A quantum time-stamped cloud privacy data access control method and system
By introducing a quantum key pool and time-bound pseudo-identifiers into the cloud-edge-mobile network integrated environment, quantum time-stamped access tokens are generated, solving the problems of lack of session security context and insufficient concealment of access tokens in existing technologies, and realizing unified session security control and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 中邮建技术有限公司
- Filing Date
- 2026-02-10
- Publication Date
- 2026-06-09
AI Technical Summary
In the cloud-edge-mobile network integrated environment, existing technologies lack a unified session security context for quantum-secure time transfer systems and access control systems, making them vulnerable to latency manipulation and time inconsistency attacks. Furthermore, access tokens lack covert protection and policy field confidentiality protection.
By introducing a time-slot-organized quantum key pool, time-bound pseudo-identifiers, quantum deformable access tokens, and a quantum time-stamped auditing mechanism, a unified session security framework is constructed. Combined with quantum key distribution and homomorphic encryption, quantum time-stamped access tokens are generated to achieve device identification privacy protection and policy field confidentiality protection.
In the integrated cloud-edge-mobile network environment, unified session security control is achieved, resisting latency manipulation and time attacks, protecting the concealment of access tokens, providing a trusted chain of evidence and privacy protection, and supporting multi-stage collaborative control.
Smart Images

Figure CN122179778A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security, quantum communication and cloud computing technologies, specifically to a quantum time-stamped cloud privacy data access control method and system. Background Technology
[0002] With the rapid development of cloud computing, edge computing, and 5G / 6G mobile communication technologies, a large number of terminal devices are wirelessly accessing operator networks, frequently accessing various services and exchanging business data between edge computing nodes and cloud data centers. The cloud environment stores personal privacy data and critical industry data, while mobile communication networks carry a large amount of location, behavior, and device identification information, significantly increasing overall security risks.
[0003] In existing technologies, traditional cryptographic systems primarily rely on mathematical problems such as large number factorization and discrete logarithms to construct symmetric or asymmetric cryptographic algorithms. While these algorithms provide sufficient security strength under classical computing models, their long-term confidentiality will be significantly weakened with the advent of scalable quantum computing devices. Therefore, new technologies such as quantum key distribution, quantum secure time transfer, and post-quantum cryptography are gradually being applied to practical systems to enhance link encryption and key negotiation security.
[0004] On the other hand, in mobile communication networks, terminal devices typically contain long-term identifiers such as the International Mobile Equipment Identity (IMEI) and the Permanent Device Identifier (PEI). To prevent counterfeit terminal access and number theft, operators often rely on mechanisms such as blacklists and graylists to manage devices. Traditional solutions usually require operators to directly obtain and process plaintext device identifiers, which poses a significant risk of privacy breaches and easily creates long-term, traceable device behavior patterns, making it difficult to meet increasingly stringent privacy protection compliance requirements.
[0005] Existing research has proposed private set membership protocols based on homomorphic encryption, which can determine whether an element belongs to a blacklist set without exposing plaintext identifiers, thereby alleviating operators' reliance on plaintext device identifiers to some extent. However, these solutions are mostly limited to the access network side, and are largely independent of cloud access control, time services, and quantum key distribution systems. They lack a unified session security context and are difficult to cover the entire path of terminal behavior from the access network to edge computing and then to the cloud data center.
[0006] Existing quantum-secure time transfer systems primarily serve the fields of high-precision clock synchronization and metrology, achieving multi-node time synchronization through entangled photons or time-coded photons, with a focus on time synchronization accuracy and stability. In business systems, time fields are typically still generated by upper-layer application servers or ordinary time synchronization protocols. Quantum time systems have weak coupling with access control and auditing subsystems, lacking a quantum-level time security anchor for session-level security, making it difficult to promptly detect and suppress security risks arising from attacks such as latency manipulation and cross-datacenter time inconsistencies.
[0007] Furthermore, existing access tokens typically only contain explicit fields, and the token content can be fully recovered after obtaining the relevant decryption key. For scenarios requiring both public access information and sensitive policy information to be carried in the same token, the common practice is to place sensitive fields separately in a restricted database or dedicated channel, which makes it difficult to balance system compatibility, deployment costs, and policy concealment. When facing threats such as forced key surrender or passive censorship, traditional access tokens usually lack the ability to present different information views at different authorization levels.
[0008] Furthermore, some existing quantum-resistant access tokens or identity token schemes attempt to strengthen existing open identity authentication and authorization protocols by combining quantum key distribution or post-quantum cryptography algorithms, mainly focusing on improving the token's resistance to quantum attacks. However, these schemes mostly focus on modifying key negotiation and signature algorithms, failing to organically integrate quantum-secure time services, time-slot-organized quantum key pools, and device identifier privacy verification, making it difficult to form a unified time stamp and session-level security context in a cloud-edge-mobile network integrated environment.
