises a globally unique key account and one or more key indexes used to locate a specific key segment stored in the database system unit.

7. The continuous variable quantum key distribution based key management system of claim 3, wherein, The data synchronization job process performed by the request processing / data synchronization module comprises: receiving a synchronization request containing a destination address and a key index from the quantum key application service layer module; querying the route calculation controller module for an optimized synchronization path to the destination address; sending a quantum key ciphertext data packet to the destination device through one or more forwarding operations according to the returned path information; receiving confirmation information returned by the destination device and updating the state of the corresponding key to distributed through the data management layer module. 8.The continuous variable quantum key distribution based key management system of claim 1, wherein, In the group key distribution process, when relay synchronization through one or more relay nodes is required, the relay node receives encrypted quantum key ciphertext, and the relay node cannot obtain the quantum key plaintext by forwarding the ciphertext according to the routing information. 9.The continuous variable quantum key distribution based key management system of claim 1, wherein, When there are N nodes that need to communicate with each other in the network, the group key distribution process is used to securely distribute a single key to multiple pre-authenticated group members, which significantly reduces the number of key synchronization times relative to the N×(N-1) / 2 times required by traditional end-to-end key negotiation.

10. A group key distribution method based on continuous variable quantum key distribution, applied to the key management system based on continuous variable quantum key distribution according to any one of claims 1 to 9, characterized in that, Comprise: Step 1: generate an original quantum key at a continuous variable quantum key distribution terminal and push it to a connected key manager; the key manager encrypts the original quantum key and stores the ciphertext and its associated metadata into a database; Step 2: The initiator application initiates a group key application to the belonging key manager; the key manager parses the application message, extracts the application identifier and initiates an identity verification request to the central controller; after the central controller verifies the legality of the application identifier, it returns a confirmation message and a path containing group member routing information; Step 3: According to the path, the key manager selects a specific link key stored as a group key and performs a synchronization operation according to the path type; if it is a non-relay path, it directly synchronizes the key index or the encrypted group key with other key managers that have the same link; If it is a relay path, the group key is forwarded in ciphertext form through one or more relay nodes hop by hop according to the path issued by the central controller until it reaches all group member belonging key managers; Step 4: The initiator application obtains the group key and the group key identifier and distributes the group key identifier to the group member applications; The group member applications use the group key identifier to apply for and obtain the group key from the belonging key manager, which is used for encrypted communication.

Citation Information

Patent Citations

  • Quantum key distribution management system

    CN116980122A