Secret communication method and device, communication node, storage medium and program product

By dividing the quantum cryptography service center into primary and secondary platforms, management and services are separated, which solves the scalability and complexity problems of quantum secure communication systems, improves the system's flexibility and adaptability, and makes it suitable for various business applications.

CN121907436APending Publication Date: 2026-04-21CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2025-09-12
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In the existing quantum secure communication system architecture, the scalability of the quantum cryptography service center is not strong, which leads to increased system complexity and operational and maintenance difficulties when there are many types or numbers of applications, and the security capabilities of different vendors vary.

Method used

The quantum cryptography service center is divided into a primary quantum cryptography service platform and a secondary quantum cryptography service platform to separate management and services. The secondary quantum cryptography service platform is responsible for business services, while the primary quantum cryptography service platform is responsible for key management and unified cryptographic security services. The modular design is adopted to adapt to different applications.

Benefits of technology

It reduces the implementation complexity of quantum cryptography service centers, improves the system's flexibility and scalability, adapts to more business applications, and solves the problem of inconsistent security levels caused by differences in the security capabilities of different vendors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907436A_ABST
    Figure CN121907436A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a secret communication method and device, a communication node, a storage medium and a program product. The method comprises the following steps: a first entity obtains a first session key and sends a first message to a second entity; the first message is used for requesting encryption and / or integrity protection of the first session key; the first message at least comprises the first session key; and / or, the first entity receives a second message sent by the second entity, the second message comprising the encrypted and / or integrity protected first session key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and specifically to a secure communication method, apparatus, communication node, storage medium, and program product. Background Technology

[0002] To meet the future needs of diversified business operations and large-scale users for quantum key distribution, the following proposals are put forward: Figure 1 The secure communication system architecture shown effectively integrates classical and quantum communication systems, providing support for the development of secure communication services based on quantum information security technology. The architecture includes a quantum cryptography service network (layer) in the middle, separating the previously tightly coupled quantum key distribution (QKD) network layer and quantum cryptography application layer. This reduces the coupling between the two, thereby avoiding the enormous service pressure on the QKD network caused by access from numerous upper-layer applications.

[0003] In this system architecture, quantum cryptography service centers typically deploy a single quantum cryptography service platform centrally. This requires the platform to be compatible with various communication applications, limiting the system's scalability. While a single quantum cryptography service platform can support a small number of applications, it needs to interface with many different upper-layer applications and adapt to various business applications when the number of applications is large. This significantly increases the implementation complexity and workload of the quantum cryptography service center, making the system cumbersome, hindering its operation and maintenance, and making it difficult to adapt to and expand with new business applications. Summary of the Invention

[0004] To address the existing technical problems, embodiments of the present invention provide a secure communication method, apparatus, communication node, storage medium, and program product.

[0005] To achieve the above objectives, the technical solution of this invention is implemented as follows:

[0006] In a first aspect, embodiments of the present invention provide a secure communication method, the method being applied to a first entity, the method comprising: the first entity obtaining a first session key and sending a first message to a second entity; the first message being used to request encryption and / or integrity protection of the first session key; the first message including at least the first session key.

[0007] And / or, the first entity receives a second message sent by the second entity, the second message including a first session key encrypted and / or protected for integrity.

[0008] In the above scheme, the method further includes: the first entity receiving a first request sent by the first application device, the first request being used to obtain a first session key, and the first request including at least a first key identifier;

[0009] And / or, the first entity sends a first response to the first application device, the first response including a first session key encrypted and / or protected for integrity.

[0010] In the above scheme, the method further includes: the first entity assigning a first identifier, the first identifier being associated with the first session key and / or the first session key identifier.

[0011] In the above scheme, the first identifier corresponds to the first mode, and the first mode is used to indicate the acquisition method and / or security protection method of the first session key.

[0012] In the above scheme, the first message further includes at least one of the following: a first key identifier and information related to a first session key; and / or,

[0013] The second message also includes at least one of the following: a first key identifier, information related to a first session key after encryption and / or integrity protection; and / or,

[0014] The first response also includes the first identifier.

[0015] In the above scheme, the first entity obtains the first session key, including:

[0016] The first entity acquires a quantum random number and generates a first session key based on the quantum random number.

[0017] In the above scheme, the first entity obtains the quantum random number by: the first entity obtaining the quantum random number from a quantum random number generator (QRNG) or the second entity.

[0018] In the above scheme, generating the first session key based on the quantum random number includes: the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, and generates the first session key based on the quantum random number; wherein, the second application device is a device that communicates with the first application device.

[0019] In the above scheme, the first request also includes second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device;

[0020] And / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: when the first entity determines that the second identification information and the third identification information are the same, the second entity serving the first application device is determined to be the same as the second entity serving the second application device.

[0021] In the above scheme, the first request carries the identifier of the first application device and / or the identifier of the second application device;

[0022] And / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: the first entity queries the third entity based on the identifier of the first application device to obtain second identifier information, and / or queries the third entity based on the identifier of the second application device to obtain third identifier information; the second identifier information is the identifier of the second entity serving the first application device, and the third identifier information is the identifier of the second entity serving the second application device;

[0023] When the first entity determines that the second identification information and the third identification information are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device.

[0024] In the above scheme, the first key corresponding to the first key identifier is used to generate the second key and then generate the first protection key and / or the second protection key, or is used to generate the first protection key and / or the second protection key;

[0025] The encrypted and / or integrity-protected first session key is obtained by encrypting and / or protecting the integrity of the first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key.

[0026] In the above scheme, the method further includes: the first entity receiving a second request sent by the second application device, the second request being used to obtain a first session key, and the second request including at least a third key identifier;

[0027] And / or, the first entity sends a second response to the second application device, the second response including a first session key that is encrypted and / or protected for integrity.

[0028] In the above scheme, the second request further includes a first identifier; the method further includes: the first entity determining a first mode based on the first identifier and searching for a first session key associated with the first identifier.

[0029] In the above scheme, the method further includes: the first entity sending a third message to the second entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message including at least the first session key;

[0030] And / or, the first entity receives a fourth message sent by the second entity, the fourth message including a first session key that is encrypted and / or protected for integrity.

[0031] In the above scheme, the third message further includes at least one of the third key identifier and related information of the first session key; and / or,

[0032] The fourth message also includes at least one of the information related to the third key identifier and the first session key after encryption and / or integrity protection.

[0033] In the above scheme, the third key corresponding to the third key identifier is used to generate the fourth key, which in turn generates the third protection key and / or the fourth protection key, or is used to generate the third protection key and the fourth protection key;

[0034] The encrypted and / or integrity-protected first session key is obtained by encrypting and / or protecting the integrity of the first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key.

[0035] In the above scheme, one or more first entities and the second entity interact with each other through a first interface.

[0036] In the above scheme, different first entities correspond to different applications, and / or, different first entities correspond to different types of applications, and / or, different first entities correspond to applications of different operating entities.

[0037] In the above scheme, the first message includes a first session key that is encrypted and / or protected for integrity; and / or, the third message includes a first session key that is encrypted and / or protected for integrity.

[0038] In a second aspect, embodiments of the present invention provide a secure communication method, the method being applied to a second entity, the method comprising: the second entity receiving a first message sent by a first entity, the first message being used to request encryption and / or integrity protection of a first session key, the first message including at least the first session key;

[0039] And / or, the second entity encrypts and / or protects the integrity of the first session key, and sends a second message to the first entity, the second message including the encrypted and / or integrity-protected first session key.

[0040] In the above scheme, the first message further includes a first key identifier related to the first application device; the second entity encrypts and / or protects the integrity of the first session key, including:

[0041] The second entity obtains the first key based on the first key identifier;

[0042] A second key is generated based on the first key, and a first protection key and / or a second protection key are generated based on the second key; or, a first protection key and / or a second protection key are generated based on the first key.

[0043] The first session key is encrypted and / or its integrity is protected based on the first key, or the second key, or the first protection key and / or the second protection key.

[0044] In the above scheme, the method further includes: the second entity receiving a third message sent by the first entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message including at least the first session key;

[0045] And / or, the second entity encrypts and / or protects the integrity of the first session key, and sends a fourth message to the first entity, the fourth message including the encrypted and / or integrity-protected first session key.

[0046] In the above scheme, the third message further includes at least one of a third key identifier related to the second application device and information related to the first session key; and / or,

[0047] The fourth message also includes at least one of the information related to the third key identifier and the first session key after encryption and / or integrity protection.

[0048] In the above scheme, the second entity encrypts and / or protects the integrity of the first session key, including: the second entity obtains the third key based on the third key identifier;

[0049] A fourth key is generated based on the third key, and a third protection key and / or a fourth protection key are generated based on the fourth key; or, a third protection key and / or a fourth protection key are generated based on the third key.

[0050] The first session key is encrypted and / or its integrity is protected based on the third key, or the fourth key, or the third protection key and / or the fourth protection key.

[0051] In the above scheme, the first message also includes information related to the first session key; and / or, the second message also includes information related to the first session key after encryption and / or integrity protection.

[0052] In the above scheme, the first message includes a first session key that is encrypted and / or protected for integrity; and / or, the third message includes a first session key that is encrypted and / or protected for integrity.

[0053] Thirdly, embodiments of the present invention provide a secure communication method, the method being applied to a first application device, the method comprising: the first application device obtaining a first key identifier, sending a first request to a first entity, the first request being used to obtain a first session key, and the first request including at least the first key identifier;

[0054] And / or, the first application device receives a first response sent by the first entity, the first response including a first session key encrypted and / or protected for integrity.

[0055] In the above scheme, the first application device obtains the first key identifier by: the cryptographic middleware of the first application device allocating the first key and obtaining the first key identifier corresponding to the first key.

[0056] In the above scheme, the method further includes: the first application device generating a second key based on a first key, and generating a first protection key and / or a second protection key based on the second key; or,

[0057] The first application device generates a first protection key and / or a second protection key based on the first key.

[0058] In the above scheme, the method further includes: the first application device performing integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key, to obtain the first session key.

[0059] In the above scheme, the first response further includes a first identifier; the first identifier is associated with the first session key and / or the first session key identifier.

[0060] In the above scheme, the first identifier corresponds to the first mode, and the first mode is used to indicate the acquisition method and / or security protection method of the first session key.

[0061] In the above scheme, the method further includes: the first application device sending a fifth message to the second application device, wherein the fifth message includes at least the first identifier.

[0062] In the above scheme, the method further includes: the first application device generating a third session key and / or a fourth session key based on the first session key, or generating a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated by the first application device and the second application device;

[0063] The third session key and / or the fourth session key are used to encrypt and / or protect the integrity of the information sent and / or received by the first application device during communication, and / or to decrypt and / or verify the integrity.

[0064] In the above scheme, the method further includes: the first application device sending a third request to the second application device, the third request being used to request the establishment of a connection;

[0065] And / or, the first application device receives a third response sent by the second application device, the third response indicating that a connection has been established.

[0066] In the above scheme, the third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or,

[0067] The third response includes third identification information, which is the identification information of the second entity serving the second application device.

[0068] In the above scheme, the first request further includes second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; and / or, the first request further includes the identification of the first application device and / or the identification of the second application device.

[0069] Fourthly, embodiments of the present invention provide a secure communication method, the method being applied to a second application device, the method comprising:

[0070] The second application device obtains the third key identifier and sends a second request to the first entity. The second request is used to obtain the first session key, and the second request includes at least the third key identifier.

[0071] And / or, the second application device receives a second response sent by the first entity, the second response including a first session key encrypted and / or protected for integrity.

[0072] In the above scheme, the second application device obtains the third key identifier by: the cryptographic middleware of the second application device allocating the third key and obtaining the third key identifier corresponding to the third key.

[0073] In the above scheme, the method further includes: the second application device generating a fourth key based on the third key, and generating a third protection key and / or a fourth protection key based on the fourth key; or,

[0074] The second application device generates a third protection key and / or a fourth protection key based on the third key.

[0075] In the above scheme, the method further includes: the second application device performing integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key, to obtain the first session key.

[0076] In the above scheme, the method further includes: the second application device receiving a fifth message sent by the first application device, the fifth message including at least a first identifier, the first identifier being associated with the first session key and / or the first session key identifier, and / or the first identifier corresponding to a first mode, the first mode being used to indicate the acquisition method and / or security protection method of the first session key;

[0077] And / or, the second request may also include the first identifier.

[0078] In the above scheme, the method further includes: the second application device generating a third session key and / or a fourth session key based on the first session key, or generating a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated between the second application device and the first application device;

[0079] The third session key and / or the fourth session key are used to encrypt and / or protect the integrity of information sent and / or received by the second application device during communication, and / or to decrypt and / or verify the integrity.

[0080] In the above scheme, the method further includes: the second application device receiving a third request sent by the first application device, the third request being used to request the establishment of a connection;

[0081] The second application device sends a third response to the first application device, the third response indicating that a connection has been established.

[0082] In the above scheme, the third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or,

[0083] The third response includes third identification information, which is the identification information of the second entity serving the second application device.

[0084] Fifthly, embodiments of the present invention provide a secure communication device, the device being applied to a first entity, the device comprising: a first processing unit and a first communication unit; wherein,

[0085] The first processing unit is used to obtain the first session key;

[0086] The first communication unit is configured to send a first message to the second entity; the first message is configured to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key; and / or, is configured to receive a second message sent by the second entity, the second message including the first session key after encryption and / or integrity protection.

