Port Internet of Things secure communication system based on quantum key distribution

Quantum key distribution technology is used to solve the security problems of the Internet of Things in ports, achieving highly secure and reliable communication, solving threats such as data leakage, tampering and equipment counterfeiting, and enhancing the stability and compatibility of the system.

CN121887380APending Publication Date: 2026-04-17XIDIAN UNIV +4
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIDIAN UNIV
Filing Date
2025-11-19
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The Internet of Things (IoT) in ports faces security threats such as data leakage, tampering, and device identity impersonation. Traditional encryption methods are ineffective in complex electromagnetic environments and are threatened by quantum computing.

Method used

A secure communication system based on quantum key distribution is adopted. Quantum key distribution equipment is used to generate and distribute quantum keys. Combining quantum and classical channels, the BB84 protocol and quantum signature technology are used for key distribution and device authentication. Data encryption is performed using the AES algorithm to achieve high security and reliability communication.

Benefits of technology

It ensures the security and reliability of port IoT communications, prevents data leakage and tampering, protects sensitive data privacy, enhances system stability and compatibility, and adapts to the increase in the number of devices and business changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887380A_ABST
    Figure CN121887380A_ABST
Patent Text Reader

Abstract

The invention discloses a port Internet of Things secure communication system based on quantum key distribution, and the system comprises quantum key distribution equipment which is used for generating and distributing quantum keys; the Internet of Things devices are distributed in all areas of the port and used for collecting and transmitting port operation related data; the control center is used for managing and controlling the whole system; and the communication network comprises a quantum channel and a classic channel, the quantum channel is used for transmitting the quantum key, and the classic channel is used for transmitting the encrypted data and control information. By combining the quantum key distribution technology with the port Internet of Things, a high-security and high-reliability solution is provided for port Internet of Things communication, and strict requirements of ports on communication security under ever-increasing service requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of quantum communication technology and port Internet of Things, specifically relating to a secure communication system for port Internet of Things based on quantum key distribution. Background Technology

[0002] Against the backdrop of continued growth in global trade, ports, as key hubs of international trade, play a decisive role in the smoothness of the entire supply chain through their efficient operation. In recent years, with the rapid development of Internet of Things (IoT) technology, port IoT has emerged, becoming an important means to improve port operational efficiency, reduce costs, and enhance competitiveness.

[0003] The Internet of Things (IoT) in ports connects a vast network of sensors, smart devices, and various information systems, enabling comprehensive perception, real-time monitoring, and intelligent management of all aspects of port operations. In cargo loading and unloading, automated equipment such as Automated Guided Vehicles (AGVs), automated yard equipment, and automated conveyors efficiently complete cargo loading, unloading, and handling tasks, significantly improving efficiency and reducing labor costs. These devices are equipped with advanced sensors and control systems, allowing them to perceive the location, weight, and status of cargo in real time and operate precisely according to preset programs and instructions.

[0004] In terms of warehousing, intelligent warehousing systems utilize IoT technology to achieve automated inventory counting, management, and intelligent scheduling of goods within the warehouse. By attaching RFID tags or QR codes to goods, combined with in-warehouse reading and writing equipment and management systems, the system can track the inbound, outbound, and storage status of goods in real time, ensuring the accuracy and timeliness of inventory information. Simultaneously, intelligent warehousing systems can automatically optimize storage layout based on factors such as the type, quantity, and storage time of goods, improving warehouse space utilization.

[0005] Furthermore, the Internet of Things (IoT) in ports also encompasses the monitoring and management of the port environment, equipment status, and personnel flow. For example, by installing environmental sensors, real-time monitoring of port weather conditions, air quality, water level changes, and other information can provide early warnings and decision support for safe port production and operation; real-time monitoring of equipment status can promptly identify equipment failures and potential risks, enabling preventative maintenance and improving equipment reliability and lifespan; and real-time monitoring of personnel flow can optimize personnel scheduling, improve work efficiency, and ensure port safety and order.

[0006] With the increasing number of connected devices and the growing volume of data transmission in the port Internet of Things (IoT), communication security issues have become increasingly prominent, becoming a significant factor restricting the development of the port IoT.