[0009] Therefore, it is necessary to propose a new technical solution that organically integrates quantum key distribution, privacy protection device identification verification, access token management, and auditing and forensics under a unified quantum time stamp, and constructs a cloud privacy data access control system suitable for the cloud-edge-mobile network integrated environment. Summary of the Invention
[0010] This invention proposes a quantum time-stamped cloud privacy data access control method and system. By introducing a quantum key pool organized by time slots, time-bound pseudo-identifiers, quantum deformable access tokens, and a quantum time-stamped auditing mechanism, a unified session security framework is formed between cloud data centers, edge computing nodes, and mobile communication networks. The aim is to establish a unified quantum time security anchor, balance device identification privacy protection with list management, and protect the confidentiality of hidden policy fields even in the face of extreme threats such as forced key surrender, thereby constructing a more complete and reliable chain of evidence. At the same time, unnecessary privacy exposure is avoided during the auditing process.
[0011] To solve the above-mentioned technical problems, the present invention provides the following technical solution: A quantum time-stamped cloud privacy data access control method, comprising the following steps: Establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes, and mobile communication network operation nodes; perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers, quantum key blocks, and quantum key indexes to form a quantum key pool organized by time slots; On the terminal side, a time-bound pseudo-identifier is generated based on the combination of permanent device identifier, time slot marker, and quantum key block, and homomorphic encryption is performed to obtain pseudo-identifier ciphertext; on the operation node side, a private set membership protocol is executed on the pseudo-identifier ciphertext to obtain set membership result; When the terminal identity authentication is successful and the set membership result meets the preset access policy, the access control node generates a quantum time-stamped access token based on the time slot marker, quantum key index, set membership result and predefined cloud access policy, including public access field, hidden policy field, time slot marker, quantum key index and integrity verification information; Based on quantum time-stamped access tokens, pre-encryption is performed on access control nodes to obtain pre-encrypted hidden fields; based on quantum deformation encryption schemes, a single access token ciphertext is generated. When transmitting business data between terminal devices, edge computing nodes and cloud data centers, access requests are authorized and controlled according to the single access token ciphertext, and a data encryption method is selected. During the process of processing access requests and forwarding data, each node records the access token identifier, time slot marker and key operation results in the security log. Upon detecting a security incident, being hit on a greylist, or receiving audit and enforcement instructions, the audit entity audits and collects evidence on the target session based on quantum time stamps, generating a chain of evidence with quantum time stamps.
[0012] Preferably, the process of performing entangled photon time transfer and time synchronization, dividing the continuous time axis into multiple time slots, running a quantum key distribution protocol to generate quantum key blocks within each time slot, and establishing a mapping relationship between time slot markers, quantum key blocks, and quantum key indices to form a quantum key pool organized by time slots includes: Quantum-secure time transfer is achieved by using quantum signals. Single-photon detection events are time-stamped at each node to form a time-stamped sequence. Each node includes cloud data centers, edge computing nodes, and mobile communication network operation nodes. Each node receives quantum signals on the quantum channel and generates a time stamp record for each detection event. The time stamp record includes at least the node identifier, the running cycle identifier, the detection event sequence number, the local arrival time, the detection channel or detector identifier, and the validity flag. Each node preprocesses the timestamp records, removes invalid events, and aggregates them according to time windows to obtain a local timestamp sequence; Each node sends a time stamp reporting message through a classic channel. The time stamp reporting message includes at least a node identifier, a running cycle identifier, a start and end time window, a number of records, a time stamp sequence, a digest value, and integrity verification information. The integrity verification information includes a message authentication code (MAC) and / or a digital signature to ensure the integrity and non-repudiation of the time stamp data during the exchange process. A synchronization algorithm is used to estimate and compensate for time offset and clock drift between nodes to obtain a unified time reference with a predetermined accuracy; the continuous running time is divided into multiple time slots, and each time slot corresponds to a unique time slot marker. Within a preset matching window, time-stamped records of different nodes are paired to obtain a set of paired events; The initial value of the time offset between nodes is calculated based on the set of paired events, and the clock drift parameter is obtained by regression estimation or equivalent estimation. The initial value of the time offset between nodes and the clock drift parameter are filtered and smoothed to obtain the compensation parameter that is updated over time. Each node converts its local time into a unified time reference according to the formula: unified time = local time - compensation parameter. When the synchronization error meets the preset threshold, the continuous time axis is divided into multiple time slots, and each time slot corresponds to a time slot mark. A quantum key distribution protocol is run within each time slot to generate quantum key blocks that correspond one-to-one with the time slot markers, and a quantum key index is assigned to each quantum key block to form a quantum key pool organized by time slots. The quantum key blocks corresponding to each time slot are divided into control plane quantum key sub-blocks and service plane quantum key sub-blocks. The control plane quantum key sub-blocks are used for time-binding pseudo-identifier generation, access token construction, and pre-encryption of hidden policy fields. The service plane quantum key blocks are used for one-time encryption of control signaling, access control related data, and some service data. Constrain the rate of quantum key usage to not exceed the rate of quantum key generation, and configure quantum key usage strategies according to different business types.
