Quantum key distribution management method, node and system based on post-quantum cryptography

By employing a post-quantum cryptography-based approach in the quantum key distribution system, and generating symmetric authentication keys using the initial QKD session, the complexity of pre-shared key management in large-scale networks is resolved. This achieves efficient and secure key consistency confirmation and end-to-end authentication, improving the system's scalability and deployment feasibility.

CN122053062BActive Publication Date: 2026-08-04YUNNAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YUNNAN UNIV
Filing Date
2026-04-14
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In quantum key distribution, when providing secure authentication for arbitrary communication between massive numbers of users, existing technologies face the problem of complex and inefficient pre-shared key management, making it difficult to achieve secure authentication of all interactive information in large-scale networks.

Method used

A quantum key distribution management method based on post-quantum cryptography is adopted. By using PQC to complete authentication and generate the final key in the initial QKD session, a symmetric authentication key is extracted from it for key consistency confirmation in subsequent sessions. This avoids the direct use of PQC for key verification and achieves efficient and secure key management.

Benefits of technology

It solves the complexity and distribution difficulties of pre-shared key management in large-scale quantum communication networks, improves the scalability and practical deployment feasibility of the system, and ensures quantum-resistant security and the authentication integrity of information exchanged throughout the process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053062B_ABST
    Figure CN122053062B_ABST
Patent Text Reader

Abstract

The application provides a quantum key distribution management method based on post-quantum cryptography, a communication node and a system, relates to the field of quantum communication and information security, is applied to a quantum communication network comprising a first communication node and a second communication node, the method is executed by the first communication node, and comprises the following steps: in a first quantum key distribution (QKD) session, completing a QKD negotiation process with the second communication node based on post-quantum cryptography (PQC) authentication, and generating a first final key; extracting a part of the first final key as a symmetric authentication key; in a second QKD session established with the second communication node, using the symmetric authentication key to confirm whether the final key of the current session held by the first communication node and the second communication node is consistent, and the second QKD session is any QKD session after the first QKD session. By using a part of the final key as a symmetric key for encryption on the basis of authentication using PQC, the flexibility of the QKD network is greatly improved on the basis of ensuring security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum communication technology, and more specifically to a quantum key distribution management method, communication node, and system based on post-quantum cryptography. Background Technology

[0002] Quantum key distribution technology requires the transmission of information over public channels to complete the key negotiation process. To prevent attackers from forging or eavesdropping, these transmitted messages must undergo strict authentication.

[0003] Currently, mainstream authentication methods rely on pre-shared keys between communicating parties. This approach is feasible in peer-to-peer scenarios, but in large-scale networks that need to support arbitrary communication between multiple users, pre-allocating and managing shared keys for each pair of users becomes extremely complex and inefficient.

[0004] Therefore, existing technologies face a challenge: how to avoid providing pre-shared keys to a massive number of users while simultaneously achieving secure authentication of all information exchanged throughout the quantum key distribution process. Summary of the Invention

[0005] In view of the above problems, the present invention provides a quantum key distribution management method, communication node and system based on post-quantum cryptography.

[0006] According to a first aspect of the present invention, a quantum key distribution management method based on post-quantum cryptography is provided, applied to a quantum communication network including a first communication node and a second communication node, the method being executed by the first communication node, comprising:

[0007] In the first quantum key distribution (QKD) session, the QKD negotiation process is completed with the second communication node based on post-quantum cryptography (PQC) authentication to generate the first final key;

[0008] Extract a portion from the first final key to serve as a symmetric authentication key;

[0009] In the second QKD session established with the second communication node, the symmetric authentication key is used to confirm whether the final key of the current session held by the first communication node and the second communication node is consistent. The second QKD session is any QKD session after the first QKD session.

[0010] In some embodiments, using the symmetric authentication key to confirm whether the final keys of the current session held by the first communication node and the second communication node are consistent includes:

[0011] Generate the final key for the current session with the second communication node;

[0012] Generate a first digest value based on the final key of the current session;

[0013] The first digest value is encrypted using the symmetric authentication key to generate the first authentication information;

[0014] The first authentication information is sent to the second communication node to receive the second authentication information from the second communication node. The second authentication information is generated by the second communication node generating a second digest value based on the final key of the current session and encrypting the second digest value using the symmetric authentication key.

[0015] Based on the first authentication information, the second authentication information, and the symmetric authentication key, verify whether the final key of the current session held by the first communication node and the second communication node is consistent.

[0016] In some embodiments, verifying whether the final keys of the current session held by the first communication node and the second communication node are consistent based on the first authentication information, the second authentication information, and the symmetric authentication key includes:

[0017] The second authentication information is decrypted using the symmetric authentication key to obtain the second digest decryption value;

[0018] Verify whether the decrypted value of the second digest is consistent with the value of the first digest;

[0019] If they match, then the authentication of the second communication node is confirmed to be successful;

[0020] After confirming that the authentication of the second communication node is successful, a successful verification response for the first authentication information is received from the second communication node;

[0021] When both authentication of the second communication node and the receipt of the authentication success response are simultaneously satisfied, the two-way authentication is determined to be complete.