[0007] 1. Data Breach Risk: The data transmitted in port IoT systems contains a large amount of sensitive information, including trade secrets, cargo information, and customer privacy. If this data is breached, it could cause significant economic losses and reputational damage to port companies, cargo owners, and customers. Hackers can steal data from port IoT systems through cyberattacks, malware infections, and other methods. For example, in 2020, a port's IoT system was hacked, resulting in the leakage of a large amount of cargo transportation information and customer data, causing serious economic losses to the port company and related customers.

[0008] 2. Data Tampering Risk: Attackers may tamper with data transmitted in the port's Internet of Things (IoT) system, thereby affecting the port's normal operations and decision-making. For example, tampering with information such as the weight, quantity, and destination of goods may lead to errors in loading and unloading, incorrect transportation routes, and other problems, causing chaos and losses in port operations. In 2018, data in a port's smart warehousing system was tampered with, resulting in incorrect cargo inventory information and affecting the normal inbound, outbound, and scheduling of goods.

[0009] 3. Device Impersonation Risk: In port IoT systems, device authentication and authorization are required to ensure secure and reliable communication. However, attackers may impersonate legitimate devices to access the port IoT system, thereby obtaining sensitive information or performing malicious operations. For example, impersonating an AGV and sending incorrect control commands could lead to AGV collisions, cargo damage, and other accidents.

[0010] 4. Shortcomings of Traditional Encryption Methods: Currently, the traditional encryption methods commonly used in port IoT are mainly encryption algorithms based on mathematical problems, such as RSA and AES. While these algorithms theoretically possess a certain level of security, they face numerous challenges in practical applications. In the complex electromagnetic environment of ports, signal interference and noise can cause errors in encrypted data transmission, affecting the encryption effect. Furthermore, with the continuous development of computing technology, traditional encryption algorithms face the risk of being cracked, especially with the development of quantum computing technology, which poses a serious threat to traditional encryption algorithms. Once quantum computers are widely deployed, existing encryption algorithms based on mathematical problems may be cracked in a short period, leaving the data in the port IoT unprotected. Summary of the Invention

[0011] The purpose of this invention is to provide a secure communication system for port IoT based on quantum key distribution, aiming to solve the security problems in port IoT communication. Utilizing the absolute security of quantum key distribution technology, it achieves secure and reliable communication between port IoT devices, preventing security threats such as data leakage, tampering, and device identity spoofing, thus ensuring the smooth operation of the port. By combining quantum key distribution technology with port IoT, a highly secure and reliable solution is provided for port IoT communication, meeting the stringent communication security requirements of ports under the increasing business demands.

[0012] To achieve the above objectives, the present invention provides the following technical solution: a port IoT secure communication system based on quantum key distribution, comprising: Quantum key distribution equipment for generating and distributing quantum keys, including quantum key distribution terminals and quantum channels; Internet of Things (IoT) devices, distributed throughout various areas of the port, are used to collect and transmit port operation-related data. They are connected to quantum key distribution devices via quantum and classical channels, and the collected data is encrypted using quantum keys. The control center is used to manage and control the entire system, including key management, device management, and communication management. It communicates with IoT devices and quantum key distribution devices through classical channels, receives encrypted data sent by IoT devices and decrypts it to obtain the original data, and can also send control commands to IoT devices. Communication networks include quantum channels and classical channels. Quantum channels are used to transmit quantum keys, while classical channels are used to transmit encrypted data and control information.

[0013] Furthermore, in the quantum key distribution device, the light source is a single-photon source used to generate single photons carrying quantum information; the detector is a high-precision single-photon detector, which can accurately detect the quantum state of a single photon; it also includes a quantum storage module for storing quantum keys, using a quantum state storage method to ensure the security of the keys.

[0014] Furthermore, the encryption module in the IoT device uses the AES algorithm to encrypt the collected data; when calling the quantum key, a key indexing mechanism is used to quickly and accurately obtain the corresponding quantum key for encryption operations through the key index allocated by the quantum key distribution device.