[0013] Preferably, the step of generating a time-bound pseudo-identifier on the terminal side based on the combination of a permanent device identifier, a time slot marker, and a quantum key block, and then performing homomorphic encryption encoding to obtain pseudo-identifier ciphertext; and executing a private set membership protocol on the pseudo-identifier ciphertext on the operation node side to obtain the set membership result includes: When a terminal device initiates network access or cloud resource access, it obtains the permanent device identifier, time slot marker and quantum key block of the current terminal device and inputs them into a predetermined pseudo-random function to generate a time-bound pseudo-identifier TB_PEI. The pseudo-random function F is a combination of key-based pseudo-random functions or cryptographic hash functions, TB_PEI=F(PEI,KQKD(Tslot),Tslot), where PEI represents the permanent device identifier, KQKD(Tslot) represents the quantum key block, and Tslot represents the time slot marker; The time-binding pseudo-identifier satisfies the following properties: given a time-binding pseudo-identifier, it is difficult to recover the permanent device identifier within feasible computational complexity; the time-binding pseudo-identifiers generated for different time slot markers are statistically independent of each other; when the quantum key block is updated or invalidated, the historical time-binding pseudo-identifier can no longer be verified. The terminal device performs homomorphic encryption encoding on the time-bound pseudo-identifier based on the homomorphic encryption public key to obtain the pseudo-identifier ciphertext; The mobile communication network operator performs a private set membership protocol on the pseudo-identifier ciphertext based on a pre-built blacklist set and graylist set. Within the homomorphically encrypted ciphertext domain, it determines whether the time-bound pseudo-identifier belongs to the blacklist set or the graylist set, and obtains the set membership result without restoring the plaintext value of the permanent device identifier or the time-bound pseudo-identifier. After obtaining an internal determination result by executing a private set membership protocol, the mobile communication network operator node generates a one-time random number and uses the operator's confidential key to mask the internal determination result to obtain the return value MaskedRes to the terminal. The masking process includes at least encrypted encapsulation or pseudo-random mapping. The operation node generates risk control context internally based on internal judgment results for access decisions, and only returns MaskedRes to the terminal. The length of the returned message and the error code / response type are consistent to avoid the terminal inferring the blacklist or graylist hit status based on the feedback.
[0014] Preferably, the quantum time-stamped access token includes a public access field, which includes at least one or more of the following: session identifier, accessible resource range, quality of service level, and session validity period. The quantum time-stamped access token includes a hidden policy field, which includes at least one or more of the following information: risk level associated with the time-bound pseudo-identifier, blacklist or graylist status, audit policy identifier, and enforcement policy identifier; The quantum time-stamped access token also includes a time slot stamp, a quantum key index, and integrity verification information; The quantum time-stamped access token is universally applicable in the cloud-edge-mobile network integrated environment. On the mobile communication access network side, the access token is used to control terminal device access, network slice selection, and edge service authorization. On the cloud data center side, the access token is used to control tenant resource access, data download, management interface calls, and cross-regional access authorization. The lifecycle of the access token is jointly limited by the time slot length and the cloud access policy. When the time slot expires or the access policy changes, the access token automatically becomes invalid and triggers a new round of time synchronization and key negotiation process.
[0015] Preferably, the access control node is pre-encrypted based on the quantum time-stamped access token to obtain a pre-encrypted hidden field; the single access token ciphertext is generated based on the quantum warp encryption scheme, including: The hidden policy field is pre-encrypted using the control plane quantum key sub-block corresponding to the current time slot mark to obtain the pre-encrypted hidden field. Based on the quantum deformation encryption scheme, the public access field, the pre-encrypted hidden field, and the metadata of the time slot marker and the quantum key index are all encapsulated into a single access token ciphertext. The quantum deformation encryption scheme includes at least the following: When decrypting a single access token ciphertext using a regular decryption key, only the public access field and the encrypted encapsulated data related to the hidden field are output, and the plaintext of the hiding policy field is not output. Under audit or enforcement authorization, when the auditing entity possesses the modified key and is authorized to obtain the quantum key block corresponding to the time slot or its derived control key, it performs secondary desealing on the encrypted data to restore the hidden policy field.
