Secret communication method and device, related equipment, storage medium and computer program product

By adopting a two-level service platform separation architecture in the quantum secure communication system, the problem of poor scalability of quantum cryptography service center business applications is solved, enabling plug-and-play secure communication and services across domains/offices, and improving the system's scalability and compatibility.

CN121907435APending Publication Date: 2026-04-21CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2025-09-12
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In the existing quantum secure communication system architecture, the business application scalability of the quantum cryptography service center is not strong, making it difficult to adapt to the future development needs of diversified business and massive user base. Furthermore, the functions of each network element, the key management system, and the business processing flow are unclear.

Method used

The system architecture of "separation of management and service" is achieved by adopting a two-level service platform (first entity and second entity). The first-level quantum cryptography service platform focuses on key management and cryptographic services, while the second entity focuses on business services. It realizes secure communication across domains/offices through encrypted and/or integrity-protected session keys, and supports plug-and-play and rapid deployment.

Benefits of technology

It improves the system's scalability and compatibility, avoids the uneven security levels caused by differences in security capabilities among different vendors, and enables flexible adaptation and rapid deployment of business applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907435A_ABST
    Figure CN121907435A_ABST
Patent Text Reader

Abstract

The invention discloses a secret communication method and device, related equipment, a storage medium and a computer program product, and the method comprises the steps that a first entity sends a first request to a second entity serving first application equipment, the first request is used for obtaining a session key, and the session key is sent to the second entity; the session key is used for secret communication between the first application device and a second application device, and a second entity serving the first application device is different from a second entity serving the second application device; and / or receiving a first response sent by the second entity serving the first application device, the first response carrying the encrypted and / or integrity protected session key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a secure communication method, apparatus, related equipment, storage medium, and computer program product. Background Technology

[0002] The related technology provides a quantum secure communication system architecture that can effectively integrate classical communication systems with quantum communication systems, providing support for the development of secure communication services based on quantum information security technology. However, it suffers from the problem of weak scalability of business applications in the quantum cryptography service center within the quantum secure communication system architecture. Summary of the Invention

[0003] To address the related technical issues, embodiments of this application provide a secure communication method, apparatus, related equipment, storage medium, and computer program product.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides a secure communication method applied to a first entity, the method comprising:

[0006] A first request is sent to a second entity that serves the first application device. The first request is used to obtain a session key, which is used for secure communication between the first application device and the second application device. The second entity that serves the first application device is different from the second entity that serves the second application device.

[0007] And / or, receive a first response from the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0008] This application embodiment also provides a secure communication method applied to a second entity serving a first application device, the method comprising:

[0009] The system receives a first request from a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; the second entity serving the first application device is different from the second entity serving the second application device.

[0010] And / or, send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

[0011] This application embodiment also provides a secure communication method, applied to a second entity serving a second application device, the method comprising:

[0012] Receive a fourth request sent by the first entity, the fourth request carrying a session key identifier;

[0013] And / or, return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

[0014] This application embodiment also provides a secure communication method applied to a first application device, the method comprising:

[0015] Send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device;

[0016] And / or, receive a second response from the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0017] This application embodiment also provides a secure communication method, characterized in that it is applied to a second application device, the method comprising:

[0018] Send a third request to the first entity, the third request carrying the first identifier;

[0019] And / or, receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0020] This application also provides a secure communication device, including:

[0021] The first transceiver unit is configured to send a first request to a second entity serving a first application device, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, the second entity serving the first application device being different from the second entity serving the second application device; and / or, to receive a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0022] This application also provides a secure communication device, including:

[0023] The second transceiver unit is configured to receive a first request sent by a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, wherein the second entity serving the first application device is different from the second entity serving the second application device; and / or, to send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

[0024] This application also provides a secure communication device, including:

[0025] The third transceiver unit is configured to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or to return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

[0026] This application also provides a secure communication device, including:

[0027] The fourth transceiver unit is configured to send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; and / or to receive a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0028] This application also provides a secure communication device, including:

[0029] The fifth transceiver unit is configured to send a third request to the first entity, the third request carrying a first identifier; and / or to receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0030] This application embodiment also provides a first entity, including: a first processor and a first communication interface; wherein,

[0031] The first communication interface is configured to send a first request to a second entity serving the first application device, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, the second entity serving the first application device being different from the second entity serving the second application device; and / or, to receive a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0032] This application also provides a second entity serving a first application device, including: a second processor and a second communication interface; wherein...

[0033] The second communication interface is configured to receive a first request sent by a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, wherein the second entity serving the first application device is different from the second entity serving the second application device; and / or, to send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

[0034] This application also provides a second entity for serving a second application device, including: a third processor and a third communication interface; wherein...

[0035] The third communication interface is used to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or to return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

[0036] This application embodiment also provides a first application device, including: a fourth processor and a fourth communication interface; wherein,

[0037] The fourth communication interface is used to send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; and / or, to receive a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0038] This application embodiment also provides a second application device, including: a fifth processor and a fifth communication interface; wherein,

[0039] The fifth communication interface is used to send a third request to the first entity, the third request carrying a first identifier; and / or to receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0040] This application also provides a communication device, characterized in that the communication device includes a first entity, a second entity serving a first application device, a second entity serving a second application device, the first application device, or the second application device, and the communication device includes a processor and a memory for storing computer programs capable of running on the processor.

[0041] When the processor runs the computer program, it executes the steps of any method on the first entity side, or executes the steps of any method on the second entity side serving the first application device, or executes the steps of any method on the second entity side serving the second application device, or executes the steps of any method on the first application device side, or executes the steps of any method on the second application device side.

[0042] This application embodiment also provides a storage medium storing a computer program thereon, wherein when the computer program is executed by a processor, it implements the steps of any method on the first entity side, or implements the steps of any method on the second entity side serving a first application device, or implements the steps of any method on the second entity side serving a second application device, or implements the steps of any method on the first application device side, or implements the steps of any method on the second application device side.

[0043] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the methods described above.

[0044] In the secure communication method, apparatus, related equipment, storage medium, and computer program products provided in this application embodiment, the first application device obtains the encrypted and / or integrity-protected session key from the second entity serving the first application device through the first entity, and the second application device obtains the encrypted and / or integrity-protected session key from the second entity serving the second application device through the first entity. This allows the first and second application devices to obtain the session key from the encrypted and / or integrity-protected session key and realize secure communication across domains / offices based on the session key. Since the above scheme adopts a two-level service platform (first entity, second entity) to achieve a "separation of management and service" system architecture, the second entity focuses on key management and cryptographic services, unifying cryptographic security service capabilities and avoiding inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. The first entity focuses on business services, allowing for the deployment of a dedicated first entity for each different secure communication application, interfacing and adapting with the secure communication application to achieve plug-and-play functionality and rapid deployment. Therefore, the system architecture provided in this embodiment has better scalability and compatibility, effectively solving the problems of weak scalability, difficult integration, and inflexible adaptation support of existing quantum cryptographic service center business applications. Attached Figure Description

[0045] Figure 1 This is an example diagram of a quantum secure communication system architecture related to the technology.

[0046] Figure 2 This is a schematic diagram of a quantum secure communication system architecture according to an embodiment of this application;

[0047] Figure 3 This is an example diagram of a key system applicable to the quantum secure communication system of this application embodiment;

[0048] Figure 4 This application scenario illustrates a quantum secure communication system.

[0049] Figure 5This is a schematic diagram of a quantum secure communication service processing flow according to an embodiment of this application;

[0050] Figure 6 This is a schematic diagram illustrating a process for obtaining the identifier of a primary quantum cryptography service platform according to an embodiment of this application;

[0051] Figure 7 This is a schematic flowchart of a secure communication method according to an embodiment of this application;

[0052] Figure 8 This is a schematic flowchart of another secure communication method according to an embodiment of this application;

[0053] Figure 9 This is a schematic flowchart of another secure communication method according to an embodiment of this application;

[0054] Figure 10 This is a schematic diagram of another secure communication method according to an embodiment of this application;

[0055] Figure 11 This is a schematic flowchart of another secure communication method according to an embodiment of this application;

[0056] Figure 12 This is a schematic diagram of a secure communication device according to an embodiment of this application;

[0057] Figure 13 This is a schematic diagram of another secure communication device according to an embodiment of this application;

[0058] Figure 14 This is a schematic diagram of another secure communication device according to an embodiment of this application;

[0059] Figure 15 This is a schematic diagram of another secure communication device according to an embodiment of this application;

[0060] Figure 16 This is a schematic diagram of another secure communication device according to an embodiment of this application;

[0061] Figure 17 This is a schematic diagram of the first entity structure according to an embodiment of this application;

[0062] Figure 18 This is a schematic diagram of the second entity structure serving the first application device in an embodiment of this application;

[0063] Figure 19 This is a schematic diagram of the second entity structure serving the second application device in an embodiment of this application;

[0064] Figure 20 This is a schematic diagram of the structure of the first application device according to an embodiment of this application;

[0065] Figure 21This is a schematic diagram of the structure of the second application device in the embodiment of this application. Detailed Implementation

[0066] To meet the diverse business and large-scale user needs for quantum key distribution in the future, related technologies provide a quantum secure communication system architecture that can effectively integrate classical and quantum communication systems, supporting the development of secure communication services based on quantum information security technology. For example... Figure 1 The system architecture shown adds a quantum cryptography service network (layer) in the middle. It separates the originally tightly coupled quantum key distribution (QKD) quantum network (layer) and quantum cryptography application (layer), reducing the coupling between the two and thus avoiding the huge business pressure on the quantum QKD network caused by access from a large number of upper-layer applications.

[0067] The Quantum Cryptography Service Center is the core entity of the quantum cryptography service (layer). To the south, it connects to the quantum QKD network via the Ak interface to obtain symmetric keys generated by the QKD network, or it connects to a quantum random number generator (QRNG) to obtain quantum random numbers. To the north, it connects to various business applications of the quantum cryptography application (layer) via the As interface, providing the quantum cryptography service center with quantum keys (including those distributed by the QKD network and those generated based on quantum random numbers) on demand. This centralized deployment of the quantum cryptography service center enables unified management of quantum keys, meeting the application needs of various secure communication applications (such as encrypted audio / video calls, encrypted conferencing, encrypted SMS / instant messaging, encrypted intercom, encrypted email, encrypted cloud storage, encrypted leased lines, etc.) and improving the system's business capacity.

[0068] The overall architecture provided by the relevant technical solutions is universal, and the quantum cryptography service center can be adapted to different communication applications. It can provide quantum keys for communication applications according to the specific application business processing mechanism and interface requirements, thereby realizing quantum empowerment and forming quantum secure communication applications.

[0069] However, in actual deployment and application of the system, it has been found that the quantum cryptography service center in related technical solutions typically deploys a single quantum cryptography service platform centrally. This requires the quantum cryptography service platform to be compatible with various communication applications (such as encrypted audio / video calls, encrypted conferencing, encrypted SMS / instant messaging, encrypted intercom, encrypted email, encrypted cloud storage, encrypted dedicated lines, etc.), thus limiting the system's scalability. When the number or variety of applications (different types of applications) is small, a single quantum cryptography service platform can still support it. However, when the number or variety of applications is large, the quantum cryptography service platform needs to interface with many different upper-layer applications and adapt to various different business applications. This significantly increases the implementation complexity and workload of the quantum cryptography service center, making the system cumbersome, detrimental to the operation and maintenance of the service center, and also hindering the adaptation and expansion of more new business applications.

[0070] In summary, while the quantum secure communication system architecture provided by the relevant technologies can meet the needs of quantum secure communication applications with a limited number of business applications and users, it cannot meet the future development needs of diversified businesses and a massive number of users. Furthermore, the scalability of quantum cryptography service center business applications is weak. In addition, the functions of each network element, the key management system, the business processing flow, and the system operation mechanism in the existing architecture are still unclear, requiring specific technical solutions for implementing quantum secure communication applications.

[0071] Based on this, in various embodiments of this application, the first application device obtains the encrypted and / or integrity-protected session key from the second entity serving the first application device through the first entity, and the second application device obtains the encrypted and / or integrity-protected session key from the second entity serving the second application device through the first entity. This allows the first and second application devices to obtain the session key from the encrypted and / or integrity-protected session key and realize secure communication across domains / offices based on the session key. Since the above scheme adopts a two-level service platform (first entity, second entity) to achieve a "separation of management and service" system architecture, the second entity focuses on key management and cryptographic services, unifying cryptographic security service capabilities and avoiding inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. The first entity focuses on business services, allowing for the deployment of a dedicated first entity for each different secure communication application, enabling plug-and-play functionality and rapid deployment. Therefore, the system architecture provided in this embodiment has better scalability and compatibility, effectively solving the problems of weak scalability, difficult integration, and inflexible adaptation support of existing quantum cryptographic service center business applications.

[0072] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0073] To address the issue of limited scalability of quantum cryptography service center applications in quantum secure communication system architectures, this application proposes a modular design for the quantum cryptography service center, resulting in the following system architecture: Figure 2 As shown.

[0074] Unlike related technologies, the core network element / core network function or entity—the quantum cryptography service platform—in this application's quantum cryptography service center is divided into two levels: a primary quantum cryptography service platform and a secondary quantum cryptography service platform. This achieves "separation of management and service," addressing the shortcomings of existing solutions in terms of flexibility, scalability, and security. The primary quantum cryptography service platform focuses on key management and cryptographic services, unifying cryptographic security service capabilities and avoiding inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. The secondary quantum cryptography service platform focuses on business services, allowing for the deployment of dedicated secondary quantum cryptography service platforms for each different quantum secure communication application. It integrates and adapts with applications, enabling plug-and-play functionality and rapid deployment.

[0075] like Figure 2 As shown, the quantum secure communication system architecture includes a quantum cryptography management center, a quantum cryptography service center, quantum secure communication application equipment, and at least two QKD nodes. The quantum cryptography management center includes an operation and management platform. The quantum cryptography service center includes a primary quantum cryptography service platform, a secondary quantum cryptography service platform, a quantum random number generator (QRNG), and a quantum key offline filling platform. The quantum secure communication application equipment includes cryptographic applications, cryptographic middleware, and cryptographic modules. At least two QKD nodes form a QKD network. Each of these will be explained in detail below.

[0076] 1. Quantum Cryptography Service Center

[0077] The Quantum Cryptography Service Center is a platform system deployed on the network side. Its core function is the full lifecycle management of Quantum Entropy Source keys, and it utilizes these managed keys to provide cryptographic service support for upper-layer applications. The Quantum Cryptography Service Center consists of a primary quantum cryptography service platform, a secondary quantum cryptography service platform, a quantum key offline filling platform, and a QRNG (Quantum Entropy Source Group).

[0078] Quantum entropy source keys are keys derived from the principles of quantum mechanics. These keys include quantum keys and quantum random number keys, and theoretically possess true randomness, used for encryption and security authentication of classical information. The Quantum Cryptography Service Center connects to the QKD network via the Ak interface to obtain and manage the quantum keys generated by the QKD network, and connects to QRNG via the Ar interface to obtain and manage keys generated based on quantum random numbers.

[0079] To enhance the multi-service expansion capabilities of the quantum cryptography service center, the quantum key management function consists of a two-tier platform. The first-tier quantum cryptography service platform (also known as the first-level quantum cryptography service platform, key management platform, cryptography service platform, etc.) is the network element / network function / entity responsible for general key management, cryptographic business processing, and providing cryptographic security services. It also injects and manages cryptographic modules, supports interfacing with multiple second-tier quantum cryptography service platforms, and provides unified basic key management and cryptographic security services to different second-tier platforms. The first-tier quantum cryptography service platform accesses the QKD network through the Ak interface and obtains quantum keys from QKD nodes. The first-tier quantum cryptography service platform establishes a quantum key resource pool, storing and maintaining quantum keys obtained from the QKD network and shared with another first-tier quantum cryptography service platform.

