Key transfer method, apparatus, device, system, storage medium and program product
The session key, negotiated and generated by the key distribution center, solves the problem that mobile terminals cannot access the quantum key distribution network, and enables secure communication between mobile terminals and servers.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2024-12-06
- Publication Date
- 2026-06-09
AI Technical Summary
In existing technologies, quantum key distribution networks cannot provide keys to mobile terminals without fiber optic connections, making it impossible to achieve secure communication based on quantum key distribution technology.
The key distribution center sends a session key request to the mobile terminal, receives and verifies the session key, and uses the session key generated by the first QKD node and the second QKD node to achieve secure communication between the mobile terminal and the server.
It enables secure transmission of quantum keys to mobile terminals, provides highly secure communication services, and solves the problem that mobile terminals cannot access quantum key distribution networks.
Smart Images

Figure CN122179083A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a key transmission method, apparatus, device, system, storage medium, and program product. Background Technology
[0002] A Quantum Key Distribution Network (QKDN) is a network that implements quantum key distribution based on Quantum Key Distribution (QKD) technology, primarily composed of QKD nodes. QKDN enables two nodes within the network to negotiate and generate a shared key. QKDN is an optical fiber-based network; if a mobile communication terminal is not connected to the QKDN via optical fiber, such as a mobile terminal, it cannot use the key generated by the QKDN. Currently, there is no solution to provide keys generated based on QKD technology for large-scale use by application layer devices, especially for mobile communication terminals without optical fiber connections.
[0003] Therefore, a method for transmitting quantum keys to mobile terminals is needed. Summary of the Invention
[0004] This application provides a key transmission method, apparatus, device, system, storage medium, and program product to provide secure key services to mobile terminals.
[0005] In a first aspect, embodiments of this application provide a key transmission method applied to a mobile terminal, comprising:
[0006] Send a session key request to the key distribution center. The session key request is used to request a session key, which is used by the mobile terminal to communicate with the server.
[0007] The session key is received from the key distribution center. The session key is obtained by the key distribution center from the first QKD node connected to the key distribution center, and the session key is generated by the first QKD node and the second QKD node connected to the server through negotiation.
[0008] Optionally, the session key request includes:
[0009] The identifier of the mobile terminal;
[0010] The identifier of the server;
[0011] First random number;
[0012] The identifier of the authentication encryption key used by the mobile terminal;
[0013] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0014] Optionally, receiving the session key sent by the key distribution center includes:
[0015] Receive a session key request response message sent by the key distribution center, the session key request response message including:
[0016] The identifier of the mobile terminal;
[0017] The identifier of the key distribution center;
[0018] First random number;
[0019] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0020] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0021] Optionally, the method further includes:
[0022] Compare the first random number in the session key request with the first random number in the session key request response message;
[0023] If the first random number in the session key request is the same as the first random number in the session key request response message, the session key request response message is authenticated.
[0024] Optionally, the method further includes one or more of the following steps:
[0025] Obtain the authentication encryption key from the key update terminal;
[0026] Delete the authentication encryption key.
[0027] Optionally, the method further includes:
[0028] Communication with the server is established based on the session key.
[0029] Optionally, establishing communication with the server based on the session key includes:
[0030] Send a session request to the server;
[0031] Receive the session request response message sent by the server;
[0032] The session request includes:
[0033] The identifier of the mobile terminal;
[0034] The identifier of the server;
[0035] First random number;
[0036] Second random number;
[0037] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0038] The session request response message includes:
[0039] The identifier of the mobile terminal;
[0040] The identifier of the server;
[0041] Second random number;
[0042] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0043] Optionally, the method further includes:
[0044] Compare the second random number in the session request with the second random number in the session request response message;
[0045] If the second random number in the session request is the same as the second random number in the session request response message, the session request response message is authenticated.
[0046] Secondly, embodiments of this application provide a key transmission method applied in a key distribution center, comprising:
[0047] Receive a session key request sent by a mobile terminal, wherein the session key request is used to request a session key, and the session key is used for communication between the mobile terminal and the server;
[0048] The session key is obtained from the first QKD node, which is generated through negotiation between the first QKD node and the second QKD node connected to the server.
[0049] Send the session key to the mobile terminal;
[0050] Send session key information to the server, the session key information including information related to the session key.
[0051] Optionally, obtaining the session key from the first QKD node includes:
[0052] Send a key request message to the first QKD node. The key request message is used to request a key between the first QKD node and a second QKD node of the quantum key distribution network. The second QKD node is a node to which the server is connected.
[0053] Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata;
[0054] The key between the first QKD node and the second QKD node is used as the session key.
[0055] Optionally, the session key request includes:
[0056] The identifier of the mobile terminal;
[0057] The identifier of the server;
[0058] First random number;
[0059] The identifier of the authentication encryption key used by the mobile terminal;
[0060] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0061] The method further includes:
[0062] Obtain the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal;
[0063] The authentication encryption key is used to verify the first message verification code.
[0064] Optionally, sending the session key to the mobile terminal includes:
[0065] Send a session key request response message to the mobile terminal, the session key request response message including:
[0066] The identifier of the mobile terminal;
[0067] The identifier of the key distribution center;
[0068] First random number;
[0069] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0070] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0071] Optionally, the session key information includes:
[0072] The identifier of the mobile terminal;
[0073] The identifier of the server;
[0074] First random number;
[0075] The identifier of the session key.
[0076] Optionally, the method further includes:
[0077] Delete the session key.
[0078] Thirdly, embodiments of this application provide a key transmission method applied to a server, including:
[0079] The system receives session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server.
[0080] Receive the session key sent by the second QKD node.
[0081] Optionally, the session key information includes:
[0082] The identifier of the mobile terminal;
[0083] The identifier of the server;
[0084] First random number;
[0085] The identifier of the session key.
[0086] Optionally, the method further includes:
[0087] Communication with the mobile terminal is established based on the session key.
[0088] Optionally, establishing communication with the mobile terminal based on the session key includes:
[0089] Receive a session request sent by the mobile terminal;
[0090] Send a session request response message to the mobile terminal;
[0091] The session request includes:
[0092] The identifier of the mobile terminal;
[0093] The identifier of the server;
[0094] First random number;
[0095] Second random number;
[0096] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0097] The session request response message includes:
[0098] The identifier of the mobile terminal;
[0099] The identifier of the server;
[0100] Second random number;
[0101] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0102] Optionally, sending a session request response message to the mobile terminal includes:
[0103] The session key is used to verify the third message verification code;
[0104] If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
[0105] Fourthly, embodiments of this application provide a key transmission device applied to a mobile terminal, comprising:
[0106] The first sending module is used to send a session key request to the key distribution center. The session key request is used to request a session key, which is used by the mobile terminal to communicate with the server.
[0107] The first receiving module is used to receive the session key sent by the key distribution center. The session key is obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key is generated by negotiation between the first QKD node and a second QKD node connected to the server.