[0016] Preferably, when transmitting business data between terminal devices, edge computing nodes, and cloud data centers, the specific implementation process of authorizing and controlling access requests based on the single access token ciphertext, selecting a data encryption method, and recording the access token identifier, time slot marker, and key operation results in the security log during the processing of access requests and data forwarding includes: Each node authorizes access requests based on the recoverable public access field in the single access token ciphertext, and selects the appropriate data encryption method based on the security level in the public access field. For control signaling, access control related data and some highly sensitive metadata, use the business plane quantum key sub-block corresponding to the current time slot to encrypt it in a one-time password book manner; For high-volume business data, use symmetric encryption or homomorphic encryption based on post-quantum cryptography algorithms for protection; During the process of handling access requests and forwarding data, each node records the access token identifier, time slot marker, and key operation results in the security log.
[0017] Preferably, the specific implementation process of the audit entity auditing and collecting evidence on the target session based on quantum time stamps and generating an evidence chain with quantum time stamps when a security event, graylist hit, or audit and enforcement instruction is detected includes: Upon detecting a security incident, being hit on a graylist, or receiving an audit and enforcement directive, the audit entity restores a unified timeline within the target time period based on the quantum secure time service and locates the relevant time slot markers. After obtaining authorization, the audit entity obtains the ciphertext of the access token corresponding to the target session and related security logs, and uses the quantum key block corresponding to the time slot and the transformed key to decrypt the ciphertext of the access token and restore the hidden policy field. The audit entity combines the risk level, blacklist or graylist status, audit policy identifier, enforcement policy identifier, and time-series operation records in the hidden policy field to perform retrospective analysis on suspicious session behavior and generate a chain of evidence with quantum time stamps.
[0018] Preferably, the mobile communication network operator does not access the plaintext of the permanent device identifier during the entire time-bound pseudo-identifier generation and privacy verification process, and does not store the plaintext value of the time-bound pseudo-identifier. The behavior-related information is only decrypted by an independent audit or law enforcement entity in a controlled environment under audit or law enforcement authorization. For sessions whose duration exceeds the length of a single time slot, it supports rolling updates of the quantum time stamp access token and its associated time slot stamp and quantum key index across multiple consecutive time slots, and seamless switching between nodes in the cloud-edge-mobile network, balancing the needs of long session services with key security.
[0019] Preferably, during the generation of quantum time slots and quantum key pools, cloud-edge-mobile network collaborative access control, and data encryption / decryption, the system continuously generates a set of monitoring indicators using a sliding statistical window, and triggers adaptive strategy adjustments based on preset thresholds; wherein the set of monitoring indicators includes at least: the quantum key generation rate r1(W) and usage rate r2(W) counted within the sliding statistical window W, and the key pressure coefficient ρ(W) = r1(W) / (α·r2(W)) is calculated, where α is the security margin coefficient; homomorphic encryption noise budget margin; link latency; node computational load; When any of the following triggering conditions are met: the key pressure coefficient is greater than or equal to the pressure coefficient threshold, the homomorphic encryption noise budget margin is less than or equal to the margin threshold, the link latency is greater than the latency threshold, or the node computing load is greater than or equal to the load threshold, a set of actions to dynamically adjust the quantum key usage ratio and access strategy will be executed. The set of actions includes at least one of the following: Key resource priority scheduling includes prioritizing control plane key derivation and consumption, and prioritizing the allocation of quantum key blocks for control plane key sub-blocks; The encryption method can be adaptively switched, including switching at least one type of high-traffic service from one-time key book encryption to low key consumption mode, including symmetric encryption combined with periodic key swapping and / or post-quantum secure key exchange, or using one-time key book encryption only for sensitive fields and conventional encryption for the remaining fields; Homomorphic computation order reduction and resource deload include reducing the circuit depth / comparison rounds of private set membership computation or adjusting homomorphic parameters when the noise budget margin is insufficient or the computational load is too high, and rate limiting, queuing or delaying low-priority requests to the next time slot. Session-level security measures include interrupting the session, revoking / freezing the relevant access token, and triggering a security alarm when the triggering conditions are met for a continuous period of time or reach a preset number of triggers.