[0087] Sixthly, embodiments of the present invention provide a secure communication device, the device being applied to a second entity, the device comprising: a second communication unit and / or a second processing unit; wherein,

[0088] The second communication unit is configured to receive a first message sent by the first entity, the first message being used to request encryption and / or integrity protection of the first session key, and the first message including at least the first session key;

[0089] The second processing unit is used to encrypt and / or protect the integrity of the first session key;

[0090] The second communication unit is further configured to send a second message to the second entity, the second message including a first session key that is encrypted and / or protected for integrity.

[0091] In a seventh aspect, embodiments of the present invention provide a secure communication device, the device being applied to a first application device, the device comprising: a third processing unit and a third communication unit; wherein,

[0092] The third processing unit is used to obtain the first key identifier;

[0093] The third communication unit is configured to send a first request to the first entity, the first request being used to obtain a first session key, the first request including at least the first key identifier; and / or to receive a first response sent by the first entity, the first response including the first session key after encryption and / or integrity protection.

[0094] Eighthly, embodiments of the present invention provide a secure communication device, the device being applied to a second application device, the device comprising: a fourth processing unit and a fourth communication unit; wherein,

[0095] The fourth processing unit is used to obtain the third key identifier;

[0096] The fourth communication unit is configured to send a second request to the first entity, the second request being used to obtain a first session key, the second request including at least the third key identifier; and / or to receive a second response sent by the first entity, the second response including the first session key after encryption and / or integrity protection.

[0097] Ninthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the secure communication method described in any one of the embodiments of the present invention.

[0098] In a tenth aspect, embodiments of the present invention provide a communication node, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of any of the secure communication methods described in the embodiments of the present invention.

[0099] Eleventhly, embodiments of the present invention provide a computer program product, including computer program instructions that cause a computer to perform the steps of the secure communication method described in any one of the embodiments of the present invention.

[0100] The secure communication method, apparatus, communication node, storage medium, and program product provided in the embodiments of the present invention include: a first entity obtaining a first session key and sending a first message to a second entity; the first message is used to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key; the second entity encrypts and / or protects the integrity of the first session key and sends a second message to the first entity, the second message including the encrypted and / or integrity-protected first session key. The technical solution of this invention involves obtaining a first session key using a first entity and securing the first session key using a second entity. Specifically, this invention divides the quantum cryptography service platform in the quantum cryptography service center into a primary quantum cryptography service platform (i.e., the second entity) and a secondary quantum cryptography service platform (i.e., the first entity), achieving separation of management and services. The secondary quantum cryptography service platform (i.e., the first entity) is primarily responsible for business services and can be deployed for different applications. The modular design reduces the implementation complexity of the quantum cryptography service center, facilitates its operation and maintenance, and allows for adaptation and expansion to more new business applications. The primary quantum cryptography service platform (i.e., the second entity) is primarily responsible for key management and services, unifying cryptographic security service capabilities and solving the problem of inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities. Attached Figure Description

[0101] Figure 1 A schematic diagram of the existing quantum secure communication system architecture;

[0102] Figure 2 This is a schematic diagram of the quantum secure communication system architecture applied to the secure communication method of this invention.

[0103] Figure 3 This is a schematic diagram of the key system related to the secure communication method of this invention.

[0104] Figure 4 A schematic diagram illustrating a deployment application scenario of a quantum secure communication system for which the secure communication method of this invention is applied;

[0105] Figure 5 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 1 ;

[0106] Figure 6 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 2 ;

[0107] Figure 7 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 3 ;

[0108] Figure 8 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 4 ;

[0109] Figure 9 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 1 ;

[0110] Figure 10 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 2 ;

[0111] Figure 11 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 3 ;

[0112] Figure 12 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 1 ;

[0113] Figure 13 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 2 ;

[0114] Figure 14 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 3 ;

[0115] Figure 15 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 4 ;

[0116] Figure 16 This is a schematic diagram of the hardware composition structure of a communication node according to an embodiment of the present invention. Detailed Implementation

[0117] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.

[0118] The technical solutions of this invention can be applied to various communication systems, such as GSM (Global System of Mobile communication), LTE (Long Term Evolution), 5G, and 6G systems. Optionally, a 5G system or 5G network can also be referred to as a New Radio (NR) system or NR network.

[0119] For example, the communication system used in this embodiment of the invention may include network devices and terminal devices (also referred to as terminals, communication terminals, etc.); the network device may be a device that communicates with the terminal device. The network device can provide communication coverage within a certain area and can communicate with terminals located within that area. Optionally, the network device may be a base station in various communication systems, such as an evolved Node B (eNB) in an LTE system, a gNB in ​​a 5G or NR system, or a base station in a 6G system, etc.

[0120] It should be understood that devices with communication functions in the network / system of this application embodiment can be referred to as communication devices. Communication devices may include network devices and terminals with communication functions. Network devices and terminal devices can be the specific devices described above, which will not be repeated here. Communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities. This embodiment of the present invention does not limit these.

[0121] It should be understood that the terms "system" and "network" are often used interchangeably in this document. The term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0122] The terms “first,” “second,” etc., used in the specification and claims of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0123] To address the issue of limited scalability of quantum cryptography service center applications in existing quantum secure communication system architectures, this invention proposes a modular design for the quantum cryptography service center. Figure 2 This is a schematic diagram of a quantum secure communication system architecture for the communication method used in an embodiment of the present invention; as shown. Figure 2 As shown, different Figure 1The quantum cryptography service center shown in this embodiment of the invention comprises a primary quantum cryptography service platform and a secondary quantum cryptography service platform. This achieves "separation of management and service," addressing issues related to flexibility, scalability, and security. The primary quantum cryptography service platform focuses on key management and cryptographic services, unifying cryptographic security service capabilities and preventing inconsistent security levels across different vendors' implementations due to varying security capabilities. The secondary quantum cryptography service platform focuses on business services, allowing for the deployment of dedicated secondary quantum cryptography service platforms for each different quantum secure communication application. These platforms are seamlessly integrated with the applications, enabling plug-and-play functionality and rapid deployment.

[0124] Quantum cryptography service center according to embodiments of the present invention:

[0125] In this embodiment of the invention, the quantum cryptography service center is a platform system deployed on the network side. Its core function is the full lifecycle management of quantum entropy source keys, and it uses the managed quantum entropy source keys to provide cryptographic service support for upper-layer applications. Figure 2 As shown, the quantum cryptography service center includes: a primary quantum cryptography service platform, a secondary quantum cryptography service platform, a quantum key offline filling platform, and a quantum random number generator (QRNG).

[0126] In this embodiment of the invention, the quantum entropy source key is a key obtained based on the principles of quantum mechanics, including quantum keys, quantum random number keys, etc., which theoretically possess true randomness and are used for encryption protection and security authentication of classical information. (Refer to...) Figure 2 As shown, the quantum cryptography service center can connect to the QKD network via the Ak interface to obtain and manage the quantum keys generated by the QKD network. Specifically, the quantum cryptography service primary platform and the quantum key offline filling platform in the quantum cryptography service center can connect to the QKD network via the Ak interface and to the QRNG via the Ar interface to obtain and manage keys generated based on quantum random numbers.

[0127] To enhance the multi-service expansion capabilities of the quantum cryptography service center, the quantum key management function comprises a two-tier platform: the primary quantum cryptography service platform (also known as the key management platform, cryptographic service platform, etc.) is the network element responsible for general key management, cryptographic business processing, and providing cryptographic security services. It also injects and manages cryptographic modules, supports interfacing with multiple secondary quantum cryptography service platforms, and provides unified basic key management and cryptographic security services to different secondary quantum cryptography service platforms. The primary quantum cryptography service platform accesses the QKD network via the Ak interface and obtains quantum keys from QKD nodes. The primary quantum cryptography service platform establishes a quantum key resource pool to store and maintain quantum keys obtained from the QKD network and shared with other primary quantum cryptography service platforms.

[0128] The quantum cryptography service secondary platform (also known as the business service platform, application service platform, etc.) is responsible for interfacing with quantum secure communication business applications, providing cryptographic security services for different types of business applications or the same type of business application operated by different entities, thereby supporting the flexible adaptation of quantum, cryptography, and communication services. Simultaneously, the quantum cryptography service secondary platform also possesses certain session key management capabilities. As one example, different types of business applications (also known as business or application registrations) include encrypted audio / video calls, encrypted conferencing, encrypted SMS / instant messaging, encrypted intercom, encrypted email, encrypted cloud storage, and encrypted leased lines. As another example, different types of business applications include real-time secure communication applications and non-real-time secure communication applications. As yet another example, different types of business applications include business applications operated by different entities, such as the same type of secure communication application provided by different telecom operators.

[0129] In embodiments of the present invention, such as Figure 2 As shown, the primary and secondary quantum cryptography service platforms are connected via the Am2 interface. Different primary quantum cryptography service platforms are connected via the Am0 interface. Different secondary quantum cryptography service platforms are connected via the Am3 interface.

[0130] The offline quantum key injection platform pre-injects a certain number of quantum entropy source keys into the cryptographic modules of a quantum secure communication application device offline under a physically secure environment. When injecting quantum random number keys, these keys are provided by the quantum cryptography service platform (Level 1) via the Af interface. When injecting quantum keys, both the quantum cryptography service platform (Level 1) and the offline quantum key injection platform obtain quantum keys from the QKD nodes via the Ak interface. These obtained quantum keys are symmetric keys distributed by the two nodes through the QKD network. Through offline injection, the quantum cryptography service platform (Level 1) and the cryptographic modules in the quantum secure communication application device are configured with several symmetric keys, each establishing a shared symmetric key resource pool locally.

[0131] In various embodiments of the present invention, the platform may also be referred to as an entity, device, function, unit, component, module, etc. For example, a primary quantum cryptography service platform may also be referred to as a primary quantum cryptography service entity, a primary quantum cryptography service device, a primary quantum cryptography service function, a primary quantum cryptography service unit, a primary quantum cryptography service component, a primary quantum cryptography service module, etc. Similarly, a secondary quantum cryptography service platform may also be referred to as a secondary quantum cryptography service entity, a secondary quantum cryptography service device, a secondary quantum cryptography service function, a secondary quantum cryptography service unit, a secondary quantum cryptography service component, a secondary quantum cryptography service module, etc. Furthermore, a quantum key offline charging platform may also be referred to as a quantum key offline charging entity, a quantum key offline charging device, a quantum key offline charging function, a quantum key offline charging unit, a quantum key offline charging component, a quantum key offline charging module, etc.

[0132] In this embodiment of the invention, QRNG is a device for generating random numbers based on quantum mechanics principles, and can provide quantum random numbers to a quantum cryptography service primary platform via an Ar interface. The quantum cryptography service primary platform can generate quantum random number keys based on quantum random numbers.

[0133] Quantum secure communication application device according to embodiments of the present invention:

[0134] Quantum secure communication application equipment includes network devices or terminal devices that incorporate cryptographic applications, cryptographic middleware, and cryptographic modules to realize quantum secure communication applications. Among them:

[0135] Cryptographic applications are software and hardware modules on a device that implement secure communication functions, and they call cryptographic services based on quantum entropy source keys through cryptographic middleware.

[0136] Cryptographic middleware is software that sits between cryptographic applications and cryptographic modules to provide cryptographic services. It is compatible with various types of cryptographic modules and provides a unified cryptographic service interface for applications. Cryptographic services include, but are not limited to, encryption / decryption, security authentication, and key management.

[0137] The cryptographic module possesses cryptographic computation capabilities and stores pre-filled quantum entropy source keys. It can take various media forms, including hardware (such as USB tokens, Universal Serial Bus keys, cryptographic cards, Subscriber Identity Module (SIM) cards, security chips, etc.) and software. The quantum cryptography service platform manages the cryptographic module online through cryptographic middleware.

[0138] For the quantum cryptography management center:

[0139] The quantum cryptography management center (also known as the quantum cryptography service management center, etc.) includes network elements such as an operation and management platform. The operation and management platform is responsible for the management, operation, and monitoring of quantum secure communication services subscribed to by users. Specifically, it can manage the binding and mapping relationships of information such as users, devices, cryptographic modules, services, the primary quantum cryptography service platform to which they belong, and the secondary quantum cryptography service platform providing the service.

[0140] based on Figure 2 The quantum secure communication system architecture shown is as follows: Figure 3 This is a schematic diagram of the key system related to the communication method in an embodiment of the present invention; as shown below. Figure 3 As shown, in this system, there can be many Quantum Service Base Keys (QSBKs) (e.g., tens of thousands or hundreds of thousands of QSBKs), thus forming a Quantum Service Base Key resource pool between the quantum cryptography service primary platform and the cryptographic module. The Quantum Service Base Keys in the pool, as well as the Quantum Session Key Protection Keys (QSKPKs) derived from them, are all single-use and destroyed after use. This ensures frequent key changes within the system, increasing the difficulty of cracking the system and improving overall system security.

[0141] In this embodiment of the invention, the Quantum Service Base Key (QSBK) is a pool of quantum entropy source keys shared between the quantum cryptography service primary platform and the cryptographic module of the quantum secure communication application device. These keys are pre-configured and securely stored within the cryptographic module through offline, online, or other injection methods, forming a QSBK resource pool. This pool can be used to derive various other keys, such as the Quantum Session Key Protection Key (QSKPK). Each QSBK is for one-time use and is destroyed after use.

