Key generation method, related device, storage medium and computer program product
By exchanging and processing data between quantum satellites and quantum ground stations, more key data resources are generated, solving the problem of the limited number of keys generated between quantum satellites and satellite ground stations, and improving the security and efficiency of satellite-to-ground communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2025-12-08
- Publication Date
- 2026-04-10
AI Technical Summary
The number of QKD keys generated by quantum satellites and satellite ground stations is limited, and quantum key resources between satellites and ground stations are precious, making it difficult to meet the need for one-time pad keys. Furthermore, they are easily affected by sunlight interference and weather conditions, which reduces communication security.
The quantum satellite acquires first data, generates multiple intermediate data based on the first key and the first data, sends them to the quantum ground station to determine the second key, and receives the intermediate data from the quantum ground station to generate the third key, thus establishing a secure communication channel between the quantum satellite and the ground application system.
It improved key production efficiency, increased the number of keys for satellite-to-ground communication, and enhanced the security of satellite-to-ground communication.
Smart Images

Figure CN121841607A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of quantum key distribution, and in particular to a key generation method, related equipment, a storage medium and a computer program product. BACKGROUND
[0002] After successfully launching a quantum satellite, it is possible to generate quantum key distribution (QKD) quantum keys in the open space between the satellite and the ground (i.e., the quantum satellite and the satellite ground station), so that the on-board application device and the ground application system can establish a secure communication channel based on the QKD quantum keys.
[0003] However, since the quantum satellite is a low-orbit satellite, the revolution period is short, the radius of ground coverage is small, and the time for flying over a ground station each time is only 5-10 minutes, and the same ground station can be flown over only 1-2 times a day. In addition, the generation of QKD quantum keys in the open space between the satellite and the ground is easily affected by weather such as sunlight interference, cloud cover and dust blockage, and usually only QKD quantum keys can be successfully generated on a clear night, further reducing the key production efficiency.
[0004] In summary, the number of QKD keys generated by the quantum satellite and the satellite ground station is limited, the quantum key resources between the satellite and the ground are very valuable, and it is usually difficult to meet the need for one-time one-key, and even the security of satellite-ground communication may be reduced. SUMMARY
[0005] To solve the above technical problems, the embodiments of the present application provide a key generation method, related equipment, a storage medium and a computer program product, which can generate more key data resources, improve the key production efficiency, and improve the security of satellite-ground communication.
[0006] The technical scheme of the embodiments of the present application is as follows: In a first aspect, the embodiments of the present application provide a key generation method, which is applied to a first device, the first device is deployed on a quantum satellite, and the method comprises: obtaining first data; wherein the first data is used to synthesize one or more first intermediate data; determining one or more first intermediate data based on the first data and a first key, and sending the one or more first intermediate data to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key comprises a quantum key; receive one or more second intermediate data sent by the quantum ground station, and determine a corresponding third key based on each of the second intermediate data, the second key and the third key being used to establish a secure communication channel between the quantum satellite and a ground application system.
[0007] In a second aspect, an embodiment of the present application provides a key generation method, applied to a third device, the third device being deployed in a quantum ground station, and the method comprising: receiving one or more first intermediate data sent by a quantum satellite, and determining a corresponding second key based on the one or more first intermediate data; obtaining second data; wherein the second data is used to synthesize one or more second intermediate data; determining one or more second intermediate data based on the second data and a first key, and sending the one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein the first key comprises a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and a ground application system.
[0008] In a third aspect, an embodiment of the present application provides a first device, comprising: a first obtaining unit, a first determining unit, a first sending unit, and a first receiving unit; wherein, the first obtaining unit is configured to obtain first data; wherein the first data is used to synthesize one or more first intermediate data; the first determining unit is configured to determine one or more first intermediate data based on the first data and a first key; the first sending unit is configured to send the one or more first intermediate data to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key comprises a quantum key; the first receiving unit is configured to receive one or more second intermediate data sent by the quantum ground station; the first determining unit is further configured to determine a corresponding third key based on each of the second intermediate data, the second key and the third key being used to establish a secure communication channel between the quantum satellite and a ground application system.
[0009] In a fourth aspect, an embodiment of the present application provides a first device, comprising: a first processor and a first memory; wherein, the first memory is configured to store a computer program capable of running on the processor; The first processor is configured to execute the key generation method as described above when the computer program is run.
[0010] In a fifth aspect, an embodiment of the present application provides a third device, the third device comprising: a second obtaining unit, a second determining unit, a second sending unit, and a second receiving unit, wherein, The second receiving unit is configured to receive one or more first intermediate data sent by a quantum satellite, and determine a corresponding second key based on the one or more first intermediate data. The second obtaining unit is configured to obtain second data, wherein the second data is used to synthesize one or more second intermediate data. The second determining unit is configured to determine the one or more second intermediate data based on the second data and a first key. The second sending unit is configured to send the one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data, wherein the first key comprises a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and a ground application system.
[0011] In a sixth aspect, an embodiment of the present application provides a third device, the third device comprising: a second processor and a second memory, wherein, The second memory is configured to store a computer program capable of running on the processor. The second processor is configured to execute the key generation method as described above when the computer program is run.
[0012] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, the storage medium storing computer program code, when the computer program code is executed by a computer, the key generation method as described above is implemented.
[0013] In an eighth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, when the computer program is executed by a processor, the key generation method as described above is implemented.
[0014] The embodiment of the present application provides a key generation method, related equipment, a storage medium and a computer program product. A first device is deployed in a quantum satellite, and the first device acquires first data; wherein the first data is used to synthesize one or more first intermediate data; one or more first intermediate data are determined based on the first data and a first key, and the one or more first intermediate data are sent to a quantum ground station, so that the quantum ground station determines corresponding second keys based on the one or more first intermediate data; wherein the first key comprises a quantum key; one or more second intermediate data sent by the quantum ground station are received, and corresponding third keys are determined based on each second intermediate data, and the second keys and the third keys are used to establish a secure communication channel between the quantum satellite and a ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key, that is, the embodiment of the present application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating more key data resources, and then the one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine corresponding second keys based on the plurality of first intermediate data; correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then can determine corresponding third keys based on each second intermediate data, thereby greatly improving the number of keys provided to the quantum satellite and the ground application system, and the second keys and the third keys are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-ground communication while improving the key production efficiency. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 A key generation method provided by the embodiment of the present application Figure One ; Figure 2 A composition structure diagram of a first device provided by the embodiment of the present application Figure 3 A key generation method provided by the embodiment of the present application Figure Two ; Figure 4 A composition structure diagram of a third device provided by the embodiment of the present application Figure 5 A key generation method provided by the embodiment of the present application Figure Three ; Figure 6 A system architecture diagram of a key generation provided by the embodiment of the present application Figure 7 A composition structure diagram of a first device provided by the embodiment of the present application Figure One ; Figure 8This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application. Figure Two ; Figure 9 This is a schematic diagram of the composition structure of the third device proposed in the embodiments of this application. Figure One ; Figure 10 This is a schematic diagram of the composition structure of the third device proposed in the embodiments of this application. Figure Two . Detailed Implementation
[0016] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining the relevant application and not for limiting the application. Furthermore, it should be noted that, for ease of description, only the parts related to the relevant application are shown in the accompanying drawings.
[0017] After the successful launch of the quantum satellite, it became possible to generate QKD quantum keys in the open space between the satellite and the ground (i.e., the quantum satellite and the satellite ground station), enabling onboard application equipment and ground application systems to establish an unconditionally secure communication channel based on QKD quantum keys.
[0018] However, because quantum satellites are low-Earth orbit satellites with short orbital periods and small ground coverage radii, each flyby of a ground station takes only 5-10 minutes, and they can only flyby the same ground station 1-2 times a day. Furthermore, generating QKD quantum keys in the open space between the satellite and the ground is easily affected by sunlight interference and weather conditions such as cloud cover and dust. Typically, QKD quantum key generation can only be successful on clear nights, further reducing key production efficiency.
[0019] In summary, the number of QKD keys produced by quantum satellites and satellite ground stations is currently limited. Quantum key resources between satellites and ground stations are extremely valuable and often fail to meet the requirements of one-time pad, which may even reduce the security of satellite-to-ground communication.
[0020] To address the current issue of limited QKD key production capacity between quantum satellites and ground stations, which may even reduce the security of satellite-to-ground communication, this application provides a key generation method, related equipment, storage medium, and computer program product. A first device is deployed on the quantum satellite and acquires first data. This first data is used to synthesize one or more first intermediate data. Based on the first data and a first key, one or more first intermediate data are determined and sent to the quantum ground station, enabling the quantum ground station to determine a corresponding second key based on the one or more first intermediate data. The first key includes a quantum key. One or more second intermediate data sent by the quantum ground station are received, and a corresponding third key is determined based on each second intermediate data. The second and third keys are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key. That is, the embodiments of this application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating a larger number of key data resources. Then, one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine the corresponding second key based on the multiple first intermediate data. Correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then determine the corresponding third key based on each second intermediate data. This greatly increases the number of keys provided to the quantum satellite and the ground application system. Moreover, the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0021] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0022] This application provides a key generation method, which is applied to a first device deployed on a quantum satellite. Figure 1 This is a schematic diagram of the key generation method proposed in the embodiments of this application. Figure One ,like Figure 1 As shown, the key generation method may include the following steps: Step 101: Obtain first data; wherein, the first data is used to synthesize one or more first intermediate data.
[0023] In embodiments of this application, the first device may acquire first data.
[0024] It should be noted that in the embodiments of this application, the first device may be a QKD satellite payload or other types of devices, and this application does not specifically limit the type of the first device.
[0025] It should be noted that, in the embodiments of this application, the first data can be used to synthesize one or more first intermediate data. For example, the first data may include quantum random numbers, pseudo-random numbers, etc. This application does not specifically limit the data type and number of data included in the first data.
[0026] Step 102: Determine one or more first intermediate data based on the first data and the first key, and send one or more first intermediate data to the quantum ground station so that the quantum ground station can determine the corresponding second key based on one or more first intermediate data; wherein, the first key includes the quantum key.
[0027] In the embodiments of this application, after acquiring the first data, the first device can determine one or more first intermediate data based on the first data and the first key, and send one or more first intermediate data to the quantum ground station.