[0020] A system for a cloud privacy data access control method using quantum time stamping, the system comprising: The time and key management module is used to establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes and mobile communication network operation nodes, perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers and quantum key blocks and quantum key indexes. The pseudo-identifier processing module is deployed on terminal devices and mobile communication network operation nodes. It is used to generate time-bound pseudo-identifiers by combining permanent device identifiers and time slot markers and quantum key blocks on the terminal side, and to calculate the private set membership relationship with blacklists and graylists on the operation node side based on homomorphic encryption. The access token generation module, deployed on edge computing nodes and cloud data centers, is used to construct quantum time-stamped access tokens based on time slot markers, quantum key indexes, privacy verification results, and access policies, and to complete the issuance, updating, revocation, and storage of access tokens. The encryption encapsulation module is used to perform quantum deformation encryption encapsulation on the public access field and hidden policy field in the quantum time-stamped access token, generate a single access token ciphertext, and manage the regular decryption key and the deformation key, so that different information views are presented under different authorization combinations; The access control module is used to transmit a single access token ciphertext between terminal devices, base stations, edge computing nodes and cloud data centers. It performs access control, network slice selection, cloud resource authorization and encryption / decryption of business data based on the quantum time-stamped access token, and records time slot markers and key operation logs. The auditing and evidence collection module is used to restore a unified timeline based on the quantum time service under audit or law enforcement authorization conditions, unblock hidden policy fields in the ciphertext of a single access token, and combine access logs to trace back terminal behavior and build a chain of evidence.
[0021] Compared with the prior art, the beneficial effects achieved by the present invention are: the present invention combines quantum secure time transfer and quantum key distribution, and organizes keys and access states with time slots as the core, enabling cloud data centers, edge nodes and operation core networks to operate under a unified quantum time reference, effectively resisting delay manipulation and time replay attacks, and providing a reliable time anchor for access control and auditing; By using time-bound pseudo-identifiers and a private set membership protocol based on homomorphic encryption, operators can perform blacklist and graylist verifications without accessing plaintext device identifiers, making policy decisions solely based on ciphertext calculation results. In most business scenarios, operators and ordinary business systems will not see the real identifiers. Only when explicitly authorized and specific conditions are triggered will an independent audit entity recover behavior-related information in a controlled environment, achieving a balance between privacy protection and security control. The quantum time-stamped access token proposed in this invention encapsulates the public access field and the hidden policy field into a single quantum-modified ciphertext, which is statistically indistinguishable from ordinary ciphertext. The system can present different information views at different authorization levels, and can still protect the confidentiality of the hidden policy field even in the face of extreme threats such as forced key surrender. This invention enables coordinated control of multiple aspects such as terminal access, edge services, and cloud resource access under a unified framework, allowing access tokens to be used in both mobile communication access networks and cloud environments, and achieving seamless integration of session context and security policies. This facilitates the implementation of unified security policies and log management in complex cloud-edge-mobile network converged architectures. This invention utilizes quantum time stamps and hidden policy fields in access tokens to reconstruct the behavioral trajectory of relevant sessions on a unified timeline during security incidents or compliance checks, enabling precise localization of attacks or abnormal access. Compared to traditional auditing methods that rely solely on distributed logs, this invention constructs a more complete and reliable chain of evidence while avoiding unnecessary privacy exposure during the auditing process. Attached Figure Description
[0022] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.
[0023] Fig. 1 This is a schematic diagram of the method flow in an embodiment of the present invention; Fig. 2 This is a schematic diagram of the system structure in an embodiment of the present invention. Detailed Implementation
[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0025] It should be noted that, in this invention, quantum-secure time transfer refers to the transmission of time information between quantum sites and cloud data centers, edge computing nodes, and / or mobile communication network operation nodes using quantum carriers such as entangled photon pairs or time-coded photons. This enables the receiving end to generate an arrival time stamp sequence that can be used for synchronization and consistency verification, and to complete time offset and drift estimation compensation with the cooperation of classical channels, thereby forming a unified time reference for multiple nodes.
[0026] A time-stamp sequence refers to a set / sequence of timestamps obtained by each node recording the received quantum signals (such as photon arrival events) based on its local clock. It is used by subsequent synchronization algorithms to estimate the time offset and clock drift between nodes.
[0027] A unified time reference refers to a consistent time base obtained by each node with a predetermined precision after exchanging partial timestamp data and performing a synchronization algorithm. It is used to drive time slot partitioning and key / session indexing.
[0028] A time slot is a discrete time interval divided into continuous time axes according to a preset slot length under a unified time reference. Time slots are used to organize key generation and session security context.
[0029] A time slot tag (Tslot) is a unique identifier for a specific time slot, used to bind and index quantum keys and access tokens generated / used within that time slot.
[0030] In a preferred implementation, Tslot can be a structured tag `{n, t0, Δt, epochID}`; or its summary `H(n‖t0‖Δt‖epochID)`, where `n` is the time slot number, `t0` is the reference start time, `Δt` is the time slot length, and `epochID` is the runtime cycle identifier (such as the generation number after restart / resynchronization / policy update).
[0031] Quantum key distribution (QKD) refers to a key generation protocol executed within each time slot in conjunction with a quantum channel and a classical channel, used to generate quantum key blocks that correspond one-to-one with time slot markers.
[0032] A quantum key block (KQKD(Tslot)) refers to a key bit string / key data block generated by QKD within a certain time slot and bound to the time slot marker Tslot, serving as the key source for session and access control within that time slot.