[0142] Quantum Session Key Protection Key (QSKPK): A key shared between the primary quantum cryptography service platform and the cryptographic modules of quantum secure communication application devices, which may include the encryption protection key QSKPK. enc and integrity protection key QSKPK int QSKPK enc and QSKPK int It can be directly derived from QSBK (e.g.) Figure 3 (as shown), or it can also be that the intermediate key QSKPK can be derived from QSBK, and then derived from QSKPK to obtain ( Figure 3(Not shown in the image), it is used to encrypt and protect the integrity of sensitive information such as the Quantum Service Session Key (QSSK). QSKPK enc and QSKPK int It is for single use only and will be destroyed after use.

[0143] Quantum Service Session Key (QSSK): A session key used for secure communication between devices in quantum-secure communication applications. Depending on the actual application needs, a further encryption protection key (QSSK) can be derived from the QSSK. enc and integrity protection key QSSK int Depending on the communication scenario (local / cross-domain, intra-office / inter-office), QSSK is based on quantum key generation or quantum random number key generation and is used to encrypt and / or protect the integrity of information exchanged between user equipment. QSSK or QSSK-derived QSSK enc and QSSK int This is for one-time use only and will be destroyed after the session ends. The encryption protection key QSSK is used for this purpose. enc and integrity protection key QSSK int It is derived from the Quantum Service Session Key (QSSK), then the encryption protection key QSSK enc and integrity protection key QSSK int It can also be called a session key.

[0144] Figure 4 This is a schematic diagram illustrating a deployment application scenario of a quantum secure communication system using the communication method of this invention; as shown. Figure 4 The diagram illustrates a single-center deployment scenario. In this scenario, the quantum cryptography service center deploys a primary quantum cryptography service platform and a secondary quantum cryptography service platform to provide cryptographic services for quantum secure communication application devices under its jurisdiction, enabling a specific quantum secure communication application. The secondary quantum cryptography service platform may optionally have QRNG device access capabilities. Quantum secure communication application device A and quantum secure communication application device B can connect to the same secondary quantum cryptography service platform via the As interface.

[0145] Figure 4The deployment method shown only supports intra-domain (i.e., intra-office) quantum secure communication and does not support cross-domain (i.e., inter-office) communication. In this case, the source and destination quantum secure communication application devices (i.e., quantum secure communication application device A and quantum secure communication application device B) belong to the same quantum cryptography service center. The quantum service basic key QSBK stored in the cryptographic modules of the source and destination quantum secure communication application devices is filled by the same quantum cryptography service primary platform. The source and destination quantum secure communication application devices are remotely managed by the same quantum cryptography service primary platform.

[0146] based on Figure 4 As shown in the deployment scenario, this embodiment of the invention provides a secure communication method, which is applied to a first entity. Figure 5 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 1 ;like Figure 5 As shown, the method includes:

[0147] Step 101: The first entity obtains the first session key and sends a first message to the second entity; the first message is used to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key; and / or,

[0148] Step 102: The first entity receives a second message sent by the second entity, the second message including a first session key that is encrypted and / or protected for integrity.

[0149] Accordingly, embodiments of the present invention provide a secure communication method, which is applied to a second entity. Figure 6 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 2 ;like Figure 6 As shown, the method includes:

[0150] Step 201: The second entity receives a first message sent by the first entity, the first message being used to request encryption and / or integrity protection of the first session key, the first message including at least the first session key; and / or,

[0151] Step 202: The second entity encrypts and / or protects the integrity of the first session key, and sends a second message to the first entity, the second message including the encrypted and / or integrity-protected first session key.

[0152] In this embodiment, the first entity can be equivalent to Figure 2 The quantum cryptography service secondary platform in the system architecture shown can be equivalent to... Figure 2 The quantum cryptography service platform in the system architecture shown.

[0153] In some alternative embodiments, the first message includes a first session key that is encrypted and / or protected for integrity.

[0154] In this embodiment, a secure channel is pre-established between the first entity and the second entity to ensure the security of the first session key transmission process. In some optional embodiments, the first entity can use the secure channel to transmit a first message carrying the first session key in plaintext to the second entity. In other optional embodiments, the first entity negotiates a fifth key with the second entity in advance, uses the fifth key to encrypt and / or protect the integrity of the first session key, and then transmits the first message carrying the encrypted and / or integrity-protected first session key through the secure channel. After receiving the first session key (or possibly related information about the first session key), the second entity, in one implementation, can directly obtain the first session key (or possibly related information about the first session key) and encrypt and / or protect its integrity for the first session key transmitted in plaintext through the secure channel; in another implementation, for the securely protected first session key, the second entity can first perform an integrity protection verification on the encrypted and / or integrity-protected first session key based on the pre-negotiated fifth key, and after the verification passes, perform decryption to obtain the first session key (or possibly related information about the first session key), and then encrypt and / or protect the integrity of the first session key (or possibly related information about the first session key).

[0155] In this embodiment, the first session key can be equivalent to Figure 3 Quantum Service Session Key (QSSK) in the context of quantum services.

[0156] In some alternative embodiments, one or more first entities interact with the second entity through a first interface.

[0157] In this embodiment, the second entity can connect to and interact with one or more first entities through the first interface. Figure 2 Taking the system architecture shown as an example, the quantum cryptography service primary platform can establish a connection and exchange information with one or more quantum cryptography service secondary platforms through the Am2 interface.

[0158] In some alternative embodiments, different first entities correspond to different applications, and / or, different first entities correspond to different types of applications, and / or, different first entities correspond to applications of different operating entities.

[0159] In this embodiment, the second entity can connect to multiple first entities. In one implementation, different first entities correspond to different applications; that is, each application can correspond to one first entity. In another implementation, different first entities correspond to different types of applications, such as encrypted audio / video calls, encrypted conferencing, encrypted SMS / instant messaging, encrypted walkie-talkie, encrypted email, encrypted cloud storage, encrypted leased lines, etc., with each application corresponding to one first entity. In yet another implementation, different first entities correspond to applications from different operating entities, for example, three operators provide applications, with each operator corresponding to one first entity. In yet another implementation, different first entities correspond to applications from different operating entities, and different first entities correspond to different applications; for example, three operators provide the same secure communication application, then each operator's secure communication application corresponds to one first entity.

[0160] The technical solution of this invention utilizes a first entity to obtain a first session key and a second entity to securely protect the first session key. Specifically, this invention divides the quantum cryptography service platform in the quantum cryptography service center into a primary quantum cryptography service platform (i.e., the second entity) and a secondary quantum cryptography service platform (i.e., the first entity), achieving separation of management and services. The secondary quantum cryptography service platform (i.e., the first entity) is primarily responsible for business services and can be deployed for different applications. The modular design reduces the implementation complexity of the quantum cryptography service center, facilitates its operation and maintenance, and allows for adaptation and expansion to more new business applications. The primary quantum cryptography service platform (i.e., the second entity) is primarily responsible for key management and services, unifying cryptographic security service capabilities and solving the problem of inconsistent security levels in cryptographic service systems implemented by different vendors due to differences in security capabilities.

[0161] In some optional embodiments of the present invention, for the first entity, the method further includes: the first entity receiving a first request sent by a first application device, the first request being used to obtain a first session key, the first request including at least a first key identifier; and / or, the first entity sending a first response to the first application device, the first response including the first session key after encryption and / or integrity protection.

[0162] In this embodiment, the first application device can be equivalent to Figure 2 The first application device is a quantum secure communication application device. For example, in a communication scenario between two quantum secure communication application devices, the first application device is the source-end quantum secure communication application device. Optionally, the first application device may be... Figure 2 Cryptographic applications in quantum secure communication devices.

[0163] In this embodiment, the first key identifier is the identifier of the first key, and the first key can be equivalent to... Figure 3 If the first key is the quantum service base key (QSBK) in the first application device, then the first key identifier is the QSBK identifier (ID). Since the first key identifier is carried through the first request of the first application device, the first key is the quantum service base key (QSBK) in the quantum service base key resource pool related to the first application device (i.e., the source quantum secure communication application device). Therefore, the first key can also be called the quantum service base key (QSBK) of the source device, denoted as QSBK(O), and the first key identifier can also be denoted as QSBKID(O).

[0164] In this embodiment, through a first request from the first application device, the first entity obtains a first session key based on the first request, and obtains the encrypted and / or integrity-protected first session key sent by the second entity through information interaction with the second entity. The first entity then sends the encrypted and / or integrity-protected first session key to the first application device so that the first application device can obtain the first session key.

[0165] In some optional embodiments of the present invention, the method further includes: the first entity assigning a first identifier, the first identifier being associated with the first session key and / or a first session key identifier.

[0166] In some alternative embodiments, the first identifier corresponds to a first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

[0167] In this embodiment, the first identifier may also be referred to as the first transaction identifier (ID) or session identifier, etc. The first identifier is associated with or corresponds to the first session key (such as QSSK) and / or the first session key identifier (QSSKID).

[0168] In this embodiment, since the same system architecture may have multiple methods for obtaining session keys and / or security protection methods, or different system architectures may have multiple methods for obtaining session keys and / or security protection methods, this embodiment of the invention focuses on one of the methods for obtaining session keys and / or security protection methods, such as the first mode (also known as mode one), that is, the first identifier corresponds to the first mode, and the first mode is used to indicate a method for obtaining session keys and / or security protection method.

[0169] In some alternative embodiments, the first message may also include at least one of the first key identifier and information related to the first session key.

[0170] In this embodiment, the relevant information of the first session key refers to any information related to the quantum service base key (QSBK) of the first application device (i.e., the source quantum secure communication application device) (i.e., any information related to the first key), such as the identifier of the quantum service base key (QSBK) (i.e., the validity period), etc.

[0171] In this embodiment, the first message may also include a first key identifier, namely QSBKID(O), which corresponds to the first application device (i.e., the source quantum secure communication application device).

[0172] In some alternative embodiments, the second message may also include at least one of the first key identifier and information related to the first session key after encryption and / or integrity protection.

[0173] In this embodiment, the information related to the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the information related to the first session key.

[0174] In this embodiment, the second message may also include a first key identifier related to the first application device (i.e., the source quantum secure communication application device), namely QSBKID(O).

[0175] In some alternative embodiments, the first response may also include the first identifier.

[0176] In this embodiment, the first response sent by the first entity to the first application device may include, in addition to the first session key after encryption and / or integrity protection, the first identifier, so that the first application device can provide the first identifier to the second application device communicating with it.

[0177] In some optional embodiments of the present invention, for the first entity, obtaining the first session key includes: the first entity acquiring a quantum random number and generating the first session key based on the quantum random number.

[0178] In some alternative embodiments, the first entity obtains the quantum random number by obtaining the quantum random number from a quantum random number generator (QRNG) or the second entity.

[0179] In this embodiment, the first entity can obtain quantum random numbers through the locally connected QRNG, or through the second entity; the second entity (i.e., the quantum cryptography service primary platform) can... Figure 2 The Ar interface shown obtains quantum random numbers from the QRNG.

[0180] In some optional embodiments, generating the first session key based on the quantum random number includes: the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, and generates the first session key based on the quantum random number; wherein the second application device is a device that communicates with the first application device.

[0181] In this embodiment, before generating the first session key based on the quantum random number, the first entity first determines whether the second entity serving the first application device is the same as the second entity serving the second application device, that is, whether the first application device and the second application device belong to the same service domain or the same bureau; if it is determined that the second entity serving the first application device is the same as the second entity serving the second application device, that is, the first application device and the second application device belong to the same service domain or the same bureau, then the first session key is generated based on the quantum random number.

[0182] In some optional embodiments, the first request may further include second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; and / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: when the first entity determines that the second identification information and the third identification information are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device.

[0183] In this embodiment, the first request sent by the first application device may optionally also carry second identification information and / or third identification information. The second identification information is the identification information of a second entity serving the first application device, that is, the second identification information represents the identifier of the quantum cryptography service level-one platform serving the first application device, for example, denoted as QCSL1 ID(O); the third identification information is the identification information of a second entity serving the second application device, that is, the third identification information represents the identifier of the quantum cryptography service level-one platform serving the second application device, for example, denoted as QCSL1 ID(T). Then, when the first entity determines that the second identification information and the third identification information are the same, that is, when QCSL1 ID(O) and QCSL1 ID(T) are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device. In other optional embodiments, when the first entity determines that the second identification information and the third identification information are different, that is, when QCSL1 ID(O) and QCSL1 ID(T) are different, it determines that the second entity serving the first application device is different from the second entity serving the second application device.

[0184] In some alternative embodiments, the first request carries the identifier of the first application device and / or the identifier of the second application device; and / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: the first entity queries a third entity based on the identifier of the first application device to obtain second identifier information, and / or queries a third entity based on the identifier of the second application device to obtain third identifier information; the second identifier information is the identifier of the second entity serving the first application device, and the third identifier information is the identifier of the second entity serving the second application device; when the first entity determines that the second identifier information and the third identifier information are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device.

[0185] In this embodiment, the first request sent by the first application device may optionally also carry the identifier of the first application device and / or the identifier of the second application device. For example, the identifier of the first application device and / or the identifier of the second application device may include at least one of the following identifiers of the first application device and / or the second application device: service identifier, application identifier, user identifier, device identifier, cryptographic module identifier, etc. The first entity can query the third entity to obtain the second identification information based on the identifier of the first application device, and / or query the third entity to obtain the third identification information based on the identifier of the second application device; for example, the first entity sends a first query request message to the third entity, the first query request message including the identifier of the first application device; the third entity performs a local query based on the identifier of the first application device to obtain the corresponding second identification information, and sends a first query request response carrying the second identification information to the first entity; and / or, the first entity sends a second query request message to the third entity, the second query request message including the identifier of the second application device; the third entity performs a local query based on the identifier of the second application device to obtain the corresponding third identification information, and sends a second query request response carrying the third identification information to the first entity; wherein, the third entity may be an operation management platform, which manages the correspondence between the identifiers of multiple application devices and the identifiers of the second entities serving the corresponding application devices. Further, when the first entity determines that the second identification information and the third identification information are the same, that is, when QCSL1 ID(O) and QCSL1 ID(T) are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device. In other alternative embodiments, when the first entity determines that the second identification information and the third identification information are different, that is, when QCSL1 ID(O) and QCSL1 ID(T) are different, it determines that the second entity serving the first application device is different from the second entity serving the second application device.

