Secure communication method based on quantum key
By standardizing the encoding and lifecycle management of quantum key data, and combining dynamic verification and round-robin decision-making, the problems of key format incompatibility and security in quantum key communication are solved, achieving efficient key management and secure communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YANGTZE UNIVERSITY
- Filing Date
- 2026-02-14
- Publication Date
- 2026-05-12
AI Technical Summary
Existing quantum key secure communication lacks standardized procedures, has insufficient key encoding adaptability leading to format incompatibility, lacks accurate marking and dynamic verification of key lifecycle, cannot identify expired keys in a timely manner, poses security risks, and has unreasonable key rotation strategies, affecting communication security and resource utilization.
The initial quantum key data is standardized and encoded with lifecycle state marking. Combined with a dynamic state verification mechanism, the validity of the key is determined. Intelligent rotation is carried out through a quantized rotation decision model. Combined with a security parameter negotiation process, the security of communication encryption and authentication is ensured.
It improves the format compatibility and adaptability of key data, ensures that only legitimate and usable keys participate in communication, strengthens the reliability of communication security protection, realizes intelligent dynamic key updates and secure parameter interaction, and meets the needs of high-security communication scenarios.
Smart Images

Figure CN122027136A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum communication technology, and in particular to a secure communication method based on quantum keys. Background Technology
[0002] In quantum key secure communication technology, the lack of standardized key management procedures and insufficient encoding adaptability of initial key data lead to format incompatibility issues during transmission and use, directly affecting the stability of the communication link and the continuity of data transmission. Furthermore, the lack of precise status marking and dynamic verification mechanisms throughout the key lifecycle makes it impossible to promptly identify expired or potentially vulnerable keys, resulting in risks such as key misuse and expired use during communication encryption, thus reducing the reliability of communication security protection.
[0003] In the key rotation and security parameter negotiation stages, existing technologies lack a scientific quantitative decision-making model, making it difficult to formulate reasonable rotation strategies by considering multiple dimensions such as the key's historical state and lifespan. This leads to untimely key updates or excessive rotation, wasting system resources and failing to effectively defend against security threats caused by key aging. Furthermore, the lack of an efficient interactive verification mechanism during security parameter negotiation results in insufficient security and integrity of parameter bindings, further weakening the protective effect of quantum keys in communication encryption and authentication, and failing to meet the needs of high-security communication scenarios. Summary of the Invention
[0004] This invention provides a secure communication method based on quantum key distribution to solve the problems mentioned in the background section.
[0005] To achieve the above objectives, the present invention provides a secure communication method based on quantum key distribution, comprising:
[0006] S1. Standardize and encode the initial quantum key data to obtain the encoded key data of the initial quantum key data;
[0007] S2. Mark the lifecycle status of the encoded key data to obtain manageable key data of the encoded key data;
[0008] S3. Based on the lifecycle status, perform status verification on the manageable key data to obtain the validity judgment result of the manageable key data;
[0009] S4. Based on the validity judgment result, perform key rotation on the manageable key data to obtain usable key data of the manageable key data;
[0010] S5. Based on the available key data, negotiate security parameters between the two communicating parties to obtain session security parameters for communication encryption and authentication;
[0011] S6. Encapsulate the communication data to be transmitted cryptographically to obtain the final ciphertext data of the communication data.
[0012] In a preferred embodiment, the step of standardizing and encoding the initial quantum key data to obtain encoded key data of the initial quantum key data includes:
[0013] In a quantum key distribution network, initial quantum key data is obtained to obtain an initial key sequence of the initial quantum key data;
[0014] Based on a specific secure communication protocol, the initial key sequence is protocol-adapted and encapsulated to obtain a formatted key sequence of the initial key sequence;
[0015] Based on preset encoding rules, code blocks are constructed from the formatted key sequence to obtain encoded key data of the initial quantum key data.
[0016] In a preferred embodiment, the step of marking the encoded key data with a lifecycle status to obtain manageable key data of the encoded key data includes:
[0017] A unique identifier is created for the encoded key data to obtain the identified key data of the encoded key data;
[0018] Perform a validity pre-validation on the identified key data to obtain the unmarked key data of the identified key data.
[0019] Based on a predefined key lifecycle strategy, an initial state label is assigned to the key data to be labeled to obtain the initial state key data of the key data to be labeled.
[0020] The initial state key data is associated and stored with the identity identifier and the initial state tag to obtain the manageable key data of the encoded key data.
[0021] In a preferred embodiment, the step of assigning an initial state label to the key data to be labeled based on a predefined key lifecycle strategy to obtain the initial state key data of the key data to be labeled includes:
[0022] Based on the key lifecycle policy, the key type of the key data to be marked is mapped by the policy to obtain the state definition rules of the key type;
[0023] Based on the state definition rules and the key type, the key data to be marked is subjected to feature parsing to obtain the generation timestamp and preset validity period of the key data to be marked;
[0024] The state transition point of the key data to be labeled is derived to obtain the first state transition time point of the key data to be labeled.
[0025] Based on the generated timestamp, the preset validity period, and the first state transition time point, the key data to be labeled is encapsulated with a state tag to obtain the initial state key data of the key data to be labeled.
[0026] In a preferred embodiment, the step of performing a status verification on the manageable key data based on the lifecycle state to obtain a validity judgment result for the manageable key data includes:
[0027] Extract the lifecycle status tag from the manageable key data to obtain the current status information of the manageable key data;
[0028] The current state information is structured and parsed to obtain the current state value and state time attribute of the manageable key data;
[0029] Based on the preset state validity rules, the current state value and the state time attribute are compared for compliance to obtain the intermediate result of the state verification of the manageable key data;
[0030] Based on the intermediate results of the status verification, the manageable key data is assessed for availability to obtain the validity judgment result of the manageable key data.
[0031] In a preferred embodiment, the step of performing key rotation on the manageable key data based on the validity judgment result to obtain usable key data of the manageable key data includes:
[0032] Based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated to obtain the quantitative rotation decision parameters of the manageable key data;
[0033] The quantized rotation decision parameters and the preset rotation trigger threshold are evaluated to obtain the rotation trigger decision for the manageable key data;
[0034] Based on the aforementioned rotation triggering decision, a new quantum key supply is triggered to obtain candidate key data for the manageable key data;
[0035] The availability of the candidate key data is verified to obtain the key data to be enabled after the candidate key data has been verified.
[0036] Replace the target key data in the manageable key data with the key data to be enabled, update its lifecycle status, and obtain the available key data of the manageable key data.
[0037] In a preferred embodiment, the step of calculating the rotation urgency index based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, to obtain the quantified rotation decision parameters of the manageable key data, includes:
[0038] Based on the manageable key data, a Boolean transformation is performed on the current validity judgment result to obtain the current valid value of the validity judgment result. When the judgment result is valid =1, invalid =0;
[0039] Obtain the manageable key data in the most recent consecutive Historical validity judgment result sequence within a verification period Calculate historical invalid frequencies ;
[0040] Based on the generation timestamp of the manageable key data, the existing time... The lifespan is determined, and the preset maximum lifespan of this type of key is obtained based on the key lifespan policy. ;
[0041] Based on preset weighting coefficients , , Calculate the rotation urgency index The quantized rotation decision parameters of the manageable key data are obtained.