[0022] In some embodiments, generating a first digest value based on the final key of the current session includes:

[0023] The first digest value is generated by using a hash algorithm pre-agreed with the second communication node to calculate the final key of the current session.

[0024] In some embodiments, the process of completing the QKD negotiation with the second communication node based on PQC authentication to generate the first final key includes:

[0025] In the first QKD session, at least one of the basis vector alignment information, error correction verification information, and random numbers used for privacy amplification, which are interacted with the second communication node, is authenticated using PQC digital signatures.

[0026] After PQC authentication is passed, the original key data obtained through negotiation is amplified for privacy purposes to generate the first final key.

[0027] In some embodiments, it also includes:

[0028] If it is confirmed that the final key of the current session held by the first communication node and the second communication node is inconsistent, the final key of the current session is discarded, and the current QKD session is stopped or reset.

[0029] In some embodiments, after determining that mutual authentication has been completed, the method further includes:

[0030] The remaining portion of the final key of the current session that is not used as the symmetric authentication key is stored in the key pool.

[0031] A second aspect of the present invention provides a quantum key distribution management communication node, comprising:

[0032] A quantum key distribution (QKD) device is used to negotiate raw key data with a peer communication node via a quantum channel;

[0033] The post-quantum cryptography PQC user terminal is connected to the QKD device for communication.

[0034] The processor is coupled to the QKD device and the PQC user terminal;

[0035] Memory, which stores computer programs;

[0036] When the processor executes the computer program, it causes the QKD communication node to perform the method described in the first aspect.

[0037] A third aspect of the present invention provides a quantum communication network system, comprising:

[0038] Network switch;

[0039] The post-quantum cryptography PQC authentication center is connected to the network switch;

[0040] At least two QKD communication nodes as described in the second aspect;

[0041] The PQC user terminal of each QKD communication node is connected to the PQC certification center through the network switch, and the QKD devices of each QKD communication node are interconnected through the quantum channel.

[0042] The system is configured to support each QKD communication node in completing PQC authentication in the initial QKD session through the PQC authentication center, and for each QKD communication node to execute the method described in the first aspect in subsequent QKD sessions.

[0043] According to embodiments of the present invention, by using PQC to complete initial authentication and generate a first final key in the first round of QKD session, and extracting a portion of it as a dedicated symmetric authentication key for subsequent authentication, both communicating parties can securely and efficiently confirm the consistency of newly generated keys in any subsequent round of QKD session simply by using this symmetric authentication key. This method eliminates the dependence of traditional QKD systems on pre-shared keys, solving the inherent bottleneck of complex pre-shared key management and difficult distribution in large-scale quantum communication networks. Simultaneously, by using the symmetric authentication key, whose security is guaranteed by the initial PQC authentication process, to perform subsequent verification, it avoids the risk of key information leakage that may arise from directly using PQC in critical key verification stages, and achieves complete authentication of all interactive information throughout the QKD process. Therefore, while ensuring quantum-resistant security, it significantly improves the scalability and practical deployment feasibility of the quantum key distribution system. Attached Figure Description

[0044] The above-described features, other objects, and advantages of the present invention will become clearer from the following description of embodiments of the invention with reference to the accompanying drawings, in which:

[0045] Figure 1 A flowchart illustrating a quantum key distribution management method based on post-quantum cryptography according to an embodiment of the present invention is shown schematically.

[0046] Figure 2 A flowchart illustrating another PQC-based QKD authentication method according to an embodiment of the present invention is shown schematically;

[0047] Figure 3 A schematic diagram illustrating a structural block diagram of a quantum key distribution and authentication device based on post-quantum cryptography according to an embodiment of the present invention; and

[0048] Figure 4 A block diagram of an electronic device based on a post-quantum cryptography-based quantum key distribution management method according to an embodiment of the present invention is shown schematically. Detailed Implementation

[0049] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the invention. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the invention for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.

[0050] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0051] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0052] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0053] In the technical solution of this invention, the user information (including but not limited to user personal information, user cross-border remittance information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, invention, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0054] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this invention offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0055] Figure 1 A flowchart illustrating a quantum key distribution (QKD) authentication method based on post-quantum cryptography (PQC) according to an embodiment of the present invention is shown. The method of this embodiment is applied to a quantum communication network comprising multiple communication nodes (e.g., a first communication node and a second communication node), and is executed by the first communication node. The following will provide a detailed description in conjunction with the system architecture and method steps.

[0056] According to embodiments of the present invention, a quantum communication network system may include a network switch, a PQC certification center, and at least two communication nodes. The PQC certification center, acting as a trusted third party, is connected to the network switch and is responsible for providing PQC certificate issuance, management, and verification services to each communication node in the network.

[0057] Each communication node (taking the first communication node as an example) mainly consists of a quantum key distribution (QKD) device and a PQC user terminal. The QKD device is responsible for the generation, transmission / reception, and measurement of quantum signals, as well as core algorithms in post-processing such as error correction and privacy amplification. The PQC user terminal is responsible for managing PQC key pairs and performing cryptographic operations such as digital signatures and verification. The two work together through an internal interface. In the network, the PQC user terminals of each node are interconnected through network switches and can access the PQC authentication center; the QKD devices of each node are directly connected through quantum channels (such as optical fibers).