[0028] It should be noted that, in the embodiments of this application, the first key may include a quantum key, which may be a QKD quantum key generated by a quantum satellite and a quantum ground station.
[0029] It should be noted that, in the embodiments of this application, the first device may include a first functional module and a second functional module, and this application does not specifically limit the number and type of functional modules included in the first device.
[0030] It should be noted that, in the embodiments of this application, the first functional module may include a key data source unit, which can generate first data. This application does not specifically limit the role of the first functional module.
[0031] It should be noted that, in the embodiments of this application, the second functional module may include a QKD quantum key synthesis unit, which can synthesize one or more first intermediate data based on the first data and the first key. This application does not specifically limit the role of the second functional module.
[0032] Optionally, in an embodiment of this application, the first functional module in the first device can acquire first data and send the first data to the second functional module; then the second functional module can determine one or more first intermediate data based on the first data and the first key, and send one or more first intermediate data to the quantum ground station.
[0033] Optionally, in embodiments of this application, before determining one or more first intermediate data based on the first data and the first key, the first device may first determine whether the first information satisfies the first preset condition; wherein, the first information includes one or more of the following: the first number of the current first key; the second number of the first key generated within the first preset time period; the third number of the remaining keys in the quantum satellite and ground application system; the key consumption rate information of the quantum satellite and ground application system within the second preset time period; the fourth number of the first key predicted to be generated within the third preset time period; if it is determined that the first preset condition is satisfied, one or more first intermediate data are determined based on the first data and the first key.
[0034] It should be noted that, in the embodiments of this application, if the first preset condition is not met, a secure communication channel is established between the quantum satellite and the ground application system based on the first key.
[0035] It should be noted that in the embodiments of this application, the first preset time period can be a recent period of time, such as within the last week, or any period of time. This application does not make specific limitations on the setting of the first preset time period.
[0036] It should be noted that in the embodiments of this application, the second preset time period can be a recent period of time, such as within the last week, or any period of time. This application does not make specific limitations on the setting of the second preset time period.
[0037] It should be noted that, in the embodiments of this application, the third preset time period can be a future period of time, such as the next month, or other future periods of time. This application does not make specific limitations on the setting of the third preset time period.
[0038] Optionally, in the embodiments of this application, when the first device determines whether the first information meets the first preset condition, it may determine that the first information meets the first preset condition when one or more of the following requirements are met; The first quantity is less than or equal to the first preset threshold; The second quantity is less than or equal to the second preset threshold; The third quantity is less than or equal to the third preset threshold; The consumption rate information is greater than or equal to the preset rate threshold; The fourth quantity is less than or equal to the fourth preset threshold.
[0039] It should be noted that, in the embodiments of this application, the first preset threshold can be used to measure whether the current number of first keys is sufficient. The first preset threshold can be set according to historical experience, and this application does not specifically limit the size of the first preset threshold.
[0040] It should be noted that, in the embodiments of this application, the second preset threshold can be used to measure whether the number of first keys generated within the first preset time period is sufficient. The second preset threshold can be set based on historical experience, and this application does not specifically limit the size of the second preset threshold.
[0041] It should be noted that, in the embodiments of this application, the third preset threshold can be used to measure whether the number of remaining keys in the quantum satellite and ground application system is sufficient, and this application does not specifically limit the size of the third preset threshold.
[0042] It should be noted that, in the embodiments of this application, the fourth preset threshold can be used to measure whether the number of first keys predicted and generated within the third preset time period is sufficient. This application does not specifically limit the size of the fourth preset threshold.
[0043] In other words, in the embodiments of this application, when one or more of the above requirements are met, if the requirement that the first quantity is less than or equal to the first preset threshold is met, it can be considered that the number of first keys currently generated is insufficient. One or more first intermediate data can be determined based on the first data and the first key, thereby expanding the number of keys (i.e., second keys) generated at the end based on the multiple first intermediate data, which greatly improves the production efficiency of keys.
[0044] It should be noted that, in the embodiments of this application, the first data may include a first quantum random number, which may include one or more quantum random numbers. This application does not specifically limit the data type and quantity of the first data.
[0045] Optionally, in embodiments of this application, when the second functional module in the first device determines one or more first intermediate data based on the first data and the first key, it can determine the corresponding first intermediate data for each quantum random number based on the first key, the quantum random number, and the first preset function; wherein, the first preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the first intermediate data.
[0046] It should be noted that, in the embodiments of this application, the first preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the first preset function.
[0047] For example, in an embodiment of this application, for each quantum random number, the corresponding first intermediate data can be determined based on the first key, the quantum random number, and the first preset function. It can be calculated using the following formula (1).
[0048] (1) in, Represents quantum random numbers, Indicates the first key. The mathematical symbol for XOR.
[0049] For example, in an embodiment of this application, for each quantum random number, the corresponding first intermediate data is determined based on the first key, the quantum random number, and the first preset function. In this case, it can also be calculated using the following formula (2).
[0050] (2) in, Represents a hash function. Represents quantum random numbers, This represents the first key.
[0051] It should be noted that, in the embodiments of this application, the first data may also include a first pseudo-random number, which includes one or more pseudo-random numbers. This application does not specifically limit the data type and the number of data included in the first data.
[0052] Optionally, in embodiments of this application, when the second functional module in the first device determines one or more first intermediate data based on the first data and the first key, it can determine the corresponding first intermediate data for each pseudo-random number based on the first key, the pseudo-random number, and the first preset function.
[0053] For example, in an embodiment of this application, for each pseudo-random number, the corresponding first intermediate data is determined based on the first key, the pseudo-random number, and the first preset function. When, it can be calculated using the following formula (3).
[0054] (3) in, Represents pseudo-random numbers. Indicates the first key. The mathematical symbol for XOR.
[0055] For example, in an embodiment of this application, for each pseudo-random number, the corresponding first intermediate data is determined based on the first key, the pseudo-random number, and the first preset function. In this case, it can also be calculated using the following formula (4).
[0056] (4) in, Represents pseudo-random numbers. Indicates the first key. This represents a hash function.
[0057] It should be noted that, in the embodiments of this application, the first data may also include a first historical key, such as the generated historical seed QKD quantum key. This application does not specifically limit the data type and quantity of the first data.
[0058] Optionally, in embodiments of this application, when the first device determines one or more first intermediate data based on the first data and the first key, it may group the first historical key based on the first key to obtain N key sets; wherein, each key set includes one or more fourth keys, the first historical key contains the fourth key, and N is a positive integer; for each key set, the corresponding first intermediate data is determined based on one or more fourth keys, the first key, and the first preset function.
[0059] For example, in an embodiment of this application, it is assumed that the first historical key includes , ..., Based on the first key, the first historical key is grouped to obtain 3 key sets, namely: , ..., ; , ..., ; , ..., For each key set, the corresponding first intermediate data can be determined based on one or more fourth keys, the first key and the first preset function in each key set. Taking the first key set as an example, it can be calculated by the following formula (5).
[0060] (5) in, , ..., This indicates the fourth key contained in the first key set. Indicates the first key. The mathematical symbol for XOR.
[0061] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more fourth keys, the first key and the first preset function in each key set, taking the first key set as an example, it can also be calculated by the following formula (6).
[0062] (6) in, Represents a hash function. , ..., This indicates the fourth key contained in the first key set. Indicates the first key. The mathematical symbol for XOR.
[0063] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more fourth keys, the first key and the first preset function in each key set, taking the first key set as an example, it can also be calculated by the following formula (7).
[0064] (7) Optionally, in embodiments of this application, when the first device determines one or more first intermediate data based on the first data and the first key, it may also determine the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function.
[0065] For example, in an embodiment of this application, when the first device determines the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function, it can calculate the data using the following formula (8).
[0066] (8) in, Represents quantum random numbers, Represents a hash function. , ..., This indicates the fourth key contained in the first key set. Indicates the first key. The mathematical symbol for XOR.
[0067] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function, it can also calculate it using the following formula (9).
[0068] (9) In other words, in the embodiments of this application, the first device can generate one or more first intermediate data in various ways. For example, it can determine the corresponding first intermediate data based on the first key, each quantum random number, and the first preset function; it can also determine the corresponding first intermediate data based on the first key, each pseudo-random number, and the first preset function; it can also group the first historical key based on the first key to obtain N key sets, and then determine the corresponding first intermediate data based on one or more fourth keys, the first key, and the first preset function in each key set. That is, the embodiments of this application can generate one or more first intermediate data through various calculation strategies, thereby generating a larger number of key data resources, which facilitates the subsequent determination of the corresponding second key by the quantum ground station based on one or more first intermediate data, greatly improving the key production efficiency.
[0069] It should be noted that, in the embodiments of this application, after the first device determines one or more first intermediate data based on the first data and the first key, it can send one or more first intermediate data to the quantum ground station so that the quantum ground station can determine the corresponding second key based on one or more first intermediate data.
[0070] It should be noted that, in the embodiments of this application, Figure 2 This is a schematic diagram of the composition structure of the first device proposed in the embodiments of this application, as shown below. Figure 2 As shown, in addition to the first functional module and the second functional module, the first device may also include a third functional module. This application does not specifically limit the number and type of functional modules included in the first device.
[0071] It should be noted that, in the embodiments of this application, the third functional module may include a satellite-to-ground data interaction unit, which can be used to transmit first intermediate data to the quantum ground station.
[0072] Optionally, in embodiments of this application, the second functional module in the first device can send one or more first intermediate data to the third functional module, so that the third functional module can send one or more first intermediate data to the quantum ground station through a data communication channel.
[0073] It should be noted that, in the embodiments of this application, the data communication channel can use radio or high-power laser. The bandwidth of the data communication channel is much greater than the rate of the channel for generating QKD quantum keys (i.e., the first key), and the availability of the data communication channel is also much higher than that of the channel for generating QKD quantum keys.
[0074] Step 103: Receive one or more second intermediate data sent by the quantum ground station, and determine the corresponding third key based on each second intermediate data. The second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0075] It should be noted that, in the embodiments of this application, the first device can receive one or more second intermediate data sent by the quantum ground station, and determine the corresponding third key based on each second intermediate data.