[0108] Optionally, the session key request includes:
[0109] The identifier of the mobile terminal;
[0110] The identifier of the server;
[0111] First random number;
[0112] The identifier of the authentication encryption key used by the mobile terminal;
[0113] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0114] Optionally, the first receiving module is further configured to receive a session key request response message sent by the key distribution center, the session key request response message including:
[0115] The identifier of the mobile terminal;
[0116] The identifier of the key distribution center;
[0117] First random number;
[0118] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0119] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0120] Optionally, the device may further include:
[0121] The first comparison module is used to compare the first random number in the session key request with the first random number in the session key request response message;
[0122] The first hot authentication module is used to authenticate the session key request response message if the first random number in the session key request is the same as the first random number in the session key request response message.
[0123] Optionally, the device may further include:
[0124] The first processing module is used to obtain the authentication encryption key from the key update terminal; and / or delete the authentication encryption key.
[0125] Optionally, the device may further include:
[0126] The second processing module is used to establish communication with the server based on the session key.
[0127] Optionally, the second processing module is further configured to:
[0128] Send a session request to the server;
[0129] Receive the session request response message sent by the server;
[0130] The session request includes:
[0131] The identifier of the mobile terminal;
[0132] The identifier of the server;
[0133] First random number;
[0134] Second random number;
[0135] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0136] The session request response message includes:
[0137] The identifier of the mobile terminal;
[0138] The identifier of the server;
[0139] Second random number;
[0140] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0141] Optionally, the device may further include:
[0142] The second comparison module is used to compare the second random number in the session request with the second random number in the session request response message;
[0143] The second verification module is used to authenticate the session request response message if the second random number in the session request is the same as the second random number in the session request response message.
[0144] Fifthly, embodiments of this application provide a key transmission device applied in a key distribution center, comprising:
[0145] The first receiving module is used to receive a session key request sent by a mobile terminal. The session key request is used to request a session key, which is used for communication between the mobile terminal and the server.
[0146] The first acquisition module is used to acquire the session key from the first QKD node;
[0147] The first sending module is used to send the session key to the mobile terminal. The session key is generated by negotiation between the first QKD node and the second QKD node connected to the server.
[0148] The second sending module is used to send session key information to the server, the session key information including information related to the session key.
[0149] Optionally, the first acquisition module is further configured to:
[0150] Send a key request message to the first QKD node. The key request message is used to request a key between the first QKD node and a second QKD node of the quantum key distribution network. The second QKD node is a node to which the server is connected.
[0151] Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata;
[0152] The key between the first QKD node and the second QKD node is used as the session key.
[0153] Optionally, the session key request includes:
[0154] The identifier of the mobile terminal;
[0155] The identifier of the server;
[0156] First random number;
[0157] The identifier of the authentication encryption key used by the mobile terminal;
[0158] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0159] The device further includes:
[0160] The second acquisition module is used to acquire the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal;
[0161] The first authentication module is used to verify the first message verification code using the authentication encryption key.
[0162] Optionally, the first sending module is further configured to send a session key request response message to the mobile terminal, the session key request response message including:
[0163] The identifier of the mobile terminal;
[0164] The identifier of the key distribution center;
[0165] First random number;
[0166] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0167] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0168] Optionally, the session key information includes:
[0169] The identifier of the mobile terminal;
[0170] The identifier of the server;
[0171] First random number;
[0172] The identifier of the session key.
[0173] Optionally, the device may further include:
[0174] The first processing module is used to delete the session key.
[0175] Sixthly, embodiments of this application provide a key transmission device applied to a server, comprising:
[0176] The first receiving module is used to receive session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated by negotiation between the first QKD node connected to the key distribution center and the second QKD node connected to the server.
[0177] The second receiving module is used to receive the session key sent by the second QKD node.
[0178] Optionally, the session key information includes:
[0179] The identifier of the mobile terminal;
[0180] The identifier of the server;
[0181] First random number;
[0182] The identifier of the session key.
[0183] Optionally, the device may further include:
[0184] The first processing module is used to establish communication with the mobile terminal based on the session key.
[0185] Optionally, the first processing module includes:
[0186] The first receiving submodule is used to receive the session request sent by the mobile terminal;
[0187] The first sending submodule is used to send a session request response message to the mobile terminal;
[0188] The session request includes:
[0189] The identifier of the mobile terminal;
[0190] The identifier of the server;
[0191] First random number;
[0192] Second random number;
[0193] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0194] The session request response message includes:
[0195] The identifier of the mobile terminal;
[0196] The identifier of the server;
[0197] Second random number;
[0198] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0199] Optionally, the first transmitting submodule is further configured to:
[0200] The session key is used to verify the third message verification code;
[0201] If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
[0202] In a seventh aspect, embodiments of this application provide a key transmission device applied to a mobile terminal, comprising: a processor and a transceiver;
[0203] The processor is configured to send a session key request to a key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server.
[0204] Optionally, the session key request includes:
[0205] The identifier of the mobile terminal;
[0206] The identifier of the server;
[0207] First random number;
[0208] The identifier of the authentication encryption key used by the mobile terminal;
[0209] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0210] Optionally, the processor is further configured to:
[0211] Receive a session key request response message sent by the key distribution center, the session key request response message including:
[0212] The identifier of the mobile terminal;
[0213] The identifier of the key distribution center;
[0214] First random number;
[0215] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0216] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0217] Optionally, the processor is further configured to:
[0218] Compare the first random number in the session key request with the first random number in the session key request response message;
[0219] If the first random number in the session key request is the same as the first random number in the session key request response message, the session key request response message is authenticated.
[0220] Optionally, the processor is also used in one or more of the following steps:
[0221] Obtain the authentication encryption key from the key update terminal;
[0222] Delete the authentication encryption key.
[0223] Optionally, the processor is further configured to:
[0224] Communication with the server is established based on the session key.
[0225] Optionally, the processor is further configured to:
[0226] Send a session request to the server;
[0227] Receive the session request response message sent by the server;
[0228] The session request includes:
[0229] The identifier of the mobile terminal;
[0230] The identifier of the server;
[0231] First random number;
[0232] Second random number;
[0233] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0234] The session request response message includes:
[0235] The identifier of the mobile terminal;
[0236] The identifier of the server;
[0237] Second random number;
[0238] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0239] Optionally, the processor is further configured to:
[0240] Compare the second random number in the session request with the second random number in the session request response message;
[0241] If the second random number in the session request is the same as the second random number in the session request response message, the session request response message is authenticated.
[0242] Eighthly, embodiments of this application provide a key transmission device applied in a key distribution center, comprising: a processor and a transceiver;
[0243] The processor is configured to receive a session key request sent by a mobile terminal, the session key request being used to request a session key, the session key being used for communication between the mobile terminal and the server; obtain the session key from a first QKD node, the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key.
[0244] Optionally, the processor is further configured to:
[0245] Send a key request message to the first QKD node. The key request message is used to request a key between the first QKD node and a second QKD node of the quantum key distribution network. The second QKD node is a node to which the server is connected.
[0246] Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata;
[0247] The key between the first QKD node and the second QKD node is used as the session key.