[0058] The authentication method provided in this embodiment achieves QKD authentication without pre-shared keys through the organic combination of two stages:

[0059] Phase 1 (Initial Trust Establishment): In the first round of the QKD session, both parties rely on the PQC certification authority to complete the initial full-process authentication using PQC digital signatures and generate a highly secure final key. Subsequently, a small portion of this key is extracted as a dedicated symmetric authentication key for both parties thereafter.

[0060] Phase Two (Efficient Continuous Authentication): In all subsequent QKD sessions, the communicating parties no longer use PQC, but instead utilize the shared symmetric authentication key to quickly confirm the consistency of the newly generated key through efficient symmetric cryptographic operations.

[0061] This method can eliminate the reliance on pre-shared keys, while avoiding the risk of information leakage that may result from directly using PQC in the key verification process.

[0062] like Figure 1 As shown, the QKD authentication method based on PQC in this embodiment includes operations S110 to S130.

[0063] In operation S110, during the first QKD session, the QKD negotiation process is completed with the second communication node based on PQC authentication to generate the first final key.

[0064] According to an embodiment of the present invention, in the initial stage of the first QKD session, when the first and second communication nodes perform PQC-based authentication, they can obtain proof of the authenticity of each other's PQC public key certificates from the PQC authentication center through a network switch, or the authentication center can directly participate in the signature verification process. This architecture is particularly suitable for multi-user, scalable quantum secure communication networks, enabling any pair of nodes to establish initial trust based on the PQC authentication center without exchanging PQC public keys beforehand during the first QKD.

[0065] According to an embodiment of the present invention, the first QKD session may be the first or a specific key distribution session between the first communication node and the second communication node for establishing a long-term usable authentication relationship.

[0066] According to an embodiment of the present invention, PQC-based authentication can refer to the use of post-quantum cryptography digital signature technology by the first and second communication nodes during the classical channel communication process of this session to sign and verify the necessary negotiated information exchanged between them, so as to ensure the authenticity and integrity of the information and thus resist man-in-the-middle attacks.

[0067] According to an embodiment of the present invention, the QKD negotiation process includes at least the steps of basis vector comparison, bit error estimation, and information reconciliation performed in a classical channel after both parties transmit and measure the quantum state through a quantum channel.

[0068] According to an embodiment of the present invention, generating the first final key may refer to the final, usable security key obtained after completing the above authentication and negotiation by performing post-processing operations such as privacy amplification on the shared original key data.

[0069] In operation S120, a portion is extracted from the first final key and used as a symmetric authentication key.

[0070] According to embodiments of the present invention, extracting a portion may refer to separating a segment or calculating a shorter key segment from the bit sequence of the first final key according to rules pre-agreed upon by the communicating parties, such as fixed-position truncation or generation using a specific function. The security of this extracted portion of key material is guaranteed by the security of the first final key.

[0071] According to an embodiment of the present invention, a symmetric authentication key can refer to a key used for symmetric encryption and decryption of specific authentication information exchanged between a first communication node and a second communication node in a classic channel, characterized in that the same key is used for encryption and decryption.

[0072] In operation S130, during the second QKD session established with the second communication node, the symmetric authentication key is used to verify whether the final key of the current session held by the first and second communication nodes is consistent.

[0073] According to an embodiment of the present invention, the second QKD session is any QKD session following the first QKD session. In this session, the first communication node and the second communication node first jointly negotiate to generate a new final key for the current session.

[0074] According to an embodiment of the present invention, verifying whether the final key of the current session held by the first communication node and the second communication node is consistent using a symmetric authentication key can mean that the first communication node and the second communication node use the symmetric authentication key established and shared in operation S120 to cross-verify whether the final keys of the current session independently generated by both parties are completely identical through a series of cryptographic operations based on the symmetric key, such as generating and exchanging message authentication codes, or encrypting and exchanging specific check values. This process aims to ensure that both parties successfully share the same key in subsequent sessions without needing to use PQC for full-process authentication again.

[0075] By utilizing PQC to complete initial authentication and generate the first final key in the first round of the QKD session, and extracting a portion of it as a dedicated symmetric authentication key for subsequent authentications, both parties can securely and efficiently verify the consistency of their newly generated keys in any subsequent QKD session using only this symmetric authentication key. This method eliminates the reliance on pre-shared keys in traditional QKD systems, overcoming the inherent bottleneck of complex pre-shared key management and distribution difficulties in large-scale quantum communication networks. Furthermore, by using the symmetric authentication key, whose security is guaranteed by the initial PQC authentication process, to perform subsequent verifications, it avoids the risk of key information leakage that might arise from directly using PQC in critical key verification stages, and achieves complete authentication of all QKD interaction information. Thus, while ensuring quantum-resistant security, it significantly improves the scalability and practical deployment feasibility of the quantum key distribution system.