[0076] It should be noted that, in the embodiments of this application, steps 101-102 can be executed in sequence; steps 101-102 as a whole and step 103 can be executed in parallel or in sequence. This application does not impose specific restrictions on the execution order.
[0077] It should be noted that, in the embodiments of this application, the second functional module in the first device can receive one or more second intermediate data sent by the quantum ground station, and determine the corresponding third key based on each second intermediate data.
[0078] Optionally, in an embodiment of this application, the third functional module in the first device can receive one or more second intermediate data sent by the quantum ground station through a data communication channel, and then send one or more second intermediate data to the second functional module.
[0079] In other words, in the embodiments of this application, the second functional module in the first device can receive one or more second intermediate data sent by the quantum ground station, thereby determining the corresponding third key based on each second intermediate data, which significantly increases the number of third keys generated; correspondingly, the quantum ground station can also determine the corresponding second key based on one or more first intermediate data, so that the quantum satellite side and the quantum ground station side can generate consistent keys (i.e., the second key and the third key), and then establish a secure communication channel between the quantum satellite and the ground application system based on the second key and the third key, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0080] It should be noted that, in the embodiments of this application, the quantum satellite may also include a second device, and this application does not specifically limit the type and number of devices included in the quantum satellite.
[0081] It should be noted that, in the embodiments of this application, the second device may include satellite application equipment, and this application does not specifically limit the type of the second device.
[0082] It should be noted that, in the embodiments of this application, the second device can at least be used to establish a secure communication channel with the ground application system based on the third key. For example, the second functional module in the first device can send the generated third key to the second device so that the second device can establish a secure communication channel with the ground application system based on the third key.
[0083] Optionally, in embodiments of this application, when the second functional module in the first device determines the corresponding third key based on each second intermediate data, it may determine the corresponding third key based on the first data, each second intermediate data, and the second preset function; or, it may determine the corresponding third key based on the first data, the first key, each second intermediate data, and the second preset function.
[0084] It should be noted that, in the embodiments of this application, the second preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the second preset function.
[0085] For example, in an embodiment of this application, when the second functional module in the first device determines the corresponding third key based on the first data, each second intermediate data and the second preset function, it can be calculated by the following formula (10).
[0086] (10) in, Indicates the third key. Indicates the first data. This indicates the second intermediate data.
[0087] For example, in an embodiment of this application, when the second functional module in the first device determines the corresponding third key based on the first data, each second intermediate data and the second preset function, it can also calculate it using the following formula (11).
[0088] (11) in, Indicates the third key. Represents a hash function. Indicates the first data. This indicates the second intermediate data.
[0089] For example, in an embodiment of this application, the second functional module in the first device can calculate the corresponding third key based on the first data, the first key, each second intermediate data and the second preset function using the following formula (12).
[0090] (12) in, Indicates the third key. Indicates the first data. This represents the second intermediate data. This represents the first key.
[0091] For example, in an embodiment of this application, when the second functional module in the first device determines the corresponding third key based on the first data, the first key, each second intermediate data and the second preset function, it can also calculate it using the following formula (13).
[0092] (13) in, Indicates the third key. Represents a hash function. Indicates the first data. This represents the second intermediate data. This represents the first key.
[0093] In summary, the first device can receive one or more second intermediate data sent by the quantum ground station and determine the corresponding third key based on each second intermediate data. This results in a significantly larger number of synthesized third keys than the number of first keys, thereby increasing the key quantity of QKD quantum keys and improving the QKD quantum key generation efficiency. The quantum ground station can also determine the corresponding second key based on one or more first intermediate data, similarly increasing the key quantity of QKD quantum keys. This ensures that there are sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, avoiding the problem that quantum keys between satellite and ground often cannot satisfy one-time pad conditions, and greatly improving the security of satellite-ground communication.
[0094] This application provides a key generation method. The method is applied to a first device deployed on a quantum satellite. The first device acquires first data; wherein the first data is used to synthesize one or more first intermediate data; one or more first intermediate data are determined based on the first data and a first key, and the one or more first intermediate data are sent to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key includes a quantum key; one or more second intermediate data are received from the quantum ground station, and a corresponding third key is determined based on each second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key. That is, the embodiments of this application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating a larger number of key data resources. Then, one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine the corresponding second key based on the multiple first intermediate data. Correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then determine the corresponding third key based on each second intermediate data. This greatly increases the number of keys provided to the quantum satellite and the ground application system. Moreover, the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0095] Based on the above embodiments, another embodiment of this application provides a key generation method, which is applied to a third device deployed at a quantum ground station. Figure 3 This is a schematic diagram of the key generation method proposed in the embodiments of this application. Figure Two ,like Figure 3 As shown, the key generation method may include the following steps: Step 201: Receive one or more first intermediate data sent by the quantum satellite, and determine the corresponding second key based on one or more first intermediate data.
[0096] In embodiments of this application, the third device may receive one or more first intermediate data sent by the quantum satellite and determine the corresponding second key based on one or more first intermediate data.
[0097] It should be noted that, in the embodiments of this application, the third device may include a fifth functional module and a sixth functional module. This application does not specifically limit the type and number of functional modules included in the third device.
[0098] It should be noted that, in the embodiments of this application, the fifth functional module may be a QKD quantum key synthesis unit, which may be used to synthesize a corresponding second key based on one or more first intermediate data. This application does not specifically limit the role of the fifth functional module.
[0099] It should be noted that, in the embodiments of this application, the sixth functional module may be a satellite-to-ground data interaction unit, which may be used to receive one or more first intermediate data sent by the quantum satellite. This application does not specifically limit the role of the sixth functional module.
[0100] Optionally, in an embodiment of this application, the sixth functional module in the third device can receive one or more first intermediate data sent by the quantum satellite through a data communication channel, and send one or more first intermediate data to the fifth functional module, so that the fifth functional module can determine the corresponding second key based on each first intermediate data.
[0101] It should be noted that, in the embodiments of this application, the data communication channel may be a communication channel established between the third functional module in the first device and the sixth functional module in the third device. The data communication channel may use radio or high-power laser; and the bandwidth of the data communication channel is much greater than the rate of the channel for generating QKD quantum keys (i.e., the first key).
[0102] Step 202: Obtain the second data; wherein the second data is used to synthesize one or more second intermediate data.
[0103] In embodiments of this application, the third device may acquire the second data.
[0104] It should be noted that, in the embodiments of this application, Figure 4 This is a schematic diagram of the composition structure of the third device proposed in the embodiments of this application, such as... Figure 4 As shown, in addition to the fifth and sixth functional modules, the third device may also include a fourth functional module. This application does not specifically limit the type and number of functional modules included in the third device.
[0105] It should be noted that, in the embodiments of this application, the fourth functional module may be a key data source unit, which can generate second data. This application does not specifically limit the role of the fourth functional module.
[0106] Optionally, in the embodiments of this application, the second data can be used to synthesize one or more second intermediate data. For example, the second data may include quantum random numbers, pseudo-random numbers, etc. This application does not specifically limit the data type and number of data included in the second data.
[0107] Optionally, in embodiments of this application, the third device may obtain the second data through the fourth functional module and send the second data to the fifth functional module.
[0108] It should be noted that, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on one or more first intermediate data, it may determine the corresponding second key based on the second data, each first intermediate data, and the fourth preset function; or, it may determine the corresponding second key based on the second data, the first key, each first intermediate data, and the fourth preset function.
[0109] It should be noted that, in the embodiments of this application, the fourth preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the fourth preset function.
[0110] For example, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on the second data, each first intermediate data and the fourth preset function, it can be calculated by the above formula (10) or formula (11).
[0111] For example, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on the second data, the first key, each first intermediate data and the fourth preset function, it can be calculated by the above formula (12) or formula (13).
[0112] Step 203: Determine one or more second intermediate data based on the second data and the first key, and send one or more second intermediate data to the quantum satellite so that the quantum satellite can determine the corresponding third key based on one or more second intermediate data; wherein, the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0113] It should be noted that, in the embodiments of this application, the first key includes a quantum key, which may be a QKD quantum key generated by the quantum satellite and the quantum ground station.
[0114] Optionally, in embodiments of this application, the fifth functional module in the third device may determine one or more second intermediate data based on the second data and the first key, and send one or more second intermediate data to the quantum satellite.
[0115] It should be noted that, in the embodiments of this application, the second data may include a second quantum random number, which may include one or more quantum random numbers. This application does not specifically limit the data type included in the second data.
[0116] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can determine the corresponding second intermediate data for each quantum random number based on the first key, the quantum random number, and a third preset function; wherein, the third preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the second intermediate data.
[0117] It should be noted that, in the embodiments of this application, the third preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function types included in the third preset function.
[0118] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data for each quantum random number based on the first key, the quantum random number and the third preset function, it can calculate it using the above formula (1) or formula (2).
[0119] It should be noted that, in the embodiments of this application, the second data may also include a second pseudo-random number, which includes one or more pseudo-random numbers. This application does not specifically limit the data type included in the second data.
[0120] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can determine the corresponding second intermediate data for each pseudo-random number based on the first key, the pseudo-random number, and the third preset function.
[0121] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data for each pseudo-random number based on the first key, the pseudo-random number and the third preset function, it can calculate it using the above formula (3) or formula (4).
[0122] It should be noted that, in the embodiments of this application, the second data may also include a second historical key, such as the generated historical seed QKD quantum key.
[0123] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can also group the second historical key based on the first key to obtain N key sets; wherein, each key set includes one or more fifth keys, the second historical key contains the fifth key, and N is a positive integer; for each key set, the corresponding second intermediate data can be determined based on one or more fifth keys, the first key, and a third preset function.
[0124] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data based on one or more fifth keys, first keys and third preset functions in each key set, it can calculate it using the above formula (5) or formula (6) or formula (7).
[0125] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it may also determine the corresponding second intermediate data based on one or more of the second quantum random number, the second pseudo-random number, the second historical key, the first key, and the third preset function.
[0126] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data based on one or more of the second quantum random number, the second pseudo-random number, the second historical key, the first key, and the third preset function, it can calculate it using the above formula (8) or formula (9).
[0127] It should be noted that, in the embodiments of this application, after the fifth functional module in the third device determines one or more second intermediate data based on the second data and the first key, it can send one or more second intermediate data to the quantum satellite.