[0033] The quantum key index idxQKD (Quantum-key index) refers to the index number used to identify different quantum key blocks (or different key replenishment rounds / batches) within the same time slot, and is used to locate the corresponding KQKD (Tslot) and its derived subkeys in the system.
[0034] A quantum key pool refers to a set of keys organized by time slots and their mapping relationships, including at least an index structure of `{Tslot → KQKD(Tslot), idxQKD}`, used to support multiple nodes to consistently access keys within the same time slot.
[0035] A control-plane quantum key sub-block refers to a key portion that is divided / derived from a quantum key block KQKD(Tslot) corresponding to a certain time slot and is used for control and security management purposes, such as time-bound pseudo-identifier generation, access token construction, and pre-encryption of hidden policy fields.
[0036] The User-plane quantum key sub-block refers to the key portion derived from KQKD (Tslot) and dedicated to the protection of service data / signaling. It is used for, for example, to perform one-time codebook encryption on control signaling, access control related data, and some sensitive metadata.
[0037] In the quantum key usage rate r1 and generation rate r2, r1 refers to the rate at which the system consumes quantum keys per unit time; r2 refers to the rate at which the system can generate quantum keys per unit time. This invention constrains r1 ≤ r2 and allows for the configuration of quantum key usage strategies according to service type.
[0038] The Permanent Equipment Identifier (PEI) refers to a long-term stable identifier for a terminal device (which can correspond to concepts such as IMEI / PEI). It is used to participate in the generation of time-bound pseudo-identifiers on the terminal side, but is not exposed in plaintext during the privacy verification process.
[0039] The time-bound pseudo-identifier TB_PEI refers to the pseudo-identifier that changes with the time slot when a terminal initiates a network access or cloud data access request. It is generated by inputting the permanent device identifier PEI, the time slot marker Tslot, and the corresponding quantum key block KQKD(Tslot) into a predetermined pseudo-random function `F`. The form can be: `TB_PEI = F(PEI, KQKD(Tslot), Tslot)`.
[0040] In the context of homomorphic encryption and pseudo-identifier ciphertext C_TB, homomorphic encryption refers to an encryption scheme that supports performing specific operations within the ciphertext field; pseudo-identifier ciphertext `C_TB` refers to ciphertext obtained by encoding the time-bound pseudo-identifier TB_PEI using a homomorphic encryption public key, which is used for subsequent verification of the ciphertext field set.
[0041] The Private Set Membership Protocol (PSP) refers to the protocol / computation process that determines whether a TB_PEI belongs to a blacklist or graylist set within the homomorphically encrypted ciphertext field without recovering the plaintext PEI or TB_PEI.
[0042] A quantum time-tagged access token is a token structure generated by an access control node when terminal authentication is successful and the set verification meets the policy. This token is bound to a time slot tag Tslot and idxQKD and is used for cloud-edge-mobile network collaborative access control.
[0043] In the public access field Ppub and the hidden policy field Phid, `Ppub` refers to the explicit field that can be used for regular access control (such as session identifier, resource scope, quality of service level, validity period, etc.); `Phid` refers to the hidden field used for risk control, auditing, law enforcement, etc. (such as risk level, list status, audit policy identifier, etc.), and its design goal is to present different information views under different authorization levels.
[0044] The pre-encrypted hidden field refers to the result of the access control node pre-encrypting the hidden policy field Phid using the control plane quantum key sub-block associated with the current time slot, so that Phid remains in a secret state during token generation, distribution and circulation.
[0045] Quantum deformable encryption (QDE) is a layered visibility encryption encapsulation mechanism for access tokens. It encapsulates the public access field `Ppub` and the pre-encrypted hidden field into a single token ciphertext. This means that entities with only regular decryption capabilities can only recover the Ppub; while entities possessing the deformable key (see next item), meeting the authorization conditions, and being associated with the quantum key material corresponding to the time slot can further recover the hidden policy field Phid. This mechanism is used in cloud-edge-mobile network collaborative scenarios to achieve "the same token, different permissions seeing different information views."
[0046] The Deformation key refers to the second-level decapsulation key material / key credential that accompanies quantum deformation encryption. It can be held by the auditing entity, the regulatory entity, or the controlled KMS / HSM / TEE environment. Together with the time slot key material and authorization conditions, it constitutes the necessary conditions for "uncapsulating the hidden field", thereby achieving minimal exposure of the hidden field and on-demand traceability.
[0047] The noise budget for homomorphic encryption refers to the upper limit of noise / error that homomorphic encryption can tolerate during ciphertext computation. The system can monitor this along with quantum key rate, link latency, computational load, etc. When the indicators are abnormal, the access policy and key usage ratio will be dynamically adjusted and an alarm will be triggered.