[0248] Optionally, the session key request includes:
[0249] The identifier of the mobile terminal;
[0250] The identifier of the server;
[0251] First random number;
[0252] The identifier of the authentication encryption key used by the mobile terminal;
[0253] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0254] The processor is also used for:
[0255] Obtain the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal;
[0256] The authentication encryption key is used to verify the first message verification code.
[0257] Optionally, the processor is further configured to: send a session key request response message to the mobile terminal, the session key request response message including:
[0258] The identifier of the mobile terminal;
[0259] The identifier of the key distribution center;
[0260] First random number;
[0261] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0262] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0263] Optionally, the session key information includes:
[0264] The identifier of the mobile terminal;
[0265] The identifier of the server;
[0266] First random number;
[0267] The identifier of the session key.
[0268] Optionally, the processor is further configured to:
[0269] Delete the session key.
[0270] Ninthly, embodiments of this application provide a key transmission device applied to a server, comprising: a processor and a transceiver;
[0271] The processor is configured to receive session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server.
[0272] Receive the session key sent by the second QKD node.
[0273] Optionally, the session key information includes:
[0274] The identifier of the mobile terminal;
[0275] The identifier of the server;
[0276] First random number;
[0277] The identifier of the session key.
[0278] Optionally, the processor is further configured to:
[0279] Communication with the mobile terminal is established based on the session key.
[0280] Optionally, the processor is further configured to:
[0281] Receive a session request sent by the mobile terminal;
[0282] Send a session request response message to the mobile terminal;
[0283] The session request includes:
[0284] The identifier of the mobile terminal;
[0285] The identifier of the server;
[0286] First random number;
[0287] Second random number;
[0288] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0289] The session request response message includes:
[0290] The identifier of the mobile terminal;
[0291] The identifier of the server;
[0292] Second random number;
[0293] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0294] Optionally, the processor is further configured to:
[0295] The session key is used to verify the third message verification code;
[0296] If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
[0297] In a tenth aspect, embodiments of this application provide a key transmission system, including: a mobile terminal, a server, and a key distribution center;
[0298] The mobile terminal is configured to send a session key request to the key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server.
[0299] The key distribution center is configured to receive a session key request sent by a mobile terminal; obtain the session key from a first QKD node; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key.
[0300] The server is used to receive session key information sent by the key distribution center, and the session key information includes information related to the session key.
[0301] Eleventhly, embodiments of this application also provide a communication device, including: a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps in the key transmission method described above.
[0302] In a twelfth aspect, embodiments of this application also provide a readable storage medium storing a program that, when executed by a processor, implements the steps in the key transmission method described above.
[0303] In a thirteenth aspect, embodiments of this application also provide a computer program product, including computer instructions that, when executed by a processor, implement the steps in the key transmission method described above.
[0304] In this embodiment of the application, the mobile terminal can obtain a session key for communicating with the server from the key distribution center. The session key is obtained by the key distribution center from the first QKD node. Therefore, the quantum key can be transmitted to the mobile terminal based on the key distribution center, thereby providing secure key services to the mobile terminal. Attached Figure Description
[0305] Figure 1 This is one of the schematic diagrams of the key transmission system provided in the embodiments of this application;
[0306] Figure 2 This is the second schematic diagram of the key transmission system provided in the embodiments of this application;
[0307] Figure 3 This is a schematic diagram of the system architecture provided in the embodiments of this application;
[0308] Figure 4 This is one of the flowcharts of the key transmission method provided in the embodiments of this application;
[0309] Figure 5 This is the second flowchart of the key transmission method provided in the embodiments of this application;
[0310] Figure 6 This is the third flowchart of the key transmission method provided in the embodiments of this application;
[0311] Figure 7 This is the fourth flowchart of the key transmission method provided in the embodiments of this application;
[0312] Figure 8 This is one of the structural diagrams of the key transmission device provided in the embodiments of this application;
[0313] Figure 9 This is a second structural diagram of the key transmission device provided in the embodiments of this application;
[0314] Figure 10 This is the third structural diagram of the key transmission device provided in the embodiments of this application;
[0315] Figure 11 This is the fourth structural diagram of the key transmission device provided in the embodiments of this application;
[0316] Figure 12 This is the fifth structural diagram of the key transmission device provided in the embodiments of this application;
[0317] Figure 13This is the sixth structural diagram of the key transmission device provided in the embodiments of this application. Detailed Implementation
[0318] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0319] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0320] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0321] In related technologies, a Key Distribution Center (KDC) is a common facility in traditional systems used to manage keys for a large number of users. Its functions include at least key generation, entity authentication, key distribution, and key lifecycle management.
[0322] In the application layer, the KDC shares a long-term key with each communicating party, generates its own session key, and transmits the session key to the communicating party through a secure channel established based on the long-term key. Currently, the KDC does not use quantum technology to generate session keys. The randomness of this session key is significantly different from the randomness of keys generated using quantum technology in a QKDN. For higher security, keys generated in a QKDN should be used as session keys. However, current KDC systems do not support distributing QKDN keys to application layer communicating parties.
[0323] Quantum key distribution networks cannot provide keys to mobile terminals without fiber optic connections. Therefore, it is necessary to propose a method for transmitting quantum keys to mobile terminals based on a key distribution center.
[0324] See Figure 1 , Figure 1 This is a schematic diagram of a key transmission system according to an embodiment of this application, including: a mobile terminal 101, a key distribution center 102, and a server 103;
[0325] The mobile terminal 101 is configured to send a session key request to the key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server.
[0326] The key distribution center 102 is used to receive a session key request sent by a mobile terminal; obtain the session key from the first QKD node; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key.
[0327] The server 103 is used to receive session key information sent by the key distribution center, the session key information including information related to the session key.
[0328] In practical applications, a mobile terminal is a device that can be used anywhere. It can be a mobile phone, laptop, tablet, etc. It is not connected to the QKDN. It seeks to securely access servers providing dedicated services using a key from the QKDN. It communicates with the KDC and servers via a wireless link (network).
[0329] Optional, see Figure 2 The system may also include a key update terminal 104 for providing authentication encryption keys to mobile terminals for communication between the mobile terminals and the key distribution center.
[0330] See Figure 3 , Figure 3 This is a schematic diagram of the system architecture of an embodiment of this application. The system architecture is a two-layer architecture. The lower layer is the QKDN layer, which generates keys and provides keys to the upper layer. The upper layer is the service layer, which consists of a key distribution center (KDC), key update terminals, servers, and mobile terminals.
[0331] The server is an application server that provides services to mobile terminals or fixed devices. It connects to the underlying QKD nodes and obtains keys from the QKDN layer. The server communicates with the KDC through a secure channel, which can be established using the keys of two QKD nodes in the QKDN layer, which are connected to the server and the KDC respectively.
[0332] Key update terminals are typically located in the service halls of mobile communication operators and are used to inject authentication encryption keys into mobile terminals from the QKDN layer. The key update terminal connects to the underlying QKD nodes to obtain keys from the QKDN layer. The key update terminal communicates with the KDC (Key Management Center) via a secure channel, which can be established using keys from two QKD nodes connected to the key update terminal and the KDC, respectively.