[0128] Optionally, in an embodiment of this application, the fifth functional module in the third device can send one or more second intermediate data to the sixth functional module; then the sixth functional module can send one or more second intermediate data to the quantum satellite through a data communication channel.
[0129] It should be noted that, in the embodiments of this application, steps 202-203 should be executed sequentially; steps 202-203 as a whole and step 201 can be executed in parallel or sequentially, and this application does not make a specific limitation on the execution order.
[0130] In summary, the third device can receive one or more first intermediate data sent by the quantum satellite and determine the corresponding second key based on one or more first intermediate data. This results in a number of synthesized second keys that are much greater than the number of first keys, thereby increasing the key quantity of QKD quantum keys and improving the QKD quantum key generation efficiency. Meanwhile, the quantum satellite can determine the corresponding third key based on one or more second intermediate data, which also increases the key quantity of QKD quantum keys. This ensures that there are sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, avoiding the problem that quantum keys between satellite and ground often cannot satisfy one-time pad, and greatly improving the security of satellite-ground communication.
[0131] This application provides a key generation method applied to a third device. The third device receives one or more first intermediate data sent by a quantum satellite and determines a corresponding second key based on the one or more first intermediate data; acquires second data; wherein the second data is used to synthesize one or more second intermediate data; determines one or more second intermediate data based on the second data and the first key, and sends one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the third device can determine one or more second intermediate data based on the second data and the first key, thereby generating a larger number of key data resources, and sends one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data. Furthermore, the third device can determine a corresponding second key based on one or more first intermediate data, allowing the third device and the quantum satellite to expand the key quantity of QKD quantum keys, thus providing sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, greatly improving the security of satellite-to-ground communication.
[0132] Based on the above embodiments, another embodiment of this application provides a key generation method, which is applied to a first device and a third device. Figure 5 This is a schematic diagram of the key generation method proposed in the embodiments of this application. Figure Three ,like Figure 5 As shown, the key generation method may include the following steps: Step 301: The first device acquires first data; wherein the first data is used to synthesize one or more first intermediate data.
[0133] It should be noted that in the embodiments of this application, the first device may be a QKD satellite payload or other types of devices, and this application does not specifically limit the type of the first device.
[0134] It should be noted that, in the embodiments of this application, the first data can be used to synthesize one or more first intermediate data. For example, the first data may include quantum random numbers, pseudo-random numbers, etc. This application does not specifically limit the data type and number of data included in the first data.
[0135] Step 302: The first device determines one or more first intermediate data based on the first data and the first key, and sends one or more first intermediate data to the quantum ground station so that the quantum ground station determines the corresponding second key based on one or more first intermediate data; wherein, the first key includes the quantum key.
[0136] It should be noted that, in the embodiments of this application, the first key may include a quantum key, which may be a QKD quantum key generated by a quantum satellite and a quantum ground station.
[0137] It should be noted that, in the embodiments of this application, the first device may include a first functional module and a second functional module, and this application does not specifically limit the number and type of functional modules included in the first device.
[0138] It should be noted that, in the embodiments of this application, the first functional module may include a key data source unit, which can generate first data. This application does not specifically limit the role of the first functional module.
[0139] It should be noted that, in the embodiments of this application, the second functional module may include a QKD quantum key synthesis unit, which can synthesize one or more first intermediate data based on the first data and the first key. This application does not specifically limit the role of the second functional module.
[0140] Optionally, in an embodiment of this application, the first functional module in the first device can acquire first data and send the first data to the second functional module; then the second functional module can determine one or more first intermediate data based on the first data and the first key, and send one or more first intermediate data to the quantum ground station.
[0141] Optionally, in embodiments of this application, before determining one or more first intermediate data based on the first data and the first key, the first device may first determine whether the first information satisfies the first preset condition; wherein, the first information includes one or more of the following: the first quantity of the current first key; the second quantity of the first key generated within the first preset time period; the third quantity of the remaining keys in the quantum satellite and ground application system; the key consumption rate information of the quantum satellite and ground application system within the second preset time period; the fourth quantity of the first key predicted to be generated within the third preset time period; if it is determined that the first preset condition is satisfied, one or more first intermediate data are determined based on the first data and the first key.
[0142] It should be noted that, in the embodiments of this application, if the first preset condition is not met, a secure communication channel is established between the quantum satellite and the ground application system based on the first key.
[0143] It should be noted that in the embodiments of this application, the first preset time period can be a recent period of time, such as within the last week, or any period of time. This application does not make specific limitations on the setting of the first preset time period.
[0144] It should be noted that in the embodiments of this application, the second preset time period can be a recent period of time, such as within the last week, or any period of time. This application does not make specific limitations on the setting of the second preset time period.
[0145] It should be noted that, in the embodiments of this application, the third preset time period can be a future period of time, such as the next month, or other future periods of time. This application does not make specific limitations on the setting of the third preset time period.
[0146] Optionally, in the embodiments of this application, when the first device determines whether the first information meets the first preset condition, it may determine that the first information meets the first preset condition when one or more of the following requirements are met; The first quantity is less than or equal to the first preset threshold; The second quantity is less than or equal to the second preset threshold; The third quantity is less than or equal to the third preset threshold; The consumption rate information is greater than or equal to the preset rate threshold; The fourth quantity is less than or equal to the fourth preset threshold.
[0147] It should be noted that, in the embodiments of this application, the first preset threshold can be used to measure whether the current number of first keys is sufficient. The first preset threshold can be set according to historical experience, and this application does not specifically limit the size of the first preset threshold.
[0148] It should be noted that, in the embodiments of this application, the second preset threshold can be used to measure whether the number of first keys generated within the first preset time period is sufficient. The second preset threshold can be set based on historical experience, and this application does not specifically limit the size of the second preset threshold.
[0149] It should be noted that, in the embodiments of this application, the third preset threshold can be used to measure whether the number of remaining keys in the quantum satellite and ground application system is sufficient, and this application does not specifically limit the size of the third preset threshold.
[0150] It should be noted that, in the embodiments of this application, the fourth preset threshold can be used to measure whether the number of first keys predicted and generated within the third preset time period is sufficient. This application does not specifically limit the size of the fourth preset threshold.
[0151] In other words, in the embodiments of this application, when one or more of the above requirements are met, if the requirement that the first quantity is less than or equal to the first preset threshold is met, it can be considered that the number of first keys currently generated is insufficient. One or more first intermediate data can be determined based on the first data and the first key, thereby expanding the number of keys (i.e., second keys) generated at the end based on the multiple first intermediate data, which greatly improves the production efficiency of keys.
[0152] It should be noted that, in the embodiments of this application, the first data may include a first quantum random number, which may include one or more quantum random numbers. This application does not specifically limit the data type and quantity of the first data.
[0153] Optionally, in embodiments of this application, when the second functional module in the first device determines one or more first intermediate data based on the first data and the first key, it can determine the corresponding first intermediate data for each quantum random number based on the first key, the quantum random number, and the first preset function; wherein, the first preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the first intermediate data.
[0154] It should be noted that, in the embodiments of this application, the first preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the first preset function.
[0155] For example, in an embodiment of this application, for each quantum random number, the corresponding first intermediate data can be determined based on the first key, the quantum random number, and the first preset function. It can be calculated using the formula (1) above.
[0156] For example, in an embodiment of this application, for each quantum random number, the corresponding first intermediate data is determined based on the first key, the quantum random number, and the first preset function. In this case, it can also be calculated using the above formula (2).
[0157] It should be noted that, in the embodiments of this application, the first data may also include a first pseudo-random number, which includes one or more pseudo-random numbers. This application does not specifically limit the data type and the number of data included in the first data.
[0158] Optionally, in embodiments of this application, when the second functional module in the first device determines one or more first intermediate data based on the first data and the first key, it can determine the corresponding first intermediate data for each pseudo-random number based on the first key, the pseudo-random number, and the first preset function.
[0159] For example, in an embodiment of this application, for each pseudo-random number, the corresponding first intermediate data is determined based on the first key, the pseudo-random number, and the first preset function. When the time is right, it can be calculated using the above formula (3).
[0160] For example, in an embodiment of this application, for each pseudo-random number, the corresponding first intermediate data is determined based on the first key, the pseudo-random number, and the first preset function. In this case, it can also be calculated using the above formula (4).
[0161] It should be noted that, in the embodiments of this application, the first data may also include a first historical key, such as the generated historical seed QKD quantum key. This application does not specifically limit the data type and quantity of the first data.
[0162] Optionally, in embodiments of this application, when the first device determines one or more first intermediate data based on the first data and the first key, it may group the first historical key based on the first key to obtain N key sets; wherein, each key set includes one or more fourth keys, the first historical key contains the fourth key, and N is a positive integer; for each key set, the corresponding first intermediate data is determined based on one or more fourth keys, the first key, and the first preset function.
[0163] For example, in an embodiment of this application, it is assumed that the first historical key includes , ..., Based on the first key, the first historical key is grouped to obtain 3 key sets, namely: , ..., ; , ..., ; , ..., For each key set, the corresponding first intermediate data can be determined based on one or more fourth keys, the first key and the first preset function in each key set. Taking the first key set as an example, it can be calculated by the above formula (5).
[0164] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more fourth keys, the first key and the first preset function in each key set, the first device can also calculate it by the above formula (6) for example, taking the first key set.
[0165] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more fourth keys, the first key and the first preset function in each key set, taking the first key set as an example, it can also be calculated by the above formula (7).
[0166] Optionally, in embodiments of this application, when the first device determines one or more first intermediate data based on the first data and the first key, it may also determine the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function.
[0167] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function, it can calculate it using the above formula (8).
[0168] For example, in the embodiments of this application, when the first device determines the corresponding first intermediate data based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function, it can also calculate it using the above formula (9).
[0169] In other words, in the embodiments of this application, the first device can generate one or more first intermediate data in various ways. For example, it can determine the corresponding first intermediate data based on the first key, each quantum random number, and the first preset function; it can also determine the corresponding first intermediate data based on the first key, each pseudo-random number, and the first preset function; it can also group the first historical key based on the first key to obtain N key sets, and then determine the corresponding first intermediate data based on one or more fourth keys, the first key, and the first preset function in each key set. That is, the embodiments of this application can generate one or more first intermediate data through various calculation strategies, thereby generating a larger number of key data resources, which facilitates the subsequent determination of the corresponding second key by the quantum ground station based on one or more first intermediate data, greatly improving the key production efficiency.