[0042] In a preferred embodiment, the step of negotiating security parameters between the communicating parties based on the available key data to obtain session security parameters for communication encryption and authentication includes:
[0043] The available key data is subjected to key material extraction to obtain the session key material of the available key data;
[0044] Based on the session key material, parameter negotiation and interaction are performed between the two communicating parties to obtain the original security parameters of the session key material;
[0045] Cryptographically bind the original security parameters to obtain the session security parameters of the original security parameters.
[0046] In a preferred embodiment, the step of performing parameter negotiation and interaction between the communicating parties based on the session key material to obtain the original security parameters of the session key material includes:
[0047] The session key material is formatted and converted to obtain the standardized key material.
[0048] The initiator of the communication generates a first random number, and based on the standardized key material and the first random number, sends a negotiation request to the receiver of the two parties.
[0049] The negotiation request is verified and parsed. The receiver generates a second random number and returns a negotiation response to the initiator based on the standardized key material.
[0050] Key negotiation is performed on the first random number, the second random number, and the normalized key material to obtain the original security parameters of the session key material.
[0051] In a preferred embodiment, the step of cryptographically encapsulating the communication data to be transmitted to obtain the final ciphertext data of the communication data includes:
[0052] The encryption algorithm identifier and session encryption key are extracted from the session security parameters to obtain the communication encryption parameters of the session security parameters;
[0053] Based on the communication encryption parameters, the communication data to be transmitted is formatted into data blocks to obtain the communication data to be encrypted and organized;
[0054] The communication data to be encrypted and regularized is subjected to cryptographic transformation to obtain the initial ciphertext data of the communication data to be encrypted and regularized.
[0055] Based on the integrity verification information of the session encryption key, the initial ciphertext data is encapsulated for integrity to obtain the final ciphertext data of the initial ciphertext data.
[0056] Compared with the prior art, the present invention has the following beneficial effects:
[0057] 1. This invention significantly improves the format compatibility and adaptability of key data by performing a standardized encoding process on the initial quantum key data, completing protocol adaptation encapsulation and code block construction. This ensures the continuity of key transmission and use in the communication link, laying a stable foundation for secure communication. Simultaneously, by assigning a unique identifier and lifecycle status tag to the encoded key data, combined with a dynamic status verification mechanism, it achieves accurate determination of key validity, ensuring that only legitimate and usable keys participate in communication encryption, greatly improving the reliability of communication security protection.
[0058] 2. This invention utilizes a quantitative rotation decision model to calculate a rotation urgency index and combines multi-dimensional factors to formulate a key rotation strategy, achieving intelligent dynamic key updates. This avoids resource waste, effectively ensures key timeliness, and enhances the ability to resist security threats. Furthermore, through standardized security parameter negotiation procedures and cryptographic binding operations, the security and integrity of parameter interaction are strengthened. Combined with professional cryptographic encapsulation of communication data, this comprehensively improves the overall protection effect of communication encryption and authentication, meeting the core requirements of high-security communication scenarios. Attached Figure Description
[0059] Figure 1 This is a flowchart illustrating a secure communication method based on quantum key distribution according to an embodiment of the present invention.
[0060] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0061] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0062] This application provides a secure communication method based on quantum key distribution. The executing entity of this secure communication method based on quantum key distribution includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the secure communication method based on quantum key distribution can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cluster of cloud servers. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0063] Reference Figure 1 The diagram shown is a flowchart illustrating a secure communication method based on quantum key distribution according to an embodiment of the present invention. In this embodiment, the secure communication method based on quantum key distribution includes:
[0064] S1. Standardize and encode the initial quantum key data to obtain the encoded key data of the initial quantum key data;
[0065] In this embodiment of the invention, the step of standardizing and encoding the initial quantum key data to obtain encoded key data of the initial quantum key data includes:
[0066] In a quantum key distribution network, initial quantum key data is obtained to obtain an initial key sequence of the initial quantum key data;
[0067] Based on a specific secure communication protocol, the initial key sequence is protocol-adapted and encapsulated to obtain a formatted key sequence of the initial key sequence;
[0068] Based on preset encoding rules, code blocks are constructed from the formatted key sequence to obtain encoded key data of the initial quantum key data.
[0069] In a quantum key distribution network, the initial quantum key data that has undergone key negotiation and screening is obtained from the key generator through the key interaction channel between network nodes. During the acquisition process, the integrity of the data transmission needs to be confirmed, that is, the data transmission identifier is verified to ensure that no data is lost or tampered with. After the acquisition is completed, the initial quantum key data is arranged into a continuous binary bit sequence according to its generation order. This sequence is the initial key sequence.
[0070] Based on the SSL / TLS secure communication protocol, the obtained initial key sequence is encapsulated for protocol adaptation. During the encapsulation process, the core bit information of the initial key sequence is extracted first, and then a protocol identifier field is added to the head and a verification field is added to the tail of the initial key sequence according to the key encapsulation format specified by the SSL / TLS secure communication protocol. The protocol identifier field is used to identify the communication protocol type adapted to the key sequence, and the verification field is used to verify the validity of the encapsulated data later. The bit sequence that conforms to the format requirements of the SSL / TLS secure communication protocol after encapsulation is the formatted key sequence.
[0071] The encoding rule is preset to fixed-length code block encoding, stipulating that each code block is 128 bits long. If the length is less than 128 bits, the end is padded with 0. Each code block is also given a unique code block identifier. The formatted key sequence is constructed by dividing the sequence into 128-bit units starting from the beginning. Each code block is given a unique code block identifier. If the last code block after division is less than 128 bits, it is padded with 0 until the length reaches 128 bits. After all code block division, identifier addition and padding operations are completed, all processed code blocks are combined in the order of division. The combined data is the encoded key data of the initial quantum key data.
[0072] S2. Mark the lifecycle status of the encoded key data to obtain manageable key data of the encoded key data;
[0073] In this embodiment of the invention, the step of marking the lifecycle status of the encoded key data to obtain manageable key data of the encoded key data includes:
[0074] A unique identifier is created for the encoded key data to obtain the identified key data of the encoded key data;
[0075] Perform a validity pre-validation on the identified key data to obtain the unmarked key data of the identified key data.
[0076] Based on a predefined key lifecycle strategy, an initial state label is assigned to the key data to be labeled to obtain the initial state key data of the key data to be labeled.
[0077] The initial state key data is associated and stored with the identity identifier and the initial state tag to obtain the manageable key data of the encoded key data.
[0078] The predefined key lifecycle strategy assigns an initial state label to the key data to be labeled, obtaining the initial state key data of the key data to be labeled, including:
[0079] Based on the key lifecycle policy, the key type of the key data to be marked is mapped by the policy to obtain the state definition rules of the key type;
[0080] Based on the state definition rules and the key type, the key data to be marked is subjected to feature parsing to obtain the generation timestamp and preset validity period of the key data to be marked;
[0081] The state transition point of the key data to be labeled is derived to obtain the first state transition time point of the key data to be labeled.
[0082] Based on the generated timestamp, the preset validity period, and the first state transition time point, the key data to be labeled is encapsulated with a state tag to obtain the initial state key data of the key data to be labeled.
[0083] A key identity generation mechanism is adopted to create a unique identity for the encoded key data. In the generation process, the core code block information of the encoded key data is extracted first. Then, combined with the generation timestamp of the encoded key data and the node number in the quantum key distribution network, the core code block information, timestamp, and node number are concatenated in a fixed order. After the concatenation is completed, the uniqueness of the concatenation result is verified to confirm that the concatenation result does not appear in the generated key identity. After the verification is passed, the concatenation result is the unique identity of the encoded key data. The identity is bound to the encoded key data to obtain the identified key data of the encoded key data.
[0084] The identified key data undergoes a validity pre-verification process using a fixed logic. First, the identity identifier and the original encoded key data are separated from the identified key data. Then, the format of the identity identifier is checked to ensure it conforms to a preset specification. Specifically, the identity identifier is 64 bits long, with the first 32 bits representing the core code block information of the encoded key data, the middle 16 bits representing the timestamp, and the last 16 bits representing the node number. After the format verification passes, the integrity of the code blocks in the original encoded key data is checked to confirm that each code block is 128 bits long and has a unique identifier. Once both the format verification and the code block integrity verification pass, the identified key data is considered valid, and the key data to be marked is obtained. If any verification fails, the identified key data is deemed invalid and will not proceed to the next step.
[0085] Based on a predefined key lifecycle strategy, an initial state label is assigned to the key data to be labeled. The assignment process first specifies that the predefined initial state label is uniquely "not enabled". This label is used to indicate that the key has not yet been used for secure communication. Then, the "not enabled" initial state label is bound to the key data to be labeled. During the binding process, the time of label assignment is recorded to ensure that the binding relationship between the label and the key data to be labeled is traceable. After the binding is completed, the initial state key data of the key data to be labeled is obtained. The initial state key data includes three parts: the key data to be labeled, the identity identifier, and the "not enabled" initial state label.
[0086] The initial state key data is associated with and stored in relation to the identity identifier and initial state tag. The storage process first establishes a fixed associated storage structure, which clearly divides three storage areas for storing the initial state key data, identity identifier, and initial state tag, respectively. Then, the initial state key data is stored in the corresponding storage area, while the identity identifier and initial state tag are stored in their respective areas. After storage, an association index is established among the three. Through this index, any query of any item can be associated with the other two items, ensuring that the association relationship among the three is not lost after storage. After storage is completed and the association index is successfully established, manageable key data of the encoded key data is obtained. This manageable key data can achieve unified management and querying of the identity identifier, initial state tag, and initial state key data through the association index.
[0087] A predefined key lifecycle policy has been pre-fixed and stored. This policy clearly distinguishes two unique key types, and each key type corresponds to a unique state definition rule. When mapping the key type of the key data to be marked, the key type identifier is first extracted from a fixed position in the key data to be marked, where binary 0 corresponds to the transmission key and binary 1 corresponds to the storage key. Then, by querying the pre-fixed key lifecycle policy, the complete rule corresponding to the key type identifier is found. The state definition rule for the transmission key is "the initial state label is uniformly set to 'not enabled,' the preset validity period is fixed at 72 hours, and the state transition is based on the expiration of the validity period." The state definition rule for the storage key is "the initial state label is uniformly set to 'not enabled,' the preset validity period is fixed at 168 hours, and the state transition is based on the expiration of the validity period." After the query is completed, the state definition rule for the key type is obtained.
[0088] Based on the state definition rules and the key type of the key data to be labeled, feature parsing is performed on the key data to be labeled. During parsing, the key type of the current key data to be labeled and the preset validity period value in the corresponding state definition rules are first determined. Then, the generated timestamp is extracted from the fixed field in the header of the key data to be labeled. The parsing method of the generated timestamp is to convert the 24-bit binary field into year, month, day, hour, minute, and second in sequence, accurate to the second, with the format fixed as "year-month-day-hour-minute-second" to ensure that the generated timestamp can be directly read and traced. At the same time, the preset validity period is determined according to the state definition rules. If the key type is a transmission key, the preset validity period is 72 hours. If it is a storage key, the preset validity period is 168 hours. After feature parsing is completed, the generated timestamp and preset validity period of the key data to be labeled are obtained.
[0089] The state transition point of the key data to be marked is derived based on the generation timestamp and preset validity period of the acquired key data. The derivation process first clarifies the specific time corresponding to the generation timestamp, and then adds the duration corresponding to the preset validity period to this specific time. When accumulating the duration, the calculation is performed sequentially by hour, minute, and second to avoid cross-unit errors. For example, if the generation timestamp is 2024-06-01-08-00-00 and the preset validity period is 72 hours, then the number of hours of the generation timestamp is added to 72, and the calculated time 2024-06-04-08-00-00 is the first state transition time point. This time point is the only trigger time for the key data to be marked to transition from the initial state to the next state. After the derivation is completed, the first state transition time point of the key data to be marked is obtained.
[0090] Based on the generated timestamp, the preset validity period, and the first state transition time, the key data to be labeled is encapsulated with a state tag. Before encapsulation, a fixed format for the initial state tag is determined. This format includes four fixed items: the initial state identifier "Not Enabled", the generated timestamp, the preset validity period, and the first state transition time. These four items are concatenated in a fixed order to form a unified tag string. During encapsulation, this tag string is added to the end of the key data to be labeled. After adding the tag string, an integrity check is performed on the entire data. The check includes ensuring that the tag string is bound to the key data to be labeled without any missing items, that the four items in the tag are complete, and that they are completely consistent with the information already obtained. After the check passes, the encapsulation of the state tag is completed, resulting in the initial state key data of the key data to be labeled. This initial state key data includes the key data to be labeled, its corresponding unique identifier, and the encapsulated complete initial state tag, which can be directly used for subsequent associated storage operations.
[0091] S3. Based on the lifecycle status, perform status verification on the manageable key data to obtain the validity judgment result of the manageable key data;
[0092] In this embodiment of the invention, the step of performing a status verification on the manageable key data based on the lifecycle state to obtain a validity judgment result of the manageable key data includes:
[0093] Extract the lifecycle status tag from the manageable key data to obtain the current status information of the manageable key data;
[0094] The current state information is structured and parsed to obtain the current state value and state time attribute of the manageable key data;
[0095] Based on the preset state validity rules, the current state value and the state time attribute are compared for compliance to obtain the intermediate result of the state verification of the manageable key data;
[0096] Based on the intermediate results of the status verification, the manageable key data is assessed for availability to obtain the validity judgment result of the manageable key data.
[0097] The manageable key data consists of three parts: the key data to be tagged, a unique identifier, and a complete lifecycle status label. These three parts are stored together through an associated index. When extracting the lifecycle status label from the manageable key data, the storage area of the lifecycle status label is first located through the associated index. This storage area is a fixed label storage segment. The label content is then completely extracted from this storage segment. During the extraction process, the start and end identifiers of the label are checked to ensure that the extracted label content is complete and free of extra characters. After extraction, the current status information of the manageable key data is obtained, which is the complete lifecycle status label content.
[0098] When performing structured parsing of the current state information, the fixed structured format of the current state information is first defined. This format is consistent with the initial state tag encapsulation format mentioned earlier, and includes four fixed items: current state identifier, generation timestamp, preset validity period, and first state transition time point. Each item is separated by a clear separator. During the parsing process, the current state information is split according to the separators, and the four items are extracted respectively. The current state identifier is the current state value. The generation timestamp, preset validity period, and first state transition time point are integrated into the state time attribute. After parsing, the current state value and state time attribute of the manageable key data are obtained. After parsing, it is necessary to verify that the four split items are consistent with the original tag content to avoid parsing errors.
[0099] The pre-defined state validity rules are stored in advance. These rules clearly define the compliance judgment criteria and compliance requirements for the state time attribute corresponding to different current state values. During compliance comparison, the pre-defined state validity rules are queried first to find the specific compliance standard corresponding to the current state value. Then, the current state value and the state time attribute are compared separately. The current state value must conform to the set of valid states preset in the rules. In the state time attribute, if the current time does not exceed the first state transition time point, it is considered compliant. If the current state value belongs to the set of valid states and the state time attribute meets the requirements, it is judged as compliant; otherwise, it is judged as non-compliant. After the comparison is completed, the intermediate result of the state verification of the manageable key data is obtained. This intermediate result is divided into only two cases: compliant and non-compliant, and the specific reasons for non-compliance are clearly marked.
[0100] When adjudicating the availability of manageable key data based on the intermediate results of status verification, a fixed adjudication logic is adopted. If the intermediate results of status verification are compliant, the manageable key data is adjudicated as available, and the validity judgment result is valid. If the intermediate results of status verification are non-compliant, the reason for non-compliance needs to be further confirmed. If it is due to non-compliance of the current status value, the manageable key data is adjudicated as unavailable, and the validity judgment result is invalid. If it is due to non-compliance of the status time attribute, the manageable key data is also adjudicated as unavailable, and the validity judgment result is invalid. After the adjudication is completed, the validity judgment result of the manageable key data is obtained. This result only includes two cases: valid and invalid, and is accompanied by the adjudication basis to ensure that the adjudication process is traceable and unambiguous.
[0101] S4. Based on the validity judgment result, perform key rotation on the manageable key data to obtain usable key data of the manageable key data;
[0102] In this embodiment of the invention, the step of performing key rotation on the manageable key data based on the validity judgment result to obtain usable key data of the manageable key data includes:
[0103] Based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated to obtain the quantitative rotation decision parameters of the manageable key data;
[0104] The quantized rotation decision parameters and the preset rotation trigger threshold are evaluated to obtain the rotation trigger decision for the manageable key data;
[0105] Based on the aforementioned rotation triggering decision, a new quantum key supply is triggered to obtain candidate key data for the manageable key data;
[0106] The availability of the candidate key data is verified to obtain the key data to be enabled after the candidate key data has been verified.
[0107] Replace the target key data in the manageable key data with the key data to be enabled, update its lifecycle status, and obtain the available key data of the manageable key data.
[0108] Based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated to obtain the quantitative rotation decision parameters of the manageable key data, including:
[0109] Based on the manageable key data, a Boolean transformation is performed on the current validity judgment result to obtain the current valid value of the validity judgment result. When the judgment result is valid =1, invalid =0;
[0110] Obtain the manageable key data in the most recent consecutive Historical validity judgment result sequence within a verification period Calculate historical invalid frequencies ;
[0111] Based on the generation timestamp of the manageable key data, the existing time... The lifespan is determined, and the preset maximum lifespan of this type of key is obtained based on the key lifespan policy. ;
[0112] Based on preset weighting coefficients , , Calculate the rotation urgency index The quantized rotation decision parameters of the manageable key data are obtained.
[0113] Based on the validity judgment result, the historical status records of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated. The calculation process first clarifies the specific extraction and value standards for the three basic pieces of information: a validity judgment result is assigned a value of 1, and an invalid result is assigned a value of 0. Historical status records are extracted from the associated storage area of the manageable key data, extracting only the three most recent complete status verification results. The generation time is extracted from the status time attribute of the manageable key data, accurate to the second and converted to the duration from the current time. During the calculation, invalid records in the historical status records are first counted. The score is determined by the number of invalid results. If the number of invalid results is 0, the base score is 10; if the number of invalid results is 1, the base score is 6; and if the number of invalid results is 2 or more, the base score is 2. The score is then adjusted based on the validity judgment result. If the validity judgment result is valid, the base score is increased by 2; if the validity judgment result is invalid, the base score is decreased by 3. Finally, the score is adjusted based on the duration converted from the generation time. If the generation time is more than 50% of its preset validity period from the current time, the current score is decreased by 2; if it is not more than 50%, the score is increased by 1. The final adjusted score is the rotation urgency index, which is the quantitative rotation decision parameter of the manageable key data.
[0114] The formula for calculating the rotation urgency index is as follows:
[0115] ;
[0116] in ;
[0117] In the formula, The rotation urgency index, To balance the weighting coefficient of immediate failure, For historical unreliability weighting coefficient, This is the key aging weight coefficient. This is the currently valid value. These are historical invalid frequencies. Survival time To preset the maximum survival time, For the length of the statistical period, This is a historical validity sequence.
[0118] The quantized rotation decision parameters and a preset rotation trigger threshold are evaluated to determine the trigger conditions. The preset rotation trigger threshold is pre-fixed and stored with a value of 5. This threshold is set based on the minimum guarantee requirements for key security, ensuring that the key is rotated in time before any security risks arise. The evaluation process first clarifies the specific score of the quantized rotation decision parameters and the fixed value of the rotation trigger threshold of 5, and then directly compares the two. During the comparison, it is only determined whether the score of the quantized rotation decision parameters is less than or equal to the rotation trigger threshold of 5. If the quantized rotation decision parameter is ≤ 5, it is determined that the rotation trigger condition is met; if the quantized rotation decision parameter is > 5, it is determined that the rotation trigger condition is not met. After the comparison is completed, the rotation trigger decision of the manageable key data is obtained. This rotation trigger decision contains only two clear results: meeting the rotation trigger condition and not meeting the rotation trigger condition, and a detailed record of the comparison process is attached.
[0119] Based on the aforementioned rotation triggering decision, a new quantum key supply is triggered. The triggering process first determines the specific result of the rotation triggering decision. The triggering operation is only executed if the rotation triggering decision meets the rotation triggering conditions. If the rotation triggering conditions are not met, the step is terminated. During the triggering operation, a key supply request in a fixed format is sent to the key generation end through the key supply channel of the quantum key distribution network. The request contains a unique identifier of the manageable key data, used to identify the target key that needs to be replaced. After receiving the request, the key generation end generates a completely new set of initial quantum key data according to the initial quantum key data generation process described above, completes the standardized encoding, generates encoded key data, and then feeds back the encoded key data to the current processing node through the same supply channel. During the reception process, the identity and integrity of the key are verified to ensure that the received key data is not lost or tampered with. After the reception is completed, candidate key data of the manageable key data is obtained. This candidate key data is the encoded key data of the newly supplied key.
[0120] The availability of the candidate key data is verified. The verification process strictly follows the state verification procedure for manageable key data described above. First, a temporary identity is created for the candidate key data and associated with it for storage. The implicit lifecycle state information is extracted, and the current state value and state time attribute are parsed. Then, compliance comparison is performed based on the preset state validity rules. At the same time, the integrity of the code block and the uniqueness of the identity of the candidate key data are additionally verified. Each code block is 128 bits long and the code block identity is unique. If all verification items pass, the verification is considered successful. If any verification item fails, the verification is considered unsuccessful, and a quantum key supply needs to be triggered again for verification. This process continues until the candidate key data that has passed verification is obtained. After successful verification, the candidate key data that has passed verification is obtained as the key data to be used. This key data to be used can be directly used for subsequent key replacement operations.
[0121] The target key data in the manageable key data is replaced with the key data to be enabled, and its lifecycle status is updated. The replacement process first locates the storage area of the target key data to be replaced through the association index of the manageable key data, and then writes the key data to be enabled completely into the storage area, overwriting the original target key data. After writing, the written content is checked to ensure that it is consistent with the key data to be enabled to avoid replacement errors. Then, the lifecycle status label of the manageable key data is updated, the initial status label is updated to "enabled", the generated timestamp is updated to the current time, and the first state transition time point is re-derived. After the update is completed, the association index of each part of the manageable key data is re-established to ensure that the association relationship is not lost. After all operations are completed, the usable key data of the manageable key data is obtained. The usable key data includes the replaced key data to be enabled, the original unique identifier, and the updated lifecycle status label, and can be directly used for secure communication.
[0122] Rotation urgency index The value is derived from the relevant attributes of manageable key data. After calculation, it serves as a quantitative rotation decision parameter for manageable key data and is used to evaluate subsequent rotation trigger conditions. Its value is calculated by each parameter in the formula according to fixed logic and is the only quantitative indicator reflecting the urgency of key rotation.
[0123] Weighting coefficient The data is derived from historical data and practical experience in quantum key security management, and all three values are fixed and sum to 1. Used to balance the immediate failure factor, with a value of 0.4. Used to balance historical unreliability factors, with a value of 0.3. The value of 0.3 is used to balance the key aging factor. This value is based on a summary of a large amount of key rotation practice data to ensure that the influence of the three factors on the rotation urgency index is reasonable, highlighting the priority of immediate failure while also taking into account the impact of historical unreliability and key aging.
[0124] Current valid value The source is the validity judgment result of the manageable key data. The extraction process involves obtaining the latest validity judgment result from the status verification record of the manageable key data. If the validity judgment result is valid, then... The value is 1; if the validity judgment result is invalid, then... The value is 0. This value is a pre-defined criterion that directly corresponds to the validity judgment result, ensuring that the parameter value is completely consistent with the current actual state of the key.
[0125] Historical invalid frequencies The source is the historical state record of manageable key data; the calculation process requires first determining the length of the statistical period. Then extract the historical validity sequence. ,in The value is a fixed value preset based on the key usage period, which is 3. This means that the results of the most recent 3 status checks are statistically analyzed, which is within a reasonable statistical range of the key's historical status. The source is nearly extracted from the associated storage area of manageable key data. Each validity judgment result corresponds to one If effective The value is 1; if invalid, then... The value is 0. After extraction, the calculation is performed. Second The average value, when subtracted from 1, is the historical invalidity frequency F, which reflects the degree of unreliability in the historical use of the key.
[0126] Survival time The source of the time is the generation time and the current time of the manageable key data. The acquisition process involves extracting the generation timestamp from the status time attribute of the manageable key data, recording the specific time of the current operation, subtracting the generation timestamp from the current time, and converting the result into hours. This duration is the time the key has been alive. The conversion process deducts amounts sequentially in hours, minutes, and seconds to ensure accurate calculation of the duration, directly reflecting the time the key has been used from generation to the present.
[0127] Preset maximum survival time The source is the preset validity period of the manageable key data. The extraction process involves extracting the specific value of the preset validity period from the status and time attributes of the manageable key data. This value is consistent with the preset validity period corresponding to the key type mentioned earlier. (The last part, "transmission key," appears to be incomplete and lacks context. It's left as is.) The value is 72 hours, used to store the key. The value is set to 168 hours, directly using the preset validity period determined when the key was generated, as the benchmark for the longest period during which the key can be used securely.
[0128] Statistical period length The source of this value is a conventional frequency preset based on key status verification, with a fixed value of 3. This value is based on practical experience in key usage. The results of the last 3 status verifications can reasonably reflect the recent historical status of the key. This ensures that the results are not biased due to too few statistical counts, nor does it increase computational redundancy due to too many statistical counts, thus ensuring that the calculation results of the historical invalid frequency F have reference value.
[0129] Historical validity sequence The source is the historical status verification record of manageable key data. The extraction process involves locating the storage area of the historical status verification record through the association index of the manageable key data, and extracting the most recent records in chronological order. Each validity judgment result corresponds to one... During extraction, ensure the records are in the correct chronological order and that no results are missing; if valid, then... The value is 1; if invalid, then... The value is 0, forming a complete historical validity sequence. For historical invalid frequencies The calculations provide the basic data.
[0130] The meaning of this formula is to obtain the rotation urgency index through quantitative calculation. This enables accurate assessment of the urgency of manageable key data rotation, integrating three key influencing factors: immediate expiration, historical unreliability, and key aging. This part is used to quantify the immediate impact of key expiration. When the validity judgment result is invalid, this part increases, thereby increasing the urgency of the rotation. This is used to quantify the impact of historical unreliability of the key. The higher the frequency of historical invalidity, the larger this value is, and the stronger the urgency of the rotation. The aging effect of the quantified key is considered; the closer the existing lifespan is to the preset maximum lifespan, the larger this value, indicating a stronger rotation urgency. The three factors are weighted to balance their influence, resulting in a final rotation urgency index. As the core basis for key rotation triggering decisions, it enables accurate triggering of key rotation, ensures that manageable key data is always in a secure and available state, avoids security communication risks caused by key expiration, aging, or historical unreliability, and avoids unnecessary key rotation, ensuring the efficiency and security of key use. It is connected with the overall key rotation process mentioned above, provides clear quantitative parameters for comparing rotation trigger thresholds, and ensures the scientific nature and reproducibility of key rotation decisions.
[0131] S5. Based on the available key data, negotiate security parameters between the two communicating parties to obtain session security parameters for communication encryption and authentication;
[0132] In this embodiment of the invention, the step of negotiating security parameters between the communicating parties based on the available key data to obtain session security parameters for communication encryption and authentication includes:
[0133] The available key data is subjected to key material extraction to obtain the session key material of the available key data;
[0134] Based on the session key material, parameter negotiation and interaction are performed between the two communicating parties to obtain the original security parameters of the session key material;
[0135] Cryptographically bind the original security parameters to obtain the session security parameters of the original security parameters.
[0136] The process of performing parameter negotiation and interaction between the two communicating parties based on the session key material to obtain the original security parameters of the session key material includes:
[0137] The session key material is formatted and converted to obtain the standardized key material.
[0138] The initiator of the communication generates a first random number, and based on the standardized key material and the first random number, sends a negotiation request to the receiver of the two parties.
[0139] The negotiation request is verified and parsed. The receiver generates a second random number and returns a negotiation response to the initiator based on the standardized key material.
[0140] Key negotiation is performed on the first random number, the second random number, and the normalized key material to obtain the original security parameters of the session key material.
[0141] The available key data includes the replaced key data to be activated, the original unique identifier, and the updated lifecycle status label. The key data to be activated is the standardized encoded key data, consisting of multiple 128-bit code blocks. When extracting key material from the available key data, the storage area of the key data to be activated is first located through the associated index, and all complete code block data in this area is extracted. Then, the first four code blocks are selected as the source of key material. The selection criterion is the four consecutive code blocks with the smallest code block identifier. After selection, the code block identifier field is removed, and only the core bit information in each code block is retained. The core bit information of the four code blocks is concatenated in ascending order of code block identifier. During the concatenation process, the length of each code block is checked to ensure that the total length after concatenation is 512 bits. After concatenation, the session key material of the available key data is obtained. This session key material is a continuous 512-bit core bit sequence, which is only used for subsequent security parameter negotiation and does not directly participate in communication encryption and authentication.
[0142] Based on the session key material, parameter negotiation is performed between the two communicating parties, namely the initiator and the receiver. Both parties have stored a unique identifier corresponding to the available key data. The interaction process begins with the initiator splitting the session key material into two 256-bit sub-sequences according to a fixed format. The first sub-sequence is then used as the negotiation initiation identifier, and after adding the initiator's node number, it is sent to the receiver through a secure communication channel. Upon receiving the sub-sequence, the receiver verifies the validity of the initiator's node number. If the verification is successful, the receiver extracts the second sub-sequence of the session key material, adds the receiver's node number, and sends it back to the initiator. Upon receiving the feedback, the initiator verifies the validity of the receiver's node number and the consistency between the fed-back sub-sequence and its own split second sub-sequence. If the verification is correct, both parties generate a set of temporary parameter sequences based on their stored session key material. This parameter sequence contains the negotiation identifier, node verification information, and temporary interaction identifier. After both parties confirm that the temporary parameter sequences are completely consistent, they obtain the original security parameters of the session key material. These original security parameters are the temporary parameter sequences that both parties have confirmed, containing the basic parameters required for communication encryption and the verification parameters required for authentication.
[0143] Cryptographic binding is performed on the original security parameters. The binding process adopts a fixed binding logic. First, the negotiation identifier and temporary interaction identifier are extracted from the original security parameters. After concatenating the two in sequence, they are associated with the session key material. The binding method is to add the concatenated identifier sequence to the end of the original security parameters to form complete binding data. Then, the integrity of the binding data is verified. The verification method is to check the total length of the binding data to ensure that the total length meets the preset standard. The preset standard is the sum of the length of the original security parameters and the length of the identifier sequence, with an error of no more than 1 bit. At the same time, the uniqueness of the association relationship is verified to ensure that the bound session key material corresponds one-to-one with the original security parameters and there is no cross-binding. After the verification is passed, the cryptographic binding operation is completed, and the session security parameters of the original security parameters are obtained. These session security parameters are complete binding data, which include the association information of the original security parameters, negotiation identifier, temporary interaction identifier, and session key material. They can be directly used for communication encryption and authentication between the two parties to ensure the security and integrity of communication data.
[0144] The session key material is a continuous 512-bit core bit sequence, used only for security parameter negotiation. When formatting the session key material, the predefined normalization format requirements are first defined. This format requires the core bit sequence to be divided into segments of 64 bits each, with a 1-bit format check bit added to the end of each segment. The check bit value is the parity check result of the core bits of that segment. During the conversion process, the 512-bit session key material is first divided into 8 segments of 64 bits each. Then, the parity check bit is calculated for each segment and added to the end of each segment. After adding the check bit, the 8 segments with check bits are concatenated in the order of division. The total length of the concatenated segment is 512 + 8 = 520 bits. After concatenation, the accuracy of the check bit in each segment is checked to ensure that the parity of the check bit in each segment is consistent with the parity of the core bits of that segment. After the conversion, the normalized key material of the session key material is obtained. This normalized key material is a 520-bit sequence with check bits, used for the generation of subsequent negotiation requests and responses.
[0145] The two communicating parties are clearly defined as the initiator and the receiver. Both parties have stored unique identifiers for their corresponding available key data and extracted session key materials. When the initiator generates the first random number, a fixed random number generation method is used. By selecting the binary sequence corresponding to the current system time, 128 bits are extracted as the first random number. During extraction, it is ensured that the binary sequence is free of repetition and errors. After generation, the length of the first random number is verified to be 128 bits. Once it is confirmed to be correct, the generation of the first random number is complete. Based on the normalized key material and the first random number, when sending a negotiation request to the receiver, the normalized key material and the first random number are first concatenated in a fixed order. After concatenation, the initiator's node number is added to the header and the request identifier is added to the tail to form a complete negotiation request. The total length of the negotiation request is fixed at 520+128+8+2=658 bits. Then, it is sent to the receiver through the secure communication channel of the quantum key distribution network. During the transmission process, the transmission time and request content are recorded to ensure that the request is traceable. After the transmission is completed, the receiver's negotiation response is awaited.
[0146] When verifying and parsing the negotiation request, the receiver first receives the negotiation request sent by the initiator. After receiving it, the receiver checks whether the total length of the negotiation request is 658 bits, whether the tail request identifier is a binary sequence of "01", and whether the initiator node number in the header is within the preset list of legitimate nodes. The preset list of legitimate nodes contains the node numbers of all participating nodes in the quantum key distribution network, totaling 32 nodes, with node numbers ranging from 00000000 to 00100000 binary numbers. After all three checks pass, the negotiation request is deemed legitimate. Then, the receiver splits the negotiation request according to the concatenation order, extracting the initiator node number, normalized key material, and the first random number in sequence. After extraction, the check bits of the normalized key material are checked. To ensure the accuracy of the checksum for each segment, after parsing, the receiver generates a second random number in the same way as the initiator generates the first random number. It selects the binary sequence corresponding to the current system time, extracts 128 bits as the second random number, and verifies its length to be 128 bits. Based on the normalized key material, it returns a negotiation response to the initiator. The concatenation format of the negotiation response is consistent with the negotiation request. The normalized key material, the second random number, the receiver node number, and the response identifier are concatenated in sequence, with a fixed total length of 520 + 128 + 8 + 2 = 658 bits. This response is sent to the initiator through the same secure communication channel, with the sending time and response content recorded during the transmission process.
[0147] When negotiating the first random number, the second random number, and the normalized key material, the initiator first receives the negotiation response sent by the receiver. After receiving it, the initiator follows the verification and parsing process of the negotiation request to check the total length of the negotiation response, the response identifier, the legality of the receiver's node number, and the check bits of the normalized key material. After successful verification, the second random number is extracted. Then, the initiator concatenates its own generated first random number, the received second random number, and the normalized key material shared by both parties in a fixed order: normalized key material first, first random number in the middle, and second random number last. After concatenation, all check bits of the normalized key material are removed, retaining only the core bit sequence. The core sequence length is 512 + 128 + 128 = 768 bits. This core sequence is then segmented and organized into three segments of 256 bits each. Each segment serves as a component of the original security parameters, corresponding to the basic parameters for communication encryption, the parameters for communication authentication, and the parameters for negotiation verification. After organization, the length of each segment is checked to ensure that there are no missing or redundant bits. After verification, the original security parameters of the session key material are obtained. These original security parameters are a continuous sequence of three 256-bit segments, containing all the basic parameters required for communication encryption and authentication, and can be directly used for subsequent cryptographic binding operations.
[0148] S6. Encapsulate the communication data to be transmitted cryptographically to obtain the final ciphertext data of the communication data.
[0149] In this embodiment of the invention, the step of cryptographically encapsulating the communication data to be transmitted to obtain the final ciphertext data of the communication data includes:
[0150] The encryption algorithm identifier and session encryption key are extracted from the session security parameters to obtain the communication encryption parameters of the session security parameters;
[0151] Based on the communication encryption parameters, the communication data to be transmitted is formatted into data blocks to obtain the communication data to be encrypted and organized;
[0152] The communication data to be encrypted and regularized is subjected to cryptographic transformation to obtain the initial ciphertext data of the communication data to be encrypted and regularized.
[0153] Based on the integrity verification information of the session encryption key, the initial ciphertext data is encapsulated for integrity to obtain the final ciphertext data of the initial ciphertext data.
[0154] The session security parameters are complete data after cryptographic binding, including original security parameters, negotiation identifiers, temporary interaction identifiers, and associated information of session key materials. The original security parameters include basic communication encryption parameters, communication authentication verification parameters, and negotiation verification parameters. The encryption algorithm identifier and session encryption key are both implicit in the basic communication encryption parameters of the original security parameters. When extracting the encryption algorithm identifier and session encryption key from the session security parameters, the storage location of the original security parameters is first located through the association index, the basic communication encryption parameters are split out, and then this segment is split according to a fixed division rule. The first 32 bits are used as the encryption algorithm identifier, and the last 224 bits are used as the session encryption key. After extraction, the legality of the encryption algorithm identifier is checked to ensure that it belongs to the preset list of legal encryption algorithm identifiers and only contains the binary sequence "00010001" corresponding to AES-256. At the same time, the length of the session encryption key is checked to be 224 bits, with no missing or extra bits. After extraction, the communication encryption parameters of the session security parameters are obtained, which are the combined data of the extracted encryption algorithm identifier and session encryption key.
[0155] Based on communication encryption parameters, the data to be transmitted is formatted into data blocks. This data is the raw data exchanged between the two communicating parties and has no fixed format. The formatting process first defines a predefined data block standard, which specifies that each data block has a fixed length of 1024 bits. Blocks shorter than 1024 bits are padded with a fixed binary sequence "00000000". Blocks longer than 1024 bits are divided into 1024-bit units. The last data block shorter than 1024 bits is padded according to the same rule. During formatting, the data to be transmitted is first statistically analyzed. The total bit length of the data is divided or padded according to the above standard. After division, a unique data block number is added to each data block, starting from 00000001 and increasing sequentially. The number is fixed at 8 bits and added to the header of each data block. After adding, the total length of each data block is checked to be 1024 + 8 = 1032 bits. The data block numbers are not repeated or missing. After formatting, the communication data to be encrypted and organized is obtained. The communication data to be encrypted and organized is a sequence of multiple 1032-bit data blocks, which can be directly used for subsequent cryptographic transformations.
[0156] Cryptographic transformation is performed on the communication data to be encrypted and organized. The transformation process strictly follows the AES-256 encryption logic corresponding to the encryption algorithm identifier in the communication encryption parameters. First, the fixed operation flow of this encryption logic is defined. Each data block in the communication data to be encrypted and organized is processed sequentially. When processing a single data block, the 8-bit header data block number is removed first, and only the 1024 bits of core data are transformed. The session encryption key in the communication encryption parameters is used as the basis for transformation. The core data is grouped into 8 groups of 128 bits each, and each group is processed one by one. The row bit rearrangement and replacement operations follow a fixed bit order for rearrangement and a fixed replacement table for replacement. After all groups are processed, they are concatenated in the original group order, and the original data block number is added back to form the transformed data of a single data block. After all data blocks are processed in sequence, all transformed data blocks are concatenated in the original order. After concatenation, the total length is checked to ensure it matches the communication data to be encrypted and normalized. After the transformation, the initial ciphertext data of the communication data to be encrypted and normalized is obtained. This initial ciphertext data is a sequence of multiple 1032-bit data blocks after transformation, which already has basic encryption protection capabilities.
[0157] Based on the integrity verification information of the session encryption key, the initial ciphertext data is encapsulated for integrity. The integrity verification information of the session encryption key is generated synchronously when the session encryption key is generated. It is a fixed-length 64-bit bit sequence, generated based on the core bit information of the session encryption key. It is obtained by performing parity checks and bit summation on the session encryption key and is stored in advance in association with the session encryption key. The encapsulation process first extracts the session encryption key from the communication encryption parameters, then retrieves the corresponding integrity verification information through the association index, and verifies that the length of the verification information is 64 bits and matches the session encryption key. After the verification is successful, the integrity verification information is added to the initial ciphertext data. The header adds an encapsulation identifier and encapsulation timestamp to the end of the initial ciphertext data. After adding these, the overall encapsulated data undergoes length verification to ensure that the total length is the initial ciphertext data length + 64 + 16 + 32 bits. At the same time, the correlation between the integrity verification information and the initial ciphertext data is verified to ensure that the verification information corresponds only to the current initial ciphertext data. After the verification passes, integrity encapsulation is completed, resulting in the final ciphertext data of the initial ciphertext data. This final ciphertext data contains the initial ciphertext data, integrity verification information, encapsulation identifier, and encapsulation timestamp, and can be directly used for transmission between communicating parties. It can effectively ensure the integrity and security of the data during transmission and prevent data from being tampered with or replaced.
[0158] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0159] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0160] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A secure communication method based on quantum key distribution, characterized in that, The method includes: S1. Standardize and encode the initial quantum key data to obtain the encoded key data of the initial quantum key data; S2. Mark the lifecycle status of the encoded key data to obtain manageable key data of the encoded key data; S3. Based on the lifecycle status, perform status verification on the manageable key data to obtain the validity judgment result of the manageable key data; S4. Based on the validity judgment result, perform key rotation on the manageable key data to obtain usable key data of the manageable key data; S5. Based on the available key data, negotiate security parameters between the two communicating parties to obtain session security parameters for communication encryption and authentication; S6. Encapsulate the communication data to be transmitted cryptographically to obtain the final ciphertext data of the communication data.
2. The secure communication method based on quantum key distribution as described in claim 1, characterized in that, The process of standardizing and encoding the initial quantum key data to obtain encoded key data includes: In a quantum key distribution network, initial quantum key data is obtained to obtain an initial key sequence of the initial quantum key data; Based on a specific secure communication protocol, the initial key sequence is protocol-adapted and encapsulated to obtain a formatted key sequence of the initial key sequence; Based on preset encoding rules, code blocks are constructed from the formatted key sequence to obtain encoded key data of the initial quantum key data.
3. The secure communication method based on quantum key distribution as described in claim 1, characterized in that, The step of marking the encoded key data with a lifecycle status to obtain manageable key data of the encoded key data includes: A unique identifier is created for the encoded key data to obtain the identified key data of the encoded key data; Perform a validity pre-validation on the identified key data to obtain the unmarked key data of the identified key data. Based on a predefined key lifecycle strategy, an initial state label is assigned to the key data to be labeled to obtain the initial state key data of the key data to be labeled. The initial state key data is associated with and stored with the identity identifier and the initial state tag to obtain the manageable key data of the encoded key data.
4. The secure communication method based on quantum key distribution as described in claim 3, characterized in that, The predefined key lifecycle strategy assigns an initial state label to the key data to be labeled, obtaining the initial state key data of the key data to be labeled, including: Based on the key lifecycle policy, the key type of the key data to be marked is mapped by the policy to obtain the state definition rules of the key type; Based on the state definition rules and the key type, the key data to be marked is subjected to feature parsing to obtain the generation timestamp and preset validity period of the key data to be marked; The state transition point of the key data to be labeled is derived to obtain the first state transition time point of the key data to be labeled. Based on the generated timestamp, the preset validity period, and the first state transition time point, the key data to be labeled is encapsulated with a state tag to obtain the initial state key data of the key data to be labeled.
5. A secure communication method based on quantum key distribution as described in claim 1, characterized in that, The step of performing a status verification on the manageable key data based on the lifecycle status to obtain a validity judgment result for the manageable key data includes: Extract the lifecycle status tag from the manageable key data to obtain the current status information of the manageable key data; The current state information is structured and parsed to obtain the current state value and state time attribute of the manageable key data; Based on the preset state validity rules, the current state value and the state time attribute are compared for compliance to obtain the intermediate result of the state verification of the manageable key data; Based on the intermediate results of the status verification, the manageable key data is assessed for availability to obtain the validity judgment result of the manageable key data.
6. The secure communication method based on quantum key distribution as described in claim 1, characterized in that, Based on the validity judgment result, the manageable key data is rotated to obtain usable key data, including: Based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated to obtain the quantitative rotation decision parameters of the manageable key data; The quantized rotation decision parameters and the preset rotation trigger threshold are evaluated to obtain the rotation trigger decision for the manageable key data; Based on the aforementioned rotation triggering decision, a new quantum key supply is triggered to obtain candidate key data for the manageable key data; The availability of the candidate key data is verified to obtain the key data to be enabled after the candidate key data has been verified. Replace the target key data in the manageable key data with the key data to be enabled, update its lifecycle status, and obtain the available key data of the manageable key data.
7. A secure communication method based on quantum key distribution as described in claim 6, characterized in that, Based on the validity judgment result, the historical status record of the manageable key data, and the generation time of the manageable key data, the rotation urgency index is calculated to obtain the quantitative rotation decision parameters of the manageable key data, including: Based on the manageable key data, a Boolean transformation is performed on the current validity judgment result to obtain the current valid value of the validity judgment result. When the judgment result is valid =1, invalid =0; Obtain the manageable key data in the most recent consecutive Historical validity judgment result sequence within a verification period Calculate historical invalid frequencies ; Based on the generation timestamp of the manageable key data, the existing time... The lifespan is determined, and the preset maximum lifespan of this type of key is obtained based on the key lifespan policy. ; Based on preset weighting coefficients , , Calculate the rotation urgency index The quantized rotation decision parameters of the manageable key data are obtained.
8. A secure communication method based on quantum key distribution as described in claim 1, characterized in that, Based on the available key data, the two communicating parties negotiate security parameters to obtain session security parameters used for communication encryption and authentication, including: The available key data is subjected to key material extraction to obtain the session key material of the available key data; Based on the session key material, parameter negotiation and interaction are performed between the two communicating parties to obtain the original security parameters of the session key material; Cryptographically bind the original security parameters to obtain the session security parameters of the original security parameters.
9. A secure communication method based on quantum key distribution as described in claim 1, characterized in that, The process of performing parameter negotiation and interaction between the two communicating parties based on the session key material to obtain the original security parameters of the session key material includes: The session key material is formatted and converted to obtain the standardized key material. The initiator of the communication generates a first random number, and based on the standardized key material and the first random number, sends a negotiation request to the receiver of the two parties. The negotiation request is verified and parsed. The receiver generates a second random number and returns a negotiation response to the initiator based on the standardized key material. Key negotiation is performed on the first random number, the second random number, and the normalized key material to obtain the original security parameters of the session key material.
10. A secure communication method based on quantum key distribution as described in claim 1, characterized in that, The cryptographic encapsulation of the communication data to be transmitted, to obtain the final ciphertext data of the communication data, includes: The encryption algorithm identifier and session encryption key are extracted from the session security parameters to obtain the communication encryption parameters of the session security parameters; Based on the communication encryption parameters, the communication data to be transmitted is formatted into data blocks to obtain the communication data to be encrypted and organized; The communication data to be encrypted and regularized is subjected to cryptographic transformation to obtain the initial ciphertext data of the communication data to be encrypted and regularized. Based on the integrity verification information of the session encryption key, the initial ciphertext data is encapsulated for integrity to obtain the final ciphertext data of the initial ciphertext data.