[0048] Rolling token update refers to the system updating the access token and its associated Tslot and idxQKD across multiple consecutive time slots when the session duration exceeds the length of a single time slot, and seamlessly switching between cloud-edge-mobile network nodes to balance the availability of long sessions and key security.
[0049] `t0` represents the reference start time; `Δt` represents the time slot length; `δ` represents the protection interval; `tref` represents the reference time used by the node to calculate the time slot; `n` represents the time slot number; and `epochID` represents the operating cycle identifier.
[0050] `KQKD(Tslot)` represents the quantum key block corresponding to the time slot; `idxQKD` represents the quantum key index.
[0051] `r1 / r2` represents the quantum key usage / generation rate, satisfying `r1 ≤ r2`.
[0052] Please see Figs. 1-2 In this first embodiment: a cloud privacy data access control method based on quantum time stamping is provided, the method comprising: Step 1: Establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes, and mobile communication network operation nodes; perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers, quantum key blocks, and quantum key indexes to form a quantum key pool organized by time slots; Quantum and classical channels are established between quantum stations and cloud data centers, edge computing nodes, and mobile communication network operation nodes. The quantum station sends quantum signals to each node, and each node timestamps the received quantum signals based on its local clock, obtaining a local time-stamped sequence. Each node exchanges partial time-stamped data through the classical channel, and a synchronization algorithm is used to estimate and compensate for time offsets and clock drift between nodes, obtaining a unified time reference with predetermined accuracy. The nodes include cloud data centers, edge computing nodes, and mobile communication network operation nodes.
[0053] Under a unified time reference, the continuous running time (i.e., the continuous time axis) is divided into a series of discrete time intervals (time slots), and a unique time slot marker is generated for each time slot to bind and index the session keys generated within that time slot. Specifically, the system presets the reference start time t0, the time slot length Δt, and sets a protection interval δ (0 < δ < Δt / 2), where δ is used to absorb boundary uncertainties caused by timing synchronization errors, crystal oscillator drift, and link jitter. The quantum station and the target node obtain the reference time tref through a timing synchronization mechanism, which can be obtained based on IEEE 1588 PTP, GNSS, a timing server, or an equivalent method, and calculate the time slot number n using a consistent time slot identification rule: n = ⌊(tref − t0) / Δt. In implementation, to prevent reference times (tref) near the boundary from being assigned to adjacent time slots by different nodes, the system can introduce an "effective time window" for determination: the current time slot is confirmed as n only when the reference time (tref) falls within the interval [t0+n·Δt+δ, t0+(n+1)·Δt−δ]; when the reference time (tref) falls within the boundary buffer (t0+n·Δt−δ, t0+n·Δt+δ) or (t0+(n+1)·Δt−δ, t0+(n+1)·Δt+δ), the node enters a "boundary pending state," and n is determined or backed to n−1 after time slot consistency confirmation through the classical channel. The time slot label Tslot can be a structured label {n, t0, Δt, epochID}, where the runtime identifier epochID is used to distinguish different runtimes (e.g., incremented each time the system restarts, time synchronization is resynchronized, or the policy is updated); or its summary value H(n‖t0‖Δt‖epochID) can be used as a compact label. To ensure that the quantum station and the target node calculate a consistent time slot label Tslot for the same time slot, they exchange "time slot synchronization and acknowledgment messages" on a classical channel. For example, message fields may include: epochID (running cycle identifier), candidate slot number n, transmission time ts, reception time tr, digest value h=H(n‖t0‖Δt‖epochID), and message authentication code MAC (Kctrl_prev,·) for integrity verification (where Kctrl_prev is the control key or pre-shared management key of the previous time slot). After the target node verifies the information, it sends back an acknowledgment ACK. When an inconsistency in epochID, h, or MAC verification is detected, a resynchronization process is triggered (e.g., re-synchronization, renegotiation of epochID, or rollback to the previous stable time slot), thereby achieving identifiable and consistent time slot allocation.
[0054] For each confirmed time slot T, the quantum site and the target node run quantum key distribution (QKD) or other quantum-secure key negotiation mechanisms within that time slot to generate a set of session keys strongly bound to the time slot marker. The quantum-secure mechanism may include, but is not limited to, decoy state BB84, the E91 entanglement scheme, continuous variable QKD (CV-QKD), or equivalent mechanisms. For ease of implementation, the specific process of generating the base key and derived key within a single time slot is illustrated using "decoy state BB84 (which can be replaced by equivalent QKD)" as an example.