[0333] The Key Distribution Center (KDC) is used to authenticate mobile terminals and distribute session keys to them from the QKDN layer. The KDC connects to the underlying QKD nodes and obtains the session keys from the QKDN layer.
[0334] Offline, mobile terminals inject keys from QKDN in batches via a key update terminal (the key between node QKD A connected to the key update terminal and node QKD C connected to the KDC), and use these keys as one-time authentication encryption keys for connecting to the KDC. The mobile terminal and KDC authenticate each other using the authentication encryption key, while the KDC transmits the mobile terminal's session information to the server through a secure channel. The KDC obtains the key between the QKD node connected to the KDC and the QKD node connected to the server (i.e., the key between the QKD node connected to the KDC and the QKD node connected to the server) from the QKDN. Figure 3 Key K CD The KDC uses this key as a session key, binds the session information to the key identifier of this session key, and transmits it to the server through a secure channel. The KDC encrypts the session key using an authentication encryption key and transmits the encrypted session key to the mobile terminal. The mobile terminal uses the session key to securely access the server.
[0335] See Figure 4 , Figure 4 This is a flowchart of a key transmission method provided in an embodiment of this application, applied to a mobile terminal, such as... Figure 4 As shown, it includes the following steps:
[0336] Step 401: Send a session key request to the key distribution center. The session key request is used to request a session key, which is used by the mobile terminal to communicate with the server.
[0337] The session key request includes:
[0338] The identifier of the mobile terminal;
[0339] The identifier of the server;
[0340] The first random number is a one-time random number generated by the mobile terminal.
[0341] The identifier of the authentication encryption key used by the mobile terminal;
[0342] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal. Here, a message verification code algorithm, such as a hash-based message authentication code (HMAC), can be used to protect the integrity of the above information to obtain the first message verification code.
[0343] Step 402: Receive the session key sent by the key distribution center. The session key is obtained by the key distribution center from the first QKD node connected to the key distribution center, and the session key is generated by negotiation between the first QKD node and the second QKD node connected to the server.
[0344] Here, the mobile terminal can receive a session key request response message sent by the key distribution center, the session key request response message including:
[0345] The identifier of the mobile terminal;
[0346] The identifier of the key distribution center;
[0347] The first random number can be the first random number received by the key distribution center from the mobile terminal;
[0348] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0349] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0350] During the process of obtaining encrypted information, encryption algorithms, such as the Advanced Encryption Standard (AES), can be used to encrypt the session key. Here, message verification code algorithms such as HMAC can be used to protect the integrity of the above information and obtain a second message verification code.
[0351] In this embodiment of the application, the mobile terminal can obtain a session key for communicating with the server from the key distribution center. The session key is obtained by the key distribution center from the first QKD node of the quantum key distribution network. Thus, the quantum key can be transmitted to the mobile terminal based on the key distribution center, thereby providing secure key services to the mobile terminal.
[0352] Building upon the above embodiments, to ensure communication security, the mobile terminal can also verify the key distribution center. Specifically, the mobile terminal can compare the first random number in the session key request with the first random number in the session key request response message. If the first random number in the session key request and the first random number in the session key request response message are the same, the communication counterpart is authenticated through the session key request response message, thus proving that the other party is the key distribution center; otherwise, the process can end.
[0353] The mobile terminal can delete the authentication encryption key, thereby ensuring the security of each communication with the key distribution center. This authentication encryption key is obtained by the mobile terminal from the key update terminal; correspondingly, before executing the embodiments of this application, the mobile terminal can also obtain the authentication encryption key from the key update terminal.
[0354] After obtaining the session key, the mobile terminal can establish communication with the server based on the session key.
[0355] Specifically, the mobile terminal can send a session request to the server and receive a session request response message from the server.
[0356] The session request includes:
[0357] The identifier of the mobile terminal;
[0358] The identifier of the server;
[0359] The first random number is a one-time random number generated by the mobile terminal.
[0360] The second random number is a one-time random number generated by the mobile terminal.
[0361] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number.
[0362] The session request response message includes:
[0363] The identifier of the mobile terminal;
[0364] The identifier of the server;
[0365] The second random number can be a second random number received from the mobile terminal;
[0366] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0367] The server can use a message verification code algorithm, such as HMAC, to protect the integrity of the above information and obtain a third message verification code. The server can also use a message verification code algorithm, such as HMAC, to protect the integrity of the above information and obtain a fourth message verification code.
[0368] After receiving the session request response message from the server, the mobile terminal can authenticate the server. Specifically, the mobile terminal can compare the second random number in the session request with the second random number in the session request response message. If the second random number in the session request and the second random number in the session request response message are the same, the mobile terminal authenticates the session request response message, thus proving that the communicating party is the server and possesses the session key.
[0369] See Figure 5 , Figure 5 This is a flowchart of a key transmission method provided in an embodiment of this application, applied in a key distribution center, such as... Figure 5 As shown, it includes the following steps:
[0370] Step 501: Receive a session key request sent by the mobile terminal. The session key request is used to request a session key, which is used for communication between the mobile terminal and the server.
[0371] The session key request includes:
[0372] The identifier of the mobile terminal;
[0373] The identifier of the server;
[0374] The first random number is a one-time random number generated by the mobile terminal;
[0375] The identifier of the authentication encryption key used by the mobile terminal;
[0376] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0377] For an explanation of the above information, please refer to the description of the foregoing embodiments.
[0378] Based on the session key request, the key distribution center can obtain the authentication encryption key according to the identifier of the authentication encryption key used by the mobile terminal, and use the authentication encryption key to verify the first message verification code. Specifically, if the key distribution center finds the corresponding authentication encryption key according to the identifier of the authentication encryption key used by the mobile terminal, it can use the authentication encryption key to verify the first message verification code; otherwise, the process can be terminated directly.
[0379] Step 502: Obtain the session key from the first QKD node. The session key is generated through negotiation between the first QKD node and the second QKD node connected to the server.
[0380] In this step, the key distribution center sends a key request message to the first QKD node. This message requests a key between the first QKD node and a second QKD node in the quantum key distribution network, where the server is connected. The key request message may include the identifiers of the first and second QKD nodes. Next, the key distribution center receives key information from the first QKD node. This key information includes the key between the first and second QKD nodes, and key metadata, including the key identifier. The key distribution center can then use the key between the first and second QKD nodes as the session key.
[0381] Step 503: Send the session key to the mobile terminal.
[0382] Specifically, the key distribution center can send a session key request response message to the mobile terminal, the session key request response message including:
[0383] The identifier of the mobile terminal;
[0384] The identifier of the key distribution center;
[0385] The first random number can be a first random number received from the mobile terminal;
[0386] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0387] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0388] After this step, the key distribution center can delete the one-time authentication encryption key from the secure storage area.
[0389] Step 504: Send session key information to the server, the session key information including information related to the session key.
[0390] The information related to the session key may include session information and the identifier of the session key. The session information includes: the identifier of the mobile terminal, the identifier of the server, and the first random number.