[0170] It should be noted that, in the embodiments of this application, after the first device determines one or more first intermediate data based on the first data and the first key, it can send one or more first intermediate data to the quantum ground station so that the quantum ground station can determine the corresponding second key based on one or more first intermediate data.
[0171] It should be noted that, in the embodiments of this application, as... Figure 2As shown, in addition to the first functional module and the second functional module, the first device may also include a third functional module. This application does not specifically limit the number and type of functional modules included in the first device.
[0172] It should be noted that, in the embodiments of this application, the third functional module may include a satellite-to-ground data interaction unit, which can be used to transmit first intermediate data to the quantum ground station.
[0173] Optionally, in embodiments of this application, the second functional module in the first device can send one or more first intermediate data to the third functional module, so that the third functional module can send one or more first intermediate data to the quantum ground station through a data communication channel.
[0174] It should be noted that, in the embodiments of this application, the data communication channel can use radio or high-power laser. The bandwidth of the data communication channel is much greater than the rate of the channel for generating QKD quantum keys (i.e., the first key), and the availability of the data communication channel is also much higher than that of the channel for generating QKD quantum keys.
[0175] Step 303: The third device determines the corresponding second key based on one or more first intermediate data.
[0176] It should be noted that, in the embodiments of this application, the third device may include a fifth functional module and a sixth functional module. This application does not specifically limit the type and number of functional modules included in the third device.
[0177] It should be noted that, in the embodiments of this application, the fifth functional module may be a QKD quantum key synthesis unit, which may be used to synthesize a corresponding second key based on one or more first intermediate data. This application does not specifically limit the role of the fifth functional module.
[0178] It should be noted that, in the embodiments of this application, the sixth functional module may be a satellite-to-ground data interaction unit, which may be used to receive one or more first intermediate data sent by the quantum satellite. This application does not specifically limit the role of the sixth functional module.
[0179] Optionally, in an embodiment of this application, the sixth functional module in the third device can receive one or more first intermediate data sent by the quantum satellite through a data communication channel, and send one or more first intermediate data to the fifth functional module, so that the fifth functional module can determine the corresponding second key based on each first intermediate data.
[0180] It should be noted that, in the embodiments of this application, the data communication channel may be a communication channel established between the third functional module in the first device and the sixth functional module in the third device. The data communication channel may use radio or high-power laser; and the bandwidth of the data communication channel is much greater than the rate of the channel for generating QKD quantum keys (i.e., the first key).
[0181] Step 304: The third device acquires the second data; wherein the second data is used to synthesize one or more second intermediate data.
[0182] It should be noted that, in the embodiments of this application, as... Figure 4 As shown, in addition to the fifth and sixth functional modules, the third device may also include a fourth functional module. This application does not specifically limit the type and number of functional modules included in the third device.
[0183] It should be noted that, in the embodiments of this application, the fourth functional module may be a key data source unit, which can generate second data. This application does not specifically limit the role of the fourth functional module.
[0184] Optionally, in the embodiments of this application, the second data can be used to synthesize one or more second intermediate data. For example, the second data may include quantum random numbers, pseudo-random numbers, etc. This application does not specifically limit the data type and number of data included in the second data.
[0185] Optionally, in embodiments of this application, the third device may obtain the second data through the fourth functional module and send the second data to the fifth functional module.
[0186] It should be noted that, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on one or more first intermediate data, it may determine the corresponding second key based on the second data, each first intermediate data, and the fourth preset function; or, it may determine the corresponding second key based on the second data, the first key, each first intermediate data, and the fourth preset function.
[0187] It should be noted that, in the embodiments of this application, the fourth preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the fourth preset function.
[0188] For example, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on the second data, each first intermediate data and the fourth preset function, it can be calculated by the above formula (10) or formula (11).
[0189] For example, in the embodiments of this application, when the fifth functional module in the third device determines the corresponding second key based on the second data, the first key, each first intermediate data and the fourth preset function, it can be calculated by the above formula (12) or formula (13).
[0190] Step 305: The third device determines one or more second intermediate data based on the second data and the first key, and sends one or more second intermediate data to the quantum satellite.
[0191] It should be noted that, in the embodiments of this application, the first key includes a quantum key, which may be a QKD quantum key generated by the quantum satellite and the quantum ground station.
[0192] Optionally, in embodiments of this application, the fifth functional module in the third device may determine one or more second intermediate data based on the second data and the first key, and send one or more second intermediate data to the quantum satellite.
[0193] It should be noted that, in the embodiments of this application, the second data may include a second quantum random number, which may include one or more quantum random numbers. This application does not specifically limit the data type included in the second data.
[0194] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can determine the corresponding second intermediate data for each quantum random number based on the first key, the quantum random number, and a third preset function; wherein, the third preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the second intermediate data.
[0195] It should be noted that, in the embodiments of this application, the third preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function types included in the third preset function.
[0196] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data for each quantum random number based on the first key, the quantum random number and the third preset function, it can calculate it using the above formula (1) or formula (2).
[0197] It should be noted that, in the embodiments of this application, the second data may also include a second pseudo-random number, which includes one or more pseudo-random numbers. This application does not specifically limit the data type included in the second data.
[0198] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can determine the corresponding second intermediate data for each pseudo-random number based on the first key, the pseudo-random number, and the third preset function.
[0199] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data for each pseudo-random number based on the first key, the pseudo-random number and the third preset function, it can calculate it using the above formula (3) or formula (4).
[0200] It should be noted that, in the embodiments of this application, the second data may also include a second historical key, such as the generated historical seed QKD quantum key.
[0201] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it can also group the second historical key based on the first key to obtain N key sets; wherein, each key set includes one or more fifth keys, the second historical key contains the fifth key, and N is a positive integer; for each key set, the corresponding second intermediate data can be determined based on one or more fifth keys, the first key, and a third preset function.
[0202] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data based on one or more fifth keys, first keys and third preset functions in each key set, it can calculate it using the above formula (5) or formula (6) or formula (7).
[0203] Optionally, in embodiments of this application, when the third device determines one or more second intermediate data based on the second data and the first key, it may also determine the corresponding second intermediate data based on one or more of the second quantum random number, the second pseudo-random number, the second historical key, the first key, and the third preset function.
[0204] For example, in the embodiments of this application, when the third device determines the corresponding second intermediate data based on one or more of the second quantum random number, the second pseudo-random number, the second historical key, the first key, and the third preset function, it can calculate it using the above formula (8) or formula (9).
[0205] It should be noted that, in the embodiments of this application, after the fifth functional module in the third device determines one or more second intermediate data based on the second data and the first key, it can send one or more second intermediate data to the quantum satellite.
[0206] Optionally, in an embodiment of this application, the fifth functional module in the third device can send one or more second intermediate data to the sixth functional module; then the sixth functional module can send one or more second intermediate data to the quantum satellite through a data communication channel.
[0207] Step 306: The first device determines the corresponding third key based on each second intermediate data. The second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0208] It should be noted that, in the embodiments of this application, the second functional module in the first device can receive one or more second intermediate data sent by the quantum ground station, and determine the corresponding third key based on each second intermediate data.
[0209] Optionally, in an embodiment of this application, the third functional module in the first device can receive one or more second intermediate data sent by the quantum ground station through a data communication channel, and then send one or more second intermediate data to the second functional module.
[0210] In other words, in the embodiments of this application, the second functional module in the first device can receive one or more second intermediate data sent by the quantum ground station, thereby determining the corresponding third key based on each second intermediate data, which significantly increases the number of third keys generated; correspondingly, the quantum ground station can also determine the corresponding second key based on one or more first intermediate data, so that the quantum satellite side and the quantum ground station side can generate consistent keys (i.e., the second key and the third key), and then establish a secure communication channel between the quantum satellite and the ground application system based on the second key and the third key, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0211] It should be noted that, in the embodiments of this application, the quantum satellite may also include a second device, and this application does not specifically limit the type and number of devices included in the quantum satellite.
[0212] It should be noted that, in the embodiments of this application, the second device may include satellite application equipment, and this application does not specifically limit the type of the second device.
[0213] It should be noted that, in the embodiments of this application, the second device can at least be used to establish a secure communication channel with the ground application system based on the third key. For example, the second functional module in the first device can send the generated third key to the second device so that the second device can establish a secure communication channel with the ground application system based on the third key.
[0214] Optionally, in embodiments of this application, when the second functional module in the first device determines the corresponding third key based on each second intermediate data, it may determine the corresponding third key based on the first data, each second intermediate data, and the second preset function; or, it may determine the corresponding third key based on the first data, the first key, each second intermediate data, and the second preset function.
[0215] It should be noted that, in the embodiments of this application, the second preset function may include hash functions, XOR functions, etc., and this application does not specifically limit the function type and number of functions included in the second preset function.
[0216] For example, in an embodiment of this application, the second functional module in the first device can calculate the corresponding third key based on the first data, each second intermediate data and the second preset function using the above formula (10).
[0217] For example, in an embodiment of this application, when the second functional module in the first device determines the corresponding third key based on the first data, each second intermediate data and the second preset function, it can also calculate it using the above formula (11).
[0218] For example, in an embodiment of this application, the second functional module in the first device can calculate the corresponding third key based on the first data, the first key, each second intermediate data and the second preset function using the above formula (12).
[0219] For example, in an embodiment of this application, when the second functional module in the first device determines the corresponding third key based on the first data, the first key, each second intermediate data and the second preset function, it can also calculate it using the above formula (13).
[0220] It should be noted that, in the embodiments of this application, steps 301-303 should be executed sequentially; steps 304-306 should be executed sequentially; steps 301-303 as a whole and steps 304-306 as a whole can be performed in parallel or sequentially. This application does not impose specific limitations on the execution order.