[0076] According to an embodiment of the present invention, if the initial PQC authentication in operation S110 fails, or the final key consistency confirmation in operation S130 fails, i.e., the two-way authentication is not completed, the quantum key distribution device of the first communication node will stop the generation or use process of the quantum key in this round. This includes discarding the generated original key data of the current session, the final key, and the related intermediate state, and may send an alarm to the network management system.

[0077] If authentication is successful, the first communication node performs key splitting and storage operations. Specifically, the final key generated in the current session and authenticated is divided into two parts: the first part is the symmetric authentication key extracted according to the protocol, used for the next round or future rounds of authentication; the second part is the remaining majority of the key. This second part of the key is called the usable security key material, which is stored in a protected key pool. The key pool is responsible for the secure storage and lifecycle management of these keys, and allows them to be accessed as needed by upper-layer secure communication applications (such as voice encryption and file encryption).

[0078] According to some embodiments of the present invention, confirming whether the final key of the current session held by the first communication node and the second communication node is consistent may specifically include the following process. First, in the second QKD session, the first communication node and the second communication node follow the standard QKD protocol process, exchange quantum states through a quantum channel and negotiate through a classical channel, and jointly generate the final key of this session, i.e., the final key of the current session. To verify whether the final key held by both parties is consistent, the first communication node needs to generate a short sequence that can characterize the key data, i.e., a first digest value, based on the final key of the current session held locally by it, through a specific operation. Subsequently, the first communication node uses the symmetric authentication key obtained and shared in operation S120 to perform encryption operation on the first digest value, thereby forming first authentication information. The first authentication information is then sent to the second communication node through the classical channel.

[0079] Correspondingly, the first communication node will also receive the second authentication information from the second communication node via the classic channel. The generation logic of the second authentication information is symmetrical to that of the first authentication information: the second communication node generates a second digest value based on its own current session final key, and also encrypts the second digest value using the shared symmetric authentication key. Finally, the first communication node will execute a set of verification logic based on its own generated first authentication information, the received second authentication information, and the symmetric authentication key to determine whether the current session final keys held by both parties are completely consistent.

[0080] According to some embodiments of the present invention, the verification logic can be specifically implemented as a two-way authentication protocol. The first communication node uses a symmetric authentication key to decrypt the received second authentication information, recovering the original second digest value generated by the second communication node, i.e., the decrypted second digest value. Then, the first communication node compares this decrypted second digest value with the first digest value it previously generated and used to construct the first authentication information. If they match, from the perspective of the first communication node, it can be confirmed that the second communication node holds the same current session final key, i.e., the authentication of the second communication node is successful.

[0081] According to some embodiments of the present invention, after the aforementioned one-way verification is successful, the first communication node needs to wait for feedback from the second communication node. This feedback is a successful verification response issued by the second communication node after successfully verifying the first authentication information sent by the first communication node. This response indicates that the second communication node has also confirmed that the first communication node holds the correct final key. Only when the first communication node successfully authenticates the second communication node and simultaneously receives a successful verification response from the other party can the two-way authentication be finally determined to be complete, that is, the final keys held by both parties for the current session are consistent. This two-way handshake mechanism can ensure the reliability and unambiguity of the authentication conclusion.

[0082] According to some embodiments of the present invention, to ensure the validity of the above-mentioned digest comparison, the specific technical means adopted by the first communication node to generate the first digest value may be: using a cryptographic hash function pre-agreed with the second communication node, i.e., a pre-agreed hash algorithm, to perform operations on the complete bit sequence or a specified part of the final key of the current session. The hash algorithm can map input data of arbitrary length to a fixed-length output, i.e., a digest value.

[0083] According to some embodiments of the present invention, the QKD negotiation process is completed with the second communication node based on PQC authentication, and the first final key is generated. This can be done during the classical channel interaction phase of the first QKD session. The information exchanged between the first and second communication nodes includes at least one or more of the following: basis vector alignment information for coordinating quantum state measurements, error correction verification information for correcting bit errors generated during transmission, and random numbers for privacy amplification to compress information and eliminate potential eavesdropper knowledge.

[0084] In this embodiment, authentication of this critical information can be achieved through PQC digital signature technology. That is, the sender signs the information using its PQC private key, and the receiver verifies the signature using the corresponding PQC public key. Only after all necessary PQC signature verifications pass can both parties confirm that the classical channel interaction has not been tampered with or forged. Based on this, both parties perform agreed-upon post-processing steps (the core of which is privacy amplification) on the raw key data generated by quantum measurement to eliminate the impact of public information leakage, ultimately outputting a highly secure first final key. This process ensures the establishment of the initial trust relationship and the security of the first final key.

[0085] According to some embodiments of the present invention, after the confirmation or verification process is performed in operation S130, if the conclusion is that the final key of the current session held by the first communication node and the second communication node is inconsistent, it indicates that there may be a security risk in the key negotiation or authentication process of this QKD session (e.g., channel interference, equipment failure, or potential attacks). To ensure system security, the first communication node will immediately discard the final key of the current session generated in this round, that is, it will not be used for any subsequent encryption or authentication purposes, in order to eliminate the potential risks caused by possible insecure key materials. At the same time, to prevent the abnormal state from continuing, the first communication node will stop the process of the current QKD session, or, if necessary, reset the session state and associated parameters with the second communication node, in preparation for starting a new, secure QKD session.