[0055] (1) Time slot binding and round numbering: The quantum site and the target node confirm the current time slot Tslot with a unified time reference; each time a QKD negotiation / key replenishment round is completed in the time slot, idxQKD is incremented once to form a unique session identifier SID=(Tslot,idxQKD) in the slot. When it is detected that the key pool balance is lower than the threshold, or the key length requested by the service side exceeds the length that can be produced in this round, or the effective key after error correction / privacy amplification is insufficient, key replenishment is triggered in the same Tslot and idxQKD is incremented.
[0056] (2) Quantum state preparation and measurement (quantum stage): The quantum station sends a quantum pulse sequence within the effective time window of the time slot Tslot, and selects a bit value and measurement basis for each pulse; in the decoy state scenario, the quantum station also selects the pulse intensity from the intensity set (signal state / decoy state) and records the intensity label. The target node measures the received pulse and records the measurement basis and detection result; both parties generate a local record list Rec_Q(Tslot, idxQKD) within the slot.
[0057] (3) Basis selection and consistency confirmation (classical stage-1): Both parties exchange screening messages SIFT in the classical channel; both parties retain the set of valid events according to the matching basis (and strength label rules) to obtain the original key bit string Kraw(Tslot,idxQKD) and its length |Kraw| in the slot.
[0058] (4) Parameter estimation and anomaly judgment (classic stage-2): Both parties extract a portion of the samples from the set of valid events to estimate the bit error rate, obtain QBER(Tslot,idxQKD), and in the decoy state scenario, count the count rate and bit error rate of different intensity subsets to estimate the security parameters; when QBER exceeds the preset threshold QBER_th or the estimated security parameters do not meet the preset confidence requirements, the negotiation of this round is judged to have failed, both parties discard the length of this round Kraw, record the alarm and can choose to: start the next round of key replenishment (idxQKD++) in the same time slot or trigger resynchronization / link diagnosis.
[0059] (5) Information Correction and Confirmation (Classic Phase-3): Both parties perform information correction (e.g., CASCADE, LDPC, or equivalent correction) on the remaining length Kraw, and exchange correction auxiliary information (e.g., check block index / parity check / syndrome, etc.); after correction, a consistency check (e.g., hash check / check tag) is performed to obtain the corrected bit string Kec(Tslot, idxQKD). The error correction leakage amount leakEC and the number of consistency check failures can be used for subsequent key length control or triggering key replenishment.
[0060] (6) Privacy Amplification and Basic Key Output (Classic Stage-4): Both parties use a preset security parameter ε as the target and perform privacy amplification on the bit string Kec (e.g., using Toeplitz matrix hashing or an equivalent general hash family), outputting a usable basic key KQKD(Tslot, idxQKD). In the implementation, the output length of the usable basic key KQKD(Tslot, idxQKD) can be dynamically determined based on the parameter estimation results, error correction leakage, and security margin; when the output length is insufficient to meet the preset minimum key length Len_min, key replenishment is triggered and idxQKD is incremented.
[0061] (7) Derivation and separation of purpose isolation (control / data sub-blocks): To meet the requirements of purpose isolation and key independence, the system performs key derivation and separation on the available basic key KQKD(Tslot, idxQKD) to obtain the control key Kctrl and the data key Kdata: Kctrl=KDF(KQKD(Tslot,idxQKD),“ctrl”‖Tslot‖idxQKD‖AlgID‖Lenctrl), Kdata=KDF(KQKD(Tslot,idxQKD),“data”‖Tslot‖idxQKD‖AlgID‖Lendata); AlgID represents the derived algorithm identifier (e.g., HKDF-SHA256 or equivalent KDF), and Lenctrl and Lendata are the lengths of the derived key, respectively. The control key Kctrl is used for pseudo-identifier generation, access token construction and verification, hidden field / metadata encryption, and message authentication; the data key Kdata is used for encryption and decryption of business data.
[0062] (8) Key mapping maintenance and expiration strategy: The system maintains the mapping relationship. Map[Tslot] → {(idxQKD,Kctrl,Kdata,validFrom,validTo,status)}, where validFrom and validTo are the start and end times of the key's validity, and status must include at least {ACTIVE,EXPIRED,QUARANTINED}. When the time slot changes or the epochID changes, the mapping of the previous time slot is set to EXPIRED or QUARANTINED according to the policy (it can be retained for audit traceability), and new services are prohibited from using it.
[0063] The system further monitors the session key generation rate r2 and usage rate r1, and performs key resource scheduling and adaptive encryption strategies accordingly. r2 represents the stable supply of available key bits per unit time, which can be calculated over a statistical window W: r2(W) = Bits_generated(W) / W (where Bits_generated is the sum of the actual available key bits after error correction and privacy amplification within the window); r1 represents the key consumption demand of the service per unit time, which can be calculated over the same window: r1(W) = Bits_consumed(W) / W, where Bits_consumed is measured according to the encryption method used (e.g., OTP consumes the same amount of plaintