Communication network security channel establishment method, device, system, equipment and medium

By constructing a dual-key resource pool in a 5G communication network and generating PSK using QKD quantum keys, the problem of insufficient quantum security of the TLS protocol is solved, achieving an efficient and secure communication network channel, reducing the impact of quantum key distribution rate on handshake efficiency, and possessing forward security.

CN121864359APending Publication Date: 2026-04-14CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-02
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing methods for establishing secure 5G communication channels suffer from insufficient quantum-resistant security of the TLS protocol when facing quantum computing threats. The PQC cryptographic algorithm suffers from large key size and low computational efficiency, and the slow quantum key distribution rate affects the efficiency of the PSK-TLS handshake.

Method used

By obtaining quantum keys and pre-shared keys from a dual-key resource pool on the client and server sides, a PSK generation mechanism based on the dual-key resource pool is constructed to isolate quantum keys and PSK, reduce the impact of quantum key distribution rate on handshake efficiency, and use QKD quantum keys to generate PSK to build a quantum-resistant secure channel.

Benefits of technology

It enables the construction of efficient and secure communication network security channels in a quantum computing environment, reduces the impact of quantum key distribution rate on handshake efficiency, has forward security, and avoids the problem of excessively large protocol messages introduced by PQC.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864359A_ABST
    Figure CN121864359A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and provides a communication network secure channel establishment method, device, system, equipment and medium, and the method comprises the steps: obtaining a standby quantum key from a QKD network and generating PSK when there is no available PSK in a local PSK resource pool and there is no available quantum key in a local quantum key resource pool, and sending a handshake request to the server side, so that the server side generates a PSK key based on a PSK generation mechanism of the local PSK resource pool and the local quantum key resource pool, sending a handshake response to the client side, generating a handshake verification request according to the PSK, and sending the handshake verification request to the server side, so that the server side constructs a communication network security channel after verifying the handshake verification request. The quantum key and the PSK are isolated through the double-key resource pool, and the influence of the slow quantum key distribution rate on the handshake efficiency in the communication network secure channel establishment process is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication network security technology, and in particular to a method, apparatus, system, device and medium for establishing a secure communication network channel. Background Technology

[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threats and challenges are becoming increasingly severe. Cryptographic security is an important foundation of information security and can be used to effectively protect the data security of network information systems. Cryptographic technology is a core technology and an important means to protect network information systems.

[0003] Currently, to ensure secure communication between Network Functions (NFs), 5G communication networks primarily employ Transport Layer Security (TLS) to establish secure channels between NFs, ensuring the confidentiality, integrity, and authentication of signaling and data transmission. TLS is a key negotiation mechanism based on public-key cryptography algorithms (ECC, RSA, etc.) that enables the establishment of secure data transmission channels between two communicating entities. Through TLS, 5G networks can effectively resist security threats such as data leakage, tampering, and man-in-the-middle attacks, ensuring reliable communication between network functions. Furthermore, TLS also supports authentication and data integrity verification, further enhancing the security of 5G communication networks.

[0004] With the rapid development of quantum computing technology, traditional public-key cryptosystems, represented by ECC and RSA, face fundamental security threats. The mathematical problems they rely on, such as discrete logarithms and large integer factorization, can be efficiently solved by quantum algorithms, making existing encryption mechanisms vulnerable to quantum attacks. TLS security protocols, due to their use of traditional public-key cryptosystems, also face security risks. To improve the quantum-resistant security of secure channels such as TLS / SSL, existing technologies mainly employ the following two methods: 1) Introduce the PQC cryptographic algorithm in TLS to improve the quantum-resistant security of the security protocol.

[0005] Although post-quantum cryptography (PQC) has been proposed, the security of its mathematical assumptions has not been fully verified, and there is a risk of it being cracked in the future. PQC suffers from problems such as large key size and low computational efficiency, and its introduction may lead to excessively large TLS messages.

[0006] 2) Introduce QKD (Quantum Key Distribution) based quantum keys as pre-shared keys for PSK-TLS in TLS.

[0007] The slow quantum key distribution rate affects the efficiency of PSK-TLS handshake, and there are forward security issues in using QKD keys as PSK for a long time. Summary of the Invention

[0008] To address the problems existing in the prior art, the present invention provides a method, apparatus, system, device, and medium for establishing a secure communication network channel.

[0009] This invention provides a method for establishing a secure communication channel, applied on the client side, comprising: When there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool, the first quantum key to be used is obtained from the quantum key distribution (QKD) network. A first PSK is generated based on the first quantum key to be used, and a handshake request is sent to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The server receives a handshake response, which includes a quantum key identifier for the second quantum key to be used and a key identifier for the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. Calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. Receive a handshake verification response sent by the server, wherein the handshake verification response is generated by the server based on the master key and session key calculated by the second PSK; The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0010] According to a method for establishing a secure communication channel provided by the present invention, the method further includes: If there is no available PSK in the first PSK resource pool, but there is a available quantum key in the first quantum key resource pool, the first quantum key to be used is obtained from the first quantum key resource pool.