[0221] In summary, the first device can receive one or more second intermediate data sent by the quantum ground station and determine the corresponding third key based on each second intermediate data. This results in a significantly larger number of synthesized third keys than the number of first keys, thereby increasing the key quantity of QKD quantum keys and improving the QKD quantum key generation efficiency. The quantum ground station can also determine the corresponding second key based on one or more first intermediate data, similarly increasing the key quantity of QKD quantum keys. This ensures that there are sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, avoiding the problem that quantum keys between satellite and ground often cannot satisfy one-time pad conditions, and greatly improving the security of satellite-ground communication.
[0222] This application provides a key generation method, which is applied to a first device and a third device. The first device acquires first data; wherein the first data is used to synthesize one or more first intermediate data; one or more first intermediate data are determined based on the first data and a first key, and the one or more first intermediate data are sent to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key includes a quantum key; one or more second intermediate data are received from the quantum ground station, and a corresponding third key is determined based on each second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key. That is, the embodiments of this application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating a larger number of key data resources. Then, one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine the corresponding second key based on the multiple first intermediate data. Correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then determine the corresponding third key based on each second intermediate data. This greatly increases the number of keys provided to the quantum satellite and the ground application system. Moreover, the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0223] Based on the above embodiments, another embodiment of this application provides a key generation method. This method does not directly use QKD quantum keys generated in the open space between the satellite and the ground, but instead uses these keys (i.e., the first key) as seed keys. At the same time, random number sources, such as quantum key random number generators (QRNGs) or QKD quantum key history sets, are deployed on the QKD quantum satellite and QKD quantum ground station. After these random number sources (i.e., the first data or the second data) are fused with the seed key (i.e., the first key), a larger number of key data resources are generated. In addition, a data channel can be established between the QKD quantum satellite and the QKD quantum ground station. The data channel supports the satellite-to-ground interaction required in the key fusion operation. Since the data channel can use radio or high-power laser, the bandwidth of the data channel is much greater than the rate of the channel that generates QKD quantum keys, and the availability of the data channel is also much higher than that of the channel that generates QKD quantum keys.
[0224] It should be noted that, in the embodiments of this application, Figure 6 This is a schematic diagram of the system architecture for key generation proposed in the embodiments of this application, such as... Figure 6 As shown, the system architecture may include a satellite, a quantum ground station, and a ground application system. For the satellite side: the satellite (i.e., the quantum satellite) may include a first device and a second device; wherein the first device may include a satellite-to-ground QKD interaction unit, a key data source unit (i.e., a first functional module), a QKD quantum key synthesis unit (i.e., a second functional module), and a satellite-to-ground data interaction unit (i.e., a third functional module); the second device may include satellite application equipment. For the quantum ground station side: the quantum ground station may include a third device; wherein the third device may include a satellite-to-ground QKD interaction unit, a key data source unit (i.e., a fourth functional module), a QKD quantum key synthesis unit (i.e., a fifth functional module), and a satellite-to-ground data interaction unit (i.e., a sixth functional module).
[0225] It should be noted that, in the embodiments of this application, based on such Figure 6The key generation method implemented by the system architecture shown may include the following steps: Step 401: The satellite-to-ground QKD interaction unit in the QKD quantum satellite and the satellite-to-ground QKD interaction unit in the QKD quantum ground station generate a QKD quantum key (i.e., the first key), which serves as the seed key; Step 402: On the satellite side, the seed QKD quantum key (i.e., the first key) is submitted to the QKD quantum key synthesis unit (i.e., the second functional module); similarly, on the ground station side, the seed QKD quantum key is submitted to the QKD quantum key synthesis unit (i.e., the fifth functional module); Step 403: On the satellite side, the QKD quantum key synthesis unit obtains the key data from the key data unit... The QKD quantum key synthesis unit (i.e., the first functional module) extracts the synthesis factor data (i.e., the first data); similarly, on the ground station side, the QKD quantum key synthesis unit extracts the synthesis factor data (i.e., the second data) from the key data unit (i.e., the fourth functional module); step 404: On the satellite side, the QKD quantum key synthesis unit performs the first synthesis calculation based on the seed QKD quantum key (i.e., the first key) and the synthesis factor data (i.e., the first data), synthesizing a piece of intermediate data (i.e., the first intermediate data), and sends it to the QKD quantum key synthesis unit on the ground station side through the satellite-to-ground data interaction unit (i.e., the third functional module); ... similarly, on the ground station side, the QKD quantum key synthesis unit extracts the synthesis factor data (i.e., the second data) from the key data unit (i.e., the third functional module); similarly, on the key station side, the QKD quantum key synthesis unit extracts the synthesis factor data (i.e., the second data) from the key data unit (i.e., the fourth functional module); step 404: On The seed QKD quantum key (i.e., the first key) and synthesis factor data (i.e., the second data) are used for the first synthesis calculation to synthesize intermediate data (i.e., the second intermediate data), which is then sent to the QKD quantum key synthesis unit on the satellite side via the satellite-to-ground data interaction unit (i.e., the sixth functional module). Step 405: On the satellite side, the QKD quantum key synthesis unit performs a second synthesis calculation based on the local synthesis factor data (i.e., the first data), the intermediate data transmitted from the ground station (i.e., the second intermediate data), and (on demand) the seed QKD quantum key (i.e., the first key) to generate the synthesized final key (i.e., the third key). On the ground station side, QKD... The QKD quantum key synthesis unit performs a second synthesis calculation based on the local synthesis factor data (i.e., the second data), the intermediate data transmitted from the satellite (i.e., the first intermediate data), and the seed QKD quantum key (as needed), to generate the synthesized final key (i.e., the second key); Step 406: On the satellite side, the QKD quantum key synthesis unit submits the synthesized final key (i.e., the third key) to the satellite application equipment; On the ground station side, the QKD quantum key synthesis unit submits the synthesized final key (i.e., the second key) to the ground application system; Step 407: The satellite application equipment and the ground application system establish a secure communication channel based on the synthesized key.
[0226] It should be noted that, in the embodiments of this application, after step 402 above, that is, after the QKD quantum key synthesis unit receives the seed QKD quantum key, it can perform a synthesis operation, that is, execute steps 403, 404, and 405; or it can directly use the seed quantum key without performing a synthesis operation, that is, skip steps 403, 404, and 405 and jump directly to step 406.
[0227] For example, in the embodiments of this application, the reasons that prompt the QKD quantum key synthesis unit to decide whether to perform the synthesis operation may be one or more of the following factors: Is the number of seed QKD quantum keys (i.e., the first key) generated this time sufficient? Is the number of seed QKD quantum keys generated in the recent period (i.e., the first preset time period) sufficient (i.e., the second quantity)? Currently, is the number of available quantum keys remaining in this pair of satellite application equipment-ground application systems sufficient? In the recent period (i.e., the second preset time period), is the quantum key consumed by this pair of satellite application equipment-ground application system fast enough (i.e. consumption rate information)? The prediction focuses on whether the number of seed QKD quantum keys (the fourth quantity) that the QKD quantum satellite and QKD ground station can generate in the future (i.e., the third preset time period) will be sufficient. For example, when the satellite is nearing the end of its service life, or when severe weather is forecasted, it may be impossible to generate a sufficient number of seed QKD quantum keys in a timely manner.
[0228] For example, in the embodiments of this application, the synthesis operation can be performed when one or more of the following requirements are met, i.e., steps 403, 404, and 405 are executed.
[0229] The first quantity is less than or equal to the first preset threshold; The second quantity is less than or equal to the second preset threshold; The third quantity is less than or equal to the third preset threshold; The consumption rate information is greater than or equal to the preset rate threshold; The fourth quantity is less than or equal to the fourth preset threshold.
[0230] It should be noted that, in the embodiments of this application, the first preset threshold can be used to measure whether the current number of first keys is sufficient. The first preset threshold can be set according to historical experience, and this application does not specifically limit the size of the first preset threshold.
[0231] It should be noted that, in the embodiments of this application, the second preset threshold can be used to measure whether the number of first keys generated within the first preset time period is sufficient. The second preset threshold can be set based on historical experience, and this application does not specifically limit the size of the second preset threshold.
[0232] It should be noted that, in the embodiments of this application, the third preset threshold can be used to measure whether the number of remaining keys in the quantum satellite and ground application system is sufficient, and this application does not specifically limit the size of the third preset threshold.
[0233] It should be noted that, in the embodiments of this application, the fourth preset threshold can be used to measure whether the number of first keys predicted and generated within the third preset time period is sufficient. This application does not specifically limit the size of the fourth preset threshold.
[0234] In other words, in the embodiments of this application, when one or more of the above requirements are met, if the requirement that the first quantity is less than or equal to the first preset threshold is met, it can be considered that the number of the first keys generated is insufficient, and steps 403, 404, and 405 can be executed to perform key synthesis operations, which greatly improves the production efficiency of keys.
[0235] Optionally, in embodiments of this application, the process of generating the first intermediate data may be as shown in the following formula (14).
[0236] (14) in, This represents the first intermediate data. Indicates the first data. Indicates the first key. This indicates the operation function (i.e., the first preset function) to be used in this satellite-side composite calculation.
[0237] Optionally, in embodiments of this application, the process of generating the second intermediate data can be as shown in the following formula (15).
[0238] (15) in, This represents the second intermediate data. Indicates the second data. This indicates the operation function (i.e., the third preset function) to be used in this synthetic calculation on the ground station side.
[0239] It should be noted that, in the embodiments of this application, the operation functions adopted by the key data unit on the satellite side and the key data unit on the ground station may be the same or different. That is... , The parentheses () can be the same function or different functions. However, the algorithms used by the satellite and the ground station must be mutually known. That is, the ground station must know... The satellite needs to know. ().
[0240] For example, in the embodiments of this application, the intermediate data can be calculated using one of the following example options: taking the satellite side as an example: 1. The key data source unit can include a quantum random number generator to generate a batch of quantum random numbers (i.e., the first quantum random number), which are then fused with the seed QKD quantum key (i.e., the first key) and used as intermediate data (i.e., the first intermediate data). In the batch of generated quantum random numbers, each random number QRN_(sat,t) is calculated using the above formula (1) or formula (2); 2. The key data source unit can include other random number generators, such as a pseudo-random number generator, to generate a batch of random numbers as extended key data (i.e., the first pseudo-random number). In a batch of generated quantum random numbers, each random number PRN_(sat,t) is calculated using the formula (3) or formula (4) above; 3. The key data source unit stores the seed QKD quantum key (i.e. the first historical key) generated previously. Based on the seed QKD quantum key of this time, multiple groups (i.e. N key sets) are selected from the previous seed QKD quantum key set. Each group is used for derivation calculation, and the calculation result is used as the extended key data. Then it is fused with the seed QKD quantum key of this time; Examples are shown in the formula (5), formula (6) and formula (7) above; 4. The above three calculation methods can also be combined, for example, intermediate data can be obtained by calculating using the formula (8) or formula (9) above.