[0080] The quantum cryptography service secondary platform (also known as the secondary quantum cryptography service platform, business service platform, application service platform, etc.) is responsible for interfacing with quantum secure communication business applications, providing cryptographic security services for different types of business applications, different categories of business applications, or business applications operated by different entities, thereby supporting the flexible adaptation of quantum, cryptography, and communication services. Simultaneously, the quantum cryptography service secondary platform may also have certain session key management capabilities. Different types of business applications include encrypted audio / video calls, encrypted conferencing, encrypted SMS / instant messaging, encrypted intercom, encrypted email, encrypted cloud storage, encrypted leased lines, etc. Different categories of business applications include real-time secure communication applications and non-real-time secure communication applications. Business applications operated by different entities include the same secure communication application provided by different telecom operators.

[0081] The quantum key offline injection platform pre-injects a certain number of quantum entropy source keys into the cryptographic module of a quantum secure communication application device offline under a physically secure environment. These quantum entropy source keys include quantum keys and quantum random number keys. When injecting quantum random number keys, these keys are provided by the quantum cryptography service primary platform via the Af interface. When injecting quantum keys, both the quantum cryptography service primary platform and the quantum key offline injection platform obtain quantum keys from the QKD nodes via the Ak interface. These obtained quantum keys are symmetric keys distributed by the two nodes (two QKD nodes) through the QKD network. Through offline injection, the quantum cryptography service primary platform and the cryptographic module configure several symmetric keys, each establishing a shared symmetric key resource pool locally.

[0082] The platform in this application may also be referred to as an entity, device, function, unit, component, module, etc. For example, the quantum cryptography service secondary platform may be referred to as the first entity, the quantum cryptography service primary platform may be referred to as the second entity, and the operation and management platform may be referred to as the third entity.

[0083] QRNG is a device that generates random numbers based on the principles of quantum mechanics. It can provide quantum random numbers to a quantum cryptography service platform via an Ar interface. The quantum cryptography service platform can generate quantum random number keys based on quantum random numbers.

[0084] 2. Quantum secure communication application equipment (also known as application equipment)

[0085] Quantum secure communication application equipment is a network device or terminal device that includes cryptographic applications (also known as cryptographic applications), cryptographic middleware, cryptographic modules, etc., to realize quantum secure communication applications.

[0086] Cryptographic applications are software and hardware modules on a device that implement secure communication functions, and they call cryptographic services based on quantum entropy source keys through cryptographic middleware.

[0087] Cryptographic middleware is software that sits between cryptographic applications and cryptographic modules to provide cryptographic services. It is compatible with various types of cryptographic modules and provides a unified cryptographic service interface for cryptographic applications. Cryptographic services include, but are not limited to, encryption / decryption, security authentication, and key management.

[0088] The cryptographic module possesses cryptographic computation capabilities and stores pre-filled quantum entropy source keys. It can take various media forms, including hardware (such as U-shields, USB-Keys, cryptographic cards, Subscriber Identity Modules (SIMs), security chips, etc.) and software. The quantum cryptography service platform manages the cryptographic module online through cryptographic middleware.

[0089] 3. Quantum Cryptography Management Center

[0090] The quantum cryptography management center (also known as the quantum cryptography service management center, etc.) consists of network elements such as the operation and management platform (also known as the third entity). The operation and management platform is responsible for the management, operation, and monitoring of quantum secure communication services subscribed by users. Specifically, it can manage the binding and mapping relationships of information such as users, equipment, cryptographic modules, services, the primary quantum cryptography service platform to which they belong, and the secondary quantum cryptography service platform providing the service.

[0091] Corresponding to Figure 2 The quantum secure communication system shown, Figure 3 The key system related to this application is given below, and the key system will be explained in detail below.

[0092] In the quantum secure communication system provided in this embodiment, there can be many quantum service base keys (QSBKs) (e.g., tens of thousands or hundreds of thousands of QSBKs). Therefore, a quantum service base key resource pool, i.e., a QSBK resource pool, is formed between the quantum cryptographic service primary platform and the cryptographic module. The QSBKs in the QSBK resource pool, as well as the quantum session key protection keys (QSKPKs) derived from them, are all single-use and destroyed after use. This ensures frequent key changes within the system, increasing the difficulty of cracking the system and improving overall system security.

[0093] In the quantum secure communication system provided in this application, the primary quantum cryptography service platform can obtain quantum keys from the quantum key distribution (QKD) network. Therefore, the source and destination primary quantum cryptography service platforms can obtain quantum keys securely distributed based on quantum physics principles from the source and destination QKD nodes, respectively. These primary quantum cryptography service platforms form a quantum key (QK) resource pool. The quantum keys in the quantum key resource pool can be further distributed to quantum secure communication application devices according to business needs, enabling secure communication between the source and destination quantum secure communication application devices.

[0094] QSBK: A pool of quantum entropy source keys shared between the primary quantum cryptography service platform and the cryptographic modules of quantum secure communication application equipment. These keys are pre-configured and securely stored within the cryptographic modules through offline, online, or other injection methods, forming a QSBK resource pool. This pool can be used to derive various other keys, such as the quantum session key protection key QSKPK. QSBKs are for one-time use and are destroyed after use.

[0095] Quantum Session Key Protection Key (QSKPK): A key shared between the primary quantum cryptography service platform and the cryptographic modules of quantum secure communication application devices, comprising the encryption protection key QSKPKenc and the integrity protection key QSKPKint. QSKPKenc and QSKPKint can be directly derived from QSBK. Figure 3 (Demonstration), it is also possible to derive the intermediate key QSKPK based on QSBK, and then derive (from QSKPK) Figure 3 (Not shown) These are used to encrypt and protect the integrity of sensitive information such as the quantum service session key (QSSK). QSKPKenc and QSKPKint are for single use only and are destroyed after use.

[0096] Quantum Service Session Key (QSSK): A session key used for secure communication between devices in quantum-secure communication applications. Depending on the specific application needs, the QSSK can be further used to derive encryption protection keys (QSSKenc) and integrity protection keys (QSSKint). Depending on the communication scenario (local / cross-domain, intra-office / inter-office), the QSSK is generated based on quantum keys or quantum random number keys and is used to encrypt and / or protect the integrity of information exchanged between user devices. The QSSK, or its derivatives QSSKenc and QSSKint, is for one-time use and is destroyed after the session ends.

[0097] Figure 4 This application provides a practical deployment scenario for a quantum secure communication system, which can be a network deployment scenario of multiple quantum cryptography service centers. The example uses two quantum cryptography service centers; the same principle applies to a network of multiple quantum cryptography service centers.

[0098] exist Figure 4 In the scenario shown, quantum cryptography service center A and quantum cryptography service center B's primary quantum cryptography service platforms communicate with each other via the Am0 interface, forming a quantum cryptography service network. The secondary quantum cryptography service platform is centrally deployed within the quantum cryptography service network and interfaces with each primary quantum cryptography service platform within the network via the Am2 interface, providing cryptographic services to all quantum secure communication application devices across the network to realize a specific quantum secure communication application. In this case, the secondary quantum cryptography service platform can belong to either quantum cryptography service center A or quantum cryptography service center B.

[0099] Figure 4 It supports two quantum secure communication scenarios: local / intra-regional and cross-regional / inter-regional. Local (i.e., intra-regional) communication refers to secure communication between source and destination quantum secure communication application devices belonging to the same quantum cryptography service center. In this scenario, the quantum service base key (QSBK) stored in the cryptographic modules of both the source and destination quantum secure communication application devices is filled by the same primary quantum cryptography service platform, and both devices are remotely managed by the same primary quantum cryptography service platform.

[0100] Cross-domain (i.e., inter-site) communication refers to secure communication between source-end quantum secure communication application devices and destination-end quantum secure communication application devices belonging to different quantum cryptography service centers. In this scenario, the quantum service foundation key (QSBK) stored in the cryptographic modules of the source-end and destination-end application devices is filled by different quantum cryptography service primary platforms, and the source-end and destination-end application devices are remotely managed by these different quantum cryptography service primary platforms.

[0101] against Figure 4 The application scenarios shown in this application are examples of this application. Figure 5 A service processing flow for quantum secure communication is presented to achieve secure communication across domains / inter-offices.

[0102] in, Figure 5 The process shown can securely distribute QSSKs to quantum secure communication application devices belonging to different quantum cryptography service centers, enabling them to use the QKD network to distribute quantum keys and achieve secure cross-domain (i.e., inter-center) communication.

[0103] Here, we assume that quantum secure communication application device A under quantum cryptography service center A is the communication source (O, Original), i.e., the source quantum secure communication application device (O); and quantum secure communication application device B under quantum cryptography service center B is the communication destination (T, Terminated), i.e., the destination quantum secure communication application device (T). Quantum cryptography service primary platform A can be understood as the source quantum cryptography service primary platform, and quantum cryptography service primary platform B can be understood as the destination quantum cryptography service primary platform.

[0104] like Figure 5 As shown, the service processing flow of quantum secure communication includes the following steps:

[0105] Step 1: The source quantum secure communication application device (O) sends a communication request to the destination quantum secure communication application device (T).

[0106] Here, when a cryptographic application on the source-end quantum secure communication application device (O) initiates a quantum secure communication service, it can first send a communication request to the cryptographic application on the destination-end quantum secure communication application device (T) to request the establishment of a communication connection, thereby establishing the quantum secure communication service. This communication request can be called a communication request message, and the quantum secure communication service can be simply referred to as the secure communication service. The communication request can carry the identification information QCSL1ID(O) of the quantum cryptographic service level 1 platform to which the source-end quantum secure communication application device (O) belongs. QCSL1 refers to the quantum cryptographic service level 1 platform; ID is the identifier. For example, if the source-end quantum secure communication application device (O) is quantum secure communication application device A, the communication request can carry the identification information QCSL1 ID(O) of the quantum cryptographic service level 1 platform A. The quantum cryptographic service level 1 platform A can provide services to the source-end quantum secure communication application device (O).

[0107] Step 2: After receiving the communication request, the destination quantum secure communication application device (T) returns a communication response to the source quantum secure communication application device (O).

[0108] Here, after receiving a communication request, the cryptographic application on the destination quantum secure communication application device (T) returns a communication response to the cryptographic application on the source quantum secure communication application device (O). This communication response can be called a communication response message. The communication response may carry the identification information QCSL1 ID(T) of the quantum cryptography service primary platform to which the destination quantum secure communication application device (T) belongs. For example, if the destination quantum secure communication application device (T) is quantum secure communication application device B, the communication response may carry the identification information QCSL1 ID(T) of the quantum cryptography service primary platform B. The quantum cryptography service primary platform B can provide services to the destination quantum secure communication application device (T).

[0109] Step 3: The cryptographic middleware of the source quantum secure communication application device (O) allocates available QSBK(O) for the cryptographic application of the source quantum secure communication application device (O), obtains QSBK ID(O), and generates or derives QSKPKenc(O) and QSKPKint(O) based on QSBK(O).

[0110] Here, QSBK(O) can be understood as the root key, and QSKPKenc(O) and QSKPKint(O) can be called quantum session key protection keys. QSKPKenc(O) stands for Quantum Session Key Public Key (Encryption), derived from QSBK(O) using a quantum-resistant algorithm, and is the session public key used for encryption. QSKPKint(O) stands for Quantum Session Key Public Key (Integration), derived from QSBK(O) using a hash function, and is the session public key used for integrity verification.

[0111] Step 4: The cryptographic application of the source quantum secure communication application device (O) sends a quantum service session key request to the quantum cryptographic service secondary platform.

[0112] Here, the quantum service session key request is used to obtain the quantum service session key (QSSK) required for this quantum secure communication. The quantum service session key request carries information such as the source service ID, the destination service ID, and the QSSK ID (O). Optionally, it may also carry the QCSL1 ID (O) and QCSL1 ID (T). The quantum service session key request can be referred to as a quantum service session key request message.

[0113] The source service ID can be understood as the service ID of the cryptographic application of the source quantum secure communication application device (O), and the destination service ID can be understood as the service ID of the cryptographic application of the destination quantum secure communication application device (T).

[0114] Step 5: After receiving the quantum service session key request, the quantum cryptography service secondary platform assigns a transaction ID to the request (the quantum service session key request), and determines whether the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same service domain based on whether the QCSL1 ID(O) and QCSL1 ID(T) are the same.

[0115] Here, the quantum cryptography service secondary platform determines whether the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same service domain based on whether QCSL1 ID(O) and QCSL1 ID(T) are the same. This includes: the quantum cryptography service secondary platform determining whether QCSL1 ID(O) and QCSL1 ID(T) are the same; if QCSL1 ID(O) and QCSL1 ID(T) are the same, it indicates that the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same service domain, that is, the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same quantum cryptography service primary platform; if QCSL1 ID(O) and QCSL1 ID(T) are different, it indicates that the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to different service domains, that is, the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to different quantum cryptography service primary platforms.

[0116] The quantum cryptography service secondary platform can obtain the QCSL1 ID(O) and QCSL1 ID(T) from the quantum service session key request, or obtain them through local query or querying the operation management platform using the source service ID and destination service ID carried in the quantum service session key request. Specifically, the source service ID can be used to obtain the QCSL1 ID(O) through local query or querying the operation management platform; the destination service ID can be used to obtain the QCSL1 ID(T) through local query or querying the operation management platform.

[0117] Step 6: If the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to different service domains, then proceed to Step 7 to initiate the cross-domain distribution process of the quantum service session key; if the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same service domain, then proceed to the local domain distribution process.

[0118] Step 7: The quantum cryptography service secondary platform sends a key request to the quantum cryptography service primary platform (O).

[0119] Here, the quantum cryptography service level one platform (O) refers to the quantum cryptography service level one platform to which the source-end quantum secure communication application device (O) belongs. The key request carries information such as the QSBK ID ​​(O), key type, and QCSL1 ID (T). The key type indicates that the request is for a quantum key, which will be used as a session key. The key request may also carry key-related information, such as the QSSK's lifetime. The key request can be called a key request message.

[0120] Step 8: The quantum cryptography service primary platform (O) queries the quantum key resource pool shared with the quantum cryptography service primary platform (T) based on the QCSL1 ID (T), allocates an available quantum key QK for this request (the key request), obtains the QKID (QKID is the identifier of the quantum key QK), and sets the status of the QK to "used".

[0121] Optionally, in step 9: the quantum cryptography service primary platform (O) can send a quantum key synchronization request to the quantum cryptography service primary platform (T) to synchronize and update the state of the quantum key QK in the resource pool.

[0122] Here, the quantum cryptography service level one platform (T) refers to the quantum cryptography service level one platform to which the destination quantum secure communication application device (T) belongs. The quantum key synchronization request carries information such as QCSL1 ID (O), QCSL1 ID (T), and key status. The quantum key synchronization request is used to synchronize and update the status of the quantum key QK in the resource pool to the quantum cryptography service level one platform (T). The key status indicates that the state of the quantum key QK corresponding to QKID is "used". The quantum key synchronization request can be referred to as a quantum key synchronization request message.

[0123] Optionally, in step 10: The quantum cryptography service primary platform (T) returns a quantum key synchronization response to the quantum cryptography service primary platform (O) to confirm the synchronization result of the quantum key. The quantum key synchronization response carries information such as QCSL1 ID (O), QCSL1 ID (T), and synchronization result. The quantum key synchronization response can also be called a quantum key synchronization response message.

[0124] Step 11: The quantum cryptography service primary platform (O) retrieves QSBK(O) based on QSBK ID(O), and generates QSKPKenc(O) and QSKPKint(O) based on QSBK(O).

[0125] Step 12: The quantum cryptography service primary platform (O) uses the allocated QK as QSSK and employs QSKPK. enc (O) and QSKPK int (O) Encrypt and protect the integrity of the QSSK and related key information. Key-related information includes, for example, the lifespan of the QSSK.

[0126] Step 13: The quantum cryptography service primary platform (O) returns a key response to the quantum cryptography service secondary platform. The key response carries the QSBK ID ​​(O), QKID, the protected QSSK, and key-related information. The key response is also called the key response message.

[0127] The protected QSSK can be understood as a QSSK with both encryption and integrity protection.

[0128] Step 14: The quantum cryptography service secondary platform associates the QKID with the transaction ID of this request (quantum service session key request) and returns the quantum service session key response to the source quantum secure communication application device (O).

[0129] Here, the quantum service session key response carries information such as the source service ID, destination service ID, QSBK ID(O), protected QSSK and key-related information, and transaction ID. The quantum service session key response is also called the quantum service session key response message.