[0011] According to the present invention, a method for establishing a secure communication channel further includes: When a usable PSK exists in the first PSK resource pool, the first PSK is directly selected from the first PSK resource pool, and a handshake request is sent to the server based on the first PSK. The handshake request includes the identifier of the first PSK. The server receives a handshake response, which includes a quantum key identifier for a second quantum key to be used and a key identifier for a second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used.

[0012] According to a method for establishing a secure communication channel provided by the present invention, obtaining a first quantum key to be used from a QKD network includes: Based on the client identifier and server identifier, obtain the first number of quantum keys associated with the client and server from the QKD network and store them in the first quantum key resource pool; Obtain the quantum key to be used from the first quantum key resource pool according to the first preset quantum key security selection strategy.

[0013] According to the method for establishing a secure communication channel provided by the present invention, the context of each key in the first quantum key resource pool includes: quantum key identifier, quantum key, quantum key validity period, and quantum key usage count.

[0014] According to a method for establishing a secure communication channel provided by the present invention, the handshake request further includes information on the network protocol types and versions supported by the client, supported cipher suites, and client random numbers; the supported cipher suites represent the security negotiation based on key encryption types supported by the client.

[0015] This invention also provides a method for establishing a secure communication channel, applied on the server side, comprising: The client receives a handshake request. The handshake request is a request sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. When there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, a second quantum key to be used is obtained from the QKD network, and a second PSK is generated based on the second quantum key to be used. A handshake response is sent to the client, and the handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK. Receive a handshake verification request sent by the client, the handshake verification request including a master key and session key generated by the client based on the first PSK; The handshake verification request is verified by calculating the master key and session key based on the second PSK, and a handshake verification response is obtained and sent to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0016] According to a method for establishing a secure communication channel provided by the present invention, the method further includes: If there is no available PSK in the second PSK resource pool, but there is a available quantum key in the second quantum key resource pool, the second quantum key to be used is obtained from the second quantum key resource pool.

[0017] According to a method for establishing a secure communication channel provided by the present invention, the method further includes: If a usable PSK exists in the second PSK resource pool, select the PSK directly from the second PSK resource pool.

[0018] According to a method for establishing a secure communication channel provided by the present invention, the handshake response further includes a selected cipher suite and a server random number.

[0019] The present invention also provides a communication network security channel establishment device, applied on the client side, comprising: The acquisition module is used to acquire the first quantum key to be used from the quantum key distribution (QKD) network when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The first sending module is used to generate a first PSK based on the first quantum key to be used, and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The first receiving module is used to receive a handshake response sent by the server. The handshake response includes the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and there is no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second sending module is used to calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. The second receiving module is used to receive the handshake verification response sent by the server. The handshake verification response is generated by the server based on the master key and session key calculated by the second PSK. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0020] The present invention also provides a communication network security channel establishment device, applied on the server side, comprising: The third receiving module is used to receive a handshake request sent by the client. The handshake request is a request sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The response module is used to obtain a second quantum key to be used from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK. The fourth receiving module is used to receive a handshake verification request sent by the client, the handshake verification request including a master key and session key generated by the client based on the first PSK; The verification module is used to calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0021] The present invention also provides a communication network security channel establishment system, including a client and a server, wherein: A client is used to obtain a first quantum key to be used from the quantum key distribution (QKD) network when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The client is used to generate a first PSK based on the first quantum key to be used and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The server is used to obtain a second quantum key to be used from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the second quantum key identifier of the second quantum key to be used and the identifier of the second PSK. The client is used to calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. The server is used to calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0022] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the above-described methods for establishing a secure communication channel.

[0023] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for establishing a secure communication channel.

[0024] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the above-described methods for establishing a secure communication channel.

[0025] This invention provides a method, apparatus, system, device, and medium for establishing a secure communication channel. When a client lacks a usable PSK in its local PSK resource pool and a usable quantum key in its local quantum key resource pool, it obtains a candidate quantum key from the QKD network, generates a PSK based on the candidate quantum key, and sends a handshake request to the server. When the server lacks a usable PSK in its local PSK resource pool and a usable quantum key in its local quantum key resource pool, it obtains a candidate quantum key from the QKD network, generates a PSK key based on the candidate quantum key, sends a handshake response to the client, calculates the master key and session key based on the PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server verifies the handshake verification request based on the PSK, obtains a handshake verification response, and sends the handshake verification response to the client. This constructs a secure communication channel and implements a PSK generation mechanism based on a dual-key resource pool. The dual-key resource pool isolates the quantum key and PSK, reducing the impact of the slow quantum key distribution rate on the handshake efficiency during the establishment of the secure communication channel. Attached Figure Description

[0026] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0027] Figure 1 This is a flowchart illustrating the method for establishing a secure communication channel provided by the present invention. Figure 1 .

[0028] Figure 2 This is a schematic diagram of the overall interactive process of the communication network security channel establishment method provided by the present invention.

[0029] Figure 3 This is a framework diagram of the quantum key acquisition process between network elements and QKD networks provided by the present invention.

[0030] Figure 4 This is a flowchart illustrating the method for establishing a secure communication channel provided by the present invention. Figure 2 .