[0086] Conversely, if operation S130 determines that two-way authentication is complete, i.e., confirms that the final keys held by both parties for the current session are consistent, then the QKD session is successful. In this case, the first communication node has already extracted the symmetric authentication key from the initial first final key in operation S120. The final key of the currently successfully authenticated session will be stored in its entirety or in its majority as highly secure cryptographic material. Specifically, the first communication node will store the remaining portion of the final key of the current session that is not used as the symmetric authentication key—that is, the vast majority of the key—into the key pool.

[0087] A key pool is a protected storage area or management system used to accumulate and manage verified and usable security keys generated by the QKD process. Keys stored in the key pool can then be provided to upper-layer applications (such as voice encryption, file transfer encryption, etc.) as needed, thereby enabling quantum-secure communication.

[0088] The following is in conjunction with the appendix Figure 2 The example provided illustrates the authentication method of this invention in detail, using a complete operation cycle as an example. In this embodiment, the two parties involved in the communication are referred to as user Alice, or simply user A (corresponding to the first communication node), and user Bob, or simply user B (the second communication node).

[0089] Figure 2 A flowchart illustrating another PQC-based QKD authentication method according to an embodiment of the present invention is shown.

[0090] like Figure 2 As shown, the QKD authentication method based on PQC in this embodiment of the invention includes a first round of QKD sessions and a second round of QKD sessions (subsequent rounds of QKD).

[0091] Phase 1: First round of QKD session (establishing initial trust and derived symmetric key)

[0092] First, User A and User B initiate their initial quantum key distribution session. User A's QKD device prepares and sends a quantum state to User B. After both parties complete the measurement, they need to exchange a series of post-processing messages through a classical channel, including: basis alignment information (used to filter out bits measured using the same basis), error correction verification information (used to negotiate the error correction code and verify whether the corrected key is consistent), and random numbers for privacy amplification (such as a random seed used to select a hash function).

[0093] In this embodiment of the invention, user A's PQC client uses its PQC private key to digitally sign all the messages to be sent (or their hash values). These messages with PQC signatures are then sent to user B via a classic channel.

[0094] After receiving the message, User B's PQC client uses User A's PQC public key certificate obtained from a trusted PQC certification authority to verify the authenticity of these signatures. This completes the QKD negotiation process based on PQC authentication. If any signature verification fails, User B's QKD device will stop the current key generation process (e.g., ...). Figure 2 (The path is marked "No"), and an error is reported to user A.

[0095] Then, if all PQC signature verifications pass (e.g.) Figure 2 (In the "Yes" path), both parties confirm the security of classical channel communication. Subsequently, based on the securely exchanged negotiation information, the QKD devices of both parties perform error correction and privacy amplification processing on the original key data, and finally generate a shared, highly secure first final key (K_final_1).

[0096] Then, after generating K_final_1, according to pre-agreed rules (e.g., taking the first 256 bits), the QKD devices of user A and user B each extract a portion from K_final_1 to obtain the same symmetric authentication key (K_auth). This key will be used exclusively for authentication in all subsequent QKD sessions between the two parties.

[0097] Finally, after extracting the symmetric authentication key, the remaining portion (i.e., the vast majority) of K_final_1 is managed. This portion of the key is stored in a key pool as usable security key material for use by upper-layer cryptographic applications. At this point, the first round of the session ends; both parties have not only obtained usable keys but have also established and shared a secret K_auth for subsequent efficient authentication.

[0098] Phase Two: Subsequent QKD Sessions (using symmetric authentication keys for efficient authentication)

[0099] Suppose that user A and user B now begin the Nth round (N≥2) of a QKD session.

[0100] Both parties first execute the standard QKD process (quantum transfer, basis vector comparison, error correction, privacy amplification) to generate a new final key (K_final_N) for this round. Then, both parties independently use the same, pre-agreed hash algorithm (such as SHA-256) to operate on their respective K_final_N keys to obtain digest values ​​Hash_A and Hash_B, respectively.

[0101] User A: Use the symmetric authentication key K_auth established in the first phase to perform symmetric encryption on Hash_A (for example, using AES-GCM), generate the first authentication information Auth_A, and send it to User B.

[0102] User B: Similarly, encrypts Hash_B using K_auth to generate the second authentication information Auth_B, and sends it to User A. Simultaneously, User B decrypts the received Auth_A using K_auth, obtaining the decrypted Hash_A'. User B compares the decrypted Hash_A' with its own calculated Hash_B. If they don't match, authentication fails, User B's QKD device stops key generation for this round, discards K_final_N, and may reset the session. If they match, User B confirms that User A possesses the same K_final_N. User B then sends a successful authentication response to User A (this response itself can also be simply protected using K_auth).

[0103] User A: After sending Auth_A, uses K_auth to decrypt the received Auth_B, obtaining Hash_B', and compares it with its own calculated Hash_A. Simultaneously, it waits for User B's successful authentication response. If the comparison is inconsistent or no valid response is received, authentication fails, and User A stops and discards K_final_N. If the comparison is consistent and User A receives User B's successful authentication response, User A determines that two-way authentication is complete, meaning both parties confirm that K_final_N is consistent.

[0104] If authentication is successful ( Figure 2 (In the "Yes" path): User A and User B split the key K_final_N. A small portion (e.g., the new 256 bits) is extracted as the new symmetric authentication key (K_auth_new) for the next round of the QKD session, used to update or rotate the authentication key. The remaining portion of K_final_N is stored in the key pool for later use. This round of the session ends successfully.

[0105] If authentication fails ( Figure 2 (No path): Both QKD devices stop the generation process and discard K_final_N. The system can log the error and wait for operator intervention or automatically attempt to re-initiate the session.

[0106] Based on the above-described quantum key distribution management method based on post-quantum cryptography, this invention also provides a quantum key distribution management communication node. The following will combine... Figure 2 The device is described in detail.

[0107] Figure 3 A schematic block diagram of a quantum key distribution management communication node according to an embodiment of the present invention is shown.

[0108] like Figure 3As shown, the quantum key distribution management communication node in this embodiment includes a generation module 310, an extraction module 320, and a confirmation module 330.

[0109] The generation module 310 is configured to complete the QKD negotiation process with the second communication node based on post-quantum cryptography (PQC) authentication during the first quantum key distribution (QKD) session, and generate the first final key. In one embodiment, the generation module 310 can be used to perform the operation S110 described above, which will not be repeated here.

[0110] The extraction module 320 is configured to extract a portion of the first final key as a symmetric authentication key. In one embodiment, the extraction module 320 can be used to perform the operation S120 described above, which will not be repeated here.

[0111] The verification module 330 is used to verify, using a symmetric authentication key, whether the final key held by the first communication node and the second communication node for the current session is consistent in the second QKD session established with the second communication node. The second QKD session is any QKD session following the first QKD session. In one embodiment, the verification module 330 can be used to perform the operation S130 described above, which will not be repeated here.

[0112] According to embodiments of the present invention, any plurality of modules of the generation module 310, extraction module 320, and confirmation module 330 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of the present invention, at least one of the generation module 310, extraction module 320, and confirmation module 330 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the generation module 310, extraction module 320, and confirmation module 330 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0113] According to other embodiments of the present invention, a quantum key distribution management communication node is also provided. This communication node is the execution entity of the aforementioned method embodiments, and its hardware architecture and functional module configuration directly support... Figure 1 The implementation of the method shown.

[0114] The quantum key distribution management communication node (taking the first communication node as an example) mainly includes the following core components: The QKD device: This device is the core of the node's quantum physics layer, responsible for performing all operations related to quantum signals. Specifically, the QKD device is configured to interact with the QKD device of the peer communication node (such as the second communication node) via a quantum channel (such as a dedicated optical fiber or free-space link). Its functions include at least: the preparation and transmission (if at the transmitter) or reception and measurement (if at the receiver) of quantum states (such as single photons); preliminary processing of measurement results; and, with the assistance of a classical channel, collaborating with the peer to complete the negotiation process from raw measurement data to raw key data. This process typically includes steps such as basis selection, error estimation, and information reconciliation.

[0115] PQC Client: This client is the core of the node's classical cryptography and authentication processing. It communicates with the QKD device via an internal data bus or communication interface to exchange commands and data. The main responsibility of the PQC client is to manage the node's PQC key pairs (including public and private keys) and perform cryptographic operations based on the PQC algorithm. These operations specifically include: in the initial QKD session, performing PQC digital signatures on negotiation information (such as basis vector comparison, error correction, etc.) that needs to be sent to the peer through the classical channel; and verifying the PQC signatures of similar information received from the peer. In some network architectures, the PQC client is also responsible for interacting with PQC certification authorities in the network to obtain and verify certificates.

[0116] Processor and Memory: The processor (e.g., CPU, microcontroller, or dedicated security chip) is coupled to both the QKD device and the PQC user terminal, responsible for coordinating and controlling their operation and executing high-level protocol logic. The memory (e.g., ROM, RAM, or flash memory) stores the computer program (or firmware instructions). When the processor executes this computer program, it drives and coordinates the QKD device and the PQC user terminal to work together according to a predetermined protocol flow, enabling the entire communication node to fully execute... Figure 1 The method involves a series of operations, including controlling the PQC authentication process of the initial session, extracting the symmetric authentication key from the generated final key, controlling the symmetric key authentication interactions in subsequent sessions, and deciding whether to discard the key or store it in the key pool based on the authentication result.

[0117] According to some embodiments of the present invention, flexible implementation schemes are provided regarding the physical or logical integration of the PQC user terminal and the QKD device. The PQC user terminal can be a separate hardware module or software entity, independent of the QKD device setup. For example, the PQC user terminal can be a PCIe cryptographic card plugged into a general-purpose server, while the QKD device is a separate quantum optical bit chassis, with the two connected via cables and standard interface protocols. The advantage of this approach is that it facilitates modular upgrades and maintenance.

[0118] Alternatively, the PQC user terminal can be embedded within the QKD device. For example, the PQC cryptographic chip, related software stack, and the QKD device's control motherboard can be integrated into the same chassis, or even onto the same circuit board. This approach provides tighter coupling, lower communication latency, and potentially higher physical security, facilitating the creation of integrated, compact QKD terminal products. Both of these implementation methods are within the scope of this invention.

[0119] According to further embodiments of the present invention, a quantum communication network system is also provided. This system embodiment places the aforementioned method and device embodiments within a practical, operational network environment. The quantum communication network system mainly comprises the following components:

[0120] Network switches: As the infrastructure of classic system communication, they are high-speed data switching devices that form the hub of all classic communication links within the system. Network switches are responsible for routing IP packets between components, ensuring reliable transmission of control signaling and authentication data.

[0121] Post-Quantum Cryptography (PQC) Certification Authority: This is the core service entity in the system responsible for establishing and maintaining initial trust. It connects to the network switch, thereby accessing the network. The PQC Certification Authority functions similarly to a Certificate Authority (CA) in a traditional Public Key Infrastructure (PKI), but uses a quantum-resistant PQC algorithm. Its main responsibilities include: issuing, managing, and revoking the PQC digital certificates of each legitimate QKD communication node in the network; and responding to node queries by providing certificate verification services. During the initial trust-building phase, it acts as a trusted third party for each communication node to verify the authenticity of the other's PQC public key.

[0122] At least two QKD communication nodes: The system includes at least two QKD communication nodes as described in the previous embodiments. These nodes are the actual generators and users of quantum keys. Each node contains a QKD device and a PQC user terminal.

[0123] Network connectivity: In the system, the connections between QKD communication nodes are divided into two parallel paths:

[0124] Classic authentication path: Each node's PQC client connects to a network switch via a standard interface such as Ethernet, enabling communication with the PQC authentication center and PQC clients of any other node. This path is used to transmit all classic messages requiring PQC signature / verification, as well as subsequent symmetric key authentication information.

[0125] Quantum transmission path: The QKD devices at each node are interconnected via a dedicated quantum channel (e.g., a one-to-one single-mode fiber or free-space optical link). This path is used to transmit weak light pulses carrying quantum information and is the physical basis for generating the original key.

[0126] The system's collaborative workflow: The entire system is configured and programmed to implement a complete QKD authentication and key distribution process without pre-shared keys, specifically in two phases:

[0127] Initial PQC Authentication Support Phase: When any two QKD communication nodes (e.g., node A and node B) conduct QKD for the first time and need to establish trust, the system supports each QKD communication node to complete PQC authentication in the initial QKD session through a PQC authentication center. Specifically, when signing and verifying messages such as basis vector comparison, the PQC client of nodes A and B can query the authentication center through the network switch to confirm the validity and authenticity of the other party's PQC public key certificate. This ensures the security of classic channel interaction in the first round of QKD session and successfully generates the first final key and derives the symmetric authentication key.

[0128] Subsequent efficient authentication execution phase: After the initial session is successful, when any new QKD session (i.e., subsequent QKD session) is initiated between node A and node B, the system will execute the following steps by each QKD communication node itself: Figure 1 This method eliminates the need for real-time involvement of the PQC authentication center. Instead, both parties can directly utilize the shared symmetric authentication key and autonomously verify the consistency of the newly generated key through efficient symmetric cryptographic operations (such as encrypting digests and exchanging verifications). The scalability of the entire network is reflected in the fact that the PQC authentication center only needs to provide services during the initial pairing of nodes; thereafter, continuous key generation between any two node pairs can be carried out efficiently and autonomously.

[0129] Figure 4 A block diagram of an electronic device based on a post-quantum cryptography-based quantum key distribution method according to an embodiment of the present invention is shown schematically.

[0130] like Figure 4As shown, an electronic device according to an embodiment of the present invention includes a processor 501, which can perform various appropriate actions and processes according to a program stored in ROM (Read-Only Memory) 502 or a program loaded from storage portion 508 into random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.

[0131] RAM 503 stores various programs and data required for the operation of electronic device 500. Processor 501, ROM 502, and RAM 503 are interconnected via bus 504. Processor 501 executes various operations of the method flow according to embodiments of the present invention by executing programs in ROM 502 and / or RAM 503. It should be noted that programs may also be stored in one or more memories other than ROM 502 and RAM 503. Processor 501 may also execute various operations of the method flow according to embodiments of the present invention by executing programs stored in one or more memories.

[0132] According to embodiments of the present invention, the electronic device may further include an input / output (I / O) interface 505, which is also connected to a bus 504. The electronic device 500 may further include one or more of the following components connected to the input / output (I / O) interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, modem, etc. The communication section 509 performs communication processing via a network such as the Internet.

[0133] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.

[0134] According to embodiments of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the present invention, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present invention, the computer-readable storage medium may include ROM 502 and / or RAM 503 and / or one or more memories other than ROM 502 and RAM 503 described above.