[0015] Furthermore, the quantum key distribution method employs the BB84 protocol to implement quantum key distribution, with the specific steps as follows: The sender randomly selects one of four quantum states to encode each bit, with each of the four quantum states corresponding to two different bases; The sender generates a series of random bit sequences and randomly selects a basis to encode each bit. Then, these encoded qubits are sent to the receiver through a quantum channel. When receiving a qubit, the receiver randomly selects a basis for measurement; After the quantum bit transmission is completed, the sender and receiver publicly exchange their chosen basis through a classical channel, but do not disclose the bit values. They then select the measurement results that have the same basis to form the original key. Error detection and correction are performed on the original key to obtain the final secure quantum key.

[0016] Furthermore, in the BB84 protocol, the measurement method for quantum states is as follows: the receiver uses a measurement device corresponding to the measurement basis to measure the qubit. If the measurement basis is the same as the basis used by the sender during encoding, the measurement result is consistent with the bit sent by the sender. The basis selection rule is as follows: the sender and receiver each randomly select a horizontal-vertical basis or a diagonal basis as the measurement basis.

[0017] Furthermore, the specific process for identity authentication between IoT devices is as follows: When each IoT device connects to the system, it has a digital certificate issued by the control center. The digital certificate contains the device's identity information and public key. When communicating with the control center, the device first uses its private key to sign the message containing the device's identity information and timestamp, and then sends the signed message and digital certificate to the control center. After receiving the message, the control center uses the public key in the device's digital certificate to verify the signature, and checks the validity of the digital certificate and the timeliness of the timestamp. If the verification passes, the device's identity is confirmed as legitimate, and the device is allowed to communicate and access the corresponding resources; if the verification fails, the device's access request is rejected.

[0018] Furthermore, during the identity authentication process, quantum signature technology is used to sign the messages sent by the device. Quantum signatures are generated based on quantum keys and are unforgeable. At the same time, timestamp technology is used to ensure the timeliness of the messages. The timestamps are generated by an authoritative time server and are attached to the messages when they are sent by the device.

[0019] Furthermore, key management includes: The key storage module uses quantum storage devices to store quantum keys, utilizing the properties of quantum states to store keys, ensuring key security. It also employs a multi-copy storage and backup mechanism, storing keys in multiple quantum storage devices and backing them up periodically. The key update module employs a combination of periodic updates and event-triggered updates. Periodic updates involve the quantum key distribution device regenerating the quantum key at preset time intervals and distributing the new key to IoT devices and the control center. Event-triggered updates are triggered immediately when the system detects a security event, such as a potential leakage of the quantum key or a device authentication failure exceeding a certain threshold. The key synchronization module is used to ensure key synchronization between multiple IoT devices and the control center. When the quantum key distribution device generates a new key, it first sends the key to the control center. After the control center verifies the validity of the key, it distributes the key to each IoT device through broadcast. After receiving the key, the IoT device verifies and stores it. If the verification fails, it requests the control center to resend the key. At the same time, the IoT devices and the control center periodically synchronize and check the key status.

[0020] Furthermore, the key storage module employs quantum encryption to encrypt and store the key, preventing it from being stolen during storage. The storage medium uses quantum storage media with high stability and anti-interference capabilities, such as quantum hard drives, to ensure the security and reliability of key storage.

[0021] Furthermore, regarding the integration of the secure communication system with existing port business systems, middleware is used for interfacing. The middleware is responsible for parsing and converting the data formats and communication protocols between the secure communication system and existing business systems, enabling seamless data transmission and interaction. In terms of network infrastructure, the port's existing fiber optic network is fully utilized as the transmission medium for quantum and classical channels. Existing network equipment, such as switches and routers, is upgraded with firmware or security modules to support quantum key distribution and encrypted communication functions.

[0022] Beneficial effects: 1. Enhanced Communication Security: This invention utilizes the absolute security of quantum key distribution technology to ensure that the key cannot be eavesdropped on or cracked during transmission. The non-cloning nature of quantum states and the interference of quantum measurements ensure that any attempt by a third party to steal the key will be detected by both communicating parties, thereby guaranteeing the security of port IoT communications and effectively preventing security threats such as data leakage, tampering, and device identity spoofing, providing reliable communication assurance for port operations.