[0391] In this embodiment of the application, the mobile terminal can obtain a session key for communicating with the server from the key distribution center. The session key is obtained by the key distribution center from the first QKD node of the quantum key distribution network. Thus, the quantum key can be transmitted to the mobile terminal based on the key distribution center, thereby providing secure key services to the mobile terminal.
[0392] See Figure 6 , Figure 6 This is a flowchart of a key transmission method provided in an embodiment of this application, applied to a server, such as... Figure 6 As shown, it includes the following steps:
[0393] Step 601: Receive session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server.
[0394] The session key information includes:
[0395] The identifier of the mobile terminal;
[0396] The identifier of the server;
[0397] The first random number is a one-time random number generated by the mobile terminal.
[0398] The identifier of the session key.
[0399] Step 602: Receive the session key sent by the second QKD node.
[0400] The second QKD node is a node in the quantum key distribution network connected to the server. Optionally, the server can also obtain key metadata from the second QKD node, which includes the key identifier of the key. The server can find the corresponding session key based on the session key identifier included in the session key information.
[0401] The server can obtain the corresponding session key based on the identifier of the session key. Then, the server can establish communication with the mobile terminal based on the session key.
[0402] Here, the server receives a session request sent by the mobile terminal and sends a session request response message to the mobile terminal. The session request includes:
[0403] The identifier of the mobile terminal;
[0404] The identifier of the server;
[0405] The first random number is a one-time random number generated by the mobile terminal.
[0406] The second random number is a one-time random number generated by the mobile terminal.
[0407] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0408] The session request response message includes:
[0409] The identifier of the mobile terminal;
[0410] The identifier of the server;
[0411] The second random number can be a second random number received from the mobile terminal;
[0412] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0413] Upon receiving a request from the mobile terminal, the server can authenticate the mobile terminal. For example, it can use the session key to verify the third message verification code. If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal. Otherwise, the process can end.
[0414] In this embodiment of the application, the mobile terminal can obtain a session key for communicating with the server from the key distribution center. The session key is obtained by the key distribution center from the first QKD node of the quantum key distribution network. Thus, the quantum key can be transmitted to the mobile terminal based on the key distribution center, thereby providing secure key services to the mobile terminal.
[0415] Combination Figure 3The system architecture shown involves the mobile terminal obtaining an authentication encryption key offline through a key update terminal. Simultaneously, the KDC binds this authentication encryption key to the mobile terminal's identifier. The mobile terminal uses the authentication encryption key to mutually authenticate with the KDC. The mobile terminal initiates a session key request message to the KDC, which retrieves session information from the message, thus confirming that the mobile terminal needs to communicate with server Y. The KDC requests a key between QKD C (connected to the KDC, i.e., the first QKD node) and QKD D (connected to server Y, i.e., the second QKD node) from the lower-level QKDN. After obtaining this key, the KDC uses it as the session key, binds the session information and key identifier, and transmits it to server Y through a secure channel. The KDC then transmits the encrypted session key to the mobile terminal, which uses it to establish secure communication with the server.
[0416] See Figure 7 , Figure 7 This is a flowchart of a key transmission method provided in an embodiment of this application, including the following steps:
[0417] Step 701: Mobile terminal X sends a session key request message to KDC, the content of which is:
[0418] Message 1 (Mobile Terminal X → KDC): IDx, IDy, N1x, KeyID, MAC1
[0419] Where IDx is the identifier of mobile terminal X, IDy is the identifier of server Y, N1x is a one-time random number generated by mobile terminal X (i.e., the first random number), KeyID is the identifier of the authentication encryption key used by the mobile terminal this time, and MAC1 (i.e., the first message verification code) is a message verification code generated based on the authentication encryption key pair IDx, IDy, N1x, and KeyID using a message verification code algorithm (such as HMAC). Its calculation formula is as follows:
[0420] MAC1=HMAC(AE-key,IDx‖IDy‖N1x‖KeyID)
[0421] Here, AE-key is the authentication encryption key corresponding to KeyID, and ‖ is a string concatenation.
[0422] Step 702: Upon receiving message 1, the KDC searches for the corresponding authentication encryption key AE-key in its storage based on the KeyID in the message. If not found, the process terminates. If the authentication encryption key AE-key is found, the KDC uses this key AE-key to verify MAC1. If verification is successful, it proves that message 1 has not been tampered with by an attacker, and also proves that the message sender's identity is mobile terminal X; if verification fails, the process terminates. Then, based on IDx and IDy, the KDC determines that mobile terminal X needs a session key with server Y. Based on IDy, the KDC determines that the destination node of the required key in the QKDN is QKD-D (connected to server Y). Therefore, the KDC needs to request the key K between node QKD-C (connected to the KDC) and node QKD-D (connected to server Y) from the QKDN. CD The KDC sends a key request message to the QKD C node it is connected to, which is:
[0423] Message 2 (KDC→QKD-C): ID QKD-C ID QKD-D
[0424] Among them, ID QKD-C ID QKD-D These are the identifiers for nodes QKD-C and QKD-D, respectively.
[0425] Step 703: After receiving the key request message, QKD-C executes the key generation process between node QKD-C and node QKD-D to obtain key K. CD and containing key K CD Key ID CD The key metadata. QKD-D also obtains the key K at the same time. CD and containing key K CD Key ID CD Key metadata.
[0426] Step 704: QKD-C sends a key request response message to KDC, which is as follows:
[0427] Message 4 (QKD-E→KDC): K CD Key metadata
[0428] QKD-D sends a key request response message to server Y, which is as follows:
[0429] Message 4 (QKD-D → Server sends Y): K CD Key metadata
[0430] Step 705: KDC combines the session information (IDx, IDy, N1x) with KeyID CDThe session information and KeyIDCD are bound and transmitted to server Y via a secure channel in a session notification message (message 5):
[0431] Message 5 (KDC → Server sends Y): IDx, IDy, N1x, KeyID CD
[0432] Step 706: KDC transfers the key K CD Used as the session key SE-key, a session key request response message is sent to mobile terminal X:
[0433] Message 6 (KDC → Mobile Terminal X): IDx, ID KDC N1x, [SE-key] AE-key MAC2
[0434] Among them, [SE-key] AE-key (i.e., encrypted information) indicates that the session key SE-key is encrypted using an encryption algorithm (such as AES) based on the authentication encryption key AE-key; MAC2 (i.e., the second message verification code) is based on the authentication encryption key pair IDx, ID KDC N1x uses message verification code algorithms (such as HMAC) to generate message verification codes, and the calculation formula is as follows:
[0435] MAC2 = HMAC(AE-key, IDx‖ID) KDC ‖N1x‖[SE-key] AE-key )
[0436] Here, both encryption algorithms and message verification code algorithms are used. Alternatively, it can be implemented using Authenticated Encryption with Associated Data (AEAD) based on the authentication encryption key. When using the AEAD scheme, [SE-key] AE-key MAC2 is the output ciphertext, IDx, IDKDC, and N1x are associated data, and MAC2 is the message verification code for the ciphertext and associated data.
[0437] KDC removes the one-time authentication encryption key from the secure storage area.
[0438] Step 707: After receiving message 6, mobile terminal X compares N1x in message 6 with N1x in message 1. If they are equal, it can be determined that message 6 is not a replay message, and MAC2 is verified using the authentication encryption key; otherwise, the process ends. If the verification is successful, it proves that the communicating party is KDC; if the verification fails, the process ends. Mobile terminal X deletes the one-time authentication encryption key. Mobile terminal X generates a session request and sends it to server Y, the content of which is:
[0439] Message 7 (Mobile Terminal X → Server Y): IDx, IDy, N1x, N2x, MAC3
[0440] Where N2x is a one-time random number (i.e., the second random number) generated by mobile terminal X, and MAC3 (i.e., the third message verification code) is a message verification code generated based on the session key SE-key using a message verification code algorithm (such as HMAC) on IDx, IDy, N1x, and N2x. Its calculation formula is as follows:
[0441] MAC3=HMAC(SE-key,IDx‖IDy‖N1x‖N2x)
[0442] Step 708: After receiving message 7, server Y finds the corresponding key identifier KeyID based on the session information (IDx, IDy, N1x). CD Thus, the key K can be found. CD This is the session key (SE-key). Server Y uses this key to verify MAC3. If the verification is successful, it proves the authenticity of mobile terminal X and that X possesses the session key; otherwise, the process ends. Server Y generates a session request response message and sends it to mobile terminal X, the content of which is:
[0443] Message 8 (Server Y → Mobile Terminal X): IDy, IDx, N2x, MAC4
[0444] MAC4 (i.e., fourth-level CAPTCHA) is a message verification code algorithm based on the session key SE-key, using IDy, IDx, and N2x. For example, the calculation formula for a message verification code generated by HMAC is as follows:
[0445] MAC4=HMAC(SE-key,IDy‖IDx‖N2x)
[0446] After receiving message 8, mobile terminal X compares the received N2x with the N2x sent in the message. If they are the same, the terminal confirms that message 8 is not a replay; otherwise, the process can end. Mobile terminal X uses the session key SE-key to verify MAC4. If the verification is successful, it proves that the communicating party is server Y and possesses the session key SE-key; otherwise, the process can end.
[0447] In this embodiment, the mobile terminal can use a key generated in a QKDN and establish a secure connection with the server based on this key. Since the key generated by QKDN is based on quantum technology and possesses truly random number characteristics, the secure connection established by the mobile terminal using this key has higher security. Furthermore, managing the key from the QKDN based on a KDC (Key Management Device) system can provide secure key services to a large number of users, including mobile users.
[0448] See Figure 8 , Figure 8 This is a structural diagram of the key transmission device provided in an embodiment of this application, applied to a mobile terminal. For example... Figure 8 As shown, the key transmission device includes:
[0449] The first sending module 801 is used to send a session key request to the key distribution center. The session key request is used to request a session key, which is used for communication between the mobile terminal and the server. The first receiving module 802 is used to receive the session key sent by the key distribution center. The session key is obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key is generated by negotiation between the first QKD node and a second QKD node connected to the server.
[0450] Optionally, the session key request includes:
[0451] The identifier of the mobile terminal;
[0452] The identifier of the server;
[0453] First random number;
[0454] The identifier of the authentication encryption key used by the mobile terminal;
[0455] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0456] Optionally, the first receiving module is further configured to receive a session key request response message sent by the key distribution center, the session key request response message including:
[0457] The identifier of the mobile terminal;
[0458] The identifier of the key distribution center;
[0459] First random number;
[0460] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0461] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0462] Optionally, the device may further include:
[0463] The first comparison module is used to compare the first random number in the session key request with the first random number in the session key request response message;
[0464] The first hot authentication module is used to authenticate the session key request response message if the first random number in the session key request is the same as the first random number in the session key request response message.
[0465] Optionally, the device may further include:
[0466] The first processing module is used to obtain the authentication encryption key from the key update terminal; and / or delete the authentication encryption key.
[0467] Optionally, the device may further include:
[0468] The second processing module is used to establish communication with the server based on the session key.
[0469] Optionally, the second processing module is further configured to:
[0470] Send a session request to the server;
[0471] Receive the session request response message sent by the server;
[0472] The session request includes:
[0473] The identifier of the mobile terminal;
[0474] The identifier of the server;
[0475] First random number;
[0476] Second random number;
[0477] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0478] The session request response message includes:
[0479] The identifier of the mobile terminal;
[0480] The identifier of the server;
[0481] Second random number;
[0482] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0483] Optionally, the device may further include:
[0484] The second comparison module is used to compare the second random number in the session request with the second random number in the session request response message;
[0485] The second verification module is used to authenticate the session request response message if the second random number in the session request is the same as the second random number in the session request response message.
[0486] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0487] See Figure 9 , Figure 9 This is a structural diagram of the key transmission device provided in an embodiment of this application, which is applied in a key distribution center. Figure 9 As shown, the key transmission device includes:
[0488] A first receiving module 901 is configured to receive a session key request sent by a mobile terminal, the session key request being used to request a session key, the session key being used for communication between the mobile terminal and the server; a first obtaining module 902 is configured to obtain the session key from a first QKD node, the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server; a first sending module 903 is configured to send the session key to the mobile terminal; and a second sending module 904 is configured to send session key information to the server, the session key information including information related to the session key.
[0489] Optionally, the first acquisition module is further configured to:
[0490] Send a key request message to the first QKD node. The key request message is used to request a key between the first QKD node and a second QKD node of the quantum key distribution network. The second QKD node is a node to which the server is connected.
[0491] Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata;
[0492] The key between the first QKD node and the second QKD node is used as the session key.
[0493] Optionally, the session key request includes:
[0494] The identifier of the mobile terminal;
[0495] The identifier of the server;
[0496] First random number;
[0497] The identifier of the authentication encryption key used by the mobile terminal;
[0498] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0499] The device further includes:
[0500] The second acquisition module is used to acquire the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal;
[0501] The first authentication module is used to verify the first message verification code using the authentication encryption key.
[0502] Optionally, the first sending module is further configured to send a session key request response message to the mobile terminal, the session key request response message including:
[0503] The identifier of the mobile terminal;
[0504] The identifier of the key distribution center;
[0505] First random number;
[0506] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0507] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0508] Optionally, the session key information includes:
[0509] The identifier of the mobile terminal;
[0510] The identifier of the server;
[0511] First random number;
[0512] The identifier of the session key.
[0513] Optionally, the device may further include:
[0514] The first processing module is used to delete the session key.
[0515] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0516] See Figure 10 , Figure 10 This is a structural diagram of the key transmission device provided in an embodiment of this application, applied to a server. For example... Figure 10 As shown, the key transmission device includes:
[0517] The first receiving module 1001 is used to receive session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated by negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server. The second receiving module 1002 is used to receive the session key sent by the second QKD node.
[0518] Optionally, the session key information includes:
[0519] The identifier of the mobile terminal;
[0520] The identifier of the server;
[0521] First random number;
[0522] The identifier of the session key.
[0523] Optionally, the device may further include:
[0524] The first processing module is used to establish communication with the mobile terminal based on the session key.