[0031] Figure 5 This is a schematic diagram of the communication network security channel establishment device provided by the present invention. Figure 1 .

[0032] Figure 6 This is a schematic diagram of the communication network security channel establishment device provided by the present invention. Figure 2 .

[0033] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0034] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0035] Figure 1 This invention provides a flowchart illustrating a method for establishing a secure communication channel. (See attached diagram.) Figure 1 The method includes the following steps: Step 11: When there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool, obtain the first quantum key to be used from the quantum key distribution (QKD) network; the first PSK resource pool and the local resource pool of the client to which the first quantum key resource pool belongs.

[0036] Step 12: Generate a first PSK based on the first quantum key to be used, and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK.

[0037] Step 13: Receive the handshake response sent by the server. The handshake response includes the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0038] Step 14: Calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server.

[0039] Step 15: Receive the handshake verification response sent by the server. The handshake verification response is generated by the server based on the master key and session key calculated by the second PSK.

[0040] Regarding steps 11-15, it should be noted that quantum key distribution (QKD), as an emerging security technology, can provide a theoretically unbreakable key distribution mechanism, offering extremely high security for data transmission. Encrypted communication systems use the quantum key distribution mechanism to generate shared encryption and decryption keys, enhancing the security of data transmission between communicating parties.

[0041] This invention aims to reduce the impact of the slow quantum key distribution rate on the handshake efficiency during the establishment of secure communication channels by using a dual-key resource pool-based PSK (Pre-Shared Key) generation mechanism. It is important to note that the PSK is a secret key pre-agreed upon by both communicating parties (such as devices, users, and systems) offline (e.g., manual configuration, secure USB drive transfer, or distribution by a trusted third party) before communication. During communication, this key is directly used for encryption / decryption or identity verification, without the need for additional key exchange processes (such as TLS handshakes or QKD distribution).

[0042] Therefore, this invention needs to monitor and analyze the key status in the dual-key resource pool to determine the PSK used by the client and server during data communication.

[0043] A network element (NE) is a basic functional entity in a communication network. It is the smallest functional unit in the network that can be independently configured and managed. It can perform a specific communication function and, through cooperation with other network elements, realize the information transmission and processing functions of the entire communication network, such as terminals and network functions. Therefore, in this invention, the network element on the client side is the client network element (denoted as NE_C), and the network element on the server side is the server network element (denoted as NE_S).

[0044] In this invention, the method is applicable to the TLS protocol (TLS protocol is a key negotiation mechanism based on public-key cryptography algorithms (ECC, RSA, etc.) in communication networks (including 5G networks, etc.), and can also support secure communication protocols such as TLS / SSL / HTTPS. The following uses the TLS protocol as an example to explain the process of the method: In this invention, the first consideration is obtaining a usable quantum key, which is stored in a local PSK resource pool. If no usable PSK exists in the local PSK resource pool, then the quantum key is converted into a PSK. To do this, it is necessary to consider whether a usable quantum key exists in the local quantum key resource pool. If no usable quantum key exists in the local quantum key resource pool, a quantum key needs to be obtained from the QKD network, i.e., the quantum key is distributed to the client and server by QKD.

[0045] Therefore, when no usable PSK exists in the first PSK resource pool and no usable quantum key exists in the first quantum key resource pool, a candidate quantum key is obtained from the QKD network (the candidate quantum key obtained by the client serves as the first quantum key). Here, multiple quantum keys are obtained from the QKD network and stored in the local quantum key resource pool. Then, a quantum key is obtained from the local quantum key resource pool as the candidate quantum key, which is used to construct the PSK.

[0046] It should also be noted that when the client network element NE_C does not have a usable PSK in its local PSK resource pool, but has a usable quantum key in its local quantum key resource pool, it will obtain the quantum key to be used from the local quantum key resource pool.

[0047] It should also be noted that when the client network element NE_C has an available PSK in its local PSK resource pool, it will directly select a PSK from the local PSK resource pool.

[0048] In this invention, both the client network element and the server network element include two modules: a quantum key management module and a secure communication module, wherein: A. Quantum Key Management Module: Primarily used to handle QKD quantum key related functions. It can be implemented using a high-security module, such as integrated into a chip or hardware.

[0049] A1. Obtain quantum keys from QKD networks.

[0050] A2. Manage and maintain the quantum key resource pool.

[0051] To improve the efficiency of quantum key generation, the following strategies can be adopted: 1) For other pre-configured network elements that require secure communication, the quantum key management module can obtain a number of quantum keys in batches from the QKD network during initialization and store them in the quantum key resource pool.

[0052] 2) The quantum key management module can trigger the quantum key acquisition process in real time according to the usage of keys in the quantum key resource pool (such as frequency), obtain relevant quantum keys from the QKD network and write them into the quantum key resource pool to ensure that the quantum key resource pool has usable quantum keys.

[0053] To ensure security, unusable quantum keys, such as expired keys, should be periodically removed from the quantum key resource pool.

[0054] A3. Receive calls from the secure communication module to generate and output a PSK.

[0055] B. Secure Communication Module: Primarily used for functions related to establishing secure channels (TLS, etc.).

[0056] B1. Manage and maintain the PSK resource pool.

[0057] To ensure security, unusable PSKs, such as expired keys, should be cleaned up from the PSK resource pool regularly.

[0058] B2. Establish a secure channel with other NEs based on the PSK resource pool.

[0059] See below. Figure 2 and Figure 3 The process of obtaining PSK is explained using the client network element module as an example, as follows: 1. When the client network element NE_C needs to establish a TLS secure connection based on QKD quantum key distribution with the server network element NE_S, the NE_C secure communication module checks whether there is an available PSK in the local PSK resource pool: 1.1 If no PSK is available, then: 1.1.1 The NE_C secure communication module sends a PSK acquisition request to the NE_C quantum key management module, which includes the NE_C identifier and the NE_S identifier.

[0060] 1.1.2. The NE_C quantum key management module checks whether there are available quantum keys in the local quantum key resource pool: 1.1.2.1 If not, NE_C obtains several quantum keys {(QKID1,QK1),(QKID2,QK2), ..., (QKIDn,QKn)} associated with NE_C and NE_S from the QKD network based on the NE_C identifier and NE_S identifier, and stores them in the quantum key resource pool.

[0061] Note: The context of each key in the key resource pool includes: key identifier QKID, quantum key QK, QK's validity period, and key usage count QK_NUM. QK_NUM should be initialized to 0 and incremented by 1 for each use. If QK has expired, it cannot be used; if QK_NUM has exceeded the maximum number of uses, it also cannot be used.

[0062] 1.1.2.2 If available, there is no need to obtain the quantum key from the QKD network.

[0063] 1.1.3 The NE_C quantum key management module obtains available quantum keys QKi from the local quantum key resource pool according to security policies (such as sequential acquisition, random acquisition, or least recently used, etc.), ensuring that they are within the validity period and that the number of key uses has not exceeded the maximum number of times, and increments the number of key uses QK_NUM.

[0064] 1.1.4 The NE_C quantum key management module randomly generates a PSK identifier PSKIDj and generates PSKPSKj=KDF(QKi, QKIDi, PSKIDj), and sets the validity period of PSKj to the validity period of QKi.

[0065] 1.1.5 The NE_C quantum key management module returns PSKIDj, PSKj, and PSKj validity period to the NE_C secure communication module.

[0066] 1.1.6 The NE_C secure communication module stores PSKIDj, PSKj, and PSKj validity period in the local PSK resource pool, and initializes the key usage count to 0.

[0067] 1.2 If a PSK is available, the NE_C secure communication module does not need to obtain a PSK from the NE_C quantum key management module. The NE_C secure communication module obtains an available PSK (PSKj) from the local PSK resource pool according to a security policy (e.g., sequential acquisition, random acquisition, or least recently used, etc.), ensuring that it is within its validity period and that the key usage count has not exceeded the maximum, and increments the key usage count.

[0068] In this invention, the client network element NE_C sends a handshake request to the server based on the PSK, and the handshake request includes the PSK identifier.

[0069] See also Figure 2 The following explains how the client network element module sends a handshake request to the server: 2. The NE_C secure communication module sends a ClientHello message (i.e., the handshake request) to the NE_S secure communication module. This message contains the protocol types and versions supported by the client (such as the TLS version), supported cipher suites, client random number, pre_shared_key extended field, etc.

[0070] Specifically, the supported cipher suites should include corresponding cipher suite identifiers, such as TLS_QKD_PSK_WITH_AES_128_CBC_SHA / TLS_QKD_PSK_WITH_AES_256_CBC_SHA, etc. These cipher suite identifiers indicate that the client supports secure negotiation based on QKD quantum keys. The PskIdentity field in the pre_shared_key extension field should be set to the specified key identifiers QKIDi and PSKIDj, i.e., the quantum key identifier and the PSK identifier.

[0071] In this invention, when the server-side network element NE_S does not have a usable PSK in its local PSK resource pool and does not have a usable quantum key in its local quantum key resource pool, it obtains a quantum key to be used from the QKD network, generates a PSK based on the quantum key to be used (the PSK generated by the client based on the quantum key is used as the first PSK), and sends a handshake response to the client.

[0072] 3. In this invention, regarding the cryptographic suite, the server-side network element NE_S secure communication module selects the highest priority cryptographic suite from those supported by NE_C in ClientHello. If the highest priority cryptographic suite of the NE_S secure communication module is a QKD quantum key-based cryptographic suite, and the cryptographic suite in ClientHello sent by NE_C includes a QKD quantum key-based cryptographic suite, then the QKD quantum key-based cryptographic suite is used to establish the secure channel. Otherwise, other corresponding cryptographic suites are used to establish the secure channel.

[0073] See also Figure 2 and Figure 3 The process of obtaining PSK is explained using two modules of the server-side network element: 4. The server-side network element NE_S obtains the quantum key QKi and generates the pre-shared key PSK used in the current session based on QKi and PSKIDj. The specific steps are as follows: 4.1 The NE_S secure communication module obtains the key identifier QKIDi||PSKIDj from the PskIdentity field of ClientHello.