[0023] 2. Protecting Data Privacy: Encrypting data transmitted by IoT devices using quantum keys ensures that the data remains encrypted during transmission and storage. Only the recipient with the correct quantum key can decrypt the data, protecting the privacy of sensitive data such as business secrets, cargo information, and customer privacy involved in port operations, and preventing the data from being illegally obtained and used.

[0024] 3. Enhance system reliability: The use of quantum repeater technology to overcome the transmission loss of quantum channels, the use of quantum error correction code technology to correct errors in the quantum key transmission process, and the use of key management and synchronization mechanisms to ensure the security and availability of keys all enhance the reliability of the entire communication system, reduce system interruptions and data errors caused by communication failures and key problems, and improve the stability and operating efficiency of the port IoT system.

[0025] 4. Excellent Compatibility and Scalability: The secure communication system of this invention can be effectively integrated with the port's existing business systems and network infrastructure. Through middleware and upgrades to existing equipment, it achieves full utilization of existing resources and reduces system deployment costs. Simultaneously, the system possesses excellent scalability, adapting to the increasing number of IoT devices in the port and the ever-changing business needs, providing strong technical support for the port's future development.

[0026] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of this application are described below. Attached Figure Description

[0027] Figure 1 This is a system architecture diagram of the present invention; Figure 2 This is a device connection diagram for the present invention; Figure 3 This is a flowchart of the key distribution process of the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims and drawings of this application are intended to cover non-exclusive inclusion.

[0030] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of the phrase "embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0031] Furthermore, the terms "first," "second," etc., in the specification and claims of this application or in the aforementioned drawings are used to distinguish different objects rather than to describe a specific order, and may explicitly or implicitly include one or more of the features.

[0032] To enable those skilled in the art to better understand the present application, the following will be combined with... Figures 1-3 The technical solutions in the embodiments of this application will be clearly and completely described.

[0033] System setup steps 1. Equipment selection: Quantum key distribution equipment: A commercially available quantum key distribution terminal with high stability and reliability is selected. It adopts advanced single-photon source technology and high-precision quantum state measurement device, which can meet the quantum key distribution needs in the complex environment of the port.

[0034] IoT Devices: Various IoT devices, including sensors, actuators, and smart terminals, are selected based on the port's different business scenarios and functional requirements. In the cargo storage area, high-precision weight sensors and temperature / humidity sensors are deployed to monitor cargo weight and the temperature and humidity of the storage environment in real time. In the cargo loading and unloading area, Automated Guided Vehicles (AGVs) equipped with advanced control systems and automated loading and unloading equipment are used to achieve automated loading, unloading, and handling of cargo. These IoT devices all have excellent communication interfaces and data processing capabilities, enabling efficient data interaction with quantum key distribution equipment and the control center.

[0035] Control center equipment: Equipped with high-performance servers and data storage devices, serving as the core hardware of the control center.

[0036] 2. Equipment installation: Quantum key distribution equipment installation: The quantum key distribution terminal will be installed in a specially designed server room with adequate electromagnetic shielding and temperature and humidity control to ensure the normal operation of the quantum key distribution equipment. The quantum channel will be connected using optical fiber to ensure low-loss transmission of quantum signals. During fiber optic cable laying, relevant construction specifications must be strictly followed, and the fiber optic cable must be properly protected and secured to prevent damage from external forces.

[0037] IoT Device Installation: Based on the port's layout and business processes, various IoT devices will be installed in appropriate locations. Sensor devices should be installed in locations capable of accurately sensing target parameters; for example, weight sensors will be installed on cargo-carrying platforms, and temperature and humidity sensors will be installed in key locations inside the warehouse. Actuators and intelligent terminal devices will be installed in easily operable and controllable locations, such as the AGV control terminal being installed in the driver's cab. All IoT devices must establish communication connections with the quantum key distribution equipment and control center via wired or wireless means.

[0038] Control Center Equipment Installation: Servers and data storage devices will be installed in the control center server room, with a reasonable layout and cabling. Servers must be equipped with redundant power supplies and cooling systems to ensure stability during long-term operation. Data storage devices should be backed up and redundantly configured to prevent data loss. Simultaneously, the control center server room must have strict access permissions and security measures to ensure the safety of equipment and data.

[0039] 3. Equipment debugging: Quantum key distribution equipment debugging: Using professional debugging tools and software, the quantum key distribution equipment is initialized and its parameters are adjusted. Key indicators such as the output power of the quantum light source, the preparation and measurement accuracy of quantum states are checked to ensure that the quantum key distribution equipment can generate and distribute quantum keys normally. By simulating the transmission environment of a quantum channel, the performance of quantum keys under different transmission distances and noise conditions is tested, and the equipment is optimized and adjusted to improve the efficiency and reliability of quantum key distribution.

[0040] IoT Device Debugging: Perform functional and communication tests on IoT devices to ensure they can collect data and execute control commands normally. Check the measurement accuracy and data transmission stability of sensor devices, and the action accuracy and response speed of actuator devices. Verify the normal data interaction between IoT devices and other system components through communication tests with quantum key distribution equipment and the control center. Promptly investigate and resolve any problems found during testing to ensure stable operation of IoT devices.

[0041] System Integration Testing: After completing the individual debugging of each device, system integration testing is conducted. Simulating actual port business scenarios, the functional integrity and performance indicators of the entire system are tested. The normality of key distribution and encrypted data transmission between the quantum key distribution device and IoT devices is checked, as well as the effectiveness of the control center's management and control of IoT devices. Problems encountered during system integration testing are recorded and analyzed in detail, the causes of faults are investigated step by step, and the system is optimized and improved to ensure that it meets the actual needs of secure communication for the port's IoT.

[0042] Taking the communication between IoT devices in the cargo loading and unloading area of ​​a port and the control center as an example, this paper describes the specific processes of quantum key generation, transmission, screening, and negotiation.

[0043] 1. Key Generation: A quantum key distribution terminal (sender, Alice) deployed in the cargo loading and unloading area uses a quantum light source to generate a random bit sequence and encodes each bit into a specific quantum state. For example, using the BB84 protocol, Alice randomly selects a horizontal-vertical basis or a diagonal basis, encoding 0 bits as a horizontally polarized photon or a +45° polarized photon, and 1 bit as a vertically polarized photon or a -45° polarized photon, thereby generating a series of qubits carrying key information. The length of the qubit sequence generated by Alice is X bits to meet the needs of subsequent key screening and processing.

[0044] 2. Key Transmission: Alice transmits the generated qubit sequence to the quantum key distribution terminal (receiver, Bob) at the control center via a quantum channel (optical fiber). During transmission, the qubits are affected by factors such as transmission loss, quantum noise, and interference from the quantum channel. To overcome these problems, quantum repeater technology is used to divide the long-distance quantum channel into multiple short-distance segments. Quantum key distribution is performed within each segment, and then the keys from each segment are connected through entanglement swapping to achieve long-distance quantum key transmission. Simultaneously, quantum error-correcting codes are used to correct erroneous qubits during transmission, improving the quality of key transmission.

[0045] 3. Key Selection: After receiving the qubits, Bob randomly selects a measurement basis for measurement. Due to the properties of quantum measurement, if Bob chooses the same measurement basis as Alice used during encoding, the measurement result will match the bits sent by Alice; if the basis is different, the measurement result will be random. After the measurement is complete, Bob and Alice publicly communicate their chosen basis through a classical channel, but do not disclose the bit values. Then, they select the measurement results with the same basis, which constitute the original key. After selection, the original key is X bits long, which is reduced compared to the initially generated qubit sequence, but ensures key consistency.

[0046] 4. Key Negotiation: Due to noise in the quantum channel and potential eavesdropping, the original key may contain erroneous bits. To obtain the final secure quantum key, Bob and Alice need to negotiate the key. They use an error correction algorithm, such as the Cascade algorithm, to detect and correct errors in the original key. In the Cascade algorithm, the two parties gradually identify and correct erroneous bits in the original key through multiple interactions. After error correction, a privacy amplification algorithm, such as a universal hash function, is used to amplify the privacy of the corrected key, further improving its security, eliminating the potential risk of information leakage, and finally obtaining a secure quantum key of length X bits.

[0047] IoT device communication process 1. Communication Request Initiation: Taking a temperature and humidity sensor in a port warehouse as an example, when the sensor collects new temperature and humidity data, it initiates a communication request to the control center. The sensor first checks its own quantum key status to ensure it has a valid quantum key for data encryption. If the key has expired or does not exist, the sensor will request a new quantum key from the quantum key distribution device.

[0048] 2. Identity Authentication: When initiating a communication request, the sensor signs a message containing its own identity information and timestamp using its private key, and then sends the signed message along with its digital certificate to the control center. Upon receiving the message, the control center verifies the signature using the public key in the sensor's digital certificate, and checks the validity of the digital certificate and the timeliness of the timestamp. If the verification passes, the sensor's identity is confirmed as legitimate, and the sensor is allowed to communicate; if the verification fails, the sensor's access request is rejected, and the relevant security event is recorded.

[0049] 3. Data Encryption and Transmission: After successful authentication, the sensor uses the received quantum key to encrypt the collected temperature and humidity data using the AES symmetric encryption algorithm. The plaintext data is grouped according to the AES algorithm requirements, and each data group is then encrypted using the quantum key to generate ciphertext data. The encrypted ciphertext data is transmitted to the control center via a classical channel (such as a wired or wireless network within the port).

[0050] 4. Decryption and Verification: After receiving the encrypted data, the control center uses the quantum key shared with the sensors to decrypt the encrypted data according to the AES algorithm, recovering the original temperature and humidity data. Simultaneously, the control center verifies the integrity of the decrypted data, for example, by calculating the hash value of the data and comparing it with the hash value sent by the sender, ensuring that the data has not been tampered with during transmission. If the verification passes, the integrity and authenticity of the data are confirmed, and the data is further processed and stored; if the verification fails, the data is discarded, and the sensors are notified to retransmit.

[0051] Key management operations 1. Key Generation: The quantum key distribution device generates a quantum key according to a predetermined quantum key distribution protocol (such as the BB84 protocol). During generation, the properties of quantum states are used to generate a random bit sequence, and the key information is transmitted to the receiver through a quantum channel. The length of the generated quantum key is determined according to the actual application requirements to meet the requirements of different encryption algorithms and security levels.

[0052] 2. Key Storage: Quantum keys are stored using quantum storage devices, leveraging the stability and non-cloning properties of quantum states to ensure key security. To prevent key loss due to quantum storage device failure, a multi-copy storage and backup mechanism is employed. The quantum key is stored across multiple quantum storage devices, each storing an identical copy, and the key is backed up periodically. The backup key is stored offline on secure storage media, such as quantum-encrypted hard drives or magnetic tape, to prevent attacks and loss during online storage.

[0053] 3. Key Update: Key updates employ a combination of periodic and event-triggered updates. Periodic updates refer to the quantum key distribution device regenerating the quantum key at preset time intervals, such as every day at midnight [specific time], and distributing the new key to IoT devices and the control center. During the update process, the new key is first transmitted to the control center via a quantum channel. After verifying the key's validity, the control center distributes the key to each IoT device via a classical channel. Event-triggered updates refer to the system immediately triggering the quantum key update process when it detects a security event, such as a potential quantum key leak or a device authentication failure exceeding a certain threshold (e.g., X consecutive authentication failures). The system sends a key update request to the quantum key distribution device, which quickly generates a new quantum key and distributes it according to the above process to ensure system security.

[0054] 4. Key Destruction: When a quantum key expires or is no longer used, it needs to be securely destroyed. Utilizing the principle of quantum state collapse, the key stored in the quantum storage device is manipulated to cause its quantum state to collapse, thereby completely erasing the key information. During the destruction process, detailed records are kept, including the destruction time and the key identifier, for security auditing and traceability. Simultaneously, the quantum storage device storing the key is reset and initialized to ensure that no key information remains on the device.

[0055] System Testing and Optimization 1. Security Testing: Eavesdropping Detection Test: This test simulates a third party eavesdropping on a quantum channel, verifying the system's eavesdropping detection capabilities by detecting changes in the quantum state. Using specialized eavesdropping simulation equipment, interference signals are injected into the quantum channel, and the system's ability to detect eavesdropping activities promptly and issue an alarm is observed.

[0056] Data encryption strength testing: Attempts were made to decrypt the encrypted data to evaluate the strength of the encryption algorithm. Methods such as brute-force attacks and cryptanalysis were used to decrypt data encrypted with quantum key distribution. After extensive testing, it was found that the encrypted data could not be successfully cracked with current computing power, proving that the encryption strength of quantum key distribution combined with symmetric encryption algorithms (such as AES) can meet the requirements of secure communication for port IoT.

[0057] Identity authentication reliability testing: This test simulates a scenario where an unauthorized device impersonates a legitimate device to test the reliability of the identity authentication mechanism. The system is accessed by forging the device's digital certificate and signature.

[0058] 2. Performance Testing: Key generation rate test: This measures the rate at which a quantum key distribution device generates quantum keys per unit time. Under different environmental conditions and loads, a high-precision time measurement tool is used to record the time required for the quantum key distribution device to generate a key of a certain length, thereby calculating the key generation rate.

[0059] Data transmission latency test: This test measures the latency of data transmission between IoT devices and the control center. Specific data frames are sent from the IoT device, and the time difference between transmission and receipt at the control center is recorded. Multiple test results are analyzed to obtain the average data transmission latency.

[0060] System throughput test: This evaluates the amount of data the system can process per unit of time. By simulating a scenario where a large number of IoT devices simultaneously send data to the control center, the total amount of data successfully received and processed by the system within a certain period is measured, and the system throughput is calculated.

[0061] 3. Optimization measures: Based on the security test results: if vulnerabilities are found in the eavesdropping detection, the quantum key distribution protocol will be optimized by adding more eavesdropping detection mechanisms and quantum state verification steps; if the data encryption strength is insufficient, more advanced encryption algorithms or increasing the key length will be considered; if the reliability of identity authentication is not high, the generation and verification mechanism of digital certificates will be improved by adopting more complex signature algorithms and multi-factor authentication methods.

[0062] Based on the performance test results: if the key generation rate is low, optimize the hardware performance of the quantum key distribution equipment, such as upgrading the quantum light source and quantum detector, or improving the quantum key distribution algorithm; if the data transmission latency is large, optimize the network, increase network bandwidth, optimize the network topology, and adopt data caching and prefetching techniques; if the system throughput is insufficient, upgrade the server in the control center, increase the server's computing power and memory capacity, and adopt distributed computing and load balancing techniques to improve the system's processing capacity.

[0063] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A secure communication system for port IoT based on quantum key distribution, characterized in that: include: Quantum key distribution equipment for generating and distributing quantum keys, including quantum key distribution terminals and quantum channels; Internet of Things (IoT) devices, distributed throughout various areas of the port, are used to collect and transmit port operation-related data. They are connected to quantum key distribution devices via quantum and classical channels, and the collected data is encrypted using quantum keys. The control center is used to manage and control the entire system, including key management, device management, and communication management. It communicates with IoT devices and quantum key distribution devices through classical channels, receives encrypted data sent by IoT devices and decrypts it to obtain the original data, and can also send control commands to IoT devices. Communication networks include quantum channels and classical channels. Quantum channels are used to transmit quantum keys, while classical channels are used to transmit encrypted data and control information.

2. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: The quantum key distribution device uses a single-photon source as the light source to generate single photons carrying quantum information; a high-precision single-photon detector is used to accurately detect the quantum state of a single photon; and a quantum storage module is also included to store the quantum key, using a quantum state storage method to ensure the security of the key.

3. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: The encryption module in the IoT device uses the AES algorithm to encrypt the collected data; when calling the quantum key, a key indexing mechanism is used to quickly and accurately obtain the corresponding quantum key for encryption operation through the key index allocated by the quantum key distribution device.

4. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: The quantum key distribution method uses the BB84 protocol to implement quantum key distribution, and the specific steps are as follows: The sender randomly selects one of four quantum states to encode each bit, with each of the four quantum states corresponding to two different bases; The sender generates a series of random bit sequences and randomly selects a basis to encode each bit. Then, these encoded qubits are sent to the receiver through a quantum channel. When receiving a qubit, the receiver randomly selects a basis for measurement; After the quantum bit transmission is completed, the sender and receiver publicly exchange their chosen basis through a classical channel, but do not disclose the bit values. They then select the measurement results that have the same basis to form the original key. Error detection and correction are performed on the original key to obtain the final secure quantum key.

5. The port IoT secure communication system based on quantum key distribution according to claim 4, characterized in that: In the BB84 protocol, the measurement method for quantum states is as follows: the receiver uses a measurement device corresponding to the measurement basis to measure the qubit. If the measurement basis is the same as the basis used by the sender during encoding, the measurement result is consistent with the bit sent by the sender. The basis selection rule is as follows: the sender and the receiver each randomly select a horizontal-vertical basis or a diagonal basis as the measurement basis.

6. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: The specific process of the IoT device authentication method is as follows: When each IoT device connects to the system, it has a digital certificate issued by the control center. The digital certificate contains the device's identity information and public key. When communicating with the control center, the device first uses its private key to sign the message containing the device's identity information and timestamp, and then sends the signed message and digital certificate to the control center. After receiving the message, the control center uses the public key in the device's digital certificate to verify the signature, and checks the validity of the digital certificate and the timeliness of the timestamp. If the verification passes, the device's identity is confirmed as legitimate, and the device is allowed to communicate and access the corresponding resources; if the verification fails, the device's access request is rejected.

7. The port IoT secure communication system based on quantum key distribution according to claim 6, characterized in that: During the identity authentication process, quantum signature technology is used to sign the messages sent by the device. Quantum signatures are generated based on quantum keys and are unforgeable. At the same time, timestamp technology is used to ensure the timeliness of the messages. The timestamps are generated by an authoritative time server and are attached to the messages when they are sent by the device.

8. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: The key management includes: The key storage module uses quantum storage devices to store quantum keys, utilizing the properties of quantum states to store keys and ensure key security. It also employs a multi-copy storage and backup mechanism, storing keys in multiple quantum storage devices and backing them up periodically. The key update module employs a combination of periodic updates and event-triggered updates. Periodic updates involve the quantum key distribution device regenerating the quantum key at preset time intervals and distributing the new key to IoT devices and the control center. Event-triggered updates are triggered immediately when the system detects a security event, such as a potential leakage of the quantum key or a device authentication failure exceeding a certain threshold. The key synchronization module is used to ensure key synchronization between multiple IoT devices and the control center. When the quantum key distribution device generates a new key, it first sends the key to the control center. After the control center verifies the validity of the key, it distributes the key to each IoT device through broadcast. After receiving the key, the IoT device verifies and stores it. If the verification fails, it requests the control center to resend the key. At the same time, the IoT devices and the control center periodically synchronize and check the key status.

9. The port IoT secure communication system based on quantum key distribution according to claim 8, characterized in that: The key storage module employs quantum encryption to encrypt and store the key, preventing it from being stolen during storage. The storage medium uses a quantum storage medium with high stability and anti-interference capabilities, such as a quantum hard disk, to ensure the security and reliability of key storage.

10. The port IoT secure communication system based on quantum key distribution according to claim 1, characterized in that: Regarding the integration of the secure communication system with the existing port business system, middleware is used for interfacing. The middleware is responsible for parsing and converting the data format and communication protocol between the secure communication system and the existing business system to achieve seamless data transmission and interaction. In terms of network infrastructure, the existing fiber optic network of the port is fully utilized as the transmission medium for quantum and classical channels. Existing network equipment, such as switches and routers, are upgraded with firmware or security modules to support quantum key distribution and encrypted communication functions.