[0525] Optionally, the first processing module includes:
[0526] The first receiving submodule is used to receive the session request sent by the mobile terminal;
[0527] The first sending submodule is used to send a session request response message to the mobile terminal;
[0528] The session request includes:
[0529] The identifier of the mobile terminal;
[0530] The identifier of the server;
[0531] First random number;
[0532] Second random number;
[0533] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0534] The session request response message includes:
[0535] The identifier of the mobile terminal;
[0536] The identifier of the server;
[0537] Second random number;
[0538] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0539] Optionally, the first transmitting submodule is further configured to:
[0540] The session key is used to verify the third message verification code;
[0541] If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
[0542] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0543] See Figure 11 , Figure 11 This is a structural diagram of the key transmission device provided in an embodiment of this application, applied to a mobile terminal. For example... Figure 11 As shown, the key transmission device includes: a processor 1101 and a transceiver 1102;
[0544] The processor 1101 is configured to send a session key request to a key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server.
[0545] Optionally, the session key request includes:
[0546] The identifier of the mobile terminal;
[0547] The identifier of the server;
[0548] First random number;
[0549] The identifier of the authentication encryption key used by the mobile terminal;
[0550] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0551] Optionally, the processor 1101 is further configured to:
[0552] Receive a session key request response message sent by the key distribution center, the session key request response message including:
[0553] The identifier of the mobile terminal;
[0554] The identifier of the key distribution center;
[0555] First random number;
[0556] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0557] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0558] Optionally, the processor 1101 is further configured to:
[0559] Compare the first random number in the session key request with the first random number in the session key request response message;
[0560] If the first random number in the session key request is the same as the first random number in the session key request response message, the session key request response message is authenticated.
[0561] Optionally, the processor is also used in one or more of the following steps:
[0562] Obtain the authentication encryption key from the key update terminal;
[0563] Delete the authentication encryption key.
[0564] Optionally, the processor 1101 is further configured to:
[0565] Communication with the server is established based on the session key.
[0566] Optionally, the processor 1101 is further configured to:
[0567] Send a session request to the server;
[0568] Receive the session request response message sent by the server;
[0569] The session request includes:
[0570] The identifier of the mobile terminal;
[0571] The identifier of the server;
[0572] First random number;
[0573] Second random number;
[0574] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0575] The session request response message includes:
[0576] The identifier of the mobile terminal;
[0577] The identifier of the server;
[0578] Second random number;
[0579] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0580] Optionally, the processor 1101 is further configured to:
[0581] Compare the second random number in the session request with the second random number in the session request response message;
[0582] If the second random number in the session request is the same as the second random number in the session request response message, the session request response message is authenticated.
[0583] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0584] See Figure 12 , Figure 12 This is a structural diagram of the key transmission device provided in an embodiment of this application, which is applied in a key distribution center. Figure 12 As shown, the key transmission device includes: a processor 1201 and a transceiver 1202;
[0585] The processor 1201 is configured to receive a session key request sent by a mobile terminal, the session key request being used to request a session key, the session key being used for communication between the mobile terminal and the server; obtain the session key from a first QKD node, the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key.
[0586] Optionally, the processor 1201 is further configured to:
[0587] Send a key request message to the first QKD node. The key request message is used to request a key between the first QKD node and a second QKD node of the quantum key distribution network. The second QKD node is a node to which the server is connected.
[0588] Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata;
[0589] The key between the first QKD node and the second QKD node is used as the session key.
[0590] Optionally, the session key request includes:
[0591] The identifier of the mobile terminal;
[0592] The identifier of the server;
[0593] First random number;
[0594] The identifier of the authentication encryption key used by the mobile terminal;
[0595] The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
[0596] The processor 1201 is also used for:
[0597] Obtain the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal;
[0598] The authentication encryption key is used to verify the first message verification code.
[0599] Optionally, the processor is further configured to: send a session key request response message to the mobile terminal, the session key request response message including:
[0600] The identifier of the mobile terminal;
[0601] The identifier of the key distribution center;
[0602] First random number;
[0603] The encrypted information is obtained by encrypting the session key using the authentication encryption key;
[0604] The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
[0605] Optionally, the session key information includes:
[0606] The identifier of the mobile terminal;
[0607] The identifier of the server;
[0608] First random number;
[0609] The identifier of the session key.
[0610] Optionally, the processor is further configured to:
[0611] Delete the session key.
[0612] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0613] See Figure 13 , Figure 13 This is a structural diagram of the key transmission device provided in an embodiment of this application, applied to a server. For example... Figure 13 As shown, the key transmission device includes: a processor 1301 and a transceiver 1302;
[0614] The processor 1301 is configured to receive session key information sent by the key distribution center, the session key information including information related to the session key, the session key being used for communication between the mobile terminal and the server, and the session key being generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server; and to receive the session key sent by the second QKD node.
[0615] Optionally, the session key information includes:
[0616] The identifier of the mobile terminal;
[0617] The identifier of the server;
[0618] First random number;
[0619] The identifier of the session key.
[0620] Optionally, the processor is further configured to:
[0621] Communication with the mobile terminal is established based on the session key.
[0622] Optionally, the processor 1301 is further configured to:
[0623] Receive a session request sent by the mobile terminal;
[0624] Send a session request response message to the mobile terminal;
[0625] The session request includes:
[0626] The identifier of the mobile terminal;
[0627] The identifier of the server;
[0628] First random number;
[0629] Second random number;
[0630] The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number;
[0631] The session request response message includes:
[0632] The identifier of the mobile terminal;
[0633] The identifier of the server;
[0634] Second random number;
[0635] The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
[0636] Optionally, the processor 1301 is further configured to:
[0637] The session key is used to verify the third message verification code;
[0638] If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
[0639] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0640] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0641] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0642] This application provides a communication device, including: a memory, a processor, and a program stored in the memory and executable on the processor; the processor is configured to read the program in the memory to implement the steps in the key transmission method as described above.
[0643] This application also provides a readable storage medium storing a program. When executed by a processor, this program implements the various processes of the above-described key transmission method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here. The readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0644] This application also provides a computer program product, including computer instructions. When executed by a processor, the computer instructions implement the various processes of the above-described key transmission method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0645] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0646] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0647] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A key transmission method, characterized in that, Applied to mobile terminals, including: Send a session key request to the key distribution center. The session key request is used to request a session key, which is used by the mobile terminal to communicate with the server. The session key is received from the key distribution center. The session key is obtained by the key distribution center from the first quantum key distribution (QKD) node connected to the key distribution center, and the session key is generated by negotiation between the first QKD node and the second QKD node connected to the server.
2. The method according to claim 1, characterized in that, The session key request includes: The identifier of the mobile terminal; The identifier of the server; First random number; The identifier of the authentication encryption key used by the mobile terminal; The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal.