[0074] 4.2 The NE_S secure communication module checks if the local PSK resource pool has a PSK corresponding to PSKIDj: 4.2.1 If not, then: 4.2.1.1 The NE_S secure communication module sends a PSK acquisition request to the NE_S quantum key management module, which includes QKIDi, PSKIDj, NE_C identifier and NE_S identifier.

[0075] 4.2.1.2. The NE_S quantum key management module checks whether there are available quantum keys corresponding to QKIDi in the local quantum key resource pool: 4.2.1.2.1 If not, NE_S obtains several quantum keys {(QKID1,QK1), (QKID2,QK2), ..., (QKIDn,QKn)} associated with NE_C and NE_S from the QKD network based on the NE_C identifier, NE_S identifier, and QKIDi. These keys should include the QKi corresponding to QKIDi and are stored in the quantum key resource pool. If the returned quantum keys do not contain the QKi corresponding to QKIDi, an error should be returned.

[0076] Note: The context of each key in the key resource pool includes: key identifier QKID, quantum key QK, QK's validity period, and key usage count QK_NUM. QK_NUM should be initialized to 0 and incremented by 1 for each use. If QK has expired, it cannot be used; if QK_NUM has exceeded the maximum number of uses, it also cannot be used.

[0077] 4.2.1.2.2 If available, there is no need to obtain the quantum key from the QKD network.

[0078] 4.2.1.3 The NE_S quantum key management module generates PSKj=KDF(QKi, QKIDi, PSKIDj) based on QKIDi and PSKIDj, and sets the validity period of PSKj to the validity period of QKi.

[0079] 4.2.1.4 The NE_S quantum key management module returns PSKj and PSKj validity period to the NE_S secure communication module.

[0080] 4.2.1.5 The NE_S secure communication module stores PSKIDj, PSKj, and PSKj validity period in the local PSK resource pool.

[0081] 4.2.2 If available, the NE_S secure communication module does not need to obtain a usable PSKj from the NE_S quantum key management module.

[0082] In this invention, the master key and session key are calculated based on the PSK, a handshake verification request is generated, and the handshake verification request is sent to the server. The server verifies the handshake verification request based on the PSK, obtains a handshake verification response, and sends the handshake verification response to the client.

[0083] See also Figure 2 The verification process of the key between the client and the server is explained as follows: 5. The NE_S secure communication module returns a ServerHello (i.e., handshake response) to the NE_C secure communication module, which includes the selected cipher suite, the identifier of the selected pre-shared key QKIDi||PSKIDj, and the server-side random number, etc.

[0084] 6. The NE_C secure communication module uses PSKj as the pre-shared key PSK with NE_S, calculates the master secret and session key using the HKDF algorithm, and generates a Finished message (i.e., a handshake verification request) containing protection digest information. The NE_C secure communication module sends the Finished message to the NE_S secure communication module.

[0085] 7. The NE_S secure communication module uses PSKj as the pre-shared key PSK with NE_C, calculates the master secret and session key using the HKDF algorithm, and verifies the Finished message. The NE_C secure communication module and the NE_S secure communication module complete the establishment of a secure channel and transmit data based on the secure channel.

[0086] The method for establishing a secure communication channel provided by this invention involves the client obtaining a pending quantum key from the QKD network when neither a usable PSK nor a usable quantum key exists in its local PSK resource pool. The client then generates a PSK based on the pending quantum key and sends a handshake request to the server. Similarly, when neither a usable PSK nor a usable quantum key exists in its local PSK resource pool, the server obtains a pending quantum key from the QKD network, generates a PSK key based on the pending quantum key, sends a handshake response to the client, calculates the master key and session key based on the PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server verifies the handshake verification request based on the PSK, obtains a handshake verification response, and sends the handshake verification response to the client. This constructs a secure communication channel and implements a PSK generation mechanism based on a dual-key resource pool. By isolating the quantum key and PSK through the dual-key resource pool, the impact of the slow quantum key distribution rate on the handshake efficiency during the establishment of the secure communication channel is reduced.

[0087] The secure channel constructed by this invention is based on the quantum resistance of QKD quantum keys and does not rely on the quantum resistance security of PQC.

[0088] The secure channel constructed by this invention does not introduce the PQC cryptographic suite, thus avoiding the problem of excessively large protocol messages.

[0089] This invention reduces the impact of slow quantum key distribution rate on PSK-TLS handshake efficiency by using a PSK generation mechanism based on a dual-key resource pool.

[0090] QKD keys are pre-generated by the NE quantum key management module, or can be obtained in real time during runtime based on the usage of keys in the quantum key resource pool (such as frequency), which can reduce their impact on handshake efficiency.

[0091] The network protocol does not use QKD keys directly, but obtains them from the PSK resource pool. The PSK can be derived from quantum keys in the quantum key resource pool in real time, so it will not affect the handshake efficiency of the network protocol.

[0092] The secure channel negotiation process based on QKD quantum keys has forward security.