[0241] It should be noted that, in the embodiments of this application, the process of synthesizing the final key is as follows, taking the satellite side as an example, based on the local synthesis factor... (i.e., the first data) and intermediate data transmitted from the ground station. (i.e., the second intermediate data), and (on demand) the seed QKD quantum key for this project. ,use The () function (i.e., the second preset function) generates the final key. (i.e., the third key), as shown in formula (16) or formula (17) below.
[0242] (16) in, Indicates the third key. Indicates the first data. This represents the second intermediate data. This represents the first key.
[0243] (17) It should be noted that, in the embodiments of this application, the ground station can adjust the local synthesis factor. (i.e., the second data), intermediate data transmitted from the satellite. (i.e., the first intermediate data), and (on demand) the seed QKD quantum key for this project. ,use The () function (i.e., the fourth preset function) generates the final key. (i.e., the second key), as shown in formula (18) or formula (19) below.
[0244] (18) in, Indicates the second key. This represents the first intermediate data. Indicates the second data. This represents the first key.
[0245] (19) It should be noted that, in the embodiments of this application, in order to ensure that the calculations on the satellite side and the ground station side are accurate, the following measures are taken: For them to be identical, the following conditions must be met:
[0246] Where X represents the seed key. B represents the second data point, and A represents the first data point.
[0247] For example, in the embodiments of this application, taking the satellite side as an example, the specific synthesis method of the final key (i.e. the third key) can be calculated by the above formula (10) or formula (11) or formula (12) or formula (13).
[0248] In summary, the first device can receive one or more second intermediate data sent by the quantum ground station and determine the corresponding third key based on each second intermediate data. This results in a significantly larger number of synthesized third keys than the number of first keys, thereby increasing the key quantity of QKD quantum keys and improving the QKD quantum key generation efficiency. The quantum ground station can also determine the corresponding second key based on one or more first intermediate data, similarly increasing the key quantity of QKD quantum keys. This ensures that there are sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, avoiding the problem that quantum keys between satellite and ground often cannot satisfy one-time pad conditions, and greatly improving the security of satellite-ground communication.
[0249] This application provides a key generation method, which is applied to a first device and a third device. The first device is deployed on a quantum satellite and acquires first data. The first data is used to synthesize one or more first intermediate data. Based on the first data and a first key, one or more first intermediate data are determined, and the one or more first intermediate data are sent to a quantum ground station so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data. The first key includes a quantum key. The method also involves receiving one or more second intermediate data sent by the quantum ground station and determining a corresponding third key based on each second intermediate data. The second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key. That is, the embodiments of this application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating a larger number of key data resources. Then, one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine the corresponding second key based on the multiple first intermediate data. Correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then determine the corresponding third key based on each second intermediate data. This greatly increases the number of keys provided to the quantum satellite and the ground application system. Moreover, the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0250] Based on the above embodiments, this application provides a first device. Figure 7 Schematic diagram of the composition structure of the first device Figure One ,like Figure 7 As shown, the first device 10 includes: a first acquisition unit 11, a first determination unit 12, a first transmission unit 13, and a first receiving unit 14; wherein, The first acquisition unit 11 is used to acquire first data; wherein, the first data is used to synthesize one or more first intermediate data; The first determining unit 12 is used to determine one or more first intermediate data based on the first data and the first key; The first sending unit 13 is configured to send one or more first intermediate data to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein, the first key includes a quantum key; The first receiving unit 14 is used to receive one or more second intermediate data sent by the quantum ground station; The first determining unit 12 is further configured to determine a corresponding third key based on each of the second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0251] In the embodiments of this application, further, Figure 8 Schematic diagram of the composition structure of the first device Figure Two ,like Figure 8 As shown, the first device 10 proposed in this application embodiment may further include a first processor 15, a first memory 16 storing instructions executable by the first processor 15, and further, the first device 10 may also include a first communication interface 17 and a first bus 18 for connecting the first processor 15, the first memory 16 and the first communication interface 17.
[0252] In the embodiments of this application, the first processor 15 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit this. The first device 10 may further include a first memory 16, which can be connected to the first processor 15. The first memory 16 is used to store executable program code, which includes computer operation instructions. The first memory 16 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.
[0253] In embodiments of this application, the first bus 18 is used to connect the first communication interface 17, the first processor 15, and the first memory 16, as well as the mutual communication between these devices.
[0254] In embodiments of this application, the first memory 16 is used to store instructions and data.
[0255] Further, in an embodiment of this application, the first processor 15 is configured to acquire first data; wherein the first data is used to synthesize one or more first intermediate data; determine one or more first intermediate data based on the first data and a first key, and send the one or more first intermediate data to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key includes a quantum key; receive one or more second intermediate data sent by the quantum ground station, and determine a corresponding third key based on each second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0256] In practical applications, the first memory 16 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 15.
[0257] This application provides a first device deployed on a quantum satellite. The first device acquires first data; wherein the first data is used to synthesize one or more first intermediate data; one or more first intermediate data are determined based on the first data and a first key, and the one or more first intermediate data are sent to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein the first key includes a quantum key; one or more second intermediate data are received from the quantum ground station, and a corresponding third key is determined based on each second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the first device can determine one or more first intermediate data based on the first data and the first key. That is, the embodiments of this application can determine one or more first intermediate data based on the quantum key and the first data, thereby generating a larger number of key data resources. Then, one or more first intermediate data can be sent to the quantum ground station, so that the quantum ground station can determine the corresponding second key based on the multiple first intermediate data. Correspondingly, the first device can also receive one or more second intermediate data sent by the quantum ground station, and then determine the corresponding third key based on each second intermediate data. This greatly increases the number of keys provided to the quantum satellite and the ground application system. Moreover, the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system, thereby improving the security of satellite-to-ground communication while improving the key production efficiency.
[0258] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the key generation method described above.
[0259] Specifically, the program instructions corresponding to a key generation method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a key generation method in the storage media are read or executed by an electronic device, the following steps are included: Obtain first data; wherein, the first data is used to synthesize one or more first intermediate data; Based on the first data and the first key, one or more first intermediate data are determined, and the one or more first intermediate data are sent to the quantum ground station, so that the quantum ground station determines the corresponding second key based on the one or more first intermediate data; wherein, the first key includes a quantum key; The system receives one or more second intermediate data sent by the quantum ground station and determines a corresponding third key based on each second intermediate data. The second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0260] This application also provides a computer program product, including a computer program that can be executed by a first processor 15 of a first device 10 to perform the steps described in any of the foregoing methods.
[0261] In the embodiments of this application, further, Figure 9 Schematic diagram of the composition structure of the third device Figure One ,like Figure 9 As shown, the third device 20 includes: a second acquisition unit 21, a second determination unit 22, a second transmission unit 23, and a second receiving unit 24; wherein, The second receiving unit 24 is used to receive one or more first intermediate data sent by the quantum satellite, and determine the corresponding second key based on the one or more first intermediate data; The second acquisition unit 21 is used to acquire second data; wherein the second data is used to synthesize one or more second intermediate data; The second determining unit 22 is used to determine one or more second intermediate data based on the second data and the first key; The second sending unit 23 is used to send one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein, the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0262] In the embodiments of this application, further, Figure 10 Schematic diagram of the composition structure of the third device Figure Two ,like Figure 10 As shown, the third device 20 proposed in this application embodiment may further include a second processor 25, a second memory 26 storing instructions executable by the second processor 25, and further, the third device 20 may also include a second communication interface 27 and a second bus 28 for connecting the second processor 25, the second memory 26 and the second communication interface 27.
[0263] In the embodiments of this application, the second processor 25 can be at least one of the following: Application-Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field-Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this application embodiment does not specifically limit the specific types. The third device 20 may further include a second memory 26, which can be connected to the second processor 25. The second memory 26 is used to store executable program code, which includes computer operation instructions. The second memory 26 may include high-speed RAM memory and may also include non-volatile memory, such as at least two disk drives.
[0264] In embodiments of this application, the second bus 28 is used to connect the second communication interface 27, the second processor 25, and the second memory 26, as well as the mutual communication between these devices.
[0265] In embodiments of this application, the second memory 26 is used to store instructions and data.
[0266] Further, in an embodiment of this application, the second processor 25 is configured to receive one or more first intermediate data sent by the quantum satellite, and determine a corresponding second key based on the one or more first intermediate data; acquire second data; wherein the second data is used to synthesize one or more second intermediate data; determine one or more second intermediate data based on the second data and the first key, and send the one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0267] In practical applications, the second memory 26 can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 25.
[0268] This application provides a third device that receives one or more first intermediate data sent by a quantum satellite and determines a corresponding second key based on the one or more first intermediate data; acquires second data; wherein the second data is used to synthesize one or more second intermediate data; determines one or more second intermediate data based on the second data and the first key, and sends the one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system. Therefore, the third device can determine one or more second intermediate data based on the second data and the first key, thereby generating a larger amount of key data resources, and sends one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data. Furthermore, the third device can determine a corresponding second key based on one or more first intermediate data, allowing the third device and the quantum satellite to expand the key quantity of QKD quantum keys, thus providing sufficient keys to establish a secure communication channel between the quantum satellite and the ground application system, greatly improving the security of satellite-to-ground communication.
[0269] This application provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the key generation method described above.
[0270] Specifically, the program instructions corresponding to a key generation method in this embodiment can be stored on storage media such as optical discs, hard disks, and USB flash drives. When the program instructions corresponding to a key generation method in the storage media are read or executed by an electronic device, the following steps are included: Receive one or more first intermediate data sent by a quantum satellite, and determine the corresponding second key based on the one or more first intermediate data; Obtain second data; wherein the second data is used to synthesize one or more second intermediate data; Based on the second data and the first key, one or more second intermediate data are determined, and the one or more second intermediate data are sent to the quantum satellite so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein, the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
[0271] This application also provides a computer program product, including a computer program that can be executed by a second processor 25 of a third device 20 to perform the steps described in any of the foregoing methods.
[0272] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0273] This application is described with reference to schematic and / or block diagrams of implementations of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the schematic and / or block diagrams can be implemented by computer program instructions, and combinations of blocks in the schematic and / or block diagrams can be implemented. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the schematic and / or block diagrams. Figure One One or more processes and / or boxes Figure One A device that provides the functions specified in one or more boxes.
[0274] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the implementation flow diagram. Figure One One or more processes and / or boxes Figure One The function specified in one or more boxes.
[0275] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure One One or more processes and / or boxes Figure One The steps of the function specified in one or more boxes.
[0276] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.
Claims
1. A key generation method, characterized in that, The method is applied to a first device, which is deployed on a quantum satellite, and the method includes: Obtain first data; wherein, the first data is used to synthesize one or more first intermediate data; Based on the first data and the first key, one or more first intermediate data are determined, and the one or more first intermediate data are sent to the quantum ground station, so that the quantum ground station determines the corresponding second key based on the one or more first intermediate data; wherein, the first key includes a quantum key; The system receives one or more second intermediate data sent by the quantum ground station and determines a corresponding third key based on each second intermediate data. The second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
2. The method according to claim 1, characterized in that, The first device includes a first functional module and a second functional module, and the method further includes: The first data is obtained through the first functional module, and the first data is sent to the second functional module; The second functional module determines one or more first intermediate data based on the first data and the first key, and sends the one or more first intermediate data to the quantum ground station; The second functional module receives one or more second intermediate data sent by the quantum ground station, and determines the corresponding third key based on each second intermediate data.
3. The method according to claim 1 or 2, characterized in that, The quantum satellite includes a second device, which is at least used to establish a secure communication channel with the ground application system based on the third key.
4. The method according to claim 1, wherein before determining one or more first intermediate data based on the first data and the first key, the method further comprises: Determine whether the first information satisfies the first preset condition; wherein, The first information includes one or more of the following: The first number of the current first key; The second number of first keys generated within a first preset time period; The third number of remaining keys in the quantum satellite and the ground application system; Information on the key consumption rate of the quantum satellite and the ground application system during a second preset time period; The fourth number of first keys predicted to be generated within the third preset time period; If the first preset condition is met, one or more first intermediate data are determined based on the first data and the first key.
5. The method according to claim 4, characterized in that, The method further includes: If the first preset condition is not met, the quantum satellite and the ground application system establish a secure communication channel based on the first key.
6. The method according to claim 4, characterized in that, The determination of whether the first information meets the first preset condition includes: The first information is determined to satisfy the first preset condition when one or more of the following requirements are met; The first quantity is less than or equal to the first preset threshold; The second quantity is less than or equal to the second preset threshold; The third quantity is less than or equal to the third preset threshold; The consumption rate information is greater than or equal to a preset rate threshold; The fourth quantity is less than or equal to the fourth preset threshold.
7. The method according to claim 1 or 2, characterized in that, The first data includes a first quantum random number, which includes one or more quantum random numbers. The step of determining one or more first intermediate data based on the first data and the first key includes: For each quantum random number, the corresponding first intermediate data is determined based on the first key, the quantum random number, and the first preset function; The first preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the first intermediate data.
8. The method according to claim 1 or 2, characterized in that, The first data includes a first pseudo-random number, which includes one or more pseudo-random numbers. The step of determining one or more first intermediate data based on the first data and the first key includes: For each of the pseudo-random numbers, the corresponding first intermediate data is determined based on the first key, the pseudo-random number, and the first preset function.
9. The method according to claim 1 or 2, characterized in that, The first data also includes a first historical key, and the step of determining one or more first intermediate data based on the first data and the first key includes: Based on the first key, the first historical key is grouped to obtain N key sets; wherein each key set includes one or more fourth keys, the first historical key contains the fourth key, and N is a positive integer; For each set of keys, the corresponding first intermediate data is determined based on one or more fourth keys, the first key, and the first preset function.
10. The method according to claim 1 or 2, characterized in that, The step of determining one or more first intermediate data based on the first data and the first key includes: The first intermediate data is determined based on one or more of the first quantum random number, the first pseudo-random number, the first historical key, the first key, and the first preset function.
11. The method according to claim 1 or 2, characterized in that, The step of determining the corresponding third key based on each of the second intermediate data includes: The corresponding third key is determined based on the first data, each of the second intermediate data, and the second preset function; or, The corresponding third key is determined based on the first data, the first key, each of the second intermediate data, and the second preset function.
12. The method according to claim 2, wherein the first device includes a third functional module, and the step of sending the one or more first intermediate data to the quantum ground station includes: The second functional module sends one or more first intermediate data to the third functional module, so that the third functional module sends one or more first intermediate data to the quantum ground station through a data communication channel.
13. The method according to claim 2, wherein receiving one or more second intermediate data transmitted by the quantum ground station comprises: The third functional module receives one or more second intermediate data sent by the quantum ground station through the data communication channel, and sends the one or more second intermediate data to the second functional module.
14. A key generation method, characterized in that, The method is applied to a third device deployed at a quantum ground station, and the method includes: Receive one or more first intermediate data sent by a quantum satellite, and determine the corresponding second key based on the one or more first intermediate data; Obtain second data; wherein the second data is used to synthesize one or more second intermediate data; Based on the second data and the first key, one or more second intermediate data are determined, and the one or more second intermediate data are sent to the quantum satellite so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein, the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
15. The method according to claim 14, characterized in that, The third device includes a fourth functional module and a fifth functional module, and the method further includes: The second data is obtained through the fourth functional module and then sent to the fifth functional module. The fifth functional module determines one or more second intermediate data based on the second data and the first key, and sends the one or more second intermediate data to the quantum satellite. The fifth functional module receives one or more first intermediate data sent by the quantum satellite, and determines the corresponding second key based on each first intermediate data.
16. The method according to claim 14 or 15, characterized in that, The second data includes a second quantum random number, which includes one or more quantum random numbers. The step of determining one or more second intermediate data based on the second data and the first key includes: For each quantum random number, the corresponding second intermediate data is determined based on the first key, the quantum random number, and the third preset function; The third preset function is used to perform a synthesis operation on the first key and the quantum random number to obtain the second intermediate data.
17. The method according to claim 14 or 15, characterized in that, The second data includes a second pseudo-random number, which includes one or more pseudo-random numbers. The step of determining one or more second intermediate data based on the second data and the first key includes: For each of the pseudo-random numbers, the corresponding second intermediate data is determined based on the first key, the pseudo-random number, and the third preset function.
18. The method according to claim 14 or 15, characterized in that, The second data also includes a second historical key, and the step of determining one or more second intermediate data based on the second data and the first key includes: Based on the first key, the second historical key is grouped to obtain N key sets; wherein each key set includes one or more fifth keys, the second historical key contains the fifth key, and N is a positive integer; For each set of keys, the corresponding second intermediate data is determined based on one or more fifth keys, the first key, and the third preset function.
19. The method according to claim 14 or 15, characterized in that, The step of determining one or more second intermediate data based on the second data and the first key includes: The corresponding second intermediate data is determined based on one or more of the second quantum random number, the second pseudo-random number, the second historical key, the first key, and the third preset function.
20. The method according to claim 14, characterized in that, Determining the corresponding second key based on the one or more first intermediate data includes: The corresponding second key is determined based on the second data, each of the first intermediate data, and the fourth preset function; or, The corresponding second key is determined based on the second data, the first key, each of the first intermediate data, and the fourth preset function.
21. The method according to claim 15, characterized in that, The third device includes a sixth functional module, wherein sending the one or more second intermediate data to the quantum satellite includes: The fifth functional module sends the one or more second intermediate data to the sixth functional module; The sixth functional module sends one or more second intermediate data to the quantum satellite through a data communication channel.
22. The method according to claim 15, characterized in that, The receipt of one or more first intermediate data transmitted by the quantum satellite includes: The sixth functional module receives one or more first intermediate data sent by the quantum satellite through the data communication channel, and sends the one or more first intermediate data to the fifth functional module.
23. A first device, characterized in that, The first device includes: a first acquisition unit, a first determination unit, a first transmission unit, and a first receiving unit; wherein, The first acquisition unit is used to acquire first data; wherein the first data is used to synthesize one or more first intermediate data; The first determining unit is configured to determine one or more first intermediate data based on the first data and the first key; The first sending unit is configured to send one or more first intermediate data to a quantum ground station, so that the quantum ground station determines a corresponding second key based on the one or more first intermediate data; wherein, the first key includes a quantum key; The first receiving unit is used to receive one or more second intermediate data sent by the quantum ground station; The first determining unit is further configured to determine a corresponding third key based on each of the second intermediate data, wherein the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
24. A first device, characterized in that, The first device includes: a first processor and a first memory; wherein, The first memory is used to store computer programs that can run on the processor; The first processor is configured to perform the method as described in any one of claims 1-13 when running the computer program.
25. A third device, characterized in that, The third device includes: a second acquisition unit, a second determination unit, a second transmission unit, and a second receiving unit; wherein, The second receiving unit is used to receive one or more first intermediate data sent by the quantum satellite, and determine the corresponding second key based on the one or more first intermediate data; The second acquisition unit is used to acquire second data; wherein the second data is used to synthesize one or more second intermediate data; The second determining unit is used to determine one or more second intermediate data based on the second data and the first key; The second transmitting unit is used to transmit one or more second intermediate data to the quantum satellite, so that the quantum satellite determines a corresponding third key based on the one or more second intermediate data; wherein, the first key includes a quantum key, and the second key and the third key are used to establish a secure communication channel between the quantum satellite and the ground application system.
26. A third device, characterized in that, The third device includes: a second processor and a second memory; wherein... The second memory is used to store computer programs that can run on the processor; The second processor is configured to perform the method as described in any one of claims 14-22 when running the computer program.
27. A computer-readable storage medium, characterized in that, The storage medium stores computer program code, which, when executed by a computer, performs the method described in any one of claims 1-13 or 14-22.
28. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1-13 or 14-22.