[0186] In some optional embodiments of the present invention, for the first entity, the first key corresponding to the first key identifier is used to generate a second key and then generate a first protection key and / or a second protection key, or is used to generate a first protection key and / or a second protection key; the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the integrity of the first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key.

[0187] Accordingly, for the second entity, the first message also includes a first key identifier related to the first application device; the second entity encrypts and / or protects the integrity of the first session key, including: the second entity obtains a first key based on the first key identifier; generates a second key based on the first key, generates a first protection key and / or a second protection key based on the second key, or generates a first protection key and / or a second protection key based on the first key; and encrypts and / or protects the integrity of the first session key based on the first key, or the second key, or the first protection key and / or the second protection key.

[0188] In this embodiment, after receiving the first message, the second entity can obtain the first key based on the first key identifier also included in the first message, for example, obtaining QSBK(O) based on the QSBK ID(O) related to the first application device. Furthermore, as one implementation, the second entity generates a second key based on the first key, and then generates a first protection key and / or a second protection key based on the second key; wherein, the second key is a protection key derived from the first key. For example, the second key can be a quantum session key protection key (QSKPK), then for the first application device, the second key can be denoted as QSKPK(O). The first protection key and / or the second protection key are protection keys obtained based on the second key. As another implementation, the second entity can directly generate the first protection key and / or the second protection key based on the first key. For example, the first protection key can be a QSKPK key used for encryption protection. enc The second protection key can be a QSKPK key used for integrity protection. int For the first application device, the first protection key can be denoted as QSKPK. enc (O), the second protection key can be denoted as QSKPK int (O).

[0189] In this embodiment, the second entity can encrypt and / or protect the integrity of the first session key based on the first key, or the second key, or the first protection key and / or the second protection key. As one implementation, the second entity can encrypt and / or protect the integrity of the first session key based on the first key. As another implementation, the second entity can encrypt and / or protect the integrity of the first session key based on the second key. As yet another implementation, the second entity can encrypt and / or protect the integrity of the first session key based on the first protection key and / or the second protection key. The first entity encrypts and / or protects the integrity of the first session key based on the first protection key (such as QSKPK). enc (O)) and the second protection key (such as QSKPK)int Taking (O) as an example, if the first session key is encrypted and its integrity protected, then the second entity first uses the first protection key (such as QSKPK) to perform encryption and integrity protection. enc (O) encrypts the first session key, and then uses the second protection key (such as QSKPK) int (O)) Perform integrity protection processing on the encrypted first session key to obtain the encrypted and integrity-protected first session key.

[0190] In various embodiments of the present invention, encrypting and / or protecting the integrity of the first session key can be done by encrypting and / or protecting the integrity of only the first session key, or it can be done by encrypting and / or protecting the integrity of the first session key and its related information (e.g., the identifier, lifespan, etc. of the session key) according to actual needs. For example, the first session key and its related information can be encrypted and / or protected together, or the first session key and its related information can be encrypted and / or protected separately. It is understood that the second message may include the encrypted and / or integrity-protected first session key, or the second message may include the encrypted and / or integrity-protected first session key and its related information.

[0191] In some optional embodiments of the present invention, for the first entity, the method further includes: the first entity receiving a second request sent by a second application device, the second request being used to obtain a first session key, the second request including at least a third key identifier; and / or, the first entity sending a second response to the second application device, the second response including the first session key after encryption and / or integrity protection.

[0192] In this embodiment, the second application device can be equivalent to Figure 2 The second application device is a quantum secure communication application device. For example, in a communication scenario between two quantum secure communication application devices, the second application device is the destination quantum secure communication application device. Optionally, the second application device may be... Figure 2 Cryptographic applications in quantum secure communication devices.

[0193] In this embodiment, the third key identifier is an identifier for the third key, and the third key can be equivalent to... Figure 3If the third key is the quantum service base key (QSBK) in the second application device, then the third key identifier is the QSBK identifier (ID). Since the third key identifier is carried through the second request of the second application device, the third key is the quantum service base key (QSBK) in the quantum service base key resource pool related to the second application device (i.e., the destination quantum secure communication application device). Therefore, the third key can also be called the quantum service base key (QSBK) of the destination device, denoted as QSBK(T), and the third key identifier can also be denoted as QSBKID(T).

[0194] In this embodiment, through a second request from the second application device, the first entity obtains a first session key based on the second request, and obtains the encrypted and / or integrity-protected first session key sent by the second entity through information interaction with the second entity. The first entity then sends the encrypted and / or integrity-protected first session key to the second application device so that the second application device can obtain the first session key.

[0195] In some alternative embodiments, the second request further includes a first identifier; the first entity obtains the first session key by: the first entity determining a first pattern based on the first identifier and searching for the first session key associated with the first identifier.

[0196] In this embodiment, the first identifier may also be referred to as the first transaction identifier (ID) or session identifier, etc. The first identifier is associated with or corresponds to the first session key (such as QSSK) and / or the first session key identifier (QSSKID).

[0197] In this embodiment, the second application device is the destination quantum secure communication application device; while in the process of the source quantum secure communication application device requesting the first session key from the first entity, the first entity assigns a first identifier to the request and sends the first identifier to the first entity. The first entity can send the first identifier to the second application device through a notification message so that the second application device can carry the first identifier when requesting the first session key from the first entity.

[0198] In this embodiment, the first entity can determine the first mode based on the first identifier, that is, determine the acquisition method and / or security protection method of the corresponding first session key according to the first identifier, and determine whether the first session key requested by the second request is distributed within the local domain or distributed across the local domain; if it is determined to be distributed within the local domain, search for the first session key associated with the first identifier (during the request process of the first session key of the first application device, the first entity has established an association between the first identifier and the first session key and / or the first session key identifier).

[0199] In some optional embodiments of the present invention, for the first entity, the method further includes: the first entity sending a third message to the second entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message including at least the first session key; and / or, the first entity receiving a fourth message sent by the second entity, the fourth message including the first session key after encryption and / or integrity protection.

[0200] Accordingly, for the second entity, the method further includes: the second entity receiving a third message sent by the first entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message including at least the first session key; and / or, the second entity encrypting and / or protecting the integrity of the first session key and sending a fourth message to the first entity, the fourth message including the encrypted and / or integrity-protected first session key.

[0201] In some alternative embodiments, the third message includes a first session key that has been encrypted and / or protected for integrity.

[0202] In this embodiment, a secure channel is pre-established between the first entity and the second entity to ensure the security of the first session key transmission process. In some alternative embodiments, the first entity may use the secure channel to transmit a third message carrying the first session key in plaintext to the second entity. In other alternative embodiments, the first entity negotiates a fifth key with the second entity beforehand, and uses the fifth key to encrypt and / or protect the integrity of the first session key before transmitting a third message carrying the encrypted and / or integrity-protected first session key through the secure channel. After receiving the first session key (or related information about the first session key), the second entity, in one implementation, can directly obtain the first session key (or related information about the first session key) and encrypt and / or protect its integrity if the first session key is transmitted in plaintext via a secure channel. In another implementation, for the securely protected first session key, the second entity can first perform an integrity protection verification on the encrypted and / or integrity-protected first session key based on a pre-negotiated fifth key, and then perform decryption processing after the verification passes to obtain the first session key (or related information about the first session key), and then encrypt and / or protect the first session key (or related information about the first session key).

[0203] In some optional embodiments, the third message may further include at least one of a third key identifier associated with the second application device and information related to the first session key; and / or, the fourth message may further include at least one of the third key identifier and information related to the encrypted and / or integrity-protected first session key.

[0204] In this embodiment, the information related to the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the information related to the first session key.

[0205] In some optional embodiments of the present invention, for the first entity, the third key corresponding to the third key identifier is used to generate a fourth key, which in turn generates a third protection key and / or a fourth protection key, or is used to generate a third protection key and a fourth protection key; the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the integrity of the first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key.

[0206] Accordingly, for the second entity, the second entity encrypts and / or protects the integrity of the first session key, including: the second entity obtaining a third key based on the third key identifier; generating a fourth key based on the third key, generating a third protection key and / or a fourth protection key based on the fourth key, or generating a third protection key and / or a fourth protection key based on the third key; and encrypting and / or protecting the integrity of the first session key based on the third key, or the fourth key, or the third protection key and / or the fourth protection key.

[0207] In this embodiment, after receiving the third message, the second entity can obtain the third key based on the third key identifier included in the third message, for example, obtaining QSBK(T) based on the QSBKID(T) associated with the second application device. Furthermore, as one implementation, the second entity generates a fourth key based on the third key, and then generates a third protection key and / or a fourth protection key based on the fourth key; wherein the fourth key is a protection key derived from the third key. For example, the fourth key can be a quantum session key protection key (QSKPK), then for the second application device, the fourth key can be denoted as QSKPK(T). The third protection key and / or the fourth protection key are protection keys obtained based on the fourth key. As another implementation, the second entity can directly generate the third protection key and / or the fourth protection key based on the third key. For example, the third protection key can be a QSKPK key used for encryption protection. encThe fourth protection key can be a QSKPK key used for integrity protection. int For the second application device, the third protection key can be denoted as QSKPK. enc (T), the fourth protection key can be denoted as QSKPK int (T).

[0208] In this embodiment, the second entity encrypts and / or protects the integrity of the first session key based on the third key, or the fourth key, or the third protection key and / or the fourth protection key. As one implementation, the second entity may encrypt and / or protect the integrity of the first session key based on the third key. As another implementation, the second entity may encrypt and / or protect the integrity of the first session key based on the fourth key. As yet another implementation, the second entity may encrypt and / or protect the integrity of the first session key based on the third protection key and / or the fourth protection key. The second entity encrypts and / or protects the integrity of the first session key based on the third protection key (such as QSKPK). enc (T) and the fourth protection key (such as QSKPK) int Taking (T) as an example, if the first session key is encrypted and its integrity protected, then the second entity first uses the third protection key (such as QSKPK) to perform encryption and integrity protection. enc (T) encrypts the first session key, and then uses the fourth protection key (such as QSKPK) int (T) Perform integrity protection processing on the encrypted first session key to obtain the encrypted and integrity-protected first session key.

[0209] In various embodiments of the present invention, encrypting and / or protecting the integrity of the first session key can be done by encrypting and / or protecting the integrity of only the first session key, or it can be done by encrypting and / or protecting the integrity of the first session key and its related information (e.g., the identifier, lifespan, etc. of the session key) according to actual needs. For example, the first session key and its related information can be encrypted and / or protected together, or the first session key and its related information can be encrypted and / or protected separately. It is understood that the fourth message may include the encrypted and / or integrity-protected first session key, or the fourth message may include the encrypted and / or integrity-protected first session key and its related information.

[0210] Based on the above embodiments, this invention also provides a secure communication method, which is applied to a first application device. Figure 7 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 3 ;like Figure 7 As shown, the method includes:

[0211] Step 301: The first application device obtains the first key identifier and sends a first request to the first entity. The first request is used to obtain the first session key, and the first request includes at least the first key identifier; and / or,

[0212] Step 302: The first application device receives a first response sent by the first entity, the first response including a first session key after encryption and / or integrity protection.

[0213] In this embodiment, the first application device can be equivalent to Figure 2 Quantum secure communication application devices. For example, in a communication scenario between two quantum secure communication application devices, the first application device is the source quantum secure communication application device.

[0214] In this embodiment, the first key identifier is the identifier of the first key, and the first key can be equivalent to... Figure 3 If the first key is the quantum service base key (QSBK) in the first application device, then the first key identifier is the QSBK identifier (ID). Since the first key identifier is carried through the first request of the first application device, the first key is the quantum service base key (QSBK) in the quantum service base key resource pool related to the first application device (i.e., the source quantum secure communication application device). Therefore, the first key can also be called the quantum service base key (QSBK) of the source device, denoted as QSBK(O), and the first key identifier can also be denoted as QSBKID(O).

[0215] In this embodiment, through a first request from the first application device, the first entity obtains a first session key based on the first request, and obtains the encrypted and / or integrity-protected first session key sent by the second entity through information interaction with the second entity. The first entity then sends the encrypted and / or integrity-protected first session key to the first application device so that the first application device can obtain the first session key.

[0216] In some optional embodiments of the present invention, the first application device obtains the first key identifier by: the cryptographic middleware of the first application device allocating a first key to the application and obtaining the first key identifier corresponding to the first key.

[0217] In some optional embodiments of the present invention, the method further includes: the first application device generating a second key based on a first key, and generating a first protection key and / or a second protection key based on the second key; or, the first application device generating a first protection key and / or a second protection key based on the first key.