3. The method according to claim 2, characterized in that, Receiving the session key sent by the key distribution center includes: Receive a session key request response message sent by the key distribution center, the session key request response message including: The identifier of the mobile terminal; The identifier of the key distribution center; First random number; The encrypted information is obtained by encrypting the session key using the authentication encryption key; The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
4. The method according to claim 3, characterized in that, The method further includes: Compare the first random number in the session key request with the first random number in the session key request response message; If the first random number in the session key request is the same as the first random number in the session key request response message, the session key request response message is authenticated.
5. The method according to any one of claims 2-4, characterized in that, The method further includes one or more of the following steps: Obtain the authentication encryption key from the key update terminal; Delete the authentication encryption key.
6. The method according to claim 1, characterized in that, The method further includes: Communication with the server is established based on the session key.
7. The method according to claim 6, characterized in that, The establishment of communication with the server based on the session key includes: Send a session request to the server; Receive the session request response message sent by the server; The session request includes: The identifier of the mobile terminal; The identifier of the server; First random number; Second random number; The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number; The session request response message includes: The identifier of the mobile terminal; The identifier of the server; Second random number; The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
8. The method according to claim 7, characterized in that, The method further includes: Compare the second random number in the session request with the second random number in the session request response message; If the second random number in the session request is the same as the second random number in the session request response message, the session request response message is authenticated.
9. A key transmission method, characterized in that, Applications in key distribution centers include: Receive a session key request sent by a mobile terminal, wherein the session key request is used to request a session key, and the session key is used for communication between the mobile terminal and the server; The session key is obtained from the first QKD node, which is generated through negotiation between the first QKD node and the second QKD node connected to the server. Send the session key to the mobile terminal; Send session key information to the server, the session key information including information related to the session key.
10. The method according to claim 9, characterized in that, Obtaining the session key from the first QKD node includes: Receive key information sent by the first QKD node, the key information including: the key between the first QKD node and the second QKD node, and key metadata; The key between the first QKD node and the second QKD node is used as the session key.
11. The method according to claim 10, characterized in that, The session key request includes: The identifier of the mobile terminal; The identifier of the server; First random number; The identifier of the authentication encryption key used by the mobile terminal; The first message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the server's identifier, the first random number, and the identifier of the authentication encryption key used by the mobile terminal. The method further includes: Obtain the authentication encryption key based on the identifier of the authentication encryption key used by the mobile terminal; The authentication encryption key is used to verify the first message verification code.
12. The method according to claim 11, characterized in that, Sending the session key to the mobile terminal includes: Send a session key request response message to the mobile terminal, the session key request response message including: The identifier of the mobile terminal; The identifier of the key distribution center; First random number; The encrypted information is obtained by encrypting the session key using the authentication encryption key; The second message verification code is obtained by using the authentication encryption key to protect the integrity of the mobile terminal's identifier, the key distribution center's identifier, the first random number, and the encrypted information.
13. The method according to claim 11, characterized in that, The session key information includes: The identifier of the mobile terminal; The identifier of the server; First random number; The identifier of the session key.
14. The method according to claim 9, characterized in that, The method further includes: Delete the session key.
15. A key transmission method, characterized in that, Applied to servers, including: The system receives session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server. Receive the session key sent by the second QKD node.
16. The method according to claim 15, characterized in that, The session key information includes: The identifier of the mobile terminal; The identifier of the server; First random number; The identifier of the session key.
17. The method according to claim 15, characterized in that, The method further includes: Communication with the mobile terminal is established based on the session key.
18. The method according to claim 17, characterized in that, The step of establishing communication with the mobile terminal based on the session key includes: Receive a session request sent by the mobile terminal; Send a session request response message to the mobile terminal; The session request includes: The identifier of the mobile terminal; The identifier of the server; First random number; Second random number; The third message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, the first random number, and the second random number; The session request response message includes: The identifier of the mobile terminal; The identifier of the server; Second random number; The fourth message verification code is obtained by using the session key to perform integrity protection on the identifier of the mobile terminal, the identifier of the server, and the second random number.
19. The method according to claim 18, characterized in that, Sending a session request response message to the mobile terminal includes: The session key is used to verify the third message verification code; If the verification of the third message verification code is successful, a session request response message is sent to the mobile terminal.
20. A key transmission device, characterized in that, Applied to mobile terminals, including: The first sending module is used to send a session key request to the key distribution center. The session key request is used to request a session key, which is used by the mobile terminal to communicate with the server. The first receiving module is used to receive the session key sent by the key distribution center. The session key is obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key is generated by negotiation between the first QKD node and a second QKD node connected to the server.
21. A key transmission device, characterized in that, Applications in key distribution centers include: The first receiving module is used to receive a session key request sent by a mobile terminal. The session key request is used to request a session key, which is used for communication between the mobile terminal and the server. The first acquisition module is used to acquire the session key from the first QKD node, the session key being generated through negotiation between the first QKD node and the second QKD node connected to the server; The first sending module is used to send the session key to the mobile terminal; The second sending module is used to send session key information to the server, the session key information including information related to the session key.
22. A key transmission device, characterized in that, Applied to servers, including: The first receiving module is used to receive session key information sent by the key distribution center. The session key information includes information related to the session key. The session key is used for communication between the mobile terminal and the server. The session key is generated by negotiation between the first QKD node connected to the key distribution center and the second QKD node connected to the server. The second receiving module is used to receive the session key sent by the second QKD node.
23. A key transmission device, characterized in that, Applied to mobile terminals, including: processors and transceivers; The processor is configured to send a session key request to a key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server.
24. A key transmission device, characterized in that, Applied to key distribution centers, including: processors and transceivers; The processor is configured to receive a session key request sent by a mobile terminal, the session key request being used to request a session key, the session key being used for communication between the mobile terminal and the server; obtain the session key from a first QKD node, the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key.
25. A key transmission device, characterized in that, Used in servers, including: processors and transceivers; The processor is configured to receive session key information sent by the key distribution center, the session key information including information related to the session key, the session key being used for communication between the mobile terminal and the server, and the session key being generated through negotiation between a first QKD node connected to the key distribution center and a second QKD node connected to the server; and to receive the session key sent by the second QKD node.
26. A key transmission system, characterized in that, include: Mobile terminal, server, key distribution center; The mobile terminal is configured to send a session key request to the key distribution center, the session key request being used to request a session key, the session key being used by the mobile terminal to communicate with the server; and to receive the session key sent by the key distribution center, the session key being obtained by the key distribution center from a first QKD node connected to the key distribution center, and the session key being generated through negotiation between the first QKD node and a second QKD node connected to the server. The key distribution center is configured to receive a session key request sent by a mobile terminal; obtain the session key from a first QKD node; send the session key to the mobile terminal; and send session key information to the server, the session key information including information related to the session key. The server is used to receive session key information sent by the key distribution center, and the session key information includes information related to the session key.
27. A communication device, comprising: A memory, a processor, and a program stored in the memory and executable on the processor; characterized in that the processor is configured to read the program from the memory to implement the steps of the key transfer method as described in any one of claims 1 to 19.
28. A computer-readable storage medium for storing a program, characterized in that, When the program is executed by a processor, it implements the steps of the key transmission method as described in any one of claims 1 to 19.
29. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps in the key transfer method as described in any one of claims 1 to 19.