[0130] Step 15: The cryptographic middleware of the source-end quantum secure communication application device (O) verifies the integrity of the QSSK and key-related information based on QSKPKint(O). After the integrity verification is successful, it uses QSKPKenc(O) to decrypt and obtain the QSSK and key-related information, and then securely stores the QSSK.

[0131] Step 16: The cryptographic application of the source quantum secure communication application device (O) sends a quantum service session key notification to the destination quantum secure communication application device (T). The quantum service session key notification carries information such as the source service ID, the destination service ID, and the transaction ID. The quantum service session key notification is also called a quantum service session key notification message.

[0132] Step 17: After receiving the quantum service session key notification, the cryptographic middleware of the destination quantum secure communication application device (T) allocates an available QSBK(T) for the cryptographic application of the destination quantum secure communication application device (T), obtains QSBKID(T), and generates QSKPKenc(T) and QSKPKint(T) based on QSBK(T).

[0133] Step 18: The cryptographic application of the destination quantum secure communication application device (T) sends a quantum service session key request to the quantum cryptographic service secondary platform to obtain the quantum service session key QSSK allocated for this quantum secure communication.

[0134] The quantum service session key request carries information such as the source service ID, destination service ID, QSBK ID(T), and transaction ID. The quantum service session key request is also known as the quantum service session key request message.

[0135] Step 19: The secondary quantum cryptography service platform determines whether the QSSK is distributed within the local domain or across domains based on the transaction ID. In the case of cross-domain distribution, the secondary quantum cryptography service platform obtains the QKID based on the transaction ID and sends a key request to the primary quantum cryptography service platform (T). The key request carries information such as the QSSK ID(T), QKID, and key type. The key type specifies the QKID of the requested quantum key, which will be used as the session key. The key request may also carry key-related information, such as the QSSK's lifetime. The key request is also called a key request message.

[0136] Step 20: The quantum cryptography service platform (T) retrieves the quantum key QK based on the QKID.

[0137] Step 21: The quantum cryptography service platform (T) retrieves QSBK(T) based on QSBKID(T), and generates QSKPKenc(T) and QSKPKint(T) based on QSBK(T).

[0138] Step 22: The quantum cryptography service platform (T) uses QK as the QSSK (at this point, QKID is used as the session key identifier) ​​and uses QSKPKenc(T) and QSKPKint(T) to encrypt and protect the QSSK and key-related information. Key-related information includes, for example, the QSSK's lifetime.

[0139] Step 23: The quantum cryptography service level 1 platform (T) returns a key response to the quantum cryptography service level 2 platform. The key response carries QSBKID(T), QKID, the protected QSSK, and key-related information. The key response is also called the key response message.

[0140] Step 24: The quantum cryptography service secondary platform returns a quantum service session key response (also known as a quantum service session key response message) to the destination quantum secure communication application device (T). The quantum service session key response carries the source service ID, destination service ID, QSBK ID ​​(T), protected QSSK and related information, transaction ID, and other information.

[0141] Step 25: The cryptographic middleware of the destination quantum secure communication application device (T) verifies the integrity of the QSSK and key-related information based on QSKPKint(T). After the integrity verification is successful, it uses QSKPKenc(T) to decrypt and obtain the QSSK and key-related information, and then securely stores the QSSK.

[0142] Step 26: The cryptographic application of the destination quantum secure communication application device (T) returns a quantum service session key response (also known as a quantum service session key response message) to the cryptographic application of the source quantum secure communication application device (O). The quantum service session key response carries the acquisition result of QSSK.

[0143] Step 27: After the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) successfully acquire the QSSK, the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) can further generate QSSKenc / QSSKint based on the QSSK as needed.

[0144] QSSKenc / QSSKint can be derived directly from QSSK, or it can be derived by fusing QSSK with session keys generated in other ways (e.g., negotiated based on asymmetric cryptography algorithms, post-quantum cryptography algorithms, etc.).

[0145] Step 28: The source quantum secure communication application device (O) and the destination quantum secure communication application device (T) use QSSK or QSSKenc / QSSKint to encrypt and / or protect the integrity of user information to achieve quantum secure communication.

[0146] It should be noted that, in Figure 5 In step 5, the secondary quantum cryptography service platform needs to determine whether the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) belong to the same service domain based on whether QCSL1ID(O) and QCSL1 ID(T) are the same. Furthermore, in step 7, when the secondary quantum cryptography service platform sends a key request message to the primary quantum cryptography service platform (O), it needs to include the QCSL1 ID(T) of the destination primary quantum cryptography service platform (T), enabling the source primary quantum cryptography service platform (O) to identify the destination primary quantum cryptography service platform (T) and allocate the available quantum key QK. However, how the secondary quantum cryptography service platform obtains the QCSL1 ID information is a problem that needs to be solved.

[0147] In this application, one method involves a quantum cryptography service secondary platform obtaining the QCSL1 ID(O) and QCSL1 ID(T) from a quantum service session key request, provided by a source-end quantum secure communication application device (O). The source-end quantum secure communication application device (O) can be pre-configured... Figure 4The QCSL1 ID(T) is obtained through interaction between steps 1 and 2, or through interaction with a communication system or cryptographic system. Another method is for the quantum cryptography service secondary platform to obtain the QCSL1 ID through local querying or querying the operation management platform; this method requires the quantum cryptography service secondary platform or operation management platform to pre-store the QCSL1 ID, the identifier information of the quantum cryptography service primary platform to which the quantum secure communication application device or user belongs. The processing flow for obtaining the QCSL1 ID from the operation management platform is as follows: Figure 6 As shown.

[0148] like Figure 6 As shown, the methods for obtaining the QCSL1 ID include:

[0149] Step 1: The quantum cryptography service secondary platform sends a home service platform query request to the operation and management platform. The home service platform query request carries the user or device identification information.

[0150] The identification information may include one or more of the following: user identifier, device identifier, cryptographic module identifier, application identifier, and service identifier. The device identifier includes the identifier of the source quantum secure communication application device (O) and / or the identifier of the destination quantum secure communication application device (T). The cryptographic module identifier includes the identifier of the cryptographic module of the source quantum secure communication application device (O), and / or the identifier of the cryptographic module of the destination quantum secure communication application device (T). The service identifier includes the source service ID and / or the destination service ID. The user identifier includes the identifier of the source user and / or the identifier of the destination user. The application identifier includes the source application ID and / or the destination application ID.

[0151] Step 2: The operation and management platform queries the identifier and / or address information of the quantum cryptography service primary platform to which the user or device belongs, based on the query request from the home service platform and the identifier information, and returns the query results through the query response from the home service platform.

[0152] It should be noted that a query request from the attribution service platform can be described as a query request from the service platform, and a query response from the attribution service platform can be described as a query response from the service platform.

[0153] In this embodiment of the application, the "separation of management and service" system architecture based on a two-level platform (quantum service primary platform and quantum service secondary platform) can effectively solve the problems of difficulty in connecting existing quantum cryptography service center business applications and inflexible adaptation and support. The quantum secure communication system proposed in this application can effectively integrate quantum, cryptography, and application aspects, and has better scalability and compatibility. It can accelerate the connection between the quantum cryptography service center and different communication services, and promote the development of quantum communication towards large-scale, diversified, and ubiquitous directions. At the same time, this application provides a complete key system for the new system architecture, which can ensure the security of the quantum service session key distribution process; it provides a deployment application scenario for the new architecture, and provides a matching quantum secure communication business processing flow for this scenario, which can realize cross-domain / inter-site quantum communication based on quantum keys distributed by the QKD network; it solves key technical problems in the process of quantum secure communication, such as the source and destination application devices obtaining quantum service session keys, and the quantum cryptography service secondary platform obtaining information on the quantum cryptography service primary platform to which the user or device belongs, making the new system architecture possible to be implemented. The above-mentioned solution can combine quantum key distribution technology with traditional communication networks and business applications to achieve quantum secure communication. It has the characteristics of low cost, high security and good scalability, and is the core key to quickly launching "quantum+" secure communication services and forming commercial services.

[0154] Based on the quantum secure communication business processing flow shown in the above embodiments, this application's embodiments are further described using the source quantum secure communication application device (O), the secondary quantum cryptography service platform, the primary quantum cryptography service platform (O) to which the source quantum secure communication application device (O) belongs, the primary quantum cryptography service platform (T) to which the destination quantum secure communication application device (T) belongs, and the destination quantum secure communication application device (T) as the executing entities. For ease of description, the source quantum secure communication application device (O) is referred to as the first application device, the destination quantum secure communication application device (O) as the second application device, and the secondary quantum cryptography service platform as the first entity; the primary quantum cryptography service platform (O) to which the source quantum secure communication application device (O) belongs is referred to as the second entity serving the first application device; the primary quantum cryptography service platform (T) to which the destination quantum secure communication application device (T) belongs is referred to as the second entity serving the second application device; and the operation and management platform is referred to as the third entity. It should be noted that the implementation principle of the secure communication method with a single executing entity can be understood in the same way as the relevant content in the above quantum secure communication business processing flow embodiments.

[0155] This application provides a secure communication method applied to a first entity, which corresponds to the quantum cryptography service secondary platform mentioned above. For example... Figure 7 As shown, the method includes:

[0156] Step 701: Send a first request to a second entity serving the first application device. The first request is used to obtain a session key, which is used for secure communication between the first application device and the second application device. The second entity serving the first application device is different from the second entity serving the second application device.

[0157] And / or, receive a first response from the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0158] Here, the first application device is the source quantum secure communication application device (O) mentioned above; the second entity serving the first application device is the quantum cryptography service level-one platform (O) to which the source quantum secure communication application device (O) belongs; the second application device is the destination quantum secure communication application device (T) mentioned above; the second entity serving the second application device is the quantum cryptography service level-one platform (T) to which the destination quantum secure communication application device (T) belongs.

[0159] The first request can be a key request, for example... Figure 5 In step 7, the quantum cryptography service secondary platform sends a key request. The first response can be a key response, for example... Figure 5 In step 13, the quantum cryptography service primary platform (O) sends a key response to the quantum cryptography service secondary platform. Session keys include, but are not limited to, QSSK and / or QK, with QK serving as the session key.

[0160] In this embodiment, the first entity focuses on business services. A dedicated first entity can be deployed for each different quantum secure communication application (also known as a cryptographic application), and it can be integrated and adapted to the quantum secure communication application to achieve plug-and-play functionality and rapid deployment. The second entity focuses on key management and cryptographic services, which can unify cryptographic security service capabilities and avoid inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. The "separation of management and service" system architecture based on the first and second entities can effectively solve the problems of difficult integration and inflexible adaptation support of existing quantum cryptographic service centers for business applications.

[0161] To save signaling overhead and transmission resources, a first application device can trigger a first entity to send a first request. Based on this, in one embodiment, the method further includes:

[0162] Receive a second request sent by the first application device, the second request being used to obtain the session key;

[0163] And / or, send a second response to the first application device, the second response carrying an encrypted and / or integrity-protected session key.

[0164] Here, before the first entity sends the first request to the second entity serving the first application device, the first entity may also receive the second request sent by the first application device.

[0165] The second request can be a session key request, or a quantum service session key request, for example. Figure 5 In step 4, the source-end quantum secure communication application device (O) sends a quantum service session key request to the quantum cryptographic service secondary platform. The second response can be a session key response or a quantum service session key response, for example... Figure 5 In step 14, the quantum cryptography service secondary platform sends a quantum service session key response to the source quantum secure communication application device (O).

[0166] To assist the second entity serving the first application device in encrypting and / or protecting the integrity of the session key, the first request may carry a first key identifier. Based on this, in one embodiment, the first request carries a first key identifier; wherein the first key identifier is carried by the second request; wherein the first key is a key shared by the first application device and the second entity serving the first application device.

[0167] The encrypted and / or integrity-protected session key in the first response is obtained by: a second entity serving the first application device obtaining the first key based on the first key identifier, and encrypting and / or protecting the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key; and / or the first key identifier is carried in the first response.

[0168] Here, the second request is sent by the first application device to the first entity to obtain the session key.

[0169] The first key identifier is the identifier of the first key, and there is an association or correspondence between the first key and the first key identifier; the first key identifier can be the QSBK ID(O) mentioned above, and the first key can be the QSBK(O) mentioned above. The first response may also carry the first key identifier.

[0170] The encrypted and / or integrity-protected session key can be obtained through one or more of the following methods:

[0171] The second entity serving the first application device obtains the first key based on the first key identifier, and uses the first key to encrypt and / or protect the integrity of the session key, thereby obtaining the encrypted and / or integrity-protected session key;

[0172] The second entity serving the first application device obtains the first key based on the first key identifier, derives the second key based on the first key, and uses the second key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The second key can be QSKPK(O).

[0173] The second entity serving the first application device obtains the first key based on the first key identifier, derives the second key based on the first key, derives the third key based on the second key, and uses the third key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The third key includes QSKPKenc(O) and / or QSKPKint(O) mentioned above.

[0174] The second entity serving the first application device obtains the first key based on the first key identifier, derives the third key based on the first key, and uses the third key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The third key includes QSKPKenc(O) and / or QSKPKint(O) mentioned above.

[0175] It should be noted that, in this application, encrypting and / or protecting the integrity of the session key can be done by encrypting and / or protecting the integrity of only the session key, or by encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) as needed. Encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) can be done by encrypting and / or protecting the integrity of the session key and its related information together, or by encrypting and / or protecting the integrity of the session key and its related information separately.

[0176] In this embodiment, since the first request carries a first key identifier, the second entity serving the first application device can obtain the first key based on the first key identifier to assist the second entity serving the first application device in encrypting and / or protecting the integrity of the session key based on the first key or a key derived from the first key, thereby improving the transmission security of the session key; since the first key is a key shared by the first application device and the second entity serving the first application device, after obtaining the encrypted and / or integrity-protected session key, the first application device can obtain the session key based on the first key or a key derived from the first key.

[0177] Considering that the solution in this application is applicable to cross-domain secure communication scenarios, in order to reduce unnecessary resource consumption and signaling overhead, the first entity verifies whether the second entity serving the first application device and the second application device is the same or different before sending the first request. Based on this, in one embodiment, before sending the first request to the second entity serving the first application device, the method further includes:

[0178] The second entity that is determined to serve the first application device and the second application device is the same or different; wherein, the determination that the second entity that is determined to serve the first application device and the second application device is the same or different includes:

[0179] Whether they are the same or different is determined based on the identifier of the second entity that serves the first application device and the second application device;

[0180] The identifier of the second entity serving the first application device and the second application device is:

[0181] Carried through the second request;

[0182] Alternatively, the first entity obtains the identifier of the first application device and / or the identifier of the second application device carried in the second request through a query.

[0183] Here, the identifier of the second entity serving the first application device can be compared with the identifier of the second entity serving the second application device to see if they are the same or different. If the identifier of the second entity serving the first application device is the same as the identifier of the second entity serving the second application device, then the second entities serving the first application device and the second application device are the same. If the identifier of the second entity serving the first application device is different from the identifier of the second entity serving the second application device, then the second entities serving the first application device and the second application device are different.

[0184] The second request may carry the identifiers of the second entity serving the first application device and the second entity serving the second application device. The first entity can obtain the identifiers of the second entity serving the first application device and the second entity serving the second application device from the second request.

[0185] The first entity can also obtain the identifier of the second entity serving the first application device by querying the identifier of the first application device carried in the second request; and / or, the first entity can also obtain the identifier of the second entity serving the second application device by querying the identifier of the second application device carried in the second request. The first entity can obtain the identifier locally, or by querying the communication system platform or a third entity (operation management platform).

[0186] It should be noted that the identifier of the first application device and / or the identifier of the second application device can be one or more of the following: service identifier, application identifier, user identifier, device identifier, cryptographic module identifier, etc. In other words, the identifier of the first application device includes at least one of the following: service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier. The identifier of the second application device includes at least one of the following: service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier.

[0187] To facilitate finding the session key associated with the second request, in one embodiment, the method further includes:

[0188] Assign a first identifier to the second request;

[0189] The first response carries a session key identifier, and the method further includes: associating the first identifier with the session key identifier; and / or, the second response carries the first identifier.

[0190] Here, when the first entity receives the second request, it can assign a first identifier to the second request, and the second response can also carry the first identifier.

[0191] If the first response carries a session key identifier, the first entity can also associate the first identifier with the session key identifier, which can be a QKID.

[0192] It should be noted that the first identifier can be a transaction identifier, a session identifier, etc. The transaction identifier can be called the transaction ID.

[0193] In this embodiment, a first identifier (e.g., transaction ID, session identifier) ​​can be used to associate quantum secure communication services with key management, further implementing the system design principle of "separation of management and service". By introducing a first identifier to identify communication service requests (second requests) and associating the first identifier with the session key identifier, the session key identifier can be separated from the communication identifier, simplifying the complexity of system design and implementation, avoiding the security risks of key-related information being exposed at the application layer due to the transmission of the session key identifier in the communication system, and improving system security while reducing system coupling.

[0194] To enable secure communication between the first application device and the second application device, the second application device needs to obtain a session key from the first entity for secure communication with the first application device. Therefore, in one embodiment, the method further includes:

[0195] The system receives a third request sent by the second application device, the third request carrying a first identifier; wherein the first identifier is sent by the first application device to the second application device.

[0196] And / or, send a fourth request to a second entity serving the second application device, the fourth request carrying a session key identifier associated with the first identifier.

[0197] Here, the third request can be a session key request, or a quantum service session key request, for example... Figure 5 In step 18, the destination quantum secure communication application device (T) sends a quantum service session key request to the quantum service secondary platform. The first identifier carried in the third request is sent from the first application device to the second application device; for example, the first identifier can be carried in... Figure 5 In step 16, the source quantum secure communication application device (O) sends a quantum service session key notification to the destination quantum secure communication application device (T).

[0198] The fourth request can be a key request, for example... Figure 5 In step 19, the quantum service secondary platform sends a key request to the quantum cryptography service primary platform (T). The session key identifier can be QKID.

[0199] To improve the diversity and flexibility of the first entity in determining whether the current situation is a cross-domain secure communication scenario, in one embodiment, the method further includes:

[0200] The second entity that serves the first application device and the second application device is identified as being the same or different based on the first identifier.

[0201] Here, upon receiving a third request, the first entity determines, based on the first identifier carried in the third request, whether the second entity serving the first application device and the second application device is the same or different. Since the first identifier is assigned by the first entity for the second request, and the second request is issued by the first application device, the first entity can determine the second entity serving the first application device based on the second request. The first entity can then determine the second entity serving the second application device and compare the second entity serving the first application device with the second entity serving the second application device to determine whether the second entities serving the first application device and the second application device are the same or different.

[0202] In the case where the first identifier is associated with the session key identifier, the first entity can identify the second entity that provides the session key identifier, which is the second entity that serves the first application device; by comparing the second entity that serves the first application device and the second entity that serves the second application device, it can be determined whether the second entity that serves the first application device and the second application device is the same or different.

[0203] In one embodiment, the session key identifier is associated with the first identifier and includes:

[0204] The session key identifier is determined by the first entity based on the first identifier.

[0205] Here, upon receiving a third request, since the session key identifier is associated with the first identifier, the first entity can determine the session key identifier associated with the first identifier based on the first identifier carried in the third request. For example, the first entity can obtain or determine the session key identifier associated with the first identifier based on the first identifier. The first identifier can be a transaction ID, and the session key identifier can be a QKID.

[0206] It should be noted that the fourth request may also carry a session key identifier, which can help the second entity serving the second application device obtain the session key.

[0207] In this embodiment, since the first identifier is associated with the session key identifier, the session key identifier can be quickly obtained based on the first identifier.

[0208] To assist the second entity serving the second application device in encrypting and / or protecting the integrity of the session key, the third request may carry a fourth key identifier. Based on this, in one embodiment, the third request carries a fourth key identifier; wherein the fourth key is a key shared by the second application device and the second entity serving the second application device.

[0209] The method further includes:

[0210] Receive a fourth response from a second entity serving the second application device, the fourth response including an encrypted and / or integrity-protected session key; and / or send a third response to the second application device, the third response carrying an encrypted and / or integrity-protected session key;

[0211] The encrypted and / or integrity-protected session key is obtained by the second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0212] Here, the third request may also carry a fourth key identifier, and the fourth request may also carry a fourth key identifier; the fourth key identifier is the identifier of the fourth key, and there is an association or correspondence between the fourth key identifier and the fourth key; the fourth key identifier can be QSBK ID(T), and the fourth key can be QSBK(T). The fourth key can be a key shared by the second application device and the second entity serving the second application device.

[0213] The fourth response can be a key response, for example Figure 5 In step 23, the quantum cryptography service level 1 platform (T) sends a key response to the quantum cryptography service level 2 platform.

[0214] The third response can be a session key response, or a quantum service session key response, for example. Figure 5 In step 24, the quantum service secondary platform sends a quantum service session key response to the second application device.

[0215] The encrypted and / or integrity-protected session key can be obtained through one or more of the following methods:

[0216] The second entity serving the second application device obtains the fourth key based on the fourth key identifier, and uses the fourth key to encrypt and / or protect the integrity of the session key, thereby obtaining the encrypted and / or integrity-protected session key;

[0217] The second entity serving the second application device obtains the fourth key based on the fourth key identifier, derives the fifth key based on the fourth key, and uses the fifth key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The fourth key can be QSBK(T) and the fifth key can be QSKPK(T).

[0218] The second entity serving the second application device obtains the fourth key based on the fourth key identifier, derives the fifth key based on the fourth key, derives the sixth key based on the fifth key, and uses the sixth key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The sixth key includes QSKPKenc(T) and / or QSKPKint(T) mentioned above.

[0219] The second entity serving the second application device obtains the fourth key based on the fourth key identifier, derives the sixth key based on the fourth key, and uses the sixth key to encrypt and / or protect the integrity of the session key to obtain the encrypted and / or integrity-protected session key. The sixth key includes QSKPKenc(T) and / or QSKPKint(T) mentioned above.

[0220] It should be noted that, in this application, encrypting and / or protecting the integrity of the session key can be done by encrypting and / or protecting the integrity of only the session key, or by encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) as needed. Encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) can be done by encrypting and / or protecting the integrity of the session key and its related information together, or by encrypting and / or protecting the integrity of the session key and its related information separately.

[0221] In this embodiment, since the fourth request carries a fourth key identifier, the second entity serving the second application device can obtain the fourth key based on the fourth key identifier. This assists the second entity serving the second application device in encrypting and / or protecting the integrity of the session key based on the fourth key or a key derived from the fourth key, thereby improving the transmission security of the session key. Since the fourth key is a key shared by the second application device and the second entity serving the second application device, after obtaining the encrypted and / or integrity-protected session key, the second application device can obtain the session key based on the fourth key or a key derived from the fourth key.

[0222] In one embodiment, the first request further carries a key type, indicating one or more of the purpose, type, and source of the requested key;

[0223] And / or, the first request may also carry an identifier of a second entity that serves the second application device.

[0224] Here, the identifier of the second entity serving the second application device can be QCSL1 ID(T).

[0225] It should be noted that in this application document, the key type can describe the purpose of the key, such as session key, key protection key, authentication key, encryption key, integrity protection key, etc.; the key type can describe the source of the key, such as quantum key, quantum random number key, physical noise source key, etc.; the key category can be a combination of key-related information such as purpose and source.

[0226] In this embodiment, the first request carries a key type to assist the second entity serving the first application device in obtaining a session key that matches the key type, so as to meet the first application device's requirement for a session key; the first request carries the identifier of the second entity serving the second application device to assist the second entity serving the first application device in obtaining a quantum key as a session key from a quantum key resource pool shared with the second entity serving the second application device.

[0227] To assist a second entity serving a first application device in obtaining the session key required by the second application device, in one embodiment, the fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

[0228] In one embodiment, the fourth response also carries a fourth key identifier and / or a session key identifier.

[0229] Here, the fourth key identifier can be QSBKID(T), and the session key identifier can be QKID.

[0230] In this embodiment, since the session key identifier is associated with the first identifier, the third request sent by the second application device carries the first identifier. Therefore, the fourth response carries the fourth key identifier and / or the session key identifier, which can help the first entity quickly determine the second application device to receive the information carried by the fourth response.

[0231] To assist the second application device in determining whether the obtained session key is the session key required for secure communication with the first application device, in one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0232] Here, the fourth key identifier can be QSBK ID(T). The identifier of the first application device includes at least one of the following: the service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier of the first application device. The identifier of the second application device includes at least one of the following: the service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier of the second application device.

[0233] In one embodiment, the first entity obtains the identifier of the first application device and / or the identifier of the second application device through a query based on the second request, including:

[0234] The first entity obtains the information by querying the third entity based on the identifier of the first application device and / or the identifier of the second application device carried in the second request.

[0235] Here, the first entity can send a query request to the third entity, the query request carrying the identifier of the first application device and / or the identifier of the second application device; and receive the query results sent by the third entity, the query results including the identifier of the first application device and / or the identifier of the second application device. The query request can be called a home service platform query request or a service platform query request. The third entity includes, but is not limited to, the operation and management platform.

[0236] The identifier of the first application device includes at least one of the following: service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier. The identifier of the second application device includes at least one of the following: service identifier, application identifier, user identifier, device identifier, and cryptographic module identifier.

[0237] In this embodiment, the identifier of the second entity can be uniformly managed by a third entity to standardize the process by which the first entity obtains the identifier of the second entity.

[0238] In order to ensure that the first application device and the second application device obtain the same session key, in one embodiment, the session key is a key shared by the second entity serving the first application device and the second entity serving the second application device.

[0239] To ensure that the first application device and the second application device obtain the same session key for secure communication and improve communication security, in one embodiment, the session key originates from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device. The keys in the shared key resource pool originate from a quantum key distribution network.

[0240] This application also provides a secure communication method, applied to a second entity serving a first application device, such as... Figure 8 As shown, the method includes:

[0241] Step 801: Receive a first request sent by a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; the second entity serving the first application device is different from the second entity serving the second application device;

[0242] And / or, send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

[0243] Here, a second entity serving the first application device receives a first request sent by the first entity, allocates an available session key based on the first request, and encrypts and / or protects the session key for integrity, thereby obtaining an encrypted and / or integrity-protected session key; and / or sends a first response to the first entity, the first response carrying the encrypted and / or integrity-protected session key.

[0244] In this embodiment, the first entity focuses on business services. A dedicated first entity can be deployed for each different quantum secure communication application (also known as a cryptographic application), and it can be integrated and adapted to the quantum secure communication application to achieve plug-and-play functionality and rapid deployment. The second entity focuses on key management and cryptographic services, which can unify cryptographic security service capabilities and avoid inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. The "separation of management and service" system architecture based on the first and second entities can effectively solve the problems of difficult integration and inflexible adaptation support of existing quantum cryptographic service centers for business applications.

[0245] To assist the second entity serving the first application device in encrypting and / or protecting the integrity of the session key, the first request may carry a first key identifier. Therefore, in one embodiment, the first request carries a first key identifier; the first key is a key shared by the first application device and the second entity serving the first application device.

[0246] And / or, the encrypted and / or integrity-protected session key in the first response is: obtained by a second entity serving the first application device based on the first key identifier, using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key, to encrypt and / or protect the session key; and / or, the first response carries the first key identifier.

[0247] Here, if the first request carries a first key identifier, the first response may also carry a first key identifier. The first key identifier is an identifier for the first key, and there is an association or correspondence between the first key identifier and the first key.

[0248] The second entity serving the first application device may obtain the encrypted and / or integrity-protected session key through one or more of the following methods:

[0249] The first key is obtained based on the first key identifier. The session key is then encrypted and / or its integrity is protected using the first key to obtain the encrypted and / or integrity-protected session key. The first key identifier can be QSBKID(O), and the first key can be QSBK(O).

[0250] A first key is obtained based on the first key identifier. A second key is derived from the first key. The session key is encrypted and / or its integrity is protected using the second key to obtain the encrypted and / or integrity-protected session key. The second key can be QSKPK(O).

[0251] The first key is obtained based on the first key identifier, the second key is derived based on the first key, the third key is derived based on the second key, and the session key is encrypted and / or protected for integrity using the third key to obtain the encrypted and / or protected session key. The third key includes QSKPKenc(O) and / or QSKPKint(O) mentioned above.

[0252] The first key is obtained based on the first key identifier. The third key is derived from the first key. The session key is encrypted and / or protected for integrity using the third key to obtain the encrypted and / or protected session key. The third key includes QSKPKenc(O) and / or QSKPKint(O) mentioned above.

[0253] It should be noted that, in this application, encrypting and / or protecting the integrity of the session key can be done by encrypting and / or protecting the integrity of only the session key, or by encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) as needed. Encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) can be done by encrypting and / or protecting the integrity of the session key and its related information together, or by encrypting and / or protecting the integrity of the session key and its related information separately.

[0254] In this embodiment, since the first request carries a first key identifier, the second entity serving the first application device can obtain the first key based on the first key identifier. This assists the second entity serving the first application device in encrypting and / or protecting the integrity of the session key based on the first key or a key derived from the first key, thereby improving the transmission security of the session key. Since the first key is a key shared by the first application device and the second entity serving the first application device, after obtaining the encrypted and / or integrity-protected session key, the first application device can decrypt and / or verify the integrity based on the first key or a key derived from the first key to obtain the session key.

[0255] In one embodiment, the first request further carries a key type, indicating one or more of the purpose, type, and source of the requested key; the method further includes:

[0256] Assign a key according to the key type in the first request and obtain a key identifier.

[0257] Here, upon receiving a first request, a key matching the key type is allocated based on the key type carried in the first request, and the identifier of that key is obtained, thus acquiring the key identifier. The allocated key can be called the session key, and the key identifier can serve as the session key identifier.

[0258] In this embodiment, the second entity serving the first application device allocates a key according to the key type carried in the first request and obtains a key identifier, which can make the allocated key match the key type, meet the key requirements of the first application device, improve the flexibility of obtaining session keys and improve the scalability of the solution.

[0259] In one embodiment, the step of allocating a key according to the key type in the first request and obtaining a key identifier includes:

[0260] When the key type is a quantum key, allocate the quantum key, obtain the identifier of the quantum key, and / or update the state of the quantum key;

[0261] And / or, when the key type is a session key, the assigned key is used as a session key to obtain the session key identifier;

[0262] And / or, when the key type is both quantum key and session key, allocate the quantum key for the session key and use the quantum key identifier as the session key identifier.

[0263] In one embodiment, to assist the second entity serving the second application device in quickly finding the quantum key allocated to the first application device, the first response carries the session key identifier. This session key identifier is a quantum key identifier (QKID).

[0264] Here, when the key type is a quantum key, the quantum key identifier is also called a quantum key identifier, which can be QKID. The session key can be QK, and its identifier can be QKID. Using a quantum key as a session key can improve communication security when the first application device uses the session key for secure communication. When the key type is a session key, a quantum key can be allocated and used as the session key. Allocating a quantum key can be understood as allocating a usable quantum key.

[0265] It should be noted that in this application, the allocated quantum key or the allocated available quantum key, i.e., the state of the quantum key, can be unused, unallocated, unreserved, occupied, ready, valid, enabled, etc. After the quantum key is allocated, its state should be updated to allocated, used, reserved, occupied, invalid, disabled, etc.

[0266] In this application, when the key type is quantum key and session key, after the quantum key is allocated for the session key, the identifier of the quantum key (QKID) is used as the identifier of the session key (QSSK).

[0267] In this embodiment, updating the state of the quantum key after it is allocated can prevent other application devices besides the first and second application devices from using the quantum key for secure communication. This allows different quantum secure communication services to use different quantum keys, or different application device pairs to use different quantum keys, thereby improving communication security.

[0268] In order to enable a second entity serving a second application device to be aware of the session key that has been used, in one embodiment, the method further includes:

[0269] A fifth request is sent to a second entity serving the second application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or

[0270] Receive a fifth response from a second entity serving the second application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

[0271] Here, when the second entity serving the first application device updates the state of the allocated quantum key, a fifth request is sent to the second entity serving the second application device, and / or a fifth response is received from the second entity serving the second application device.

[0272] It should be noted that the fifth request can be a key synchronization request or a quantum key synchronization request, for example... Figure 5 The quantum key synchronization request in step 9 can be referred to as a quantum key synchronization request message. The fifth response can be a key synchronization response or a quantum key synchronization response, for example... Figure 5 The quantum key synchronization response in step 10 can be referred to as the quantum key synchronization response message.

[0273] In this embodiment, the second entity serving the first application device synchronously updates the used quantum key to the second entity serving the second application device. This can prevent the second entity serving the second application device from allocating the used quantum key to application devices other than the second application device, thereby reducing or avoiding the risks caused by using duplicate quantum keys for secure communication and further improving communication security.

[0274] In one embodiment, the fifth request further carries: an identifier of a second entity serving the first application device and / or an identifier of a second entity serving the second application device; and / or,

[0275] The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0276] Here, the fifth request may also carry the identifier of the second entity serving the first application device, and / or the identifier of the second entity serving the second application device; the fifth response may also carry the identifier of the second entity serving the first application device, and / or the identifier of the second entity serving the second application device. The identifier of the second entity serving the first application device may be QCSL1 ID(O), and the identifier of the second entity serving the second application device may be QCSL1 ID(T).

[0277] In this embodiment, the fifth request and / or the fifth response may also carry the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device, which can assist the receiver in identity verification to confirm whether it needs to process the received request or response and reduce the probability of misoperation.

[0278] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0279] Here, since the quantum keys in the quantum key resource pool can be further distributed to application devices according to business needs, the session key is a key shared by the second entity serving the first application device and the second entity serving the second application device, which can make the first application device and the second application device obtain the same session key.

[0280] To ensure that the first application device and the second application device obtain the same session key for secure communication and improve communication security, in one embodiment, the session key originates from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device. The keys in the shared key resource pool originate from a quantum key distribution network.

[0281] Here, the session key can be a quantum key, and the shared key resource pool can be the quantum key resource pool mentioned above.

[0282] In this embodiment, a shared key resource pool exists between different second entities, enabling secure communication between different application devices served by each second entity using the same session key. This improves communication security and the flexibility of key distribution. The keys in the shared key resource pool originate from a quantum key distribution network, enhancing the security of the key distribution process.

[0283] This application also provides a secure communication method, applied to a second entity serving a second application device, such as... Figure 9 As shown, the method includes:

[0284] Step 901: Receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or, return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

[0285] Here, the second entity serving the second application device receives a fourth request. Since the fourth request is used to obtain a session key, the second entity serving the second application device searches for the session key based on the fourth request and encrypts and / or protects the session key for integrity, obtaining the encrypted and / or integrity-protected session key; it then returns a fourth response to the first entity, the fourth response carrying at least the encrypted and / or integrity-protected session key. The session key identifier is associated with a first identifier, which is sent by the first application device to the second application device.

[0286] The fourth request can be a key request, for example... Figure 5 In step 19, the quantum cryptography service secondary platform sends a key request to the quantum cryptography service primary platform (T); the fourth response can be a key response, for example... Figure 5 In step 23, the quantum cryptography service level 1 platform (T) sends a key response to the quantum cryptography service level 2 platform.

[0287] It should be noted that the session key identifier can be QKID. The session key identifier carried in the fourth request is associated with the first identifier, which is sent by the first application device to the second application device. The first identifier can be called the transaction identifier or the session identifier.

[0288] In one embodiment, the fourth request carries a fourth key identifier; the method further includes:

[0289] The fourth key is obtained based on the fourth key identifier;

[0290] The session key is encrypted and / or its integrity is protected using the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth or fifth key.

[0291] Here, the second entity serving the second application device can obtain the corresponding fourth key based on the fourth key identifier carried in the fourth request, and obtain the encrypted and / or integrity-protected session key based on the fourth key. The fourth request also carries a fourth key identifier, which can be a QSBK ID(T), and the fourth key can be a QSBK(T). There is a correspondence or association between the fourth key identifier and the fourth key.

[0292] A second entity serving a second application device may obtain a encrypted and / or integrity-protected session key through one or more of the following methods:

[0293] The fourth key is obtained based on the fourth key identifier. The session key is then encrypted and / or its integrity is protected using the fourth key to obtain the encrypted and / or integrity-protected session key.

[0294] The fourth key is obtained based on the fourth key identifier, the fifth key is derived based on the fourth key, and the session key is encrypted and / or protected for integrity using the fifth key to obtain the encrypted and / or protected session key. The fourth key can be QSBK(T), and the fifth key can be QSKPK(T).

[0295] The fourth key is obtained based on the fourth key identifier, the fifth key is derived based on the fourth key, the sixth key is derived based on the fifth key, and the session key is encrypted and / or protected for integrity using the sixth key to obtain the encrypted and / or protected session key. The sixth key includes QSKPKenc(T) and / or QSKPKint(T) mentioned above.

[0296] The fourth key is obtained based on the fourth key identifier. The sixth key is derived from the fourth key. The session key is encrypted and / or protected for integrity using the sixth key to obtain the encrypted and / or protected session key. The sixth key includes QSKPKenc(T) and / or QSKPKint(T) mentioned above.

[0297] It should be noted that, in this application, encrypting and / or protecting the integrity of the session key can be done by encrypting and / or protecting the integrity of only the session key, or by encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) as needed. Encrypting and / or protecting the integrity of the session key and its related information (e.g., the session key's identifier, lifespan, etc.) can be done by encrypting and / or protecting the integrity of the session key and its related information together, or by encrypting and / or protecting the integrity of the session key and its related information separately.

[0298] In this embodiment, since the fourth request carries a fourth key identifier, the second entity serving the second application device can obtain the fourth key based on the fourth key identifier. This assists the second entity serving the second application device in encrypting and / or protecting the integrity of the session key based on the fourth key or a key derived from the fourth key, thereby improving the transmission security of the session key. Since the fourth key is a key shared by the second application device and the second entity serving the second application device, after obtaining the encrypted and / or integrity-protected session key, the second application device can decrypt and / or verify the integrity based on the fourth key or a key derived from the fourth key to obtain the session key.

[0299] In one embodiment, the fourth response further carries: the session key identifier and / or the fourth key identifier.

[0300] Here, the fourth key identifier can be QSBKID(T), and the session key identifier can be QKID.

[0301] In this embodiment, since the session key identifier is associated with the first identifier, the third request sent by the second application device carries the first identifier. Therefore, the fourth response carries the fourth key identifier and / or the session key identifier, which can help the first entity quickly determine the second application device to receive the information carried by the fourth response.

[0302] In one embodiment, the session key identifier is a quantum key identifier, and the method further includes:

[0303] The quantum key is retrieved based on the session key identifier; wherein...

[0304] The quantum key is a key shared by the second entity serving the first application device and the second entity serving the second application device. It comes from a shared key resource pool of the second entity serving the first application device and the second entity serving the second application device. The keys in the shared key resource pool come from a quantum key distribution network.

[0305] Here, when the second entity serving the second application device receives the fourth request sent by the first entity, since the fourth request carries a session key identifier, which is a quantum key identifier, and there is a storage association or correspondence between the quantum key identifier and the quantum key, it can accurately and quickly find the quantum key corresponding to the quantum key identifier in the shared key resource pool of the second entity serving the first application device and the second entity serving the second application device, and use the found quantum key as the session key.

[0306] In this embodiment, the second entity serving the second application device searches for the session key from the shared key resource pool based on the session key identifier, and the key in the shared key resource pool comes from the quantum key distribution network, which improves the security of the session key distribution process.

[0307] In one embodiment, the fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

[0308] Here, if the first request carries a key type, the fourth request may also carry a key type to assist the second entity serving the second application device in allocating a session key that matches the key type to the second application device.

[0309] In one embodiment, the method further includes:

[0310] Receive a fifth request from a second entity serving the first application device, the fifth request being used to synchronously update the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or,

[0311] A fifth response is sent to a second entity serving the first application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

[0312] Here, before receiving the fourth request, the second entity serving the second application device may receive the fifth request sent by the second entity serving the first application device, and may update the quantum key and / or the state of the quantum key carried in the fifth request based on synchronization; and / or send a fifth response to the second entity serving the first application device.

[0313] To assist the second entity in authenticating based on the fifth request or fifth response, in one embodiment, the fifth request further carries: an identifier of the second entity serving the first application device and / or an identifier of the second entity serving the second application device; and / or,

[0314] The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0315] In this embodiment, the fifth request and / or the fifth response may also carry the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device, which can assist the receiver in identity verification to confirm whether it needs to process the received request or response and reduce the probability of misoperation.

[0316] In order to ensure that the first application device and the second application device obtain the same session key, in one embodiment, the session key is a key shared by the second entity serving the first application device and the second entity serving the second application device.

[0317] To ensure that the first application device and the second application device obtain the same session key for secure communication and improve communication security, in one embodiment, the session key originates from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device. The keys in the shared key resource pool originate from a quantum key distribution network.

[0318] This application embodiment also provides a first application device, such as Figure 10 As shown, the method includes:

[0319] Step 1001: Send a second request to the first entity. The second request is used to obtain a session key, which is used for secure communication between the first application device and the second application device.

[0320] And / or, receive a second response from the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0321] Here, when the first application device and the second application device establish a communication connection, the first application device sends a second request to the first entity and / or receives a second response from the first entity. The second entity serving the first application device is different from the second entity serving the second application device.

[0322] The session key includes the QSSK. The second request can be a session key request, or a quantum service session key request, for example... Figure 5 In step 4, the source-end quantum secure communication application device (O) sends a quantum service session key request to the quantum cryptographic service secondary platform. The second response can be a session key response or a quantum service session key response, for example... Figure 5 In step 14, the quantum cryptography service secondary platform sends a quantum service session key response to the source quantum secure communication application device (O).

[0323] To mitigate the risk of session key leakage, the session key is transmitted after encryption and / or integrity protection. Therefore, in one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the first application device, which obtains the first key based on the first key identifier, and then encrypts and / or protects the session key using the first key, or a second key derived from the first key, or a third key derived from the first or second key.

[0324] In one embodiment, the method further includes:

[0325] Assign a first key and obtain the identifier of the first key; wherein, the first key is: a key shared by the first application device and the second entity serving the first application device;

[0326] And / or, derive a third key based on the first key;

[0327] And / or, derive a second key based on the first key;

[0328] And / or, derive a second key based on the first key, and derive a third key based on the second key.

[0329] Here, the first application device can allocate an available first key and obtain the identifier of the first key before or after sending the second request to the first entity. Allocating the first key includes: the cryptographic middleware of the first application device allocating an available first key for the cryptographic application of the first application device; the first key can be QSBK(O), and the first key identifier can be QSBKID(O); different cryptographic applications may correspond to different first keys.

[0330] Derivation of a third key based on a first key can include: directly deriving a third key from the first key, and / or deriving a second key from the first key, and then deriving a third key from the second key. The third key includes, but is not limited to, QSKPKenc(O) and / or QSKPKint(O).

[0331] In this embodiment, the first application device allocates an available first key to assist the second entity serving the first application device in obtaining a key for encrypting and / or protecting the integrity of the session key, and to assist the first application device in obtaining a key for verifying the integrity of the session key and / or decrypting it, thereby reducing the risk of leakage of the session key during transmission.

[0332] To improve the security of session key transmission, the session key is transmitted after encryption and / or integrity protection. After receiving the encrypted and / or integrity-protected session key, the first application device needs to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key. Based on this, in one embodiment, the method further includes:

[0333] Based on the first key, or the second key, or the third key, perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key to obtain the session key.

[0334] Here, when the first application device obtains the first key, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the first key to obtain the session key. When the first application device obtains the second key, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the second key to obtain the session key. When the first application device obtains the third key, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the third key to obtain the session key. Integrity verification corresponds to integrity protection; when an encrypted session key is obtained, the encrypted session key is decrypted; when an integrity-protected session key is obtained, integrity verification is performed on the integrity-protected session key. When both encrypted and integrity-protected session keys are obtained, integrity verification can be performed on the encrypted and integrity-protected session key first, and decryption can be performed only after the integrity verification is successful.

[0335] The second key can be QSKPK(O); the third key includes QSKPKenc(O) and / or QSKPKint(O). Since QSKPKenc(O) is used for encryption and QSKPKint(O) is used for integrity protection, the first application device can perform integrity verification on the integrity-protected session key based on QSKPKint(O), and / or decrypt the encrypted session key based on QSKPKenc(O).

[0336] It should be noted that when the third key includes QSKPKenc(O) and QSKPKint(O), the integrity of the session key after integrity protection can be verified based on QSKPKint(O). After the integrity verification is passed, the encrypted session key can be decrypted based on QSKPKenc(O).

[0337] To improve data security during communication, in one embodiment, the method further includes:

[0338] A seventh key is derived based on the session key; and / or,

[0339] A seventh key is derived based on the session key and the eighth key, wherein the eighth key is the session key negotiated between the first application device and the second application device; wherein...

[0340] The seventh key is used to encrypt and / or protect the integrity of information sent by the first application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the first application device.

[0341] Here, the first application device, having obtained the session key, conducts secure communication with the second application device based on the session key; and / or, derives a seventh key based on the session key, and / or, derives a seventh key based on the session key and the eighth key. The eighth key is a session key negotiated by the first and second application devices. For example, the eighth key can be a session key negotiated based on an asymmetric cryptographic algorithm and / or a post-quantum cryptographic algorithm. The seventh key includes, but is not limited to, QSSKenc and / or QSSKint; QSSKenc is used for encryption, and QSSKint is used for integrity protection.

[0342] It should be noted that, after obtaining the seventh key, the first application device can also conduct secure communication with the second application device based on the seventh key.

[0343] In one embodiment, the second response carries a first identifier; the method further includes:

[0344] Send a first message to the second application device, the first message carrying a first identifier, the first identifier being associated with the session key identifier;

[0345] And / or, receive a second message sent by the second application device, the second message indicating the result of obtaining the session key.

[0346] Here, after receiving the second response sent by the first entity, the first application device may send a first message to the second application device, the first message carrying a first identifier, and / or receive the second message sent by the second application device, the result of obtaining the session key being either successful or failed.

[0347] The first message could be, for example: Figure 5 In step 16, the quantum service session key notification. The second message could be... Figure 5 The quantum service session key response in step 26.

[0348] In this embodiment, the first application device sends a first identifier to the second application device, causing the second application device to send a fourth request carrying the first identifier to the first entity. This assists the first entity in quickly determining whether the session key is distributed within the same domain or across domains. If it is determined that the session key is distributed across domains, the first entity obtains the session key identifier associated with the first identifier and sends a third request to the second entity providing services to the second application device to request the session key. The second application device sends a first message to the first application device to help the first application device know whether the second application device has successfully obtained the session key.

[0349] This application also provides a second application device, such as... Figure 11 As shown, the method includes:

[0350] Step 1101: Send a third request to the first entity, the third request carrying the first identifier;

[0351] And / or, receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0352] Here, upon receiving the first identifier sent by the first application device, the second application device sends a third request to the first entity. The third request is used to obtain the session key and carries the first identifier, which is sent by the first application device to the second application device. The first identifier can be called a session identifier or a transaction identifier.

[0353] The third request can be a session key request, or a quantum service session key request, for example. Figure 5 In step 18, the destination quantum secure communication application device (T) sends a quantum service session key request to the quantum service secondary platform. The third response can be a session key response or a quantum service session key response, for example... Figure 5 In step 24, the quantum service secondary platform sends a quantum service session key response to the second application device.

[0354] To reduce the risk of session key leakage during transmission, in one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0355] Here, the fourth key can be QSBK(T), the fifth key can be QSKPK(T), and the sixth key includes QSKPKenc(T) and / or QSKPKint(T).

[0356] To assist the second application device in determining whether the obtained session key is the session key required for secure communication with the first application device, in one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0357] Here, the fourth key identifier can be QSBKID(T).

[0358] In one embodiment, the method further includes:

[0359] Assign a fourth key and obtain a fourth key identifier; wherein, the fourth key is: a key shared by the second application device and the second entity serving the second application device;

[0360] And / or, derive a sixth key based on the fourth key;

[0361] And / or, derive a fifth key based on the fourth key;

[0362] And / or, derive a fifth key based on the fourth key, and derive a sixth key based on the fifth key.

[0363] Here, the second application device can allocate a usable fourth key and obtain a fourth key identifier before or after sending the fourth request to the first entity. The fourth key identifier is the identifier of the fourth key, and there is an association or correspondence between the fourth key and the fourth key identifier. Allocating the fourth key includes: the cryptographic middleware of the second application device allocating a usable fourth key for the cryptographic application of the second application device. The fourth key can be QSBK(T), and the fourth key identifier can be QSBKID(T); different cryptographic applications may correspond to different fourth keys.

[0364] The sixth key can be derived from the fourth key, including: directly deriving the sixth key from the fourth key, and / or deriving the fifth key from the fourth key, and then deriving the sixth key from the fifth key. The sixth key includes, but is not limited to, QSKPKenc(T) and / or QSKPKint(T).

[0365] In this embodiment, the second application device allocates a fourth available key to assist the second entity serving the second application device in obtaining a key for encrypting and / or protecting the integrity of the session key, and to assist the second application device in obtaining a key for verifying and / or decrypting the session key, thereby reducing the risk of leakage of the session key during transmission.

[0366] To enhance the security of session key transmission, the session key is transmitted after encryption and / or integrity protection. Upon receiving the encrypted and / or integrity-protected session key, the second application device needs to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key. Therefore, in one embodiment, the method further includes:

[0367] Based on the fourth key, or the fifth key, or the sixth key, the encrypted and / or integrity-protected session key is subjected to integrity verification and / or decryption to obtain the session key.

[0368] Here, the second application device acquires the sixth key. Upon receiving the third response, and if the fourth key is obtained, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the fourth key to obtain the session key. If the fifth key is obtained, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the fifth key to obtain the session key. If the sixth key is obtained, it performs integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the sixth key to obtain the session key. The fifth key can be QSKPK(T); the sixth key includes QSKPKenc(T) and / or QSKPKint(T). Since QSKPKenc(T) is used for encryption and QSKPKint(T) is used for integrity protection, the second application device can perform integrity verification on the integrity-protected session key based on QSKPKint(T) and / or decrypt the encrypted session key based on QSKPKenc(T).

[0369] It should be noted that when the sixth key includes QSKPKenc(T) and QSKPKint(T), the second application device can perform integrity verification on the integrity-protected session key based on QSKPKint(T), and after the integrity verification is successful, decrypt the encrypted session key based on QSKPKenc(T).

[0370] To improve data security during communication, in one embodiment, the method further includes:

[0371] A seventh key is derived based on the session key; and / or

[0372] A seventh key is derived based on the session key and the eighth key, wherein the eighth key is the session key negotiated between the first application device and the second application device; wherein...

[0373] The seventh key is used to encrypt and / or protect the integrity of information sent by the second application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the second application device.

[0374] Here, the second application device, having obtained the session key, conducts secure communication with the first application device based on the session key; and / or, derives a seventh key based on the session key, and / or, derives a seventh key based on the session key and the eighth key. The eighth key is a session key negotiated between the first and second application devices. For example, the eighth key can be a session key negotiated based on an asymmetric cryptographic algorithm and / or a post-quantum cryptographic algorithm. The seventh key includes, but is not limited to, QSSKenc and / or QSSKint; QSSKenc is used for encryption, and QSSKint is used for integrity protection.

[0375] It should be noted that, if the second application device obtains the seventh key, it can also conduct secure communication with the first application device based on the seventh key.

[0376] In one embodiment, the method further includes:

[0377] The system receives the first message sent by the first application device, the first message carrying a first identifier, and the first identifier being associated with the session key identifier;

[0378] And / or, send a second message to the first application device, the second message indicating the result of obtaining the session key.

[0379] Here, the second application device may receive a first message sent by the first application device before sending a fourth request to the first entity, and / or send a second message to the first application device after receiving a third response sent by the first entity. The result of obtaining the session key is whether the session key acquisition was successful or failed.

[0380] The first message could be, for example: Figure 5 In step 16, the quantum service session key notification. The second message could be... Figure 5 The quantum service session key response in step 26.

[0381] In this embodiment, the first application device sends a first message to the second application device, causing the second application device to send a fourth request carrying a first identifier to the first entity. This assists the first entity in quickly determining whether the session key is distributed within the same domain or across domains. If it is determined that the session key is distributed across domains, the first entity obtains the session key identifier associated with the first identifier and sends a third request to the second entity providing services to the second application device to request the session key. The second application device then sends a second message to the first application device to help the first application device determine whether the second application device has successfully obtained the session key.

[0382] In one embodiment, the third request carries a fourth key identifier.

[0383] Here, the fourth key identifier can be QSBK ID(T). The fourth key identifier is used to assist the second entity serving the second application device in obtaining the fourth key based on the fourth key identifier, and to encrypt and / or protect the integrity of the session key based on the fourth key or a key derived from the fourth key, so as to reduce the risk of leakage of the session key.

[0384] To implement the method on the first entity side of the embodiments of this application, the embodiments of this application also provide a secure communication device, which is disposed on the first entity, such as... Figure 12 As shown, the device includes:

[0385] The first transceiver unit 1201 is configured to send a first request to a second entity serving a first application device, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, the second entity serving the first application device being different from the second entity serving the second application device; and / or, to receive a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0386] In one embodiment, the device further includes:

[0387] The sixth transceiver unit is used to receive a second request sent by the first application device, the second request being used to obtain the session key;

[0388] And / or, to send a second response to the first application device, the second response carrying an encrypted and / or integrity-protected session key.

[0389] In one embodiment, the first request carries a first key identifier; wherein the first key identifier is carried in the second request; wherein the first key is a key shared by the first application device and a second entity serving the first application device;

[0390] The encrypted and / or integrity-protected session key in the first response is obtained by: a second entity serving the first application device obtaining the first key based on the first key identifier, and encrypting and / or protecting the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key; and / or the first key identifier is carried in the first response.

[0391] In one embodiment, the device further includes:

[0392] A first determining unit is configured to determine whether a second entity serving the first application device and the second application device is the same or different; wherein, the first determining unit is specifically configured to: determine whether they are the same or different based on the identifier of the second entity serving the first application device and the second application device; wherein, the identifier of the second entity serving the first application device and the second application device is:

[0393] Carried through the second request;

[0394] Alternatively, the first entity obtains the identifier of the first application device and / or the identifier of the second application device carried in the second request through a query.

[0395] In one embodiment, the device further includes:

[0396] A first allocation unit is configured to allocate a first identifier to the second request;

[0397] The first response carries a session key identifier, and the device further includes: an association unit for associating the first identifier with the session key identifier; and / or, the second response carries the first identifier.

[0398] In one embodiment, the device further includes:

[0399] The seventh transceiver unit is configured to receive a third request sent by the second application device, wherein the third request carries a first identifier; wherein the first identifier is sent by the first application device to the second application device;

[0400] And / or, to send a fourth request to a second entity serving the second application device, the fourth request carrying a session key identifier associated with the first identifier.

[0401] In one embodiment, the device further includes:

[0402] The second determining unit is configured to determine, based on the first identifier, whether the second entity serving the first application device and the second application device is the same or different.

[0403] In one embodiment, the session key identifier is associated with the first identifier, including: the session key identifier is determined by the first entity based on the first identifier.

[0404] In one embodiment, the third request carries a fourth key identifier; the fourth request carries the fourth key identifier; wherein the fourth key is a key shared by the second application device and a second entity serving the second application device; the apparatus further includes:

[0405] The eighth transceiver unit is configured to receive a fourth response sent by a second entity serving the second application device, the fourth response including an encrypted and / or integrity-protected session key; and / or send a third response to the second application device, the third response carrying an encrypted and / or integrity-protected session key;

[0406] The encrypted and / or integrity-protected session key is obtained by the second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0407] In one embodiment, the first request further carries a key type, indicating one or more of the purpose, type, and source of the requested key;

[0408] And / or, the first request may also carry an identifier of a second entity that serves the second application device.

[0409] In one embodiment, the fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

[0410] In one embodiment, the fourth response also carries a fourth key identifier and / or a session key identifier.

[0411] In one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0412] In one embodiment, the first entity obtains the identifier of the first application device and / or the identifier of the second application device through a query based on the second request, including:

[0413] The first entity obtains the information by querying the third entity based on the identifier of the first application device and / or the identifier of the second application device carried in the second request.

[0414] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0415] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0416] In practical applications, the first transceiver unit 1201, the sixth transceiver unit, the seventh transceiver unit, and the eighth transceiver unit can be implemented by a processor in the secure communication device combined with a communication interface; the first determining unit, the first allocating unit, the associating unit, and the second determining unit can be implemented by a processor in the secure communication device.

[0417] To implement the method for the second entity serving the first application device according to the embodiments of this application, the embodiments of this application also provide a secure communication device, which is installed on the second entity serving the first application device, such as... Figure 13 As shown, the device includes:

[0418] The second transceiver unit 1301 is configured to receive a first request sent by a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, wherein the second entity serving the first application device is different from the second entity serving the second application device; and / or, to send a first response to the first entity, the first response carrying the encrypted and / or integrity-protected session key.

[0419] In one embodiment, the first request carries a first key identifier; the first key is a key shared by the first application device and a second entity serving the first application device.

[0420] And / or, the encrypted and / or integrity-protected session key in the first response is: obtained by a second entity serving the first application device based on the first key identifier, using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key, to encrypt and / or protect the session key; and / or, the first response carries the first key identifier.

[0421] In one embodiment, the first request further carries a key type, indicating one or more of the purpose, type, and source of the requested key; the device further includes:

[0422] The second allocation unit is used to allocate a key according to the key type in the first request and obtain a key identifier.

[0423] In one embodiment, the second allocation unit is specifically used for:

[0424] When the key type is quantum key, allocate the quantum key, obtain the identifier (QKID) of the quantum key, and / or update the state of the quantum key;

[0425] And / or, when the key type is a session key, the assigned key is used as a session key to obtain the session key identifier;

[0426] And / or, when the key type is both quantum key and session key, allocate the quantum key for the session key and use the quantum key identifier as the session key identifier.

[0427] In one embodiment, the first response carries the session key identifier.

[0428] In one embodiment, the device further includes:

[0429] The ninth transceiver unit is configured to send a fifth request to a second entity serving the second application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or,

[0430] This is used to receive a fifth response sent by a second entity serving the second application device, the fifth response carrying the quantum key identifier and the synchronization result of the quantum key.

[0431] In one embodiment, the fifth request further carries: an identifier of a second entity serving the first application device and / or an identifier of a second entity serving the second application device; and / or,

[0432] The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0433] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0434] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0435] In practical applications, the second transceiver unit 1301 and the ninth transceiver unit can be implemented by a processor in the secure communication device combined with a communication interface, and the second allocation unit can be implemented by a processor in the secure communication device.

[0436] To implement the method for serving the second entity side of the second application device according to the embodiments of this application, the embodiments of this application also provide a secure communication device, which is installed on the second entity serving the second application device, such as... Figure 14 As shown, the device includes:

[0437] The third transceiver unit 1401 is configured to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or to return a fourth response to the first entity, the fourth response including an encrypted and / or integrity-protected session key.

[0438] In one embodiment, the fourth request carries a fourth key identifier; the device further includes:

[0439] The first processing unit is configured to obtain a fourth key based on the fourth key identifier, and use the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the integrity of the session key, thereby obtaining an encrypted and / or integrity-protected session key.

[0440] In one embodiment, the fourth response further carries: the session key identifier and / or the fourth key identifier.

[0441] In one embodiment, the session key identifier is a quantum key identifier; the device further includes:

[0442] The lookup unit is used to look up the quantum key based on the session key identifier; wherein,

[0443] The quantum key is a key shared by the second entity serving the first application device and the second entity serving the second application device. It comes from a shared key resource pool of the second entity serving the first application device and the second entity serving the second application device. The keys in the shared key resource pool come from a quantum key distribution network.

[0444] In one embodiment, the fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

[0445] In one embodiment, the device further includes:

[0446] The tenth transceiver unit is configured to receive a fifth request sent by a second entity serving the first application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or, to send a fifth response to the second entity serving the first application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

[0447] In one embodiment, the fifth request further carries: an identifier of a second entity serving the first application device and / or an identifier of a second entity serving the second application device; and / or,

[0448] The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0449] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0450] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0451] In practical applications, the third transceiver unit 1401 and the tenth transceiver unit can be implemented by a processor in the secure communication device combined with a communication interface, and the search unit and the first processing unit can be implemented by a processor in the secure communication device.

[0452] To implement the method on the first application device side of this application embodiment, this application embodiment also provides a secure communication device, which is installed on the first application device, such as... Figure 15 As shown, the device includes:

[0453] The fourth transceiver unit 1501 is configured to send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; and / or to receive a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0454] In one embodiment, the device further includes:

[0455] The third allocation unit allocates the first key and obtains the identifier of the first key; wherein, the first key is: a key shared by the first application device and the second entity serving the first application device;

[0456] And / or, used to derive a third key based on the first key;

[0457] And / or, used to derive a second key based on the first key;

[0458] And / or, used to derive a second key based on the first key, and to derive a third key based on the second key.

[0459] In one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the first application device, which obtains the first key based on the first key identifier, and then encrypts and / or protects the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key.

[0460] In one embodiment, the device further includes:

[0461] The second processing unit is used to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the first key, or the second key, or the third key, to obtain the session key.

[0462] In one embodiment, the second processing unit is further configured to derive a seventh key based on the session key; and / or, to derive a seventh key based on the session key and an eighth key, wherein the eighth key is a session key negotiated between the first application device and the second application device; wherein...

[0463] The seventh key is used to encrypt and / or protect the integrity of information sent by the first application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the first application device.

[0464] In one embodiment, the second response carries a first identifier; the device further includes:

[0465] The eleventh transceiver unit is used to send a first message to the second application device. The first message carries a first identifier, which is associated with the session key identifier.

[0466] And / or, for receiving a second message sent by the second application device, the second message indicating the result of obtaining the session key.

[0467] In practical applications, the fourth transceiver unit 1501 and the eleventh transceiver unit can be implemented by a processor in the secure communication device combined with a communication interface, and the second processing unit and the third allocation unit can be implemented by a processor in the secure communication device.

[0468] To implement the method on the second application device side of this application embodiment, this application embodiment also provides a secure communication device, which is installed on the second application device, such as... Figure 16 As shown, the device includes:

[0469] The fifth transceiver unit 1601 is configured to send a third request to the first entity, the third request carrying a first identifier; and / or to receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0470] In one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0471] In one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0472] In one embodiment, the device further includes:

[0473] The fourth allocation unit is used to allocate a fourth key and obtain a fourth key identifier; wherein, the fourth key is a key shared by the second application device and the second entity serving the second application device;

[0474] And / or, for deriving a sixth key based on the fourth key;

[0475] And / or, for deriving a fifth key based on the fourth key;

[0476] And / or, for deriving a fifth key based on the fourth key, and deriving a sixth key based on the fifth key.

[0477] In one embodiment, the device further includes:

[0478] The third processing unit is used to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the fourth key, the fifth key, or the sixth key, to obtain the session key.

[0479] In one embodiment, the third processing unit is further configured to derive a seventh key based on the session key; and / or, to derive a seventh key based on the session key and an eighth key, wherein the eighth key is a session key negotiated between the first application device and the second application device; wherein...

[0480] The seventh key is used to encrypt and / or protect the integrity of information sent by the second application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the second application device.

[0481] In one embodiment, the device further includes:

[0482] The twelfth transceiver unit is used to receive the first message sent by the first application device, wherein the first message carries a first identifier, and the first identifier is associated with the session key identifier;

[0483] And / or, to send a second message to the first application device, the second message indicating the result of obtaining the session key.

[0484] In one embodiment, the third request carries a fourth key identifier.

[0485] In practical applications, the fifth transceiver unit 1601 and the twelfth transceiver unit can be implemented by a processor in the secure communication device combined with a communication interface, and the third processing unit and the fourth allocation unit can be implemented by a processor in the secure communication device.

[0486] It should be noted that the secure communication device provided in the above embodiments is only illustrated by the division of the above program modules when performing secure communication. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the secure communication device and the secure communication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0487] Based on the hardware implementation of the above program modules, and in order to implement the method of the first entity side of the embodiments of this application, the embodiments of this application also provide a first entity, such as... Figure 17 As shown, the first entity 1700 includes:

[0488] The first communication interface 1701 is capable of exchanging information with other network nodes;

[0489] The first processor 1702 is connected to the first communication interface 1701 to enable information interaction with other network nodes and to execute the methods provided by one or more technical solutions on the first entity side when running a computer program. The computer program is stored in the first memory 1703.

[0490] Specifically, the first communication interface 1701 is used to send a first request to a second entity serving the first application device, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, the second entity serving the first application device being different from the second entity serving the second application device; and / or, to receive a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

[0491] In one embodiment, the first communication interface 1701 is further configured to receive a second request sent by the first application device, the second request being used to obtain the session key; and / or to send a second response to the first application device, the second response carrying the encrypted and / or integrity-protected session key.

[0492] In one embodiment, the first request carries a first key identifier; wherein the first key identifier is carried in the second request; wherein the first key is a key shared by the first application device and a second entity serving the first application device;

[0493] The encrypted and / or integrity-protected session key in the first response is obtained by: a second entity serving the first application device obtaining the first key based on the first key identifier, and encrypting and / or protecting the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key; and / or the first key identifier is carried in the first response.

[0494] In one embodiment, the first processor 1702 is configured to determine whether a second entity serving the first application device and the second application device is the same or different; wherein, the first processor 1702 is specifically configured to: determine whether they are the same or different based on the identifier of the second entity serving the first application device and the second application device; wherein, the identifier of the second entity serving the first application device and the second application device is:

[0495] Carried through the second request;

[0496] Alternatively, the first entity obtains the identifier of the first application device and / or the identifier of the second application device carried in the second request through a query.

[0497] In one embodiment, the first processor 1702 is further configured to assign a first identifier to the second request;

[0498] The first response carries a session key identifier, and the first processor 1702 is further configured to associate the first identifier with the session key identifier; and / or, the second response carries the first identifier.

[0499] In one embodiment, the first communication interface 1701 is further configured to receive a third request sent by the second application device, the third request carrying a first identifier; wherein the first identifier is sent by the first application device to the second application device;

[0500] And / or, to send a fourth request to a second entity serving the second application device, the fourth request carrying a session key identifier associated with a first identifier.

[0501] In one embodiment, the first processor 1702 is further configured to determine, based on the first identifier, whether the second entity serving the first application device and the second application device is the same or different.

[0502] In one embodiment, the session key identifier is associated with the first identifier and includes:

[0503] The session key identifier is determined by the first entity based on the first identifier.

[0504] In one embodiment, the third request carries a fourth key identifier; the fourth request carries the fourth key identifier; wherein the fourth key corresponding to the fourth key identifier is: a key shared by the second application device and the second entity serving the second application device;

[0505] The first communication interface 1701 is also configured to receive a fourth response sent by a second entity serving the second application device, the fourth response carrying an encrypted and / or integrity-protected session key; and / or send a third response to the second application device, the third response carrying an encrypted and / or integrity-protected session key;

[0506] The encrypted and / or integrity-protected session key is obtained by the second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0507] In one embodiment, the first request further carries a key type, indicating one or more of the purpose, type, and source of the requested key;

[0508] And / or, the first request may also carry an identifier of a second entity that serves the second application device.

[0509] In one embodiment, the fourth request also carries the key type, indicating one or more of the purpose, type, and source of the requested key.

[0510] In one embodiment, the fourth response also carries a fourth key identifier and / or a session key identifier.

[0511] In one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0512] In one embodiment, the first entity obtains the identifier of the first application device and / or the identifier of the second application device through a query based on the second request, including:

[0513] The first entity obtains the information by querying the third entity based on the identifier of the first application device and / or the identifier of the second application device carried in the second request.

[0514] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0515] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0516] It should be noted that the specific processing procedures of the first processor 1702 and the first communication interface 1701 can be understood by referring to the above method.

[0517] Of course, in practical applications, the various components in the first entity 1700 are coupled together via a bus system 1704. It can be understood that the bus system 1704 is used to implement communication between these components. In addition to a data bus, the bus system 1704 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 17 The general labeled all buses as Bus System 1704.

[0518] The first memory 1703 in this embodiment is used to store various types of data to support the operation of the first entity 1700. Examples of such data include any computer program used to operate on the first entity 1700.

[0519] The methods disclosed in the above embodiments of this application can be applied to the first processor 1702, or implemented by the first processor 1702. The first processor 1702 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1702. The first processor 1702 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1702 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1703. The first processor 1702 reads the information in the first memory 1703 and completes the steps of the aforementioned method in combination with its hardware.

[0520] In an exemplary embodiment, the first entity 1700 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0521] Based on the hardware implementation of the above program modules, and in order to implement the method of the second entity side serving the first application device in this application embodiment, this application embodiment also provides a second entity serving the first application device. For example... Figure 18 As shown, the second entity 1800 serving the first application device includes:

[0522] The second communication interface 1801 is capable of exchanging information with other network nodes;

[0523] The second processor 1802 is connected to the second communication interface 1801 to enable information interaction with other network nodes. When running a computer program, it executes the methods provided by one or more technical solutions on the second entity side that serve the first application device. The computer program is stored in the second memory 1803.

[0524] Specifically, the second communication interface 1801 is used to receive a first request sent by a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device, the second entity serving the first application device being different from the second entity serving the second application device; and / or, to send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

[0525] In one embodiment, the first request carries a first key identifier; the first key is a key shared by the first application device and a second entity serving the first application device.

[0526] And / or, the encrypted and / or integrity-protected session key in the first response is: obtained by a second entity serving the first application device based on the first key identifier, using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key, to encrypt and / or protect the session key; and / or, the first response carries the first key identifier.

[0527] In one embodiment, the first request further carries a key type, which indicates one or more of the purpose, type, and source of the requested key; the second processor 1802 is used to allocate a key according to the key type in the first request and obtain a key identifier.

[0528] In one embodiment, the second processor 1802 is specifically used for:

[0529] When the key type is a quantum key, allocate the quantum key, obtain the identifier of the quantum key, and / or update the state of the quantum key;

[0530] And / or, when the key type is a session key, the assigned key is used as a session key to obtain the session key identifier;

[0531] And / or, when the key type is both quantum key and session key, allocate the quantum key for the session key and use the quantum key identifier as the session key identifier.

[0532] In one embodiment, the first response carries the session key identifier.

[0533] In one embodiment, the second communication interface 1801 is further configured to send a fifth request to a second entity serving the second application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or

[0534] This is used to receive a fifth response sent by a second entity serving the second application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

[0535] In one embodiment, the fifth request further carries: an identifier of a second entity serving the first application device and / or an identifier of a second entity serving the second application device; and / or,

[0536] The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0537] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0538] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0539] It should be noted that the specific processing procedures of the second processor 1802 and the second communication interface 1801 can be understood by referring to the above method.

[0540] Of course, in practical applications, the various components in the second entity 1800 serving the first application device are coupled together via a bus system 1804. It can be understood that the bus system 1804 is used to implement communication between these components. In addition to a data bus, the bus system 1804 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 18 The general labeled all buses as Bus System 1804.

[0541] The second memory 1803 in this embodiment is used to store various types of data to support the operation of the second entity 1800 serving the first application device. Examples of such data include any computer program used to operate on the second entity 1800 serving the first application device.

[0542] The methods disclosed in the embodiments of this application can be applied to the second processor 1802, or implemented by the second processor 1802. The second processor 1802 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the second processor 1802. The second processor 1802 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1802 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the second memory 1803. The second processor 1802 reads the information in the second memory 1803 and completes the steps of the aforementioned method in combination with its hardware.

[0543] In an exemplary embodiment, the second entity 1800 serving the first application device may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0544] Based on the hardware implementation of the above program modules, and in order to implement the method of the second entity side serving the second application device in the embodiments of this application, the embodiments of this application also provide a second entity serving the second application device, such as... Figure 19 As shown, the second entity 1900 serving the second application device includes:

[0545] The third communication interface 1901 is capable of exchanging information with other network nodes;

[0546] The third processor 1902 is connected to the third communication interface 1901 to enable information interaction with other network nodes. When running a computer program, it executes the methods provided by one or more technical solutions on the second entity side that serve the second application device. The computer program is stored on the third memory 1903.

[0547] Specifically, the third communication interface 1901 is used to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or to return a fourth response to the first entity, the fourth response including an encrypted and / or integrity-protected session key.

[0548] In one embodiment, the fourth request carries a fourth key identifier; the third processor 1902 is further configured to obtain a fourth key based on the fourth key identifier, and use the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the integrity of the session key, thereby obtaining an encrypted and / or integrity-protected session key.

[0549] In one embodiment, the fourth response further carries: the session key identifier and / or the fourth key identifier.

[0550] In one embodiment, the session key identifier is a quantum key identifier; the third processor 1902 is further configured to search for the quantum key based on the session key identifier; wherein,

[0551] The quantum key is a key shared by the second entity serving the first application device and the second entity serving the second application device. It comes from a shared key resource pool of the second entity serving the first application device and the second entity serving the second application device. The keys in the shared key resource pool come from a quantum key distribution network.

[0552] In one embodiment, the fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

[0553] In one embodiment, the third communication interface 1901 is further configured to receive a fifth request sent by a second entity serving the first application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or,

[0554] Used to send a fifth response to a second entity serving the first application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

[0555] In one embodiment, the fifth request further carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device; and / or, the fifth response further carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

[0556] In one embodiment, the session key is a key shared by a second entity serving the first application device and a second entity serving the second application device.

[0557] In one embodiment, the session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, wherein the keys in the shared key resource pool come from a quantum key distribution network.

[0558] It should be noted that the specific processing procedures of the third processor 1902 and the third communication interface 1901 can be understood by referring to the above method.

[0559] Of course, in practical applications, the various components in the second entity 1900 serving the second application device are coupled together via a bus system 1904. It can be understood that the bus system 1904 is used to implement communication between these components. In addition to a data bus, the bus system 1904 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 19 The general labeled all buses as Bus System 1904.

[0560] The third memory 1903 in this embodiment is used to store various types of data to support the operation of the second entity 1900 serving the second application device. Examples of such data include any computer program used to operate on the second entity 1900 serving the second application device.

[0561] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the third processor 1902. The third processor 1902 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the third processor 1902. The third processor 1902 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1902 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a third memory 1903. The third processor 1902 reads information from the third memory 1903 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0562] In an exemplary embodiment, the second entity 1900 serving the second application device may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0563] Based on the hardware implementation of the above program modules, and in order to implement the method on the first application device side of the embodiments of this application, the embodiments of this application also provide a first application device. For example... Figure 20 As shown, the first application device 2000 includes:

[0564] The fourth communication interface 2001 is capable of exchanging information with other network nodes;

[0565] The fourth processor 2002 is connected to the fourth communication interface 2001 to enable information interaction with other network nodes. When running a computer program, it executes the methods provided by one or more technical solutions on the first application device side. The computer program is stored on the fourth memory 2003.

[0566] Specifically, the fourth communication interface 2001 is used to send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; and / or, to receive a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

[0567] In one embodiment, the fourth processor 2002 is configured to allocate a first key and obtain an identifier for the first key; wherein the first key is a key shared by the first application device and a second entity serving the first application device.

[0568] And / or, used to derive a third key based on the first key;

[0569] And / or, used to derive a second key based on the first key;

[0570] And / or, used to derive a second key based on the first key, and to derive a third key based on the second key.

[0571] In one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the first application device, which obtains the first key based on the first key identifier, and then encrypts and / or protects the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key.

[0572] In one embodiment, the fourth processor 2002 is configured to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the first key, the second key, or the third key, to obtain the session key.

[0573] In one embodiment, the fourth processor 2002 is further configured to derive a seventh key based on the session key; and / or, to derive a seventh key based on the session key and an eighth key, wherein the eighth key is a session key negotiated between the first application device and the second application device; wherein...

[0574] The seventh key is used to encrypt and / or protect the integrity of information sent by the first application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the first application device.

[0575] In one embodiment, the second response carries a first identifier; the fourth communication interface 2001 is further configured to send a first message to the second application device, the first message carrying the first identifier, the first identifier being associated with the session key identifier; and / or, to receive a second message sent by the second application device, the second message indicating the acquisition result of the session key.

[0576] It should be noted that the specific processing procedures of the fourth processor 2002 and the fourth communication interface 2001 can be understood by referring to the above method.

[0577] Of course, in practical applications, the various components in the first application device 2000 are coupled together through the bus system 2004. It can be understood that the bus system 2004 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 2004 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 20 The general labeled all buses as Bus System 2004.

[0578] The fourth memory 2003 in this embodiment is used to store various types of data to support the operation of the first application device 2000. Examples of such data include any computer program used to operate on the first application device 2000.

[0579] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the fourth processor 2002. The fourth processor 2002 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuits in the hardware of the fourth processor 2002 or by instructions in software form. The fourth processor 2002 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fourth processor 2002 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a fourth memory 2003. The fourth processor 2002 reads information from the fourth memory 2003 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0580] In an exemplary embodiment, the first application device 2000 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0581] Based on the hardware implementation of the above program modules, and in order to implement the method on the second application device side of this application embodiment, this application embodiment also provides a second node. For example... Figure 21 As shown, the second application device 2100 includes:

[0582] The fifth communication interface 2101 is capable of exchanging information with other network nodes;

[0583] The fifth processor 2102 is connected to the fifth communication interface 2101 to enable information interaction with other network nodes. When running a computer program, it executes the methods provided by one or more technical solutions on the second application device side. The computer program is stored on the fifth memory 2103.

[0584] Specifically, the fifth communication interface 2101 is used to send a third request to the first entity, the third request carrying a first identifier; and / or to receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

[0585] In one embodiment, the encrypted and / or integrity-protected session key is obtained by a second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

[0586] In one embodiment, the third response further carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

[0587] In one embodiment, the fifth processor 2102 is configured to allocate a fourth key and obtain a fourth key identifier; wherein the fourth key is a key shared by the second application device and a second entity serving the second application device;

[0588] And / or, for deriving a sixth key based on the fourth key;

[0589] And / or, for deriving a fifth key based on the fourth key;

[0590] And / or, for deriving a fifth key based on the fourth key, and deriving a sixth key based on the fifth key.

[0591] In one embodiment, the fifth processor 2102 is further configured to perform integrity verification and / or decryption on the encrypted and / or integrity-protected session key based on the fourth key, or the fifth key, or the sixth key, to obtain the session key.

[0592] In one embodiment, the fifth processor 2102 is further configured to derive a seventh key based on the session key; and / or, to derive a seventh key based on the session key and an eighth key, wherein the eighth key is a session key negotiated between the first application device and the second application device; wherein...

[0593] The seventh key is used to encrypt and / or protect the integrity of information sent by the second application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the second application device.

[0594] In one embodiment, the fifth communication interface 2101 is further configured to receive the first message sent by the first application device, the first message carrying a first identifier, the first identifier being associated with the session key identifier;

[0595] And / or, to send a second message to the first application device, the second message indicating the result of obtaining the session key.

[0596] In one embodiment, the third request carries a fourth key identifier.

[0597] It should be noted that the specific processing procedures of the fifth processor 2102 and the fifth communication interface 2101 can be understood by referring to the above method.

[0598] Of course, in practical applications, the various components in the second application device 2100 are coupled together through the bus system 2104. It can be understood that the bus system 2104 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 2104 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 21 The general designated all buses as Bus System 2104.

[0599] The fifth memory 2103 in this embodiment is used to store various types of data to support the operation of the second application device 2100. Examples of such data include any computer program used to operate on the second application device 2100.

[0600] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the fifth processor 2102. The fifth processor 2102 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuits in the hardware of the fifth processor 2102 or by instructions in software form. The fifth processor 2102 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fifth processor 2102 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a fifth memory 2103. The fifth processor 2102 reads information from the fifth memory 2103 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0601] In an exemplary embodiment, the second application device 2100 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0602] It is understood that the memories (first memory 1703, second memory 1803, third memory 1903, fourth memory 2003, and fifth memory 2103) in the embodiments of this application can be volatile memories or non-volatile memories, or may include both volatile and non-volatile memories. Specifically, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk storage device or a magnetic tape storage device. Volatile memory can be random access memory (RAM), which is used as an external cache.By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memory.

[0603] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 1703 storing a computer program, which can be executed by a first processor 1702 of a first entity 1700 to complete the steps described in the aforementioned first entity-side method. Another example is a second memory 1803 storing a computer program, which can be executed by a second processor 1802 of a second entity 1800 serving a first application device to complete the steps described in the aforementioned second entity-side method serving the first application device. Yet another example is a computer program executed by a third processor 1902 of a second entity 1900 serving a second application device to complete the steps described in the aforementioned second entity-side method serving the second application device. Still another example is a fourth memory 2003 storing a computer program, which can be executed by a fourth processor 2002 of a first application device 2000 to complete the steps described in the aforementioned first application device-side method. For example, a fifth memory 2103 may be included to store a computer program, which may be executed by a fifth processor 2102 of the second application device 2100 to complete the steps described in the method on the second application device side. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0604] Exemplary embodiments of this application also provide a computer program product, including a computer program executable by a first processor 1702 of a first entity 1700 to complete the steps described in the aforementioned first entity-side method. The computer program can be executed by a second processor 1802 of a second entity 1800 serving a first application device to complete the steps described in the aforementioned second entity-side method serving the first application device. The computer program can be executed by a third processor 1902 of a second entity 1900 serving a second application device to complete the steps described in the aforementioned second entity-side method serving the second application device. The computer program can be executed by a fourth processor 2002 of a first application device 2000 to complete the steps described in the aforementioned first application device-side method. The computer program can be executed by a fifth processor 2102 of a second application device 2100 to complete the steps described in the aforementioned second application device-side method.

[0605] It should be noted that terms such as "first" and "second" are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. "Multiple" can refer to two or more items, and "multiple" can refer to two or more items. The term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, the term "one or more" in this document refers to any combination of at least two of the multiple elements. For example, including one or more of A, B, and C can represent including any one or at least two or more elements selected from the set consisting of A, B, and C.

[0606] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0607] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. A secure communication method, characterized in that, Applied to a first entity, the method includes: A first request is sent to a second entity that serves the first application device. The first request is used to obtain a session key, which is used for secure communication between the first application device and the second application device. The second entity that serves the first application device is different from the second entity that serves the second application device. And / or, receive a first response from the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

2. The method according to claim 1, characterized in that, The method further includes: Receive a second request sent by the first application device, the second request being used to obtain the session key; And / or, send a second response to the first application device, the second response carrying an encrypted and / or integrity-protected session key.

3. The method according to claim 1 or 2, characterized in that, The first request carries a first key identifier; wherein the first key identifier is carried in the second request; wherein the first key is a key shared by the first application device and the second entity serving the first application device; The encrypted and / or integrity-protected session key in the first response is obtained by: a second entity serving the first application device obtaining the first key based on the first key identifier, and encrypting and / or protecting the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key; and / or the first key identifier is carried in the first response.

4. The method according to claim 2, characterized in that, Before sending the first request, the method further includes: The second entity that is determined to serve the first application device and the second application device is the same or different; wherein, the determination that the second entity that is determined to serve the first application device and the second application device is the same or different includes: Whether they are the same or different is determined based on the identifier of the second entity that serves the first application device and the second application device; The identifier of the second entity serving the first application device and the second application device is: Carried through the second request; Alternatively, the first entity obtains the identifier of the first application device and / or the identifier of the second application device carried in the second request through a query.

5. The method according to claim 2, characterized in that, The method further includes: Assign a first identifier to the second request; The first response carries a session key identifier, and the method further includes: associating the first identifier with the session key identifier; and / or, the second response carries the first identifier.

6. The method according to claim 2, characterized in that, The method further includes: The system receives a third request sent by the second application device, the third request carrying a first identifier; wherein the first identifier is sent by the first application device to the second application device. And / or, send a fourth request to a second entity serving the second application device, the fourth request carrying a session key identifier associated with the first identifier.

7. The method according to claim 5 or 6, characterized in that, The method further includes: The second entity identified by the first identifier as serving the first application device and the second application device is either the same or different.

8. The method according to claim 6, characterized in that, The session key identifier is associated with the first identifier and includes: The session key identifier is determined by the first entity based on the first identifier.

9. The method according to claim 6, characterized in that, The third request carries the fourth key identifier; the fourth request carries the fourth key identifier; wherein, the fourth key is: a key shared by the second application device and the second entity serving the second application device; The method further includes: Receive a fourth response from a second entity serving the second application device, the fourth response including an encrypted and / or integrity-protected session key; and / or send a third response to the second application device, the third response carrying an encrypted and / or integrity-protected session key; The encrypted and / or integrity-protected session key is obtained by the second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and encrypts and / or protects the session key using the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key.

10. The method according to claim 1, characterized in that, The first request also carries a key type, which indicates one or more of the purpose, type, and source of the requested key; And / or, the first request may also carry an identifier of a second entity that serves the second application device.

11. The method according to any one of claims 6 to 10, characterized in that, The fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

12. The method according to claim 9, characterized in that, The fourth response also carries a fourth key identifier and / or a session key identifier.

13. The method according to claim 9, characterized in that, The third response also carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

14. The method according to claim 4, characterized in that, The first entity obtains the identifier of the first application device and / or the identifier of the second application device through a query based on the second request, including: The first entity obtains the information by querying the third entity based on the identifier of the first application device and / or the identifier of the second application device carried in the second request.

15. The method according to claim 1, characterized in that, The session key is a key shared by the second entity serving the first application device and the second entity serving the second application device.

16. The method according to claim 15, characterized in that, The session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, and the keys in the shared key resource pool come from a quantum key distribution network.

17. A secure communication method, characterized in that, The method, applied to a second entity serving a first application device, includes: The system receives a first request from a first entity, the first request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; the second entity serving the first application device is different from the second entity serving the second application device. And / or, send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

18. The method according to claim 17, characterized in that, The first request carries a first key identifier; the first key is a key shared by the first application device and the second entity serving the first application device. And / or, the encrypted and / or integrity-protected session key in the first response is obtained by the second entity serving the first application device by encrypting and / or protecting the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key; And / or, the first response carries the first key identifier.

19. The method according to claim 17 or 18, characterized in that, The first request also carries a key type, indicating one or more of the purpose, type, and source of the requested key; the method further includes: Assign a key according to the key type in the first request and obtain a key identifier.

20. The method according to claim 19, characterized in that, The step of allocating a key according to the key type in the first request and obtaining a key identifier includes: When the key type is a quantum key, allocate the quantum key, obtain the identifier of the quantum key, and / or update the state of the quantum key; And / or, when the key type is a session key, the assigned key is used as a session key to obtain the session key identifier; And / or, when the key type is both quantum key and session key, allocate the quantum key for the session key and use the quantum key identifier as the session key identifier.

21. The method according to claim 20, characterized in that, The first response carries the session key identifier.

22. The method according to claim 20, characterized in that, The method further includes: A fifth request is sent to a second entity serving the second application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or Receive a fifth response from a second entity serving the second application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

23. The method according to claim 22, characterized in that, The fifth request also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device; And / or, the fifth response may also carry: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

24. The method according to any one of claims 17 to 23, characterized in that, The session key is a key shared by the second entity serving the first application device and the second entity serving the second application device.

25. The method according to any one of claims 17 to 24, characterized in that, The session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, and the keys in the shared key resource pool come from a quantum key distribution network.

26. A secure communication method, characterized in that, The method, applied to a second entity serving a second application device, includes: Receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; And / or, return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

27. The method according to claim 26, characterized in that, The fourth request carries a fourth key identifier; the method further includes: The fourth key is obtained based on the fourth key identifier; The session key is encrypted and / or its integrity is protected using the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth or fifth key.

28. The method according to claim 26, characterized in that, The fourth response also carries: the session key identifier and / or the fourth key identifier.

29. The method according to any one of claims 26 to 28, characterized in that, The session key identifier is a quantum key identifier; the method further includes: The quantum key is retrieved based on the session key identifier; wherein... The quantum key is a key shared by the second entity serving the first application device and the second entity serving the second application device. It comes from a shared key resource pool of the second entity serving the first application device and the second entity serving the second application device. The keys in the shared key resource pool come from a quantum key distribution network.

30. The method according to claim 26, characterized in that, The fourth request also carries a key type, indicating one or more of the purpose, type, and source of the requested key.

31. The method according to any one of claims 26 to 30, characterized in that, The method further includes: receiving a fifth request sent by a second entity serving the first application device, the fifth request being used to synchronize the state of the quantum key, the fifth request carrying the quantum key identifier and / or the state of the quantum key; and / or, A fifth response is sent to a second entity serving the first application device, the fifth response carrying the quantum key identifier and / or the synchronization result of the quantum key.

32. The method according to claim 31, characterized in that, The fifth request also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device; And / or, The fifth response also carries: the identifier of the second entity serving the first application device and / or the identifier of the second entity serving the second application device.

33. The method according to any one of claims 26 to 32, characterized in that, The session key is a key shared by the second entity serving the first application device and the second entity serving the second application device.

34. The method according to any one of claims 26 to 33, characterized in that, The session key comes from a shared key resource pool of a second entity serving the first application device and a second entity serving the second application device, and the keys in the shared key resource pool come from a quantum key distribution network.

35. A secure communication method, characterized in that, Applied to a first application device, the method includes: Send a second request to the first entity, the second request being used to obtain a session key, the session key being used for secure communication between the first application device and the second application device; And / or, receive a second response from the first entity, the second response carrying an encrypted and / or integrity-protected session key.

36. The method according to claim 35, characterized in that, The method further includes: Assign a first key and obtain the identifier of the first key; wherein, the first key is: a key shared by the first application device and the second entity serving the first application device; And / or, derive a third key based on the first key; And / or, derive a second key based on the first key; And / or, derive a second key based on the first key, and derive a third key based on the second key.

37. The method according to claim 35 or 36, characterized in that, The encrypted and / or integrity-protected session key is obtained by a second entity serving the first application device, which obtains the first key based on the first key identifier, and then encrypts and / or protects the session key using the first key, or a second key derived from the first key, or a third key derived from the first key or the second key.

38. The method according to claim 37, characterized in that, The method further includes: Based on the first key, or the second key, or the third key, the encrypted and / or integrity-protected session key is subjected to integrity verification and / or decryption to obtain the session key.

39. The method according to claim 38, characterized in that, The method further includes: A seventh key is derived based on the session key; And / or, a seventh key is derived based on the session key and the eighth key, wherein the eighth key is the session key negotiated between the first application device and the second application device; wherein, The seventh key is used to encrypt and / or protect the integrity of information sent by the first application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the first application device.

40. The method according to any one of claims 35 to 39, characterized in that, The second response carries a first identifier; the method further includes: Send a first message to the second application device, the first message carrying a first identifier, the first identifier being associated with the session key identifier; And / or, receive a second message sent by the second application device, the second message indicating the result of obtaining the session key.

41. A secure communication method, characterized in that, Applied to a second application device, the method includes: Send a third request to the first entity, the third request carrying the first identifier; And / or, receive a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

42. The method according to claim 41, characterized in that, The encrypted and / or integrity-protected session key is obtained by a second entity serving the second application device, which obtains the fourth key based on the fourth key identifier, and uses the fourth key, or a fifth key derived from the fourth key, or a sixth key derived from the fourth key or the fifth key to encrypt and / or protect the session key.

43. The method according to claim 41, characterized in that, The third response also carries one or more of the following: the identifier of the first application device, the identifier of the second application device, the fourth key identifier, and the first identifier.

44. The method according to any one of claims 41 to 43, characterized in that, The method further includes: Assign a fourth key and obtain a fourth key identifier; wherein, the fourth key is a key shared by the second application device and the second entity serving the second application device; And / or, derive a sixth key based on the fourth key; And / or, derive a fifth key based on the fourth key; And / or, derive a fifth key based on the fourth key, and derive a sixth key based on the fifth key.

45. The method according to claim 44, characterized in that, The method further includes: Based on the fourth key, or the fifth key, or the sixth key, the encrypted and / or integrity-protected session key is subjected to integrity verification and / or decryption to obtain the session key.

46. ​​The method according to claim 45, characterized in that, The method further includes: A seventh key is derived based on the session key; And / or, a seventh key is derived based on the session key and the eighth key, wherein the eighth key is the session key negotiated between the first application device and the second application device; wherein, The seventh key is used to encrypt and / or protect the integrity of information sent by the second application device during secure communication, and / or to decrypt and / or verify the integrity of information received by the second application device.

47. The method according to any one of claims 41 to 46, characterized in that, The method further includes: The system receives the first message sent by the first application device, the first message carrying a first identifier, and the first identifier being associated with the session key identifier; And / or, send a second message to the first application device, the second message indicating the result of obtaining the session key.

48. The method according to any one of claims 41 to 47, characterized in that, The third request carries a fourth key identifier.

49. A secure communication device, characterized in that, include: The first transceiver unit is configured to send a first request to a second entity serving the first application device. The first request is used to obtain a session key. The session key is used for secure communication between the first application device and the second application device. The second entity serving the first application device is different from the second entity serving the second application device. And / or, for receiving a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

50. A secure communication device, characterized in that, include: The second transceiver unit is used to receive a first request sent by the first entity. The first request is used to obtain a session key. The session key is used for secure communication between the first application device and the second application device. The second entity serving the first application device is different from the second entity serving the second application device. And / or, to send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

51. A secure communication device, characterized in that, include: The third transceiver unit is used to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; And / or, to return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

52. A secure communication device, characterized in that, include: The fourth transceiver unit is used to send a second request to the first entity. The second request is used to obtain a session key, which is used for secure communication between the first application device and the second application device. And / or, for receiving a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

53. A secure communication device, characterized in that, include: The fifth transceiver unit is used to send a third request to the first entity, the third request carrying a first identifier; And / or, for receiving a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

54. A first entity, characterized in that, include: A first processor and a first communication interface; wherein... The first communication interface is used to send a first request to a second entity that serves the first application device. The first request is used to obtain a session key. The session key is used for secure communication between the first application device and the second application device. The second entity that serves the first application device is different from the second entity that serves the second application device. And / or, for receiving a first response sent by the second entity serving the first application device, the first response carrying an encrypted and / or integrity-protected session key.

55. A second entity serving a first application device, characterized in that, include: A second processor and a second communication interface; wherein... The second communication interface is used to receive a first request sent by the first entity. The first request is used to obtain a session key. The session key is used for secure communication between the first application device and the second application device. The second entity serving the first application device is different from the second entity serving the second application device. And / or, to send a first response to the first entity, the first response carrying an encrypted and / or integrity-protected session key.

56. A second entity serving a second application device, characterized in that, include: A third processor and a third communication interface; wherein... The third communication interface is used to receive a fourth request sent by the first entity, the fourth request carrying a session key identifier; and / or to return a fourth response to the first entity, the fourth response carrying an encrypted and / or integrity-protected session key.

57. A first application device, characterized in that, include: The fourth processor and the fourth communication interface; wherein, The fourth communication interface is used to send a second request to the first entity. The second request is used to obtain a session key. The session key is used for secure communication between the first application device and the second application device. And / or, for receiving a second response sent by the first entity, the second response carrying an encrypted and / or integrity-protected session key.

58. A second application device, characterized in that, include: The fifth processor and the fifth communication interface; among which, The fifth communication interface is used to send a third request to the first entity, the third request carrying a first identifier; And / or, for receiving a third response sent by the first entity, the third response carrying an encrypted and / or integrity-protected session key.

59. A communication device, characterized in that, The communication device includes a first entity, a second entity serving a first application device, a second entity serving a second application device, the first application device, or the second application device. The communication device includes a processor and a memory for storing computer programs capable of running on the processor. When the processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 16, or the steps of the method according to any one of claims 17 to 25, or the steps of the method according to any one of claims 26 to 34, or the steps of the method according to any one of claims 35 to 40, or the steps of the method according to any one of claims 41 to 48.

60. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 16, or the steps of the method according to any one of claims 17 to 25, or the steps of the method according to any one of claims 26 to 34, or the steps of the method according to any one of claims 35 to 40, or the steps of the method according to any one of claims 41 to 48.

61. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 48.