[0093] The number of times a PSK can be used in the PSK resource pool can be set to a small value (such as a maximum of 1 use). Once the maximum number of uses is exceeded, it will no longer be used. Therefore, even if the PSK is leaked, it will only affect the current session and will not affect other sessions.

[0094] The quantum key is stored in a secure area and is not used directly as a PSK, thus giving the protocol forward security.

[0095] The following describes the method for establishing a secure communication channel provided by the present invention. The method described below is applied to the server side and can be referred to in correspondence with the method described above.

[0096] Figure 4 This invention provides a flowchart illustrating a method for establishing a secure communication channel. (See attached diagram.) Figure 4 The method includes the following steps: Step 41: Receive a handshake request sent by the client. The handshake request is sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used, when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK; the first PSK resource pool and the local resource pool to which the first quantum key resource pool belongs.

[0097] Step 42: When there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, obtain the second quantum key to be used from the QKD network, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK; the second PSK resource pool and the local resource pool of the server to which the second quantum key resource pool belongs.

[0098] Step 43: Receive a handshake verification request sent by the client. The handshake verification request includes the master key and session key generated by the client based on the first PSK.

[0099] Step 44: Calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client.

[0100] In a further step of the above method, the method further includes: If there is no available PSK in the second PSK resource pool, but there is a available quantum key in the second quantum key resource pool, the second quantum key to be used is obtained from the second quantum key resource pool.

[0101] The method also includes: If a usable PSK exists in the second PSK resource pool, the second PSK is selected directly from the second PSK resource pool.

[0102] The handshake response also includes the selected cipher suite and a server-side random number.

[0103] Since the apparatus of this embodiment is based on the same principle as the method of the above embodiment, more detailed explanations will not be repeated here.

[0104] The following describes the communication network security channel establishment device provided by the present invention. The communication network security channel establishment device described below can be referred to in correspondence with the communication network security channel establishment method described above.

[0105] Figure 5 A schematic diagram of a communication network security channel establishment device provided by the present invention is shown below. Figure 5 The device includes an acquisition module 51, a first transmitting module 52, a first receiving module 53, a second transmitting module 54, and a second receiving module 55, wherein: The acquisition module is used to acquire the first quantum key to be used from the quantum key distribution (QKD) network when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The first sending module is used to generate a first PSK based on the first quantum key to be used, and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The first receiving module is used to receive the handshake response sent by the server. The handshake response includes the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and there is no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second sending module is used to calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. The second receiving module is used to receive the handshake verification response sent by the server. The handshake verification response is generated by the server based on the master key and session key calculated by the second PSK. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0106] Figure 6 A schematic diagram of a communication network security channel establishment device provided by the present invention is shown below. Figure 6 The device includes a three-receiving module 61, a response module 62, a fourth receiving module 63, and a verification module 64, wherein: The third receiving module is used to receive a handshake request sent by the client. The handshake request is a request sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The response module is used to obtain a second quantum key to be used from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK. The fourth receiving module is used to receive the handshake verification request sent by the client. The handshake verification request includes the master key and session key generated by the client based on the first PSK. The verification module is used to calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

[0107] Since the apparatus of this embodiment is based on the same principle as the method of the above embodiment, more detailed explanations will not be repeated here.

[0108] It should be noted that, in the embodiments of the present invention, the relevant functional modules can be implemented by a hardware processor.

[0109] The communication network security channel establishment device provided by this invention enables a client to obtain a pending quantum key from the QKD network when neither a usable PSK nor a usable quantum key exists in its local PSK resource pool. The client then generates a PSK based on the pending quantum key and sends a handshake request to the server. Similarly, when neither a usable PSK nor a usable quantum key exists in its local PSK resource pool, the server obtains a pending quantum key from the QKD network, generates a PSK key based on the pending quantum key, sends a handshake response to the client, calculates the master key and session key based on the PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server verifies the handshake verification request based on the PSK, obtains a handshake verification response, and sends the response back to the client. This establishes a secure communication network channel and implements a PSK generation mechanism based on a dual-key resource pool. By isolating the quantum key and PSK through the dual-key resource pool, the impact of the slow quantum key distribution rate on the handshake efficiency during the establishment of the secure communication network channel is reduced.

[0110] Figure 7 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 7 As shown, the electronic device may include: a processor 71, a communication interface 72, a memory 73, and a communication bus 74. The processor 71, communication interface 72, and memory 73 communicate with each other via the communication bus 74. The processor 71 can invoke logical instructions stored in the memory 73 to execute a method for establishing a secure communication channel. This method includes: When no available PSK exists in the first pre-shared key PSK resource pool and no available quantum key exists in the first quantum key resource pool, a first quantum key to be used is obtained from the quantum key distribution (QKD) network; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs are also retrieved; a first PSK is generated based on the first quantum key to be used, and a handshake request is sent to the server, the handshake request including the quantum key identifier of the first quantum key to be used and the identifier of the first PSK; a handshake response is received from the server, the handshake response including the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool. The server calculates the master key and session key based on the first PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server receives the handshake verification response, which is generated by the server based on the master key and session key calculated by the second PSK.

[0111] Or, The system receives a handshake request from a client. This handshake request is sent by the client after obtaining a first quantum key from the quantum key distribution (QKD) network and generating a first PSK based on the first pre-shared key (PSK) resource pool, when no available PSK exists in the first pre-shared key (PSK) resource pool and no available quantum key exists in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key and the identifier of the first PSK; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs; and the second PSK resource pool and the second quantum key resource pool. When using a quantum key, the system obtains a second quantum key to be used from the QKD network, generates a second PSK based on the second quantum key to be used, and sends a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK; the second PSK resource pool and the local resource pool of the server to which the second quantum key resource pool belongs; receives a handshake verification request sent by the client. The handshake verification request includes the master key and session key generated by the client based on the first PSK; verifies the handshake verification request based on the master key and session key calculated by the second PSK, obtains a handshake verification response, and sends the handshake verification response to the client.

[0112] Furthermore, the logical instructions in the aforementioned memory 73 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0113] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program that can be stored on a non-transitory computer-readable storage medium, wherein when the computer program is executed by a processor, the computer is capable of executing a method for establishing a secure communication channel, the method comprising: When no available PSK exists in the first pre-shared key PSK resource pool and no available quantum key exists in the first quantum key resource pool, a first quantum key to be used is obtained from the quantum key distribution (QKD) network; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs are also retrieved; a first PSK is generated based on the first quantum key to be used, and a handshake request is sent to the server, the handshake request including the quantum key identifier of the first quantum key to be used and the identifier of the first PSK; a handshake response is received from the server, the handshake response including the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool. The server calculates the master key and session key based on the first PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server receives the handshake verification response, which is generated by the server based on the master key and session key calculated by the second PSK.

[0114] Or, The system receives a handshake request from a client. This handshake request is sent by the client after obtaining a first quantum key from the quantum key distribution (QKD) network and generating a first PSK based on the first pre-shared key (PSK) resource pool, when no available PSK exists in the first pre-shared key (PSK) resource pool and no available quantum key exists in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key and the identifier of the first PSK; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs; and the second PSK resource pool and the second quantum key resource pool. When using a quantum key, the system obtains a second quantum key to be used from the QKD network, generates a second PSK based on the second quantum key to be used, and sends a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK; the second PSK resource pool and the local resource pool of the server to which the second quantum key resource pool belongs; receives a handshake verification request sent by the client. The handshake verification request includes the master key and session key generated by the client based on the first PSK; verifies the handshake verification request based on the master key and session key calculated by the second PSK, obtains a handshake verification response, and sends the handshake verification response to the client.

[0115] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform a method for establishing a secure communication channel, the method comprising: When no available PSK exists in the first pre-shared key PSK resource pool and no available quantum key exists in the first quantum key resource pool, a first quantum key to be used is obtained from the quantum key distribution (QKD) network; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs are also retrieved; a first PSK is generated based on the first quantum key to be used, and a handshake request is sent to the server, the handshake request including the quantum key identifier of the first quantum key to be used and the identifier of the first PSK; a handshake response is received from the server, the handshake response including the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool. The server calculates the master key and session key based on the first PSK, generates a handshake verification request, and sends the handshake verification request to the server. The server receives the handshake verification response, which is generated by the server based on the master key and session key calculated by the second PSK.

[0116] Or, The system receives a handshake request from a client. This handshake request is sent by the client after obtaining a first quantum key from the quantum key distribution (QKD) network and generating a first PSK based on the first pre-shared key (PSK) resource pool, when no available PSK exists in the first pre-shared key (PSK) resource pool and no available quantum key exists in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key and the identifier of the first PSK; the first PSK resource pool and the client's local resource pool to which the first quantum key resource pool belongs; and the second PSK resource pool and the second quantum key resource pool. When using a quantum key, the system obtains a second quantum key to be used from the QKD network, generates a second PSK based on the second quantum key to be used, and sends a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK; the second PSK resource pool and the local resource pool of the server to which the second quantum key resource pool belongs; receives a handshake verification request sent by the client. The handshake verification request includes the master key and session key generated by the client based on the first PSK; verifies the handshake verification request based on the master key and session key calculated by the second PSK, obtains a handshake verification response, and sends the handshake verification response to the client.

[0117] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for establishing a secure communication channel, characterized in that, Applied to the client side, including: When there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool, the first quantum key to be used is obtained from the quantum key distribution (QKD) network. A first PSK is generated based on the first quantum key to be used, and a handshake request is sent to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The server receives a handshake response, which includes a quantum key identifier for the second quantum key to be used and a key identifier for the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. Calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. Receive a handshake verification response sent by the server, wherein the handshake verification response is generated by the server based on the master key and session key calculated by the second PSK; The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

2. The method for establishing a secure communication channel according to claim 1, characterized in that, The method further includes: If there is no available PSK in the first PSK resource pool, but there is a available quantum key in the first quantum key resource pool, the first quantum key to be used is obtained from the first quantum key resource pool.

3. The method for establishing a secure communication channel according to claim 2, characterized in that, The method further includes: When a usable PSK exists in the first PSK resource pool, the first PSK is directly selected from the first PSK resource pool, and a handshake request is sent to the server based on the first PSK. The handshake request includes the identifier of the first PSK. The server receives a handshake response, which includes a quantum key identifier for a second quantum key to be used and a key identifier for a second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used.

4. The method for establishing a secure communication channel according to claim 1, characterized in that, The process of obtaining the first quantum key to be used from the QKD network includes: Based on the client identifier and server identifier, obtain the first number of quantum keys associated with the client and server from the QKD network and store them in the first quantum key resource pool; Obtain the quantum key to be used from the first quantum key resource pool according to the first preset quantum key security selection strategy.

5. The method for establishing a secure communication channel according to claim 1, characterized in that, The context of each key in the first quantum key resource pool includes: quantum key identifier, quantum key, quantum key validity period, and quantum key usage count.

6. The method for establishing a secure communication channel according to claim 1, characterized in that, The handshake request also includes information on the network protocol types and versions supported by the client, supported cipher suites, and client random numbers; the supported cipher suites represent the security negotiation based on key encryption types supported by the client.

7. A method for establishing a secure communication channel, characterized in that, Applied to the server side, including: The client receives a handshake request. The handshake request is a request sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. When there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, a second quantum key to be used is obtained from the QKD network, and a second PSK is generated based on the second quantum key to be used. A handshake response is sent to the client, and the handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK. Receive a handshake verification request sent by the client, the handshake verification request including a master key and session key generated by the client based on the first PSK; The handshake verification request is verified by calculating the master key and session key based on the second PSK, and a handshake verification response is obtained and sent to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

8. The method for establishing a secure communication channel according to claim 7, characterized in that, The method further includes: If there is no available PSK in the second PSK resource pool, but there is a available quantum key in the second quantum key resource pool, the second quantum key to be used is obtained from the second quantum key resource pool.

9. The method for establishing a secure communication channel according to claim 8, characterized in that, The method further includes: If a usable PSK exists in the second PSK resource pool, the second PSK is selected directly from the second PSK resource pool.

10. The method for establishing a secure communication channel according to claim 9, characterized in that, The handshake response also includes the selected cipher suite and a server-side random number.

11. A device for establishing a secure communication channel, characterized in that, Applied to the client side, including: The acquisition module is used to acquire the first quantum key to be used from the quantum key distribution (QKD) network when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The first sending module is used to generate a first PSK based on the first quantum key to be used, and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The first receiving module is used to receive a handshake response sent by the server. The handshake response includes the quantum key identifier of the second quantum key to be used and the key identifier of the second PSK. The second quantum key to be used is obtained by the server from the QKD network when there is no available PSK in the second PSK resource pool and there is no available quantum key in the second quantum key resource pool. The second PSK is generated by the server based on the second quantum key to be used. The second sending module is used to calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. The second receiving module is used to receive the handshake verification response sent by the server. The handshake verification response is generated by the server based on the master key and session key calculated by the second PSK. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

12. A device for establishing a secure communication channel, characterized in that, Applied to the server side, including: The third receiving module is used to receive a handshake request sent by the client. The handshake request is a request sent by the client after obtaining a first quantum key to be used from the quantum key distribution (QKD) network and generating a first PSK based on the first quantum key to be used when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The response module is used to obtain a second quantum key to be used from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the quantum key identifier of the second quantum key to be used and the identifier of the second PSK. The fourth receiving module is used to receive a handshake verification request sent by the client, the handshake verification request including a master key and session key generated by the client based on the first PSK; The verification module is used to calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

13. A system for establishing a secure communication channel, characterized in that, Including client and server sides, among which: A client is used to obtain a first quantum key to be used from the quantum key distribution (QKD) network when there is no available PSK in the first pre-shared key PSK resource pool and no available quantum key in the first quantum key resource pool. The client is used to generate a first PSK based on the first quantum key to be used and send a handshake request to the server. The handshake request includes the quantum key identifier of the first quantum key to be used and the identifier of the first PSK. The server is used to obtain a second quantum key to be used from the QKD network when there is no available PSK in the second PSK resource pool and no available quantum key in the second quantum key resource pool, generate a second PSK based on the second quantum key to be used, and send a handshake response to the client. The handshake response includes the second quantum key identifier of the second quantum key to be used and the identifier of the second PSK. The client is used to calculate the master key and session key based on the first PSK, generate a handshake verification request, and send the handshake verification request to the server. The server is used to calculate the master key and session key based on the second PSK to verify the handshake verification request, obtain the handshake verification response, and send the handshake verification response to the client. The first PSK resource pool and the first quantum key resource pool belong to the client's local resource pool; the second PSK resource pool and the second quantum key resource pool belong to the server's local resource pool.

14. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method for establishing a secure communication channel as described in any one of claims 1-6, or the method for establishing a secure communication channel as described in any one of claims 7-10.

15. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for establishing a secure communication channel as described in any one of claims 1-6, or the method for establishing a secure communication channel as described in any one of claims 7-10.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method for establishing a secure communication channel as described in any one of claims 1-6, or the method for establishing a secure communication channel as described in any one of claims 7-10.