[0135] Embodiments of the present invention also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the real-time risk warning method for financial trading systems provided in the embodiments of the present invention.

[0136] When the computer program is executed by the processor 501, it performs the functions defined in the system / apparatus of this invention. According to embodiments of the invention, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0137] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 509, and / or installed from a removable medium. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0138] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 509, and / or installed from a removable medium. When the computer program is executed by the processor 501, it performs the functions defined in the system of this embodiment of the invention. According to embodiments of the invention, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0139] According to embodiments of the present invention, program code for executing the computer programs provided in the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0140] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0141] Those skilled in the art will understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention can be combined and / or combined in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or combinations fall within the scope of the present invention.

Claims

1. A quantum key distribution management method based on post-quantum cryptography, characterized by, Applied to a quantum communication network including a first communication node and a second communication node, the method is executed by the first communication node and includes: In the first quantum key distribution session, the quantum key distribution negotiation process is completed with the second communication node based on post-quantum cryptographic authentication to generate the first final key; A portion of the first final key is extracted as a symmetric authentication key, which is used for authentication in at least one subsequent quantum key distribution session after the first quantum key distribution session; In the second quantum key distribution session established with the second communication node, the symmetric authentication key is used to confirm whether the final key of the current session held by the first communication node and the second communication node is consistent. The second quantum key distribution session is any quantum key distribution session after the first quantum key distribution session. The step of using the symmetric authentication key to confirm whether the final key of the current session held by the first communication node and the second communication node is consistent includes: Generate the final key for the current session with the second communication node; Generate a first digest value based on the final key of the current session; The first digest value is encrypted using the symmetric authentication key to generate the first authentication information; The first authentication information is sent to the second communication node to receive the second authentication information from the second communication node. The second authentication information is generated by the second communication node generating a second digest value based on the final key of the current session and encrypting the second digest value using the symmetric authentication key. Based on the first authentication information, the second authentication information, and the symmetric authentication key, verify whether the final key of the current session held by the first communication node and the second communication node is consistent; The process of negotiating quantum key distribution with the second communication node based on post-quantum cryptographic authentication to generate the first final key includes: In the first quantum key distribution session, at least one of the basis vector alignment information, error correction verification information, and random numbers used for privacy amplification, which are exchanged with the second communication node, is authenticated using a post-quantum cryptographic digital signature. After the post-quantum cryptography authentication is successful, the original key data obtained through negotiation is amplified for privacy purposes to generate the first final key.

2. The method of claim 1, wherein, The step of verifying whether the final keys of the current session held by the first communication node and the second communication node are consistent based on the first authentication information, the second authentication information, and the symmetric authentication key includes: The second authentication information is decrypted using the symmetric authentication key to obtain the second digest decryption value; Verify whether the decrypted value of the second digest is consistent with the value of the first digest; If they match, then the authentication of the second communication node is confirmed to be successful; After confirming that the authentication of the second communication node is successful, a successful verification response for the first authentication information is received from the second communication node; When both authentication of the second communication node and the receipt of the authentication success response are simultaneously satisfied, the two-way authentication is determined to be complete.

3. The method according to claim 1 or 2, characterized in that, The step of generating a first digest value based on the final key of the current session includes: The first digest value is generated by using a hash algorithm pre-agreed with the second communication node to calculate the final key of the current session.

4. The method of claim 1, wherein, Also includes: If it is confirmed that the final key of the current session held by the first communication node and the second communication node is inconsistent, the final key of the current session is discarded, and the current quantum key distribution session is stopped or reset.

5. The method of claim 2, wherein, After determining whether two-way authentication is complete, the following steps are also included: The remaining portion of the final key of the current session that is not used as the symmetric authentication key is stored in the key pool.

6. A quantum key distribution management communication node, characterized by, include: A quantum key distribution device used to negotiate raw key data with a peer communication node via a quantum channel; The post-quantum cryptography user terminal is communicatively connected to the quantum key distribution device. The processor is coupled to the quantum key distribution device and the post-quantum cryptography user terminal; Memory, which stores computer programs; When the processor executes the computer program, it performs the method as described in any one of claims 1 to 5.

7. The quantum key distribution management communication node according to claim 6, c h a r a c t e r i z e d b y The post-quantum cryptography user terminal is set up independently of the quantum key distribution device, or is embedded in the quantum key distribution device.

8. A quantum communication network system, characterized by, include: Network switch; The post-quantum cryptography authentication center is connected to the network switch; At least two quantum key distribution management communication nodes as described in claim 6 or 7; The post-quantum cryptography user terminal of each quantum key distribution management communication node is connected to the post-quantum cryptography authentication center through the network switch, and the quantum key distribution devices of each quantum key distribution management communication node are interconnected through quantum channels. The system is configured to support each quantum key distribution management communication node in completing quantum cryptographic authentication in the initial quantum key distribution session through the post-quantum cryptographic authentication center, and for each quantum key distribution management communication node to execute the method as described in any one of claims 1 to 5 in subsequent quantum key distribution sessions.