[0218] In this embodiment, as one implementation, the first application device can generate a second key based on a first key, and then generate a first protection key and / or a second protection key based on the second key; wherein, the second key is a protection key derived from the first key. For example, the second key can be a Quantum Session Key Protection Key (QSKPK), then for the first application device, the second key can be denoted as QSKPK(O). The first protection key and / or the second protection key are protection keys obtained based on the second key. As another implementation, the first application device can directly generate the first protection key and / or the second protection key based on the first key. For example, the first protection key can be a QSKPK key used for encryption protection. enc The second protection key can be a QSKPK key used for integrity protection. int For the first application device, the first protection key can be denoted as QSKPK. enc (O), the second protection key can be denoted as QSKPK int (O).

[0219] In some optional embodiments of the present invention, the method further includes: the first application device performing integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key, to obtain the first session key.

[0220] In this embodiment, the first application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key, or the second key, or the first protection key and / or the second protection key, to obtain the first session key. As one implementation, the first application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key. As another implementation, the first application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the second key. As yet another implementation, the first application device can perform integrity verification and decryption on the encrypted and / or integrity-protected first session key based on the first protection key and / or the second protection key. The first application device uses the first protection key (such as QSKPK) as a basis for further verification. enc (O)) and the second protection key (such as QSKPK) int Taking the integrity verification and decryption of the first session key after encryption and integrity protection (O) as an example, the first application device first performs integrity verification and decryption based on the second protection key (such as QSKPK). int(O) Perform integrity verification on the first session key after encryption and integrity protection. After the verification passes, then use the first protection key (such as QSKPK). enc (O)) Decrypt the encrypted first session key to obtain the first session key.

[0221] In some optional embodiments of the present invention, the method further includes: the first application device generating a third session key and / or a fourth session key based on the first session key, or generating a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated by the first application device and the second application device; wherein the third session key and / or the fourth session key are used to encrypt and / or protect the integrity of information sent and / or received by the first application device during communication, and / or to decrypt and / or verify the integrity.

[0222] In this embodiment, the first application device can further derive a third session key and / or a fourth session key based on the first session key as needed. As one implementation, the first application device can directly derive the third session key and / or the fourth session key based on the first session key. As another implementation, the first application device can derive the third session key and / or the fourth session key based on the first session key and the second session key, wherein the second session key is a session key generated through other means, such as a session key obtained through negotiation between the first and second application devices using asymmetric cryptography algorithms or post-quantum cryptography algorithms. The first application device fuses the first session key and the second session key to obtain the third session key and / or the fourth session key. Optionally, the first application device performs a fusion process on the first session key and the second session key, specifically by performing hashing, digest, XOR, or other methods to fuse the first and second session keys, thereby obtaining the third session key and / or the fourth session key.

[0223] In this embodiment, the third session key and / or the fourth session key are encryption protection keys, used to encrypt and / or protect the integrity of information sent by the first application device during communication between the first application device and the second application device, and / or to decrypt and / or verify the integrity of information received from the second application device, thereby achieving quantum secure communication. For example, the third session key can be denoted as QSSK. enc The fourth session key can be denoted as QSSK. int .

[0224] In some optional embodiments of the present invention, the method further includes: the first application device sending a third request to the second application device, the third request being used to request the establishment of a connection; the first application device receiving a third response sent by the second application device, the third response indicating that the connection has been established.

[0225] In some alternative embodiments, the third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or, the third response includes third identification information, which is the identification information of a second entity serving the second application device.

[0226] In some optional embodiments, the first request may further include second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; and / or, the first request may further include the identification of the first application device and / or the identification of the second application device.

[0227] In this embodiment, the first request sent by the first application device may optionally also carry second identification information and / or third identification information. The second identification information is the identification information of the second entity serving the first application device, that is, the second identification information represents the identifier of the quantum cryptography service level one platform serving the first application device, for example, denoted as QCSL1 ID(O); the third identification information is the identification information of the second entity serving the second application device, that is, the third identification information represents the identifier of the quantum cryptography service level one platform serving the second application device, for example, denoted as QCSL1 ID(T), so that the first entity can determine, based on the second identification information and the third identification information, whether the second entity serving the first application device is the same as the second entity serving the second application device, or whether the first application device and the second application device belong to the same service domain or the same bureau. Alternatively, in other optional embodiments, the first request sent by the first application device may optionally also carry the identifier of the first application device and / or the identifier of the second application device. The identifier of the first application device and / or the identifier of the second application device are used by the first entity to query the second identifier information and / or the third identifier information from the third entity, so that the first entity can determine, based on the second identifier information and the third identifier information, whether the second entity serving the first application device is the same as the second entity serving the second application device, or whether the first application device and the second application device belong to the same service domain or the same bureau.

[0228] In some alternative embodiments of the present invention, the first response further includes a first identifier; the first identifier is associated with the first session key and / or a first session key identifier.

[0229] In some alternative embodiments, the first identifier corresponds to a first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

[0230] In this embodiment, the first identifier may also be referred to as the first transaction identifier (ID) or session identifier, etc. The first identifier is associated with or corresponds to the first session key (such as QSSK) and / or the first session key identifier (QSSKID).

[0231] In this embodiment, since the same system architecture may have multiple methods for obtaining session keys and / or security protection methods, or different system architectures may have multiple methods for obtaining session keys and / or security protection methods, this embodiment of the invention focuses on one of the methods for obtaining session keys and / or security protection methods, such as the first mode (also known as mode one), that is, the first identifier corresponds to the first mode, and the first mode is used to indicate a method for obtaining session keys and / or security protection method.

[0232] In this embodiment, the first response sent by the first entity to the first application device may include, in addition to the first session key after encryption and / or integrity protection, the first identifier, so that the first application device can provide the first identifier to the second application device communicating with it.

[0233] In some optional embodiments of the present invention, the method further includes: the first application device sending a fifth message to the second application device, the fifth message including at least the first identifier.

[0234] Based on the above embodiments, this invention also provides a secure communication method, which is applied to a second application device. Figure 8 This is a flowchart illustrating the secure communication method according to an embodiment of the present invention. Figure 4 ;like Figure 8 As shown, the method includes:

[0235] Step 401: The second application device obtains the third key identifier and sends a second request to the first entity. The second request is used to obtain the first session key, and the second request includes at least the third key identifier; and / or,

[0236] Step 402: The second application device receives a second response sent by the first entity, the second response including a first session key that is encrypted and / or protected for integrity.

[0237] In this embodiment, the second application device can be equivalent to Figure 2 Quantum secure communication application devices. For example, in a communication scenario between two quantum secure communication application devices, the second application device is the destination quantum secure communication application device.

[0238] In this embodiment, the third key identifier is an identifier for the third key, and the third key can be equivalent to... Figure 3 If the third key is the quantum service base key (QSBK) in the second application device, then the third key identifier is the QSBK identifier (ID). Since the third key identifier is carried through the second request of the second application device, the third key is the quantum service base key (QSBK) in the quantum service base key resource pool related to the second application device (i.e., the destination quantum secure communication application device). Therefore, the third key can also be called the quantum service base key (QSBK) of the destination device, denoted as QSBK(T), and the third key identifier can also be denoted as QSBKID(T).

[0239] In this embodiment, through a second request from the second application device, the first entity obtains a first session key based on the second request, and obtains the encrypted and / or integrity-protected first session key sent by the second entity through information interaction with the second entity. The first entity then sends the encrypted and / or integrity-protected first session key to the second application device so that the second application device can obtain the first session key.

[0240] In some optional embodiments of the present invention, the second application device obtains the third key identifier by: the cryptographic middleware of the second application device allocating a third key to the application and obtaining the third key identifier corresponding to the third key.

[0241] In some optional embodiments of the present invention, the method further includes: the second application device generating a fourth key based on a third key, and generating a third protection key and / or a fourth protection key based on the fourth key; or, the second application device generating a third protection key and / or a fourth protection key based on the third key.

[0242] In this embodiment, as one implementation, the second application device generates a fourth key based on the third key, and then generates a third protection key and / or a fourth protection key based on the fourth key; wherein, the fourth key is a protection key derived from the third key. For example, the fourth key can be a Quantum Session Key Protection Key (QSKPK), and for the second application device, the fourth key can be denoted as QSKPK(T). The third protection key and / or the fourth protection key are protection keys obtained based on the fourth key. As another implementation, the second application device can directly generate the third protection key and / or the fourth protection key based on the third key. For example, the third protection key can be a QSKPK key used for encryption protection. enc The fourth protection key can be a QSKPK key used for integrity protection. int For the second application device, the third protection key can be denoted as QSKPK. enc (T), the fourth protection key can be denoted as QSKPK int (T).

[0243] In some optional embodiments of the present invention, the method further includes: the second application device performing integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key, to obtain the first session key.

[0244] In this embodiment, the second application device performs integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key, or the fourth key, or the third protection key and / or the fourth protection key. As one implementation, the second application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key. As another implementation, the second application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the fourth key. As yet another implementation, the second application device can perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third protection key and / or the fourth protection key. The second application device uses the third protection key (such as QSKPK) as a basis for further verification. enc (T) and the fourth protection key (such as QSKPK) int Taking the integrity verification and decryption of the first session key after encryption and integrity protection (T) as an example, the second application device first performs integrity verification and decryption based on the fourth protection key (such as QSKPK). int(T) performs integrity verification on the first session key after encryption and integrity protection. After the verification passes, the third protection key (such as QSKPK) is then used. enc (T)) Decrypt the encrypted first session key to obtain the first session key.

[0245] In some optional embodiments of the present invention, the method further includes: the second application device receiving a fifth message sent by the first application device, the fifth message including at least a first identifier, the first identifier being associated with the first session key and / or a first session key identifier, and / or the first identifier corresponding to a first mode, the first mode being used to indicate the acquisition method and / or security protection method of the first session key; and / or the second request further including the first identifier.

[0246] In this embodiment, the first identifier may also be referred to as the first transaction identifier (ID) or session identifier, etc. The first identifier is associated with or corresponds to the first session key (such as QSSK) and / or the first session key identifier (QSSKID).

[0247] In this embodiment, after the first application device obtains the first identifier from the first entity, it can send the first identifier to the second application device so that the second application device can carry the first identifier when requesting the first session key from the first entity.

[0248] In some optional embodiments of the present invention, the method further includes: the second application device generating a third session key and / or a fourth session key based on the first session key, or generating a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated between the second application device and the first application device; wherein the third session key and / or the fourth session key are used to encrypt and / or protect the integrity of information sent and / or received by the second application device during communication, and / or to decrypt and / or verify the integrity.

[0249] In this embodiment, the second application device can further derive a third session key and / or a fourth session key based on the first session key as needed. As one implementation, the second application device can directly derive the third session key and / or the fourth session key based on the first session key. As another implementation, the second application device can derive the third session key and / or the fourth session key based on the first session key and the second session key, wherein the second session key is a session key generated through other means, such as a session key obtained by the second application device and the first application device through negotiation using asymmetric cryptography algorithms or post-quantum cryptography algorithms. The second application device fuses the first session key and the second session key to obtain the third session key and / or the fourth session key. Optionally, the second application device performs a fusion process on the first session key and the second session key, specifically by performing hashing, digest, XOR, or other methods to fuse the first session key and the second session key, thereby obtaining the third session key and / or the fourth session key.

[0250] In this embodiment, the third session key and / or the fourth session key are encryption protection keys, used to encrypt and / or protect the integrity of information sent by the second application device during communication between the second application device and the first application device, and / or to decrypt and / or verify the integrity of information received from the first application device, thereby achieving quantum secure communication. For example, the third session key can be denoted as QSSK. enc The fourth session key can be denoted as QSSK. int .

[0251] In some optional embodiments of the present invention, the method further includes: the second application device receiving a third request sent by the first application device, the third request being used to request the establishment of a connection; the second application device sending a third response to the first application device, the third response indicating that the connection has been established.

[0252] In some alternative embodiments, the third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or, the third response includes third identification information, which is the identification information of a second entity serving the second application device.

[0253] The communication method of this invention will be described below with specific examples. In the following examples, the first entity is a quantum cryptography service secondary platform, the second entity is a quantum cryptography service primary platform, the first application device is a source quantum secure communication application device, and the second application device is a destination quantum secure communication application device. The source end can also be called the communication source end (O, Original), and the source quantum secure communication application device can be simply referred to as the (O) side; the destination end can also be called the communication destination end (T, Terminator), and the destination quantum secure communication application device can be simply referred to as the (T) side. To distinguish the same type of messages or information transmitted by the source quantum secure communication application device and the destination quantum secure communication application device, the message or information corresponding to the source quantum secure communication application device can be followed by (O), and the message or information corresponding to the destination quantum secure communication application device can be followed by (T).

[0254] In the following embodiments, the first session key is QSSK, the first key is QSBK(O), the first key identifier is QSBK ID(O), the second identifier is QCSL1 ID(O), the third identifier is QCSL1 ID(T), the second key is QSKPK(O), and the first protection key is QSKPK. enc (O) The second protection key is QSKPK int (O), the third key is QSBK(T), the third key identifier is QSBKID(T), the fourth key is QSKPK(T), and the third protection key is QSKPK. enc (T), The fourth protection key is QSKPK int (T), The third session key is QSSK enc The fourth session key is QSSK int Let's take an example to illustrate.

[0255] Figure 9 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 1 This embodiment proposes a service processing flow for quantum secure communication to achieve secure communication within a local domain / local office. This flow can securely distribute quantum service session keys (QSSKs) to application devices belonging to the same quantum cryptography service center, enabling them to achieve secure communication within their local domain (i.e., within the local office) using quantum random number keys generated based on QRNG. For example... Figure 9 As shown, the method includes:

[0256] Step 501: When initiating a quantum secure communication service, the cryptographic application of the source quantum secure communication application device (O) can first send a communication request message to the cryptographic application of the destination secure communication application device (T) to request the establishment of a connection.

[0257] Here, the communication request message may optionally carry the identification information QCSL1 ID(O) of the quantum cryptography service level 1 platform to which the source quantum secure communication application device (O) belongs.

[0258] Here, the communication request message can be equivalent to the third request in the above embodiments.

[0259] Step 502: After receiving the communication request message, the cryptographic application of the destination quantum secure communication application device (T) returns a communication response message.

[0260] Here, the communication response message may carry the identification information QCSL1 ID(T) of the quantum cryptography service level 1 platform to which the destination quantum secure communication application device (T) belongs.

[0261] Here, the communication response message can be equivalent to the third response in the above embodiments.

[0262] Step 503: The cryptographic middleware of the source-end quantum secure communication application device (O) allocates available QSBK(O) for the cryptographic application, obtains the QSBK ID(O), and generates a QSKPK based on the QSBK(O). enc (O) and QSKPK int (O).

[0263] Step 504: The cryptographic application of the quantum secure communication application device (O) sends a quantum service session key request message to the quantum cryptographic service secondary platform to obtain the quantum service session key (QSSK) required for this quantum secure communication.

[0264] Here, the quantum service session key request message may carry information such as the source service ID, the destination service ID, and QSBKID(O); optionally, the quantum service session key request message may also carry QCSL1ID(O) and QCSL1 ID(T).

[0265] Here, the quantum service session key request message can be equivalent to the first request in the above embodiments.

[0266] Step 505: After receiving the quantum service session key request message, the quantum cryptography service secondary platform assigns a transaction identifier (ID) to this request message and determines whether the source quantum secure communication application device and the destination quantum secure communication application device belong to the same service domain.

[0267] Here, the transaction identifier (ID) is equivalent to the first identifier in the above embodiments.

[0268] Here, the quantum cryptography service secondary platform can determine whether the source-end quantum secure communication application device and the destination-end quantum secure communication application device belong to the same service domain based on whether the QCSL1 ID(O) and QCSL1 ID(T) are the same. As one implementation, the quantum cryptography service secondary platform can obtain the QCSL1 ID(O) and QCSL1 ID(T) from the quantum service session key request message, or obtain them through local query or querying the operation management platform using the source-end service ID and destination-end service ID information carried in the quantum service session key request message. If the QCSL1 ID(O) and QCSL1 ID(T) are the same, it can be determined that the source-end quantum secure communication application device and the destination-end quantum secure communication application device belong to the same service domain; if the QCSL1 ID(O) and QCSL1 ID(T) are different, it can be determined that the source-end quantum secure communication application device and the destination-end quantum secure communication application device belong to different service domains.

[0269] Step 506: If it is determined that the source quantum secure communication application device and the destination quantum secure communication application device belong to the same service domain, then proceed to step 507 to start the quantum service session key local domain distribution process; otherwise, proceed to the cross-domain distribution process. This embodiment of the invention does not involve the cross-domain distribution process.

[0270] Step 507: The quantum cryptography service secondary platform allocates a QSSK for this request.

[0271] The quantum secure communication system of this invention supports four session key acquisition and protection modes, which the quantum cryptography service secondary platform selects to use based on local conditions. This embodiment of the invention uses mode one (i.e., the first mode) for session key acquisition and protection.

[0272] The acquisition and protection modes of QSSK will be discussed later. Figure 10 And the corresponding detailed explanations, which will not be elaborated on here.

[0273] Step 508: The quantum cryptography service secondary platform returns a quantum service session key response message to the quantum secure communication application device (O).

[0274] Here, the quantum service session key response message carries the source service ID, destination service ID, QSBK ID(O), encrypted and integrity-protected QSSK and related information, transaction ID, and other information. The QSSK and related information can be represented using QSKPK. enc (O) and QSKPK int (O) Encryption and integrity protection.

[0275] Here, the quantum service session key response message can be equivalent to the first response in the above embodiment.

[0276] Step 509: Source-side quantum secure communication application device (O) cryptographic middleware based on QSKPK int (O) Verify the integrity of the encrypted and integrity-protected QSSK and related information. After successful verification, use QSKPK. enc (O) Decrypt to obtain QSSK and related information, and store QSSK securely.

[0277] Step 510: The cryptographic application of the source quantum secure communication application device (O) sends a quantum service session key notification message to the destination quantum secure communication application device (T).

[0278] Here, the quantum service session key notification message carries information such as the source service ID, the destination service ID, and the transaction ID.

[0279] Here, the quantum service session key notification message can be equivalent to the fifth message in the above embodiments.

[0280] Step 511: After receiving the quantum service session key notification message, the quantum secure communication application device (T) at the destination end allocates an available QSBK(T) for the cryptographic application, obtains the QSBKID(T), and generates a QSKPK based on the QSBK(T). enc (T) and QSKPK int (T).

[0281] Step 512: The cryptographic application of the quantum secure communication application device (T) sends a quantum service session key request message to the quantum cryptographic service secondary platform to obtain the QSSK allocated for this quantum secure communication.

[0282] Here, the quantum service session key request message carries information such as the source service ID, the destination service ID, QSBKID(T), and the transaction ID.

[0283] Here, the quantum service session key request message can be equivalent to the second request in the above embodiments.

[0284] Step 513: The quantum cryptography service secondary platform determines whether the QSSK is distributed within the local domain or across domains based on the transaction ID. If it is determined to be distributed within the local domain, the quantum cryptography service secondary platform then determines the acquisition and protection mode of the QSSK based on the transaction ID to obtain the QSSK.

[0285] Here, the quantum cryptography service secondary platform can determine the acquisition and protection mode of QSSK as Mode 1 (i.e., the first mode) based on the transaction ID. The specific processing flow is described later. Figure 11 And the corresponding detailed explanations, which will not be elaborated on here.

[0286] Step 514: The quantum cryptography service secondary platform returns a quantum service session key response message to the destination quantum secure communication application device (T).

[0287] Here, the quantum service session key response message carries the source service ID, destination service ID, QSBK ID(T), encrypted and integrity-protected QSSK and related information, transaction ID, and other information. The QSSK and related information can be represented using QSKPK. enc (T) and QSKPK int (T) Encryption and integrity protection are performed.

[0288] Here, the quantum service session key response message can be equivalent to the second response in the above embodiment.

[0289] Step 515: The cryptographic middleware of the destination quantum secure communication application device (T) is based on QSKPK. int (T) Verify the integrity of the QSSK and related information. After successful verification, use QSKPK. enc (T) Decrypt to obtain the QSSK and related information, and store the QSSK securely.

[0290] Step 516: The cryptographic application of the destination quantum secure communication application device (T) returns a quantum service session key response message to the source.

[0291] Here, the quantum service session key response message carries the QSSK acquisition result; wherein, the QSSK acquisition result indicates whether the QSSK was successfully acquired.

[0292] Here, the quantum service session key response message can be equivalent to the sixth message in the above embodiments.

[0293] Step 517: After successfully acquiring the QSSK, the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) generate a QSSK based on the QSSK. enc / QSSK int .

[0294] Here, the source-end quantum secure communication application device (O) and the destination-end quantum secure communication application device (T) can generate QSSK as needed. enc / QSSK int As one implementation method, QSSK enc / QSSKint It can be derived directly from QSSK, or it can be derived by fusing QSSK with a second session key generated by other means (e.g., generated by negotiation between the source quantum secure communication application device (O) and the destination quantum secure communication application device (T) based on an asymmetric cryptographic algorithm).

[0295] Step 518: Use QSSK or QSSK enc / QSSK int The source-end quantum secure communication application device (O) and the destination-end quantum secure communication application device (T) encrypt and / or protect the integrity of user information to achieve quantum secure communication.

[0296] Figure 10 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 2 This embodiment describes a processing flow for obtaining and protecting session keys. This session key acquisition and protection mode is the first mode (or mode one). In the first mode, the quantum cryptography service secondary platform generates a quantum service session key (QSSK) based on quantum random numbers and then hands the QSSK over to the quantum cryptography service primary platform for security protection. A secure channel is pre-established between the quantum cryptography service secondary platform and the quantum cryptography service primary platform to ensure the security of the QSSK transmission process. The quantum cryptography service secondary platform can obtain quantum random numbers through a locally connected QRNG (if any) or through the quantum cryptography service primary platform. This embodiment corresponds to the processing flow at the source end, such as... Figure 10 As shown, the method includes:

[0297] Step 601: After receiving the quantum service session key request message from the source quantum secure communication application device (O) and determining it to be a local domain communication, the quantum cryptography service secondary platform determines the session key acquisition and protection mode for this transaction. If mode one (i.e., the first mode) is selected, the quantum cryptography service secondary platform acquires a quantum random number and generates a QSSK based on the acquired quantum random number, associating the QSSK with the transaction ID.

[0298] Step 602: The quantum cryptography service secondary platform sends a session key protection request message to the quantum cryptography service primary platform. The session key protection request message carries QSBKID(O), QSSK and key-related information, etc., and is used to request the quantum cryptography service primary platform to provide security protection for the QSSK.

[0299] Here, the session key protection request message is equivalent to the first message in the above embodiment.

[0300] Here, security protection for QSSK includes, for example, encryption and integrity protection of QSSK.

[0301] The key-related information includes, for example, the lifetime of the QSSK.

[0302] Step 603: The quantum cryptography service primary platform retrieves the QSBK(O) based on the QSBK ID(O) and generates the QSKPK based on the QSBK(O). enc (O) and QSKPK int (O).

[0303] Step 604: The quantum cryptography service's primary platform uses QSKPK enc (O) and QSKPK int (O) Encrypt and protect the integrity of the received QSSK and key-related information.

[0304] This includes key-related information such as the lifetime of the QSSK.

[0305] Step 605: The quantum cryptography service level 1 platform returns a session key protection response message to the quantum cryptography service level 2 platform, which carries the QSBK ID(O) and the encrypted and / or integrity protected QSSK and key-related information.

[0306] Here, the session key protection response message can be equivalent to the second message in the above embodiment.

[0307] Figure 11 This is a schematic diagram of the interaction flow of the secure communication method according to an embodiment of the present invention. Figure 3 This embodiment describes a processing flow for obtaining and protecting session keys. This session key acquisition and protection mode is the first mode (or mode one). In the first mode, the quantum cryptography service secondary platform generates a quantum service session key (QSSK) based on quantum random numbers and then hands the QSSK over to the quantum cryptography service primary platform for security protection. A secure channel is pre-established between the quantum cryptography service secondary platform and the quantum cryptography service primary platform to ensure the security of the QSSK transmission process. The quantum cryptography service secondary platform can obtain quantum random numbers through a locally connected QRNG (if any) or through the quantum cryptography service primary platform. This embodiment corresponds to the processing flow at the destination end, such as... Figure 11 As shown, the method includes:

[0308] Step 701: After receiving the quantum service session key request message from the destination quantum secure communication application device (T), the quantum cryptography service secondary platform determines the session key acquisition and protection mode for this transaction based on the transaction ID carried in the quantum service session key request message. In mode one (i.e., the first mode), the quantum cryptography service secondary platform searches for the generated QSSK locally based on the transaction ID.

[0309] Step 702. The quantum cryptography service secondary platform sends a session key protection request message to the quantum cryptography service primary platform. The message carries QSBKID(T), QSSK, key-related information, etc., requesting the quantum cryptography service primary platform to provide security protection for the QSSK.

[0310] Here, the session key protection request message is equivalent to the third message in the above embodiment.

[0311] Here, security protection for QSSK includes, for example, encryption and integrity protection of QSSK.

[0312] The key-related information includes, for example, the lifetime of the QSSK.

[0313] Step 703. The quantum cryptography service primary platform retrieves QSBK(T) based on QSBKID(T) and generates QSKPK based on QSBK(T). enc (T) and QSKPK int (T).

[0314] Step 704. The quantum cryptography service's primary platform uses QSKPK. enc (T) and QSKPK int (T) Encrypt and protect the integrity of the received QSSK and key-related information.

[0315] This includes key-related information such as the lifetime of the QSSK.

[0316] Step 705. The quantum cryptography service primary platform returns a session key protection response message to the quantum cryptography service secondary platform, which carries the QSBK ID(T) and the encrypted and / or integrity-protected QSSK and related information.

[0317] Here, the session key protection response message can be equivalent to the fourth message in the above embodiments.

[0318] Examples of implementations of the present invention Figure 2The "separation of management and service" system architecture shown can effectively solve the problems of difficulty in connecting existing quantum cryptography service centers with business applications and inflexible adaptation and support. It can effectively integrate quantum, cryptography and application aspects, and has better scalability and compatibility. It can accelerate the connection between quantum cryptography service centers and different communication services, and promote the development of quantum communication towards large-scale, diversified and ubiquitous directions.

[0319] Furthermore, in the "separation of management and service" system architecture, the session key acquisition and mode one (i.e., the first mode) proposed in this embodiment of the invention solves the problem of how the secondary quantum cryptography service platform obtains the quantum service session key (QSSK) and encrypts and protects the key to ensure the secure distribution of the QSSK to the application device in the case of local / inter-regional quantum secure communication services. It provides a mechanism and method for the interaction and cooperation between the secondary quantum cryptography service platform and the primary platform, and provides an effective technical solution for the practical application of the "separation of management and service" system architecture.

[0320] Furthermore, this embodiment of the invention uses a first identifier (such as a transaction ID) to associate quantum secure communication services with key management, further implementing the system design principle of "separation of management and service". By introducing a first identifier (such as a transaction ID) to identify communication service requests and associating it with the QSSK acquisition and protection working mode (i.e., the first mode) and the QSSK key, the key identifier and the communication identifier are separated, simplifying the complexity of system design and implementation, avoiding the security risks of key-related information being exposed at the application layer due to the transmission of the key ID in the communication system, and improving system security while reducing system coupling.

[0321] Based on the above embodiments, this invention also provides a secure communication device, which is applied to a first entity. Figure 12 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 1 ;like Figure 12 As shown, the device includes: a first processing unit 11 and a first communication unit 12; wherein,

[0322] The first processing unit 11 is used to obtain the first session key;

[0323] The first communication unit 12 is configured to send a first message to the second entity; the first message is configured to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key; and / or, is configured to receive a second message sent by the second entity, the second message including the first session key after encryption and / or integrity protection.

[0324] In some optional embodiments of the present invention, the first communication unit 12 is further configured to receive a first request sent by the first application device, the first request being used to obtain a first session key, the first request including at least a first key identifier; and / or, further configured to send a first response to the first application device, the first response including the first session key after encryption and / or integrity protection.

[0325] In some optional embodiments of the present invention, the first processing unit 11 is further configured to allocate a first identifier, the first identifier being associated with the first session key and / or the first session key identifier.

[0326] In some optional embodiments of the present invention, the first identifier corresponds to a first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

[0327] In some optional embodiments of the present invention, the first message further includes at least one of the first key identifier and related information of the first session key; and / or,

[0328] The second message also includes at least one of the following: information related to the first key identifier, the encrypted and / or integrity-protected first session key; and / or,

[0329] The first response also includes the first identifier.

[0330] In some optional embodiments of the present invention, the first processing unit 11 is used to obtain a quantum random number and generate a first session key based on the quantum random number.

[0331] In some alternative embodiments of the present invention, the first processing unit 11 is configured to obtain the quantum random number from a quantum random number generator (QRNG) or the second entity.

[0332] In some optional embodiments of the present invention, the first processing unit 11 is configured to determine that the second entity serving the first application device is the same as the second entity serving the second application device, and generate a first session key based on the quantum random number; wherein the second application device is a device that communicates with the first application device.

[0333] In some optional embodiments of the present invention, the first request further includes second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device;

[0334] And / or, the first processing unit 11 is configured to determine that when the second identification information and the third identification information are the same, the second entity serving the first application device is the same as the second entity serving the second application device.

[0335] In some optional embodiments of the present invention, the first request carries the identifier of the first application device and / or the identifier of the second application device;

[0336] And / or, the first processing unit 11 is configured to query a third entity based on the identifier of the first application device to obtain second identifier information, and / or query a third entity based on the identifier of the second application device to obtain third identifier information; the second identifier information is the identifier of a second entity serving the first application device, and the third identifier information is the identifier of a second entity serving the second application device; when the second identifier information and the third identifier information are determined to be the same, it is determined that the second entity serving the first application device is the same as the second entity serving the second application device.

[0337] In some optional embodiments of the present invention, the first key corresponding to the first key identifier is used to generate the second key and then to generate the first protection key and / or the second protection key, or is used to generate the first protection key and / or the second protection key; the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the integrity of the first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key.

[0338] In some optional embodiments of the present invention, the first communication unit 12 is further configured to receive a second request sent by the second application device, the second request being used to obtain a first session key, the second request including at least a third key identifier; and / or, further configured to send a second response to the second application device, the second response including the first session key after encryption and / or integrity protection.

[0339] In some optional embodiments of the present invention, the second request further includes a first identifier; the first processing unit 11 is further configured to determine a first mode based on the first identifier and search for a first session key associated with the first identifier.

[0340] In some optional embodiments of the present invention, the first communication unit 12 is further configured to send a third message to the second entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message including at least the first session key; and / or, further configured to receive a fourth message sent by the second entity, the fourth message including the first session key after encryption and / or integrity protection.

[0341] In some optional embodiments of the present invention, the third message may further include at least one of the third key identifier and the relevant information of the first session key; and / or, the fourth message may further include at least one of the third key identifier and the relevant information of the encrypted and / or integrity-protected first session key.

[0342] In some optional embodiments of the present invention, the third key corresponding to the third key identifier is used to generate a fourth key and then generate a third protection key and / or a fourth protection key, or is used to generate a third protection key and a fourth protection key; the first session key after encryption and / or integrity protection is obtained by encrypting and / or protecting the integrity of the first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key.

[0343] In some alternative embodiments of the present invention, one or more first entities and the second entity interact with each other through a first interface.

[0344] In some alternative embodiments of the present invention, different first entities correspond to different applications, and / or, different first entities correspond to different types of applications, and / or, different first entities correspond to applications of different operating entities.

[0345] In some optional embodiments of the present invention, the first message includes a first session key that is encrypted and / or protected for integrity; and / or, the third message includes a first session key that is encrypted and / or protected for integrity.

[0346] In this embodiment of the invention, the first processing unit 11 in the device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA) in practical applications; the first communication unit 12 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in practical applications.

[0347] This invention also provides a secure communication device, which is applied to a second entity. Figure 13 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 2 ;like Figure 13As shown, the device includes: a second communication unit 21 and / or a second processing unit 22; wherein,

[0348] The second communication unit 21 is used to receive a first message sent by the first entity, the first message being used to request encryption and / or integrity protection of the first session key, and the first message including at least the first session key;

[0349] The second processing unit 22 is used to encrypt and / or protect the integrity of the first session key;

[0350] The second communication unit 21 is further configured to send a second message to the first entity, the second message including a first session key after encryption and / or integrity protection.

[0351] In some optional embodiments of the present invention, the first message further includes a first key identifier associated with the first application device; the second processing unit 22 is configured to obtain a first key based on the first key identifier; and is also configured to generate a second key based on the first key, generate a first protection key and / or a second protection key based on the second key, or generate a first protection key and / or a second protection key based on the first key; and is also configured to encrypt and / or protect the integrity of the first session key based on the first key, or the second key, or the first protection key and / or the second protection key.

[0352] In some optional embodiments of the present invention, the second communication unit 21 is further configured to receive a third message sent by the first entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message includes at least the first session key;

[0353] The second processing unit 22 is further configured to encrypt and / or protect the integrity of the first session key;

[0354] The second communication unit 21 is further configured to send a fourth message to the first entity, the fourth message including a first session key after encryption and / or integrity protection.

[0355] In some optional embodiments of the present invention, the third message may further include at least one of a third key identifier associated with the second application device and information related to the first session key; and / or, the fourth message may further include at least one of the third key identifier and information related to the encrypted and / or integrity-protected first session key.

[0356] In some optional embodiments of the present invention, the second processing unit 22 is further configured to obtain a third key based on the third key identifier; further configured to generate a fourth key based on the third key, generate a third protection key and / or a fourth protection key based on the fourth key, or generate a third protection key and / or a fourth protection key based on the third key; and further configured to encrypt and / or protect the integrity of the first session key based on the third key, or the fourth key, or the third protection key and / or the fourth protection key.

[0357] In some optional embodiments of the present invention, the first message may further include information related to the first session key; and / or, the second message may further include information related to the first session key after encryption and / or integrity protection.

[0358] In some optional embodiments of the present invention, the first message includes a first session key that is encrypted and / or protected for integrity; and / or, the third message includes a first session key that is encrypted and / or protected for integrity.

[0359] In this embodiment of the invention, the second processing unit 22 in the device can be implemented by a CPU, DSP, MCU or FPGA in practical applications; the second communication unit 21 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.

[0360] This invention also provides a secure communication device, which is applied to a first application device. Figure 14 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 3 ;like Figure 14 As shown, the device includes: a third processing unit 31 and a third communication unit 32; wherein,

[0361] The third processing unit 31 is used to obtain the first key identifier;

[0362] The third communication unit 32 is configured to send a first request to the first entity, the first request being used to obtain a first session key, the first request including at least the first key identifier; and / or to receive a first response sent by the first entity, the first response including the first session key after encryption and / or integrity protection.

[0363] In some optional embodiments of the present invention, the third processing unit 31 is used to allocate a first key to the application through a cryptographic middleware and obtain a first key identifier corresponding to the first key.

[0364] In some optional embodiments of the present invention, the third processing unit 31 is further configured to generate a second key based on the first key, and generate a first protection key and / or a second protection key based on the second key; or, generate a first protection key and / or a second protection key based on the first key.

[0365] In some optional embodiments of the present invention, the third processing unit 31 is further configured to perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key, to obtain the first session key.

[0366] In some alternative embodiments of the present invention, the first response further includes a first identifier; the first identifier is associated with the first session key and / or a first session key identifier.

[0367] In some optional embodiments of the present invention, the first identifier corresponds to a first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

[0368] In some optional embodiments of the present invention, the third communication unit 32 is further configured to send a fifth message to the second application device, the fifth message including at least the first identifier.

[0369] In some optional embodiments of the present invention, the third processing unit 31 is further configured to generate a third session key and / or a fourth session key based on the first session key, or to generate a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated by the first application device and the second application device; wherein the third session key and / or the fourth session key are used to encrypt and / or protect the integrity of the information sent and / or received by the third communication unit 32 during communication, and / or to decrypt and / or verify the integrity.

[0370] In some optional embodiments of the present invention, the third communication unit 32 is further configured to send a third request to the second application device, the third request being used to request the establishment of a connection; and to receive a third response sent by the second application device, the third response indicating that the connection has been established.

[0371] In some optional embodiments of the present invention, the third request includes second identification information, which is identification information of a second entity serving the first application device; and / or, the third response includes third identification information, which is identification information of a second entity serving the second application device.

[0372] In some optional embodiments of the present invention, the first request may further include second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; and / or, the first request may further include the identification of the first application device and / or the identification of the second application device.

[0373] In this embodiment of the invention, the third processing unit 31 in the device can be implemented by a CPU, DSP, MCU or FPGA in practical applications; the third communication unit 32 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.

[0374] This invention also provides a secure communication device, which is applied to a second application device. Figure 15 This is a schematic diagram of the composition structure of a secure communication device according to an embodiment of the present invention. Figure 4 ;like Figure 15 As shown, the device includes: a fourth processing unit 41 and a fourth communication unit 42; wherein,

[0375] The fourth processing unit 41 is used to obtain the third key identifier;

[0376] The fourth communication unit 42 is configured to send a second request to the first entity, the second request being used to obtain a first session key, the second request including at least the third key identifier; and / or to receive a second response sent by the first entity, the second response including the first session key after encryption and / or integrity protection.

[0377] In some optional embodiments of the present invention, the fourth processing unit 41 is used to allocate a third key to the application through a cryptographic middleware and obtain a third key identifier corresponding to the third key.

[0378] In some optional embodiments of the present invention, the fourth processing unit 41 is further configured to generate a fourth key based on the third key, and generate a third protection key and / or a fourth protection key based on the fourth key; or, generate a third protection key and / or a fourth protection key based on the third key.

[0379] In some optional embodiments of the present invention, the fourth processing unit 41 is further configured to perform integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key, to obtain the first session key.

[0380] In some optional embodiments of the present invention, the fourth communication unit 42 is further configured to receive a fifth message sent by the first application device, the fifth message including at least a first identifier, the first identifier being associated with the first session key and / or the first session key identifier, and / or the first identifier corresponding to a first mode, the first mode being used to indicate the acquisition method and / or security protection method of the first session key;

[0381] And / or, the second request may also include the first identifier.

[0382] In some optional embodiments of the present invention, the fourth processing unit 41 is further configured to generate a third session key and / or a fourth session key based on the first session key, or to generate a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated between the second application device and the first application device; wherein the third session key and / or the fourth session key are used to encrypt and / or protect the integrity of the information sent and / or received by the fourth communication unit 42 during communication, and / or to decrypt and / or verify the integrity.

[0383] In some optional embodiments of the present invention, the fourth communication unit 42 is further configured to receive a third request sent by the first application device, the third request being used to request the establishment of a connection; and to send a third response to the first application device, the third response indicating that the connection has been established.

[0384] In some optional embodiments of the present invention, the third request includes second identification information, which is identification information of a second entity serving the first application device; and / or, the third response includes third identification information, which is identification information of a second entity serving the second application device.

[0385] In this embodiment of the invention, the fourth processing unit 41 in the device can be implemented by a CPU, DSP, MCU or FPGA in practical applications; the fourth communication unit 42 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.

[0386] It should be noted that the secure communication device provided in the above embodiments is only illustrated by the division of the above program modules when performing secure communication. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the secure communication device and the secure communication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0387] This invention also provides a communication node. Figure 16 This is a schematic diagram of the hardware composition structure of the communication node according to an embodiment of the present invention, as shown below. Figure 16 As shown, the communication node includes a memory 52, a processor 51, and a computer program stored in the memory 52 and executable on the processor 51. When the processor 51 executes the program, it implements the steps of any of the secure communication methods of the present invention.

[0388] Optionally, the communication node may also include at least one network interface 53. The various components in the communication node are coupled together via a bus system 54. It is understood that the bus system 54 is used to implement communication between these components. In addition to a data bus, the bus system 54 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 16 The general labeled all buses as Bus System 54.

[0389] It is understood that memory 52 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 52 described in this embodiment of the invention is intended to include, but is not limited to, these and any other suitable types of memory.

[0390] The methods disclosed in the above embodiments of the present invention can be applied to processor 51, or implemented by processor 51. Processor 51 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 51 or by instructions in the form of software. The processor 51 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 51 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present invention can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 52. ​​Processor 51 reads the information in memory 52 and completes the steps of the aforementioned method in combination with its hardware.

[0391] In an exemplary embodiment, the communication node may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0392] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 52 including a computer program, which can be executed by a processor 51 of a communication node to perform the steps described in the foregoing method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM; or it may be various devices including one or any combination of the above-mentioned memories.

[0393] The computer-readable storage medium provided in the embodiments of the present invention stores a computer program thereon, which, when executed by a processor, implements the steps of any of the secure communication methods of the embodiments of the present invention.

[0394] This application also provides a computer program product, including a computer program that can be executed by a communication node (such as the processor 51 of the communication node) to complete the steps of any of the aforementioned secure communication methods.

[0395] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0396] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0397] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0398] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0399] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0400] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0401] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A secure communication method, characterized in that, The method is applied to a first entity, and the method includes: The first entity obtains the first session key and sends a first message to the second entity; the first message is used to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key. And / or, the first entity receives a second message sent by the second entity, the second message including a first session key encrypted and / or protected for integrity.

2. The method according to claim 1, characterized in that, The method further includes: The first entity receives a first request sent by the first application device, the first request being used to obtain a first session key, and the first request including at least a first key identifier; And / or, the first entity sends a first response to the first application device, the first response including a first session key encrypted and / or protected for integrity.

3. The method according to claim 2, characterized in that, The method further includes: The first entity assigns a first identifier, which is associated with the first session key and / or the first session key identifier.

4. The method according to claim 3, characterized in that, The first identifier corresponds to the first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

5. The method according to claim 1 or 3, characterized in that, The first message also includes at least one of the following: a first key identifier, information related to a first session key; and / or, The second message also includes at least one of the following: a first key identifier, information related to a first session key after encryption and / or integrity protection; and / or, The first response also includes the first identifier.

6. The method according to claim 1, characterized in that, The first entity obtains the first session key, including: The first entity acquires a quantum random number and generates a first session key based on the quantum random number.

7. The method according to claim 6, characterized in that, The first entity acquires quantum random numbers, including: The first entity obtains the quantum random number from the quantum random number generator (QRNG) or the second entity.

8. The method according to claim 6, characterized in that, The generation of the first session key based on the quantum random number includes: The first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, and generates a first session key based on the quantum random number; wherein, the second application device is a device that communicates with the first application device.

9. The method according to claim 8, characterized in that, The first request also includes second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; And / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: When the first entity determines that the second identification information and the third identification information are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device.

10. The method according to claim 8, characterized in that, The first request carries the identifier of the first application device and / or the identifier of the second application device; And / or, the first entity determines that the second entity serving the first application device is the same as the second entity serving the second application device, including: The first entity queries the third entity based on the identifier of the first application device to obtain the second identifier information, and / or queries the third entity based on the identifier of the second application device to obtain the third identifier information; the second identifier information is the identifier of the second entity serving the first application device, and the third identifier information is the identifier of the second entity serving the second application device; When the first entity determines that the second identification information and the third identification information are the same, it determines that the second entity serving the first application device is the same as the second entity serving the second application device.

11. The method according to claim 1, 2 or 4, characterized in that, The first key corresponding to the first key identifier is used to generate the second key, which in turn generates the first protection key and / or the second protection key, or is used to generate the first protection key and / or the second protection key; The encrypted and / or integrity-protected first session key is obtained by encrypting and / or protecting the integrity of the first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key.

12. The method according to claim 1, 3, or 4, characterized in that, The method further includes: The first entity receives a second request sent by the second application device, the second request being used to obtain a first session key, and the second request including at least a third key identifier; And / or, the first entity sends a second response to the second application device, the second response including a first session key that is encrypted and / or protected for integrity.

13. The method according to claim 12, characterized in that, The second request also includes a first identifier; the method further includes: The first entity determines a first pattern based on the first identifier and searches for a first session key associated with the first identifier.

14. The method according to claim 12, characterized in that, The method further includes: The first entity sends a third message to the second entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message includes at least the first session key; And / or, the first entity receives a fourth message sent by the second entity, the fourth message including a first session key that is encrypted and / or protected for integrity.

15. The method according to claim 14, characterized in that, The third message also includes at least one of the third key identifier and related information of the first session key; and / or, The fourth message also includes at least one of the information related to the third key identifier and the first session key after encryption and / or integrity protection.

16. The method according to claim 15, characterized in that, The third key corresponding to the third key identifier is used to generate the fourth key, which in turn generates the third protection key and / or the fourth protection key, or is used to generate the third protection key and the fourth protection key. The encrypted and / or integrity-protected first session key is obtained by encrypting and / or protecting the integrity of the first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key.

17. The method according to claim 1, characterized in that, One or more first entities interact with the second entity through a first interface.

18. The method according to claim 17, characterized in that, Different first entities correspond to different applications, and / or, different first entities correspond to different types of applications, and / or, different first entities correspond to applications operated by different entities.

19. The method according to claim 1 or 14, characterized in that, The first message includes a first session key that is encrypted and / or protected for integrity; and / or, The third message includes the first session key after encryption and / or integrity protection.

20. A secure communication method, characterized in that, The method is applied to a second entity, and the method includes: The second entity receives a first message sent by the first entity, the first message being used to request encryption and / or integrity protection of the first session key, the first message including at least the first session key; And / or, the second entity encrypts and / or protects the integrity of the first session key, and sends a second message to the first entity, the second message including the encrypted and / or integrity-protected first session key.

21. The method according to claim 20, characterized in that, The first message also includes a first key identifier associated with the first application device; the second entity encrypts and / or protects the integrity of the first session key, including: The second entity obtains the first key based on the first key identifier; A second key is generated based on the first key, and a first protection key and / or a second protection key are generated based on the second key; or, a first protection key and / or a second protection key are generated based on the first key. The first session key is encrypted and / or its integrity is protected based on the first key, or the second key, or the first protection key and / or the second protection key.

22. The method according to claim 20, characterized in that, The method further includes: The second entity receives a third message sent by the first entity, the third message being used to request encryption and / or integrity protection of the first session key; the third message includes at least the first session key; And / or, the second entity encrypts and / or protects the integrity of the first session key, and sends a fourth message to the first entity, the fourth message including the encrypted and / or integrity-protected first session key.

23. The method according to claim 22, characterized in that, The third message also includes at least one of a third key identifier related to the second application device and information related to the first session key; and / or, The fourth message also includes at least one of the information related to the third key identifier and the first session key after encryption and / or integrity protection.

24. The method according to claim 23, characterized in that, The second entity encrypts and / or protects the integrity of the first session key, including: The second entity obtains the third key based on the third key identifier; A fourth key is generated based on the third key, and a third protection key and / or a fourth protection key are generated based on the fourth key; or, a third protection key and / or a fourth protection key are generated based on the third key. The first session key is encrypted and / or its integrity is protected based on the third key, or the fourth key, or the third protection key and / or the fourth protection key.

25. The method according to claim 20, characterized in that, The first message also includes information related to the first session key; and / or, The second message also includes information about the first session key after encryption and / or integrity protection.

26. The method according to claim 20 or 22, characterized in that, The first message includes a first session key that is encrypted and / or protected for integrity; and / or, The third message includes the first session key after encryption and / or integrity protection.

27. A secure communication method, characterized in that, The method is applied to a first application device, and the method includes: The first application device obtains the first key identifier and sends a first request to the first entity. The first request is used to obtain the first session key and includes at least the first key identifier. And / or, the first application device receives a first response sent by the first entity, the first response including a first session key encrypted and / or protected for integrity.

28. The method according to claim 27, characterized in that, The first application device obtains the first key identifier, including: The cryptographic middleware of the first application device allocates a first key and obtains a first key identifier corresponding to the first key.

29. The method according to claim 27 or 28, characterized in that, The method further includes: The first application device generates a second key based on a first key, and generates a first protection key and / or a second protection key based on the second key; or, The first application device generates a first protection key and / or a second protection key based on the first key.

30. The method according to claim 29, characterized in that, The method further includes: The first application device performs integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the first key, or based on the second key, or based on the first protection key and / or the second protection key, to obtain the first session key.

31. The method according to claim 27, characterized in that, The first response also includes a first identifier; the first identifier is associated with the first session key and / or the first session key identifier.

32. The method according to claim 31, characterized in that, The first identifier corresponds to the first mode, which is used to indicate the method of obtaining the first session key and / or the method of security protection.

33. The method according to claim 31 or 32, characterized in that, The method further includes: The first application device sends a fifth message to the second application device, and the fifth message includes at least the first identifier.

34. The method according to claim 30, characterized in that, The method further includes: The first application device generates a third session key and / or a fourth session key based on the first session key, or generates a third session key and / or a fourth session key based on the first session key and a second session key, wherein the second session key is a session key negotiated between the first application device and the second application device; The third session key and / or the fourth session key are used to encrypt and / or protect the integrity of the information sent and / or received by the first application device during communication, and / or to decrypt and / or verify the integrity.

35. The method according to claim 27, characterized in that, The method further includes: The first application device sends a third request to the second application device, the third request being used to request the establishment of a connection; And / or, the first application device receives a third response sent by the second application device, the third response indicating that a connection has been established.

36. The method according to claim 35, characterized in that, The third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or, The third response includes third identification information, which is the identification information of the second entity serving the second application device.

37. The method according to claim 27 or 35, characterized in that, The first request also includes second identification information and / or third identification information; the second identification information is the identification information of a second entity serving the first application device; the third identification information is the identification information of a second entity serving the second application device; and / or, The first request also includes the identifier of the first application device and / or the identifier of the second application device.

38. A secure communication method, characterized in that, The method is applied to a second application device, and the method includes: The second application device obtains the third key identifier and sends a second request to the first entity. The second request is used to obtain the first session key, and the second request includes at least the third key identifier. And / or, the second application device receives a second response sent by the first entity, the second response including a first session key encrypted and / or protected for integrity.

39. The method according to claim 38, characterized in that, The second application device obtains a third key identifier, including: The cryptographic middleware of the second application device allocates a third key and obtains the third key identifier corresponding to the third key.

40. The method according to claim 38 or 39, characterized in that, The method further includes: The second application device generates a fourth key based on the third key, and generates a third protection key and / or a fourth protection key based on the fourth key; or, The second application device generates a third protection key and / or a fourth protection key based on the third key.

41. The method according to claim 40, characterized in that, The method further includes: The second application device performs integrity verification and / or decryption on the encrypted and / or integrity-protected first session key based on the third key, or based on the fourth key, or based on the third protection key and / or the fourth protection key, to obtain the first session key.

42. The method according to claim 38, characterized in that, The method further includes: The second application device receives a fifth message sent by the first application device. The fifth message includes at least a first identifier, which is associated with the first session key and / or the first session key identifier, and / or the first identifier corresponds to a first mode, which is used to indicate the acquisition method and / or security protection method of the first session key. And / or, the second request may also include the first identifier.

43. The method according to claim 41, characterized in that, The method further includes: The second application device generates a third session key and / or a fourth session key based on the first session key, or generates a third session key and / or a fourth session key based on the first session key and the second session key, wherein the second session key is a session key negotiated between the second application device and the first application device. The third session key and / or the fourth session key are used to encrypt and / or protect the integrity of information sent and / or received by the second application device during communication, and / or to decrypt and / or verify the integrity.

44. The method according to claim 38, characterized in that, The method further includes: The second application device receives a third request sent by the first application device, the third request being used to request the establishment of a connection; The second application device sends a third response to the first application device, the third response indicating that a connection has been established.

45. The method according to claim 44, characterized in that, The third request includes second identification information, which is the identification information of a second entity serving the first application device; and / or, The third response includes third identification information, which is the identification information of the second entity serving the second application device.

46. ​​A secure communication device, characterized in that, The device is applied to a first entity, and the device includes: a first processing unit and a first communication unit; wherein... The first processing unit is used to obtain the first session key; The first communication unit is configured to send a first message to the second entity; the first message is configured to request encryption and / or integrity protection of the first session key; the first message includes at least the first session key; and / or, is configured to receive a second message sent by the second entity, the second message including the first session key after encryption and / or integrity protection.

47. A secure communication device, characterized in that, The device is applied to a second entity, and the device includes: a second communication unit and / or a second processing unit; wherein... The second communication unit is configured to receive a first message sent by the first entity, the first message being used to request encryption and / or integrity protection of the first session key, and the first message including at least the first session key; The second processing unit is used to encrypt and / or protect the integrity of the first session key; The second communication unit is further configured to send a second message to the second entity, the second message including a first session key that is encrypted and / or protected for integrity.

48. A secure communication device, characterized in that, The device is applied to a first application device, and the device includes: a third processing unit and a third communication unit; wherein... The third processing unit is used to obtain the first key identifier; The third communication unit is configured to send a first request to the first entity, the first request being used to obtain a first session key, the first request including at least the first key identifier; and / or to receive a first response sent by the first entity, the first response including the first session key after encryption and / or integrity protection.

49. A secure communication device, characterized in that, The device is applied to a second application device, and the device includes: a fourth processing unit and a fourth communication unit; wherein... The fourth processing unit is used to obtain the third key identifier; The fourth communication unit is configured to send a second request to the first entity, the second request being used to obtain a first session key, the second request including at least the third key identifier; and / or to receive a second response sent by the first entity, the second response including the first session key after encryption and / or integrity protection.

50. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method according to any one of claims 1 to 45.

51. A communication node, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 45.

52. A computer program product, characterized in that, It includes computer program instructions that cause a computer to perform the steps of the method according to any one of claims 1 to 45.