Intelligent chip equipment security authentication method and system based on quantum SIM card

By combining quantum SIM cards and quantum keys, the security vulnerabilities of traditional smart chip device security authentication methods are solved, enabling reliable identity authentication and dynamic secure connections, preventing replay attacks, and improving the security of IoT devices.

CN121841648APending Publication Date: 2026-04-10BEIJING FEINNO COMM TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING FEINNO COMM TECH
Filing Date
2026-01-23
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional smart chip devices rely on symmetric or asymmetric cryptographic algorithms for security authentication. The keys are easily extracted physically or attacked by side channels, making it difficult to meet the high security requirements of IoT scenarios.

Method used

A smart chip device security authentication method based on quantum SIM cards is adopted. The challenge and response are encrypted and decrypted using quantum keys, and combined with a quantum key distribution protocol, identity authentication and key negotiation are realized. A Markov chain evaluation model is constructed to dynamically monitor the communication status.

Benefits of technology

It achieves reliable authentication between smart chip devices and quantum authentication systems, prevents replay attacks, dynamically monitors communication status, and comprehensively ensures secure connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841648A_ABST
    Figure CN121841648A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent chip equipment security authentication method and system based on a quantum SIM card, and the method comprises the steps: receiving a first challenge initiated by a quantum authentication system, and carrying out the decryption of the first challenge through a quantum key, and obtaining a first challenge plaintext; generating a first response based on the first challenge plaintext; encrypting the first response through the quantum key based on the quantum SIM card, and sending the encrypted first response to the quantum authentication system, so that the quantum authentication system performs identity authentication on the intelligent chip equipment based on the first response; under the condition that the identity authentication is successful, performing key negotiation with a quantum authentication system based on a quantum key distribution protocol to obtain a shared key; and establishing a communication connection with the quantum authentication system by using the shared key. Therefore, according to the method, reliable authentication of the intelligent chip equipment and the quantum authentication system can be realized by fusing the quantum SIM card and the quantum key, so that secure connection is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of network security technology and smart chip technology, and in particular to a method and system for security authentication of smart chip devices based on quantum SIM cards. Background Technology

[0002] A smart chip (or smart chip for short) is the core computing unit of an Internet of Things (IoT) device, integrating modules such as identity authentication, secure storage, and communication interfaces. For example, applying a smart chip to an electric vehicle can enable vehicle status monitoring and remote vehicle control. Devices equipped with a smart chip can be simply referred to as smart chip devices or smart chip devices.

[0003] Security authentication of smart chip devices is generally achieved through a challenge-response mechanism. A random challenge is initiated by the cloud, the smart chip device generates a response using a pre-stored key and signs it back, and the cloud verifies the legality of the signature to confirm the device's identity.

[0004] However, this type of security authentication method relies entirely on symmetric or asymmetric cryptographic algorithms to ensure data integrity. The key is generally stored in the open storage area of ​​the chip, which is easily extracted by physical means or attacked by side channels. Once the key is leaked, it will lead to long-term security risks and is difficult to meet the high security requirements of IoT scenarios. Summary of the Invention

[0005] This application provides a method and system for secure authentication of smart chip devices based on quantum SIM cards, in order to solve the security risks of traditional smart chip device security authentication methods.

[0006] In a first aspect, embodiments of this application provide a method for secure authentication of a smart chip device based on a quantum SIM card. The smart chip device includes at least a quantum SIM card, which has a pre-installed quantum key. The method includes: receiving a first challenge initiated by a quantum authentication system and decrypting the first challenge using the quantum key to obtain plaintext of the first challenge; wherein the first challenge is generated by the quantum authentication system using a quantum key corresponding to the smart chip device; generating a first response based on the plaintext of the first challenge; encrypting the first response using the quantum key on the quantum SIM card and sending the encrypted first response to the quantum authentication system, so that the quantum authentication system can authenticate the smart chip device based on the first response; if the authentication is successful, negotiating a key with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key; and establishing a communication connection with the quantum authentication system using the shared key.

[0007] In one possible implementation, before encrypting the first response using a quantum key based on a quantum SIM card and sending the encrypted first response to the quantum authentication system, the method further includes: encrypting the first response using a private key; wherein the private key is pre-stored in the smart chip device; encrypting the first response using a quantum key based on a quantum SIM card and sending the encrypted first response to the quantum authentication system includes: encrypting the first response encrypted with the private key and additional information using a quantum key based on a quantum SIM card and obtaining an encrypted response, and sending the encrypted response to the quantum authentication system, wherein the additional information includes at least the device identifier of the smart chip device.

[0008] In one possible implementation, before obtaining a shared key by negotiating a key with the quantum authentication system based on a quantum key distribution protocol using the SIM card module, the method further includes: the quantum authentication system receiving an encrypted response and decrypting it using the quantum key to obtain additional information and a first response encrypted with the private key; the quantum authentication system decrypting the first response encrypted with the private key a second time based on the public key paired with the private key to obtain the plaintext of the first response; wherein the public key and the private key are a pair of asymmetric keys; the quantum authentication system verifying whether the additional information is consistent with the smart chip registration information, and verifying whether the first response matches the first challenge; if the additional information is consistent with the smart chip registration information and the first response matches the first challenge, the authentication is determined to be successful; if the additional information is inconsistent with the smart chip registration information, and / or the first response does not match the first challenge, the authentication is determined to be unsuccessful.

[0009] In one possible implementation, the method further includes: if authentication is successful, the quantum authentication system generates an authentication success message and sends the authentication success message to the smart chip device; if authentication fails, the quantum authentication system generates an authentication failure message and sends the authentication failure message to the smart chip device.

[0010] In one possible implementation, establishing a communication connection with the quantum authentication system using a shared key includes: receiving an encryption challenge initiated by the quantum authentication system and decrypting the encryption challenge using the quantum key to obtain the plaintext of the second challenge and the shared key; wherein the encryption challenge is generated by the quantum authentication system encrypting the second challenge and / or the shared key using the quantum key; generating a second response based on the plaintext of the second challenge and encrypting the second response using the shared key; and sending the encrypted second response to the quantum authentication system to establish a communication connection.

[0011] In one possible implementation, after establishing a communication connection with the quantum authentication system using a shared key, the method further includes: receiving a third challenge initiated by the quantum authentication system at a first preset frequency; decrypting the third challenge based on the shared key to obtain the plaintext of the third challenge; wherein the third challenge is generated by the quantum authentication system using a shared key corresponding to the smart chip device; generating a third response based on the plaintext of the third challenge and encrypting the third response using the shared key; sending the encrypted third response to the quantum authentication system; and the quantum authentication system decrypting and verifying the third response using the shared key to complete a communication security verification.

[0012] In one possible implementation, the method further includes: constructing a Markov chain for the Markov chain evaluation model based on the communication connection states, and constructing an initial state distribution vector; wherein the communication connection states include legal states, suspicious states, and illegal states; the state distribution vector is a three-dimensional row vector, with the first dimension corresponding to the state probability value of the legal state, the second dimension corresponding to the state probability value of the suspicious state, and the third dimension corresponding to the state probability value of the illegal state; collecting communication state data at a second preset frequency; the communication state data is determined based on the running state log, and the communication state data includes at least the challenge response time and / or response verification result during the communication security verification process; calculating and updating the state transition probability matrix of the Markov chain evaluation model based on the communication state data; wherein the state transition probability matrix is ​​a third-order square matrix P, P ij Indicates from state s i Transition to state s j The probabilities of i and j are 1, 2, and 3, where 1 represents a legal state, 2 represents a suspicious state, and 3 represents an illegal state. Based on the state transition probability matrix and the state distribution vector at the current time, the state distribution vector at the current time is calculated based on the initial state distribution vector or the state distribution vector at the previous time step.

[0013] In one possible implementation, after calculating the current state distribution vector based on the state transition probability matrix and the initial state distribution vector or the state distribution vector of the previous moment, the method further includes: in the current state distribution vector, if its first-dimensional state probability value is greater than a first threshold, determining that the communication connection of the smart chip device is in a legitimate state; if its first-dimensional state probability value is less than or equal to the first threshold and greater than a second threshold, determining that the communication state of the smart chip is in a suspicious state; wherein the second threshold is less than the first threshold; if its first-dimensional state probability value is less than the second threshold, and its second-dimensional state probability value and / or third-dimensional state probability value is greater than the second threshold, determining that the communication connection of the smart chip device is in an illegitimate state; when the communication connection is in a suspicious or illegitimate state, the quantum authentication system executes a preset security policy, which includes at least one or more of disconnecting the communication connection, negotiating a new shared key, and freezing the access permissions of the smart chip device.

[0014] In one possible implementation, before receiving the first challenge initiated by the quantum authentication system, the method further includes: responding to a user-triggered connection request to generate a connection request, the connection request carrying a device identifier of the smart chip device; sending the connection request to the quantum authentication system via a quantum SIM card, so that the quantum authentication system generates the first challenge in response to the connection request, determines the quantum key corresponding to the smart chip device based on the device identifier, and then encrypts the first challenge using the quantum key, and sends the encrypted first challenge to the smart chip device.

[0015] Secondly, embodiments of this application provide a security authentication system for smart chip devices based on quantum SIM cards. The smart chip device includes at least a quantum SIM card, which has a pre-installed quantum key. The system includes: a decryption module configured to receive a first challenge initiated by a quantum authentication system and decrypt the first challenge using the quantum key to obtain plaintext of the first challenge; wherein the first challenge is generated by the quantum authentication system using a quantum key corresponding to the smart chip device; a response module configured to generate a first response based on the plaintext of the first challenge; an encryption module configured to encrypt the first response using the quantum key based on the quantum SIM card and send the encrypted first response to the quantum authentication system, so that the quantum authentication system can authenticate the smart chip device based on the first response; a key negotiation module configured to, in the case of successful authentication, negotiate a key with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key; and a communication connection module configured to establish a communication connection with the quantum authentication system using the shared key.

[0016] As described above, this application provides a secure authentication method and system for smart chip devices based on a quantum SIM card. The method includes: receiving a first challenge initiated by a quantum authentication system and decrypting the first challenge using a quantum key to obtain plaintext of the first challenge; wherein the first challenge is generated by the quantum authentication system using a quantum key corresponding to the smart chip device; generating a first response based on the plaintext of the first challenge; encrypting the first response using a quantum key on the quantum SIM card and sending the encrypted first response to the quantum authentication system, so that the quantum authentication system can authenticate the smart chip device based on the first response; if authentication is successful, negotiating a key with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key; and establishing a communication connection with the quantum authentication system using the shared key. It is evident that this method, by integrating a quantum SIM card and a quantum key, can achieve reliable authentication between the smart chip device and the quantum authentication system. Furthermore, the challenge-response mechanism effectively prevents replay attacks. Additionally, this method can construct a Markov chain evaluation model to dynamically monitor the communication status, thereby comprehensively ensuring a secure connection. Attached Figure Description

[0017] Figure 1 A schematic diagram illustrating an application scenario of the smart chip device security authentication method based on a quantum SIM card provided in this application embodiment; Figure 2 A schematic diagram of the first process of a security authentication method for smart chip devices based on quantum SIM cards provided in an embodiment of this application; Figure 3 A schematic diagram of a second process for a security authentication method for smart chip devices based on a quantum SIM card, provided in an embodiment of this application; Figure 4 A flowchart illustrating the verification of the first response provided in an embodiment of this application; Figure 5 A schematic diagram of the third process of the smart chip device security authentication method based on quantum SIM card provided in the embodiments of this application; Figure 6 A schematic diagram of the fourth process of the security authentication method for smart chip devices based on quantum SIM cards provided in the embodiments of this application; Figure 7 This is a schematic diagram of the structure of a smart chip device security authentication system based on a quantum SIM card, provided in an embodiment of this application. Detailed Implementation

[0018] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of this application.

[0019] Before introducing the technical solutions of the embodiments of this application, the terminology involved in the embodiments of this application will be introduced by way of example.

[0020] 1. Super SIM Card: A highly integrated smart security chip used in existing communication networks. Essentially, it is a SIM card with enhanced secure storage (up to 256GB) and financial-grade security chip and NFC capabilities. In addition to making calls and accessing the internet, it can also be used as a bank card, transportation card, access card, digital ID card, etc.

[0021] 2. Quantum SIM Card: A SIM card hardware module that enables quantum security. It uses a quantum random number generation mechanism and quantum key distribution technology to achieve end-to-end encryption of "one key per voice call", ensuring the security of voice, message and file transmission.

[0022] 3. Smart Chips: Dedicated chips or modules with sensing, computing, security encryption and communication capabilities are widely used in consumer electronics (such as smartphones and tablets), smart homes (such as smart speakers and robot vacuum cleaners), automobiles, industry, security, wearables (such as smartwatches and AR / VR glasses), medical and health (such as blood glucose meters) and the Internet of Things. Devices equipped with smart chips can be simply referred to as smart chip devices or smart chip devices.

[0023] To address the security vulnerabilities of traditional smart chip device security authentication methods, this application provides a smart chip device security authentication method and system based on a quantum SIM card. This method and system achieve reliable authentication of smart chip devices and ensure communication security by introducing a quantum SIM card and combining it with a quantum authentication system.

[0024] Figure 1 This is a schematic diagram illustrating an application scenario of the smart chip device security authentication method based on a quantum SIM card provided in this application embodiment.

[0025] Specifically, such as Figure 1 As shown, the smart chip device security authentication method based on quantum SIM card provided in this application embodiment can be applied to multi-terminal communication scenarios, and can involve four communication terminals: quantum SIM card, smart chip, quantum authentication system and Internet of Things platform.

[0026] Quantum SIM Card: It can serve as a carrier for secure identity authentication in smart chips. The quantum SIM card stores the generated quantum key and can be securely distributed with other related devices (such as quantum authentication systems and smart chips). It supports multiple identity authentication methods and high-level encryption technology.

[0027] The smart chip integrates a SIM card interface and an identity authentication module, enabling it to read and verify the identity information in the quantum SIM card and achieve integration and communication with other systems in the electric vehicle (such as the battery management system and motor controller). In this embodiment, the SIM card interface and the quantum SIM card can be integrated into a SIM card module to provide quantum communication capabilities for the smart chip.

[0028] Furthermore, the smart chip can be an electric vehicle smart chip. By installing the smart chip in an electric vehicle, functions such as keyless start, remote vehicle control, battery monitoring, and anti-theft tracking can be achieved. In some implementations, the smart chip can also be a smart charging pile smart chip, a smart remote control smart chip, etc., but this application does not specifically limit this.

[0029] Furthermore, on the user side, smart chip devices can provide users with convenient device management and control capabilities in the form of applications (APPs) or user terminals. For example, users can remotely view the status of electric vehicles, send control commands, receive safety alarms, and manage accounts and set permissions through an APP, realizing safe interaction between people and vehicles.

[0030] Quantum authentication system: This application embodiment can establish a quantum authentication system, which can run on a local or cloud server and can realize identity authentication and information protection of the smart chip based on quantum key distribution (QKD) and quantum encryption technology.

[0031] IoT platform: This is a backend platform used to manage access devices. It is responsible for the authentication, connection management, and data transmission of smart chip devices (such as electric vehicle devices). It records user operation logs and device operating status logs to facilitate auditing and troubleshooting, and to promptly identify potential security issues.

[0032] Figure 2 This is a schematic diagram of the first process of a security authentication method for smart chip devices based on quantum SIM cards provided in an embodiment of this application.

[0033] like Figure 2As shown, the smart chip device security authentication method based on quantum SIM card provided in this application embodiment may include a quantum SIM card initialization step, which may specifically include the following steps S101-S103.

[0034] S101: After the quantum SIM card is manufactured, an initialization operation is performed to generate a quantum key.

[0035] It is worth noting that a quantum key is a completely random digital password (a sequence of 0s and 1s) generated by quantum physical processes and whose distribution is secure. Quantum keys can be generated by a quantum platform.

[0036] S102: The generated quantum key is written into the quantum SIM card.

[0037] The filling operation is performed by the quantum filling platform.

[0038] S103: Bind and activate the quantum SIM card with the corresponding smart chip device.

[0039] It is worth noting that the smart chip device provided in this application embodiment may include an identity authentication module and a SIM card module. The SIM card module integrates a quantum SIM card, and the quantum SIM card is pre-loaded with a quantum key.

[0040] In some implementations, the identity authentication module and the SIM card module can be integrated into the smart chip.

[0041] Furthermore, the smart chip device security authentication method based on quantum SIM card provided in this application embodiment also includes the step of establishing and configuring a quantum authentication system, which may specifically include the following steps S104-S105.

[0042] S104: Establish a quantum authentication system, configure system parameters and network connections, and ensure the system operates normally.

[0043] This quantum authentication system can run on a local or cloud server. In other words, this embodiment of the application can establish a quantum authentication system interactively on the server side. For example, the system parameters of the quantum authentication system may include service configuration parameters (such as system service address, port number, and database connection information), security policy parameters (such as authentication session timeout, quantum key update threshold, security audit level, and anti-replay attack time window size), and device management parameters (such as a list of supported device models, firmware version verification rules, and device registration whitelist policy). This embodiment of the application does not specifically limit these parameters.

[0044] S105: In the quantum authentication system, bind and record the device identifier of the smart chip device, the identity information of the quantum SIM card, and / or the quantum key.

[0045] For example, the device identifier ID is Dev_001. Furthermore, the identity information of the quantum SIM card may include the International Mobile Equipment Identity (IMEI), Integrated Circuit Card Identifier (ICCID), etc., which can be determined based on the actual situation; this application embodiment does not impose specific limitations on this.

[0046] Understandably, during the initialization phase of the quantum SIM card, the generated quantum key is written into the quantum SIM card. Simultaneously, a copy of this quantum key can be securely stored in the quantum authentication system's database. This allows the quantum authentication system to use this key for encrypted communication with smart chip devices during subsequent authentication processes.

[0047] In some implementations, the quantum authentication system may also have a corresponding identifier, which is, for example, equal to the identifier of the server it is mounted on, such as server identifier ID=Auth_Server_01.

[0048] It is understandable that the above steps are the preparatory stage for the operation of the smart chip device security authentication method. Based on the above steps, the connection between the smart chip and the quantum authentication system can be realized, providing a communication foundation for security authentication.

[0049] Figure 3 This is a second flowchart illustrating the security authentication method for smart chip devices based on quantum SIM cards provided in this application embodiment.

[0050] like Figure 3 As shown, the smart chip device security authentication method based on quantum SIM card provided in this application embodiment may further include the following steps S201-S204.

[0051] S201: In response to a user-triggered connection request, the connection request carries the device identifier of the smart chip device.

[0052] Specifically, when a user needs to start a smart chip device such as an electric vehicle, they can trigger identity authentication through a terminal device (such as a mobile app or in-vehicle terminal) by clicking the "unlock" control. Upon receiving this trigger command, the identity authentication module immediately generates a connection request message. This connection request message contains at least a unique device identifier for the smart chip device (such as a device serial number or device identifier ID) and a request timestamp, used to identify the smart chip device to the quantum authentication system.

[0053] S202: Send the connection request to the quantum authentication system via the quantum SIM card.

[0054] Specifically, after generating a connection request message, the identity authentication module sends the message to the SIM card module via the communication bus inside the smart chip device. Upon receiving the connection request message, the SIM card module uses its built-in communication functions (such as mobile communication networks, IoT communication protocols, etc.) to send the connection request message to the quantum authentication system.

[0055] S203: The quantum authentication system generates a first challenge in response to a connection request and determines the quantum key corresponding to the smart chip device based on the device identifier.

[0056] Specifically, after receiving a connection request message from a smart chip device, the quantum authentication system first parses the message to obtain the device identifier of the smart chip device. Then, the quantum authentication system can use this device identifier to search for the corresponding smart chip information in its database and determine the quantum key bound to that smart chip device.

[0057] Furthermore, embodiments of this application can employ a challenge-response mechanism for authentication requests, which can effectively prevent replay attacks. Specifically, the quantum authentication system can generate a random first challenge value (e.g., a random number, a random string, etc.), and then the quantum authentication system can search its database for the corresponding smart chip device information based on the device identifier, and determine the quantum key bound to that smart chip device.

[0058] S204: The quantum authentication system uses a quantum key to encrypt the first challenge and sends the encrypted first challenge to the smart chip device.

[0059] Specifically, after the quantum authentication system determines the quantum key corresponding to the smart chip device, it can use the quantum key to encrypt the generated first challenge value to obtain the encrypted first challenge message (i.e., the first challenge), for example, "Challenge="RandomString_12345".

[0060] Subsequently, to ensure the physical layer security of the encrypted message (the first challenge after encryption) during transmission, the quantum authentication system can send it to the SIM card module of the smart chip device via a quantum channel. Here, a "quantum channel" refers to a physical link that uses quantum physical carriers (such as single photons) to transmit information. The essence of transmission via a quantum channel is to modulate each bit of the encrypted message (or ciphertext bit stream) onto a specific quantum state of a single photon (e.g., polarization state, phase, or time-bin state). These photon sequences carrying information can be transmitted to the receiving end (the quantum receiving unit within the SIM card module) via media such as optical fibers or free space.

[0061] The core of quantum channel security lies in the fact that, according to the no-cloning theorem, any eavesdropping or measurement of the quantum state of a photon during transmission will inevitably disturb that state, introducing detectable abnormal errors at the receiver. This allows both communicating parties to sense whether the channel is being eavesdropped on, thus ensuring the anti-eavesdropping and anti-tampering characteristics of encrypted message transmission at the physical layer.

[0062] Following this, the quantum receiving unit of the SIM card module can demodulate (or recover) the ciphertext bit stream from the photon sequence through quantum measurements. Furthermore, the SIM card module can use a locally stored quantum key to perform classical decryption algorithms on the ciphertext bit stream to recover the first challenge plaintext.

[0063] In some implementations, the quantum authentication system can also send the server timestamp, challenge ID, and other information along with the encrypted first response to the SIM card module. This allows the SIM card module to verify the timeliness, uniqueness, and integrity of the first challenge, preventing replay attacks and message tampering. For example, the SIM card module can verify whether the server timestamp is within a preset valid time window, check whether the challenge ID already exists in the anti-replay cache list, and / or verify the legitimacy of the Message Authentication Code (MAC) using a quantum key, ensuring that the encrypted first response has not been maliciously tampered with or reused during transmission.

[0064] See also Figure 3 The smart chip device security authentication method based on quantum SIM card provided in this application embodiment also includes the following step S300.

[0065] S300: Receives the first challenge initiated by the quantum authentication system and decrypts the first challenge using a quantum key to obtain the plaintext of the first challenge; wherein, the first challenge is generated by the quantum authentication system using a quantum key corresponding to the smart chip device.

[0066] It should be noted that the embodiments of this application can utilize the SIM card module to receive the first challenge. The communication link between the quantum authentication system and the SIM card module for transmitting the encrypted first challenge can be achieved using a quantum channel for secure transmission. Specifically, the quantum channel may include a free space channel (such as a wireless quantum transmission channel based on laser or microwave) or an optical fiber channel (such as a wired quantum transmission channel based on single-mode optical fiber). Relying on the characteristics of the quantum channel that can detect eavesdropping behavior and the non-cloning property of quantum states, the absolute security of the first challenge transmission process is further guaranteed, preventing the encrypted first challenge from being stolen or tampered with.

[0067] Understandably, the first challenge plaintext is the random challenge information generated by the quantum authentication system, i.e., the first challenge value. The SIM card module can then send this first challenge plaintext to the identity authentication module.

[0068] Furthermore, step S300 is followed by steps S401-S402.

[0069] S401: Generate the first response based on the plaintext of the first challenge.

[0070] Specifically, after the SIM card module decrypts the first challenge and obtains the first challenge plaintext, it can synchronize the first challenge plaintext to the identity authentication module via the communication bus inside the smart chip device. Upon receiving the first challenge plaintext, the identity authentication module processes it according to preset response generation rules (such as performing hash operations, XOR operations on the first challenge plaintext, or combining it with hardware information built into the smart chip device) to generate a unique first response. This first response uniquely maps the first challenge plaintext to the legitimate identity of the smart chip device, ensuring that the quantum authentication system can verify the identity of the smart chip device by checking the consistency of the response.

[0071] S402: Encrypt the first response using a private key; wherein the private key is pre-stored in the smart chip device.

[0072] Specifically, to further enhance the security of the first response transmission, the identity authentication module calls the private key (identifier can be PrivateKey_SIM_Card_001) pre-stored in its own secure storage area to perform asymmetric encryption on the generated first response, thus obtaining the encrypted first response.

[0073] The private key is the private key in the asymmetric encryption algorithm, and it is paired with the public key stored in the quantum authentication system (the identifier can be PublicKey_SIM_Card_001). The asymmetric encryption algorithm is, for example, the RSA (Rivest–Shamir–Adleman) encryption algorithm. This application does not specifically limit this.

[0074] Furthermore, the identity authentication module can also package the encrypted first response and additional information into a unified response data packet, which is then sent to the SIM card module through the communication channel inside the smart chip device. The additional information includes at least the device identifier of the smart chip device. In some implementations, the additional information may also include a timestamp, ICCID, IMEI, etc., but this application embodiment does not specifically limit this.

[0075] Furthermore, step S402 may be followed by step S500.

[0076] S500: Based on the quantum SIM card, the first response is encrypted with a quantum key and sent to the quantum authentication system so that the quantum authentication system can authenticate the smart chip device based on the first response.

[0077] Specifically, step S500 includes the following steps S501: Based on the SIM card module, the first response and additional information encrypted with the private key are encrypted using a quantum key to obtain an encrypted response, and the encrypted response is sent to the quantum authentication system.

[0078] In this embodiment, after receiving the first response and additional information encrypted with a private key from the identity authentication module, the SIM card module can call upon the quantum key pre-stored in its internal secure storage area to perform secondary encryption on the data using a symmetric encryption algorithm (such as the SM4 algorithm), generating an encrypted response data packet. This encrypted response data packet can be securely transmitted to the quantum authentication system via a quantum channel (such as a fiber optic channel or a free-space channel), ensuring that the data is not eavesdropped on or tampered with during transmission.

[0079] Figure 4 This is a schematic diagram of the verification process for the first response provided in an embodiment of this application.

[0080] Furthermore, such as Figure 4 As shown, step S500 may be followed by steps S601-S605.

[0081] S601: The quantum authentication system receives the encrypted response and decrypts it using a quantum key to obtain additional information and the first response encrypted with the private key.

[0082] Specifically, after receiving the encrypted response data packet through the quantum channel, the quantum authentication system can retrieve the corresponding quantum key based on the device identifier of the smart chip device, and use the same symmetric encryption algorithm to decrypt the encrypted response data packet, extracting additional information and the first response data encrypted with the private key.

[0083] Understandably, through the connection request-challenge interaction process, the quantum authentication system has already confirmed (but not authenticated) the identity of the smart chip device through the device identifier. Therefore, when the quantum authentication system receives an encrypted response, it has already determined which smart chip device the response came from and can accurately retrieve the corresponding quantum key for decryption.

[0084] S602: The quantum authentication system uses a public key paired with the private key to perform a second decryption on the first response encrypted with the private key, obtaining the plaintext of the first response; wherein, the public key and the private key are a pair of asymmetric keys.

[0085] Specifically, the quantum authentication system retrieves the public key that matches the private key of the smart chip device from its database, and uses an asymmetric encryption algorithm to decrypt the first response data encrypted with the private key, restoring the plaintext of the first response.

[0086] S603: The quantum authentication system verifies whether the additional information is consistent with the smart chip registration information, and verifies whether the first response matches the first challenge.

[0087] Specifically, the quantum authentication system compares the additional information obtained from decryption with the pre-stored smart chip registration information (such as device ID, ICCID, IMEI, etc.) in the system to verify the consistency of the information; at the same time, according to the preset response verification rules (such as hash verification, signature verification, etc.), the plaintext of the first response is matched and verified with the first challenge generated by the quantum authentication system to confirm the validity of the response.

[0088] S604: If the additional information matches the smart chip registration information and the first response matches the first challenge, the identity authentication is confirmed to be successful.

[0089] Specifically, when the additional information verification passes and the first response matches the first challenge, the quantum authentication system determines that the smart chip device is legitimate, generates a successful authentication result, records the timestamp of this authentication, device information, etc., and can generate a log.

[0090] S605: If the additional information is inconsistent with the smart chip registration information, and / or the first response does not match the first challenge, the authentication is determined to have failed.

[0091] Specifically, when the additional information verification fails and / or the first response does not match the first challenge, the quantum authentication system can determine that the smart chip device is illegitimate or poses a security risk, generate an authentication failure result, and record the reason for the failure, device information, etc., and can also generate a log.

[0092] In some implementations, step S604 may be followed by step S606.

[0093] S606: If the identity authentication is successful, the quantum authentication system generates an authentication success message and sends the authentication success message to the smart chip device.

[0094] Specifically, once the quantum authentication system confirms successful identity authentication, it generates an authentication success data packet, i.e., an authentication success message, containing information such as the authentication result, timestamp, and session identifier. This packet is sent to the SIM card module via a quantum channel or a network channel. The network channel is a logical path built on classical communication protocols (such as TCP / IP) for transmitting digital signals (data packets) between nodes. After receiving and decrypting the message, the SIM card module can forward it to the identity authentication module so that the smart chip device can confirm the current authentication status and trigger subsequent operations.

[0095] In some implementations, the quantum authentication system can generate a new random challenge and send it along with an authentication success message to the SIM card module. The SIM card module then uses its communication capabilities to send the random challenge and authentication success message to the identity authentication module.

[0096] In some implementations, step S605 may be followed by step S607.

[0097] S607: In the event of authentication failure, the quantum authentication system generates an authentication failure message and sends the message to the smart chip device.

[0098] In this embodiment of the application, the authentication failure message may carry a reason for failure, such as challenge mismatch or information mismatch.

[0099] Understandably, authentication failure indicates that the connection request was rejected by the quantum authentication system. The smart chip device is unable to establish a further communication connection with the quantum authentication system, and the process ends.

[0100] In some implementations, the quantum authentication system can generate a new random challenge and send it along with an authentication failure message to the SIM card module. The SIM card module then uses its communication capabilities to send the random challenge and the authentication failure message to the identity authentication module.

[0101] Figure 5 This is a schematic diagram of the third process of the security authentication method for smart chip devices based on quantum SIM cards provided in the embodiments of this application.

[0102] Furthermore, such as Figure 5 As shown, after step S606, the method provided in this application embodiment may further include the following step S700.

[0103] S700: Upon successful authentication, it negotiates a shared key with the quantum authentication system based on the quantum key distribution protocol.

[0104] It is worth noting that, upon successful authentication, the smart chip device can engage in key derivation negotiation with the quantum authentication system based on a pre-set quantum root key. This key negotiation is conducted through the established quantum channel between the two parties, ultimately generating a shared key. For example, the identifier of the shared key can be SharedKey_Dev_001_Auth_Sever_01. Specifically, this key derivation process follows these steps: After successful authentication in step S704, the quantum authentication system sends a key derivation command to the SIM card module. This command, encrypted with a quantum key, contains a set of derivation parameters, including at least the current session ID, timestamp, device hardware fingerprint, and key validity period. Upon receiving the command, the SIM card module invokes a preset algorithm, such as the HKDF (HMAC-based Key Derivation Function) algorithm compliant with the NIST SP800-108 standard. Using the quantum root key as the input key material (IKM) and the device identifier, challenge response value, and system-negotiated salt value as derivation context information, it generates a 128-bit shared key through two HMAC-SHA256 operations. Throughout the derivation process, the quantum root key remains on the card, ensuring the physical isolation of the derivation computation environment.

[0105] Furthermore, the quantum authentication system can synchronously execute the same derivation algorithm, using the same quantum root key copy as the SIM card module to generate an identical shared key. Both parties verify consistency through the MAC value of the derivation result. After confirming successful key synchronization, the shared key is marked as "activated," and a countdown to the key's validity period (e.g., 24 hours) begins.

[0106] In some implementations, after the shared key is activated, the quantum authentication system and / or the SIM card module can return only a key handle to the authentication module. This key handle can be a unique identifier for the shared key, specifically its index or hash digest, rather than the plaintext key itself. Subsequent encryption and decryption operations are performed via APDU instructions calling the SIM card module. The plaintext key always resides in the security chip's memory and is erased immediately after use.

[0107] It's worth noting that the shared key is essentially a session key; that is, the relationship between quantum keys and shared keys is a derivation of the root key and the session key. In some implementations, the session key's validity period can be set to 24 hours, automatically triggering a key update process upon expiration. In other implementations, the session key can be configured to be valid for a single session (One-Session-One-Key), meaning it is destroyed immediately after each communication session ends.

[0108] Furthermore, step S700 may be followed by the following step S800: S800: Establishes a communication connection between the identity authentication module and the quantum authentication system using a shared key.

[0109] Specifically, see [link to relevant document] Figure 5 Step S800 may include the following steps S801-S805.

[0110] S801: The quantum authentication system generates a second challenge and encrypts the second challenge and / or the shared key using a quantum key to obtain an encrypted challenge.

[0111] It is worth noting that, to avoid the risk of leakage of the shared key plaintext during transmission and processing, this step transmits and encrypts not the shared key plaintext itself, but the shared key handle. This key handle is a unique identifier of the shared key within the system (such as an index value or hash digest), and is only used to retrieve the corresponding shared key plaintext in the secure storage areas of the quantum authentication system and the SIM card module. The entire process does not involve the exposure of the key plaintext, further enhancing the security of key management.

[0112] Understandably, the encryption challenge is generated by the quantum authentication system using a quantum key to encrypt the second challenge and / or the shared key.

[0113] S802: The quantum authentication system sends the encryption challenge to the SIM card module.

[0114] It is understood that the encryption challenge can be transmitted via a quantum channel in the embodiments of this application.

[0115] S803: Receives an encryption challenge initiated by the quantum authentication system and decrypts the encryption challenge using the quantum key to obtain the plaintext of the second challenge and the shared key.

[0116] This step can be performed by the SIM card module. After decryption, at least the second challenge plaintext can be obtained, and the SIM card module can send the second challenge plaintext and the shared key to the authentication module.

[0117] In some implementations, the SIM card module can obtain a shared key handle after decryption, and then send the shared key handle to the authentication module.

[0118] In some implementations, the quantum authentication system can use the quantum key to encrypt only the second challenge to obtain the encryption challenge. That is, the encryption challenge does not carry the shared key. The identity authentication module can directly interact with the SIM card module to obtain the shared key, specifically the shared key handle.

[0119] S804: Generate a second response based on the plaintext of the second challenge, and encrypt the second response using a shared key.

[0120] Specifically, the identity authentication module can process the second challenge plaintext according to preset response generation rules (such as hash operation and message digest combination) to generate a unique corresponding second response, and then call the shared key to encrypt the second response.

[0121] In some implementations, the identity authentication module can retrieve the corresponding shared key plaintext from the hardware security unit of the smart chip based on the shared key handle.

[0122] S805: Send the encrypted second response to the quantum authentication system to establish a communication connection.

[0123] Specifically, this step can be implemented by the identity authentication module through the SIM card module. After receiving the encrypted second response, the quantum authentication system can use the locally stored shared key to decrypt it and verify the matching of the second response with the second challenge; if the verification is successful, a secure communication connection based on the shared key is formally established between the smart chip device (identity authentication module) and the quantum authentication system.

[0124] In some implementations, upon successful verification, the shared key serves as the session key for establishing a secure communication connection. Both communicating parties can negotiate and enable the Transport Layer Security / Secure Sockets Layer (TLS / SSL) protocol based on this shared key to establish the connection. Within the encrypted channel established by this TLS / SSL protocol, the shared key can be directly used as the session key for symmetric encryption, decryption, and integrity verification of application-layer business data.

[0125] It should be further explained that after identity verification and the establishment of a secure communication connection, the system has the following core functions: All interactive data between the smart chip device and the quantum authentication system (such as electric vehicle status reporting, remote vehicle control commands, and battery monitoring data) can be transmitted encrypted using a shared key, ensuring that the data is not eavesdropped on, tampered with, or forged; smart chip devices that have passed identity verification and established a secure connection will be granted corresponding operating permissions by the quantum authentication system (such as keyless start permissions and anti-theft tracking permissions), while devices that have not passed authentication will not be able to access the system or perform related operations, effectively preventing malicious access by unauthorized devices; and the quantum authentication system can synchronize the authentication results to the IoT platform, facilitating real-time management of the smart chip device's access status and providing legitimate identity evidence for subsequent operation log auditing and fault diagnosis, thus constructing a full-link security protection system of "authentication-authorization-transmission".

[0126] In some implementations, the shared key can also be used in the interaction between smart chip devices and IoT platforms, but this application does not specifically limit this.

[0127] Furthermore, during the communication process between the smart chip device and the quantum authentication system, this embodiment of the application can continuously monitor the status and security of the communication connection, and if an anomaly is detected, renegotiate the key or disconnect the connection. Specifically, after step S800, the method provided in this embodiment of the application may further include the following steps S901-S906.

[0128] S901: The quantum authentication system initiates a third challenge at a first preset frequency and encrypts the third challenge using a shared key.

[0129] The first preset frequency is, for example, 1 minute / time, 3 minutes / time, or 5 minutes / time, and this application embodiment does not specifically limit it.

[0130] Understandably, the third challenge could be a random number, a random string, or something similar.

[0131] S902: The quantum authentication system sends the encrypted third challenge to the identity authentication module via the SIM card module.

[0132] Specifically, the third challenge can be transmitted via network channels or quantum channels. After receiving the third challenge, the SIM card module does not need encryption and can forward it to the authentication module through the secure interface or communication bus within the smart chip device. In this step, the SIM card module can simply act as a communication relay.

[0133] S903: Receive the third challenge initiated by the quantum authentication system at a first preset frequency, decrypt the third challenge based on the shared key, and obtain the plaintext of the third challenge.

[0134] The step of receiving the third challenge can be performed by the SIM card module, and the decryption step can be performed by the identity authentication module.

[0135] S904: Generate a third response based on the plaintext of the third challenge, and encrypt the third response using a shared key.

[0136] Specifically, the identity authentication module can generate a third response that uniquely corresponds to the third challenge plaintext according to preset response generation rules (such as performing a SHA-256 hash operation on the third challenge plaintext); then, the shared key is called again to encrypt the third response to ensure that the response information is not tampered with or eavesdropped on during transmission.

[0137] S905: Send the encrypted third response to the quantum authentication system.

[0138] Specifically, the identity authentication module can use the communication capabilities of the SIM card module to send the encrypted third response to the quantum authentication system via a quantum channel or network channel.

[0139] In some implementations, a timestamp of the third response being generated can be included during transmission for subsequent replay attack verification.

[0140] S906: The quantum authentication system decrypts and verifies a third response using a shared key to complete a communication security verification.

[0141] Specifically, the quantum authentication system can call the locally stored shared key to decrypt the received third response, obtain the plaintext of the third response, and then verify whether the plaintext of the third response matches the locally generated third challenge. At the same time, it verifies whether the response timestamp is within the valid time window, thereby determining whether the current communication link is in a secure and tamper-proof state.

[0142] It is worth noting that regardless of whether the communication security verification succeeds or fails, the quantum authentication system can record the verification result in the operational status log. This log can be stored in the quantum authentication system's storage area or uploaded to the IoT platform. The log content can include a verification timestamp, a summary of the third challenge, the third response verification result, the smart chip device identifier, and communication link status information, etc.

[0143] Furthermore, the method provided in this application embodiment may also include the following steps S907-S910. Steps S907-S910 may be executed by a monitoring and evaluation module, which may be a sub-module of an Internet of Things platform, and this module may communicate with the quantum authentication system.

[0144] S907: A Markov chain that constructs a Markov-chain-based evaluation model based on the communication connection state, and constructs an initial state distribution vector.

[0145] Specifically, the Markov chain evaluation model (or Markov model for short) is a dynamic model based on state transition probabilities. This application embodiment can utilize the Markov chain evaluation model to assess communication security states. Specifically, this application embodiment can consider the communication state between the smart chip device and the quantum authentication system as states in a Markov chain. Communication connection states include legitimate states, suspicious states, and illegal states. A Markov chain is a discrete-time stochastic process that describes the probability distribution of state changes over time. Assume the system has Q possible states, denoted as S = {s1, s2, ..., sQ}. At time t, the probability of being in state si is denoted as P(X...). t =s i The property of a Markov chain is that the state at any future time depends only on the current state and is independent of past states. That is, for any time t and state S... i ,have: ; At time t+1, the state is s. j probability The state at time t is determined solely by the state at time t. The decision is made based on any historical state prior to time t. None of these are relevant. This represents the state at time t-1. This represents the state at time 0, and so on.

[0146] Furthermore, the state distribution vector This is a three-dimensional row vector. The first dimension corresponds to the state probability value of a legal state, the second dimension corresponds to the state probability value of a suspicious state, and the third dimension corresponds to the state probability value of an illegal state. It is worth noting that... .

[0147] For example, the initial state distribution vector It can be [1, 0, 0] or [0.95, 0.04, 0.01].

[0148] S908: Collect communication status data at a second preset frequency; the communication status data is determined based on the operation status log, and the communication status data includes at least the challenge response time and / or response verification result during the communication security verification process.

[0149] Specifically, the second preset frequency can be flexibly configured according to communication security requirements and system computing power, and the second preset frequency can be lower than the first preset frequency. For example, the second preset frequency can be 15 minutes / time, 30 minutes / time, or 1 hour / time, and this application embodiment does not specifically limit it.

[0150] Furthermore, the communication status data originates from the operational status logs of the smart chip device and / or the quantum authentication system. The challenge response duration refers to the time interval from when the quantum authentication system sends the third challenge to when it receives the third response. The response verification result includes "verification successful," "verification failed," and "response timeout." In other words, the communication status data can specifically include the response duration of the third challenge and the response verification result of the third challenge.

[0151] In some implementations, communication state data may also include parameters such as communication link packet loss rate, providing more comprehensive data support for subsequent state transition probability calculations.

[0152] S909: Calculate and update the state transition probability matrix of the Markov chain evaluation model based on communication state data; where the state transition probability matrix is ​​a third-order square matrix P, P ij Indicates from state s i Transition to state s j The probability of i and j is 1, 2, and 3, where 1 represents a legal state, 2 represents a suspicious state, and 3 represents an illegal state.

[0153] The third-order square matrix P is as follows: ; Among them, P 12 P represents the probability of transitioning from a legal state to a questionable state. 13 This represents the probability of transitioning from a legal state to an illegal state, and so on.

[0154] Furthermore, in embodiments of this application, the state transition probability matrix can be calculated according to the following steps: First, predefined rules are established, and communication status data within the time window (statistical window) corresponding to the second preset frequency are organized based on these rules. For example, data with a response timeout and verification failure is determined as "illegal" status data; data with only a response timeout is determined as "suspicious" status data; and data with a normal response and successful verification is determined as "legal" status data. Continuous monitoring data points are transformed into a status sequence that changes over time, such as [s1, s2, s1, s3, s2,...].

[0155] Furthermore, traversing the above state sequence, the number of transitions from state si to state sj is counted, forming a transition counting matrix N, where the elements N... ijThis represents the total number of observed transitions from state i to state j, where i and j take values ​​of 1, 2, and 3, where 1 represents a legal state, 2 represents a suspicious state, and 3 represents an illegal state.

[0156] Furthermore, embodiments of this application can perform maximum likelihood estimation calculations: based on the statistically obtained transition count matrix N, the maximum likelihood estimation method is used to calculate each element in the state transition probability matrix P. The specific calculation formula is as follows: P ij = N ij / (N i1 + N i2 + N i3 ).

[0157] Among them, P ij Let N represent the element in the i-th row and j-th column of the state transition probability matrix P, i.e., the probability that the communication connection state transitions from the i-th state to the j-th state; ij This represents the element in the i-th row and j-th column of the transition counting matrix N, which is the actual number of times the communication connection state transitions from the i-th state to the j-th state within the statistical window; N i1 +N i2 +N i3 This represents the total number of transitions starting from state i within the statistical window, which is the sum of the number of transitions from state i to the three states of legal, suspicious, and illegal. The values ​​of i and j are 1, 2, and 3, respectively, corresponding to the legal, suspicious, and illegal states of the communication connection.

[0158] It is worth noting that this calculation ensures that for any state i, the sum of the probabilities of transitioning to all possible states is 1 (i.e., Pi1 + Pi2 + Pi3 = 1).

[0159] S910: Based on the state transition probability matrix, and based on the initial state distribution vector or the state distribution vector of the previous time step, the current state distribution vector is calculated.

[0160] Specifically, the state distribution vector at the current moment is calculated based on the following formula.

[0161] ; in, It is the state distribution vector at time t (the current time). It is the state distribution vector at time t-1 (the previous time step). This is the latest calculated state transition probability matrix. When t=1... It is the initial state distribution vector.

[0162] After step S910, the method provided in this application embodiment may further include the following steps S911-S914.

[0163] S911: In the state distribution vector at the current moment, if the first dimension state probability value is greater than the first threshold, it is determined that the communication connection of the smart chip device is in a legal state.

[0164] It is understood that the embodiments of this application can be adapted to the current state. The distribution is used to assess the communication security status of smart chip devices.

[0165] For example, if the state distribution vector of the previous time step =[0.9,0.08,0.02], the state transition probability matrix is: ,but =[0.9×0.85+0.08×0.5+0.02×0.05,0.9×0.12+0.08×0.35+0.02×0.15,0.9×0.03+0.08×0.15+0.02×0.8]=[0.811, 0.126, 0.063].

[0166] For example, the first threshold can be equal to 0.9, 0.85, or 0.8, preferably 0.9. If the first dimension state probability value... If the value is greater than 0.9, then it can be determined that the communication connection between the smart chip and the quantum communication system is in a legal state.

[0167] S912: If the probability value of its first dimension state is less than or equal to the first threshold and greater than the second threshold, the communication state of the smart chip is determined to be suspicious; wherein the second threshold is less than the first threshold.

[0168] For example, the second threshold can be equal to 0.4 or 0.3, etc., and this application embodiment does not specifically limit it. For example, the first dimension state probability value If the value is less than 0.9 and greater than 0.4, then the communication connection between the smart chip device and the quantum communication system is in a questionable state.

[0169] S913: If its first-dimensional state probability value is less than the second threshold, and its second-dimensional state probability value and / or third-dimensional state probability value is greater than the second threshold, it is determined that the communication connection of the smart chip device is in an illegal state. For example, the probability value of the first dimension of the state. Less than 0.4, and the probability value of the second-dimensional state. and / or third-dimensional state probability value If the value is greater than 0.4, then it can be determined that the communication connection between the smart chip device and the quantum communication system is in an illegal state.

[0170] S914: When the quantum authentication system is in a suspicious or illegal state, it executes a preset security policy, which includes at least one or more of the following: disconnecting the communication connection, negotiating a new shared key, and freezing the access permissions of the smart chip device.

[0171] It is understood that disconnecting the communication connection refers to disconnecting the communication connection between the smart chip device (identity authentication module) and the quantum authentication system. This allows for the periodic checking of the key's validity status. It is also understood that the steps for negotiating a new shared key are the same as those in step S700, and the steps for re-establishing the communication connection are the same as those in step S800; therefore, they will not be elaborated upon here.

[0172] In some implementations, the preset security policy may also include sending security alerts to the quantum authentication system.

[0173] Figure 6 This is a schematic diagram of the fourth process of the smart chip device security authentication method based on quantum SIM card provided in the embodiments of this application.

[0174] like Figure 6 As shown, this application provides a security authentication method for smart chip devices based on quantum SIM cards. The smart chip device includes at least a quantum SIM card, which has a pre-installed quantum key. The method includes: S1001: Receive the first challenge initiated by the quantum authentication system, and decrypt the first challenge using the quantum key to obtain the plaintext of the first challenge; wherein, the first challenge is generated by the quantum authentication system using the quantum key corresponding to the smart chip device; S1002: Generate the first response based on the plaintext of the first challenge; S1003: Based on the quantum SIM card, the first response is encrypted with a quantum key and sent to the quantum authentication system so that the quantum authentication system can authenticate the smart chip device based on the first response; S1004: If identity authentication is successful, key negotiation is performed with the quantum authentication system based on the quantum key distribution protocol to obtain a shared key; S1005: Establish a communication connection with the quantum authentication system using a shared key.

[0175] As described above, this application provides a secure authentication method for smart chip devices based on quantum SIM cards. This method integrates quantum SIM cards and quantum keys to achieve reliable authentication between smart chip devices and quantum authentication systems. Furthermore, the method employs a challenge-response mechanism to effectively prevent replay attacks. Additionally, this method can construct a Markov chain evaluation model to dynamically monitor communication status, thereby comprehensively ensuring secure connections.

[0176] Figure 7 This is a schematic diagram of the structure of a smart chip device security authentication system based on a quantum SIM card, provided in an embodiment of this application.

[0177] like Figure 7 As shown, this application provides a security authentication system for smart chip devices based on quantum SIM cards. The smart chip device includes at least a quantum SIM card, which has a pre-installed quantum key. The system includes: The decryption module 1001 is configured to: receive the first challenge initiated by the quantum authentication system, and decrypt the first challenge using a quantum key to obtain the plaintext of the first challenge; wherein, the first challenge is generated by the quantum authentication system using a quantum key corresponding to the smart chip device; Response module 1002 is configured to generate a first response based on the plaintext of the first challenge; The encryption module 1003 is configured to: encrypt the first response using a quantum key based on the quantum SIM card, and send the encrypted first response to the quantum authentication system, so that the quantum authentication system can authenticate the smart chip device based on the first response; The key negotiation module 1004 is configured to: upon successful authentication, negotiate a shared key with the quantum authentication system based on the quantum key distribution protocol to obtain the shared key. The communication connection module 1005 is configured to establish a communication connection with the quantum authentication system using a shared key.

[0178] In one possible implementation, the response module 1002 is further configured to encrypt the first response using a private key, wherein the private key is pre-stored in the smart chip device.

[0179] In one possible implementation, the encryption module 1003 is further configured to: based on a quantum SIM card, encrypt the first response and additional information encrypted with the private key using a quantum key to obtain an encrypted response, and send the encrypted response to a quantum authentication system, wherein the additional information includes at least the device identifier of the smart chip device.

[0180] In one possible implementation, the smart chip device security authentication system based on a quantum SIM card provided in this application embodiment may further include a quantum authentication module, specifically configured to: receive an encrypted response using a quantum authentication system, and decrypt the encrypted response using a quantum key to obtain a first response encrypted with additional information and a private key; decrypt the first response encrypted with the private key a second time using a public key paired with the private key using a quantum authentication system to obtain the plaintext of the first response; wherein the public key and the private key are a pair of asymmetric keys; verify whether the additional information is consistent with the smart chip registration information, and verify whether the first response matches the first challenge using a quantum authentication system; if the additional information is consistent with the smart chip registration information and the first response matches the first challenge, the authentication is determined to be successful; if the additional information is inconsistent with the smart chip registration information, and / or the first response does not match the first challenge, the authentication is determined to be unsuccessful.

[0181] In one possible implementation, the quantum authentication module is further configured to: generate an authentication success message using the quantum authentication system and send the authentication success message to the smart chip device when authentication is successful; and generate an authentication failure message using the quantum authentication system and send the authentication failure message to the smart chip device when authentication fails.

[0182] In one possible implementation, the communication connection module 1005 is specifically configured to: receive an encryption challenge initiated by the quantum authentication system, and decrypt the encryption challenge using a quantum key to obtain the plaintext of the second challenge and the shared key corresponding to the second challenge; wherein the encryption challenge is generated by the quantum authentication system encrypting the second challenge and / or the shared key using a quantum key; generate a second response based on the plaintext of the second challenge, and encrypt the second response using the shared key; and send the encrypted second response to the quantum authentication system to establish a communication connection.

[0183] In one possible implementation, the quantum authentication module is further configured to: receive a third challenge initiated by the quantum authentication system at a first preset frequency; decrypt the third challenge based on a shared key to obtain the plaintext of the third challenge; wherein the third challenge is generated by the quantum authentication system using a shared key corresponding to the smart chip device; generate a third response based on the plaintext of the third challenge and encrypt the third response using the shared key; send the encrypted third response to the quantum authentication system; and use the quantum authentication system to decrypt and verify the third response using the shared key to complete a communication security verification.

[0184] In one possible implementation, the smart chip device security authentication system based on a quantum SIM card provided in this application embodiment may further include a monitoring module, specifically configured to: construct a Markov chain for the Markov chain evaluation model based on the communication connection state, and construct an initial state distribution vector; wherein, the communication connection state includes a legal state, a suspicious state, and an illegal state; the state distribution vector is a three-dimensional row vector, the first dimension corresponding to the state probability value of the legal state, the second dimension corresponding to the state probability value of the suspicious state, and the third dimension corresponding to the state probability value of the illegal state; collect communication state data at a second preset frequency; the communication state data is determined based on the running state log, and the communication state data includes at least the challenge response time and / or response verification result during the communication security verification process; calculate and update the state transition probability matrix of the Markov chain evaluation model based on the communication state data; wherein, the state transition probability matrix is ​​a third-order square matrix P, P ij Indicates from state s i Transition to state s j The probabilities of i and j are 1, 2, and 3, where 1 represents a legal state, 2 represents a suspicious state, and 3 represents an illegal state. Based on the state transition probability matrix and the state distribution vector at the current time, the state distribution vector at the current time is calculated based on the initial state distribution vector or the state distribution vector at the previous time step.

[0185] In one possible implementation, the monitoring module is further configured to: determine that the communication connection of the smart chip device is in a legitimate state if the first-dimensional state probability value of the current state distribution vector is greater than a first threshold; determine that the communication state of the smart chip is in a suspicious state if the first-dimensional state probability value is less than or equal to the first threshold and greater than a second threshold; wherein the second threshold is less than the first threshold; determine that the communication connection of the smart chip device is in an illegal state if the first-dimensional state probability value is less than the second threshold and the second-dimensional state probability value and / or the third-dimensional state probability value is greater than the second threshold; and execute a preset security policy using the quantum authentication system when the communication connection is in a suspicious or illegal state, wherein the preset security policy includes at least one or more of disconnecting the communication connection, negotiating a new shared key, and freezing the access permissions of the smart chip device.

[0186] In one possible implementation, the quantum authentication module is further configured to: generate a connection request in response to a user triggering the connection request, the connection request carrying a device identifier of the smart chip device; send the connection request to the quantum authentication system via a quantum SIM card, so that the quantum authentication system generates a first challenge in response to the connection request, determines the quantum key corresponding to the smart chip device based on the device identifier, and then uses the quantum key to encrypt the first challenge, and sends the encrypted first challenge to the smart chip device.

[0187] In a specific implementation, the present invention also provides a computer storage medium, wherein the computer storage medium may store a program, which, when executed, may include some or all of the steps of the various embodiments of the smart chip device security authentication method based on quantum SIM card provided by the present invention. The storage medium may be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0188] It is readily understood that, based on the several embodiments provided in this application, those skilled in the art can combine, split, or reorganize the embodiments of this application to obtain other embodiments, none of which exceed the protection scope of this application.

[0189] The above detailed embodiments further illustrate the purpose, technical solution, and beneficial effects of the embodiments of this application. It should be understood that the above are merely specific embodiments of the embodiments of this application and are not intended to limit the protection scope of the embodiments of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solutions of the embodiments of this application should be included within the protection scope of the embodiments of this application.

Claims

1. A quantum SIM card-based smart chip device security authentication method, characterized in that, The smart chip device at least includes a quantum SIM card, and the quantum SIM card is pre-stored with a quantum key; the method comprises: receiving a first challenge initiated by a quantum authentication system, and decrypting the first challenge by using the quantum key to obtain a first challenge plaintext; wherein the first challenge is generated by the quantum authentication system by using the quantum key corresponding to the smart chip device; generating a first response based on the first challenge plaintext; encrypting the first response by using the quantum key based on the quantum SIM card, and sending the encrypted first response to the quantum authentication system, so that the quantum authentication system performs identity authentication on the smart chip device based on the first response; in the case of successful identity authentication, performing key negotiation with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key; establishing a communication connection with the quantum authentication system by using the shared key. 2.The quantum SIM card based smart chip device security authentication method of claim 1, wherein, Before the step of encrypting the first response by using the quantum key based on the quantum SIM card, and sending the encrypted first response to the quantum authentication system, the method further comprises: encrypting the first response by using a private key; wherein the private key is pre-stored in the smart chip device; the step of encrypting the first response by using the quantum key based on the quantum SIM card, and sending the encrypted first response to the quantum authentication system, comprises: encrypting the first response and additional information after encryption of the private key by using the quantum key based on the quantum SIM card, to obtain an encrypted response, and sending the encrypted response to the quantum authentication system; the additional information at least includes a device identifier of the smart chip device. 3.The quantum SIM card based smart chip device security authentication method of claim 2, wherein, Before the step of performing key negotiation with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key in the case of successful identity authentication, the method further comprises: the quantum authentication system receives the encrypted response, and decrypts the encrypted response by using the quantum key to obtain the additional information and the first response after encryption of the private key; the quantum authentication system performs secondary decryption on the first response after encryption of the private key based on a public key paired with the private key to obtain a first response plaintext; wherein the public key and the private key are a pair of asymmetric keys; the quantum authentication system checks whether the additional information is consistent with smart chip registration information, and checks whether the first response matches the first challenge; in the case that the additional information is consistent with the smart chip registration information, and the first response matches the first challenge, it is determined that the identity authentication is successful; in the case that the additional information is not consistent with the smart chip registration information, and / or the first response does not match the first challenge, it is determined that the identity authentication fails. 4.The quantum SIM card based smart chip device security authentication method according to claim 1 or 3, characterized in that, The method further comprises: in the case of successful identity authentication, the quantum authentication system generates an authentication success message, and sends the authentication success message to the smart chip device; In the case of identity authentication failure, the quantum authentication system generates an authentication failure message and sends the authentication failure message to the smart chip device. 5.The quantum SIM card based smart chip device security authentication method of claim 1, wherein, The method further comprises: receiving an encrypted challenge initiated by the quantum authentication system, and decrypting the encrypted challenge using the quantum key to obtain a second challenge plaintext corresponding to the second challenge and the shared key; wherein the encrypted challenge is generated by the quantum authentication system using the quantum key to encrypt the second challenge and / or the shared key; generating a second response based on the second challenge plaintext, and encrypting the second response using the shared key; sending the encrypted second response to the quantum authentication system to establish a communication connection. 6.The quantum SIM card based smart chip device security authentication method of claim 1, wherein, After establishing the communication connection with the quantum authentication system using the shared key, the method further comprises: receiving a third challenge initiated by the quantum authentication system at a first preset frequency, decrypting the third challenge based on the shared key to obtain a third challenge plaintext; wherein the third challenge is generated by the quantum authentication system using the shared key corresponding to the smart chip device; generating a third response based on the third challenge plaintext, and encrypting the third response using the shared key; sending the encrypted third response to the quantum authentication system; The quantum authentication system decrypts the third response using the shared key and verifies it to complete a one-time communication security verification. 7.The quantum SIM card based smart chip device security authentication method according to claim 1 or 6, characterized in that, The method further comprises: constructing a Markov chain of a Markov chain evaluation model based on a communication connection state, and constructing an initial state distribution vector; wherein the communication connection state includes a legal state, a suspicious state, and an illegal state; the state distribution vector is a three-dimensional row vector, the first dimension corresponds to the state probability value of the legal state, the second dimension corresponds to the state probability value of the suspicious state, and the third dimension corresponds to the state probability value of the illegal state; collecting communication state data at a second preset frequency; the communication state data is determined based on a running state log, and the communication state data at least includes challenge response duration and / or response verification result in the communication security verification process; calculating and updating a state transition probability matrix of a Markov chain evaluation model based on the communication state data; wherein the state transition probability matrix is a three-order matrix P, P ij represents a probability of transitioning from a state s i to a state s j , i and j take values of 1, 2, and 3, 1 represents a legal state, 2 represents a suspicious state, and 3 represents an illegal state; based on the state transition probability matrix, and based on the initial state distribution vector or the state distribution vector at the previous moment, the state distribution vector at the current moment is calculated. 8.The quantum SIM card based smart chip device security authentication method of claim 7, wherein, After calculating the state distribution vector at the current moment based on the state transition probability matrix and based on the initial state distribution vector or the state distribution vector at the previous moment, the method further comprises: if the first dimension state probability value in the state distribution vector at the current moment is greater than a first threshold value, it is determined that the communication connection of the smart chip device is in a legal state; if the first dimension state probability value is less than or equal to the first threshold value and greater than a second threshold value, it is determined that the communication state of the smart chip is in a suspicious state; wherein the second threshold value is less than the first threshold value; If the first-dimension state probability value of the smart chip device is less than the second threshold value, and the second-dimension state probability value and / or the third-dimension state probability value of the smart chip device is greater than the second threshold value, it is determined that the communication connection of the smart chip device is in an illegal state; The quantum authentication system executes a preset security policy in the case that the communication connection is in a suspicious state or an illegal state, and the preset security policy at least includes one or more of disconnecting the communication connection, negotiating a new shared key, and freezing the access permission of the smart chip device. 9.The quantum SIM card based smart chip device security authentication method of claim 1, wherein, Before receiving the first challenge initiated by the quantum authentication system, the method further includes: generating a connection request in response to a user trigger, the connection request carrying a device identifier of the smart chip device; sending the connection request to the quantum authentication system through the quantum SIM card, so that the quantum authentication system generates the first challenge in response to the connection request and determines the quantum key corresponding to the smart chip device based on the device identifier, and then causes the quantum authentication system to encrypt the first challenge by using the quantum key and sends the encrypted first challenge to the smart chip device.

10. A quantum SIM card-based smart chip device security authentication system, characterized in that, The smart chip device at least includes a quantum SIM card, and the quantum SIM card is pre-provisioned with a quantum key; the system includes: a decryption module configured to receive the first challenge initiated by the quantum authentication system and decrypt the first challenge by using the quantum key to obtain a first challenge plaintext; wherein the first challenge is generated by the quantum authentication system by using the quantum key corresponding to the smart chip device; a response module configured to generate a first response based on the first challenge plaintext; an encryption module configured to encrypt the first response by using the quantum key based on the quantum SIM card, and send the encrypted first response to the quantum authentication system, so that the quantum authentication system performs identity authentication on the smart chip device based on the first response; a key negotiation module configured to perform key negotiation with the quantum authentication system based on a quantum key distribution protocol to obtain a shared key in the case that the identity authentication is successful; a communication connection module configured to establish a communication connection with the quantum authentication system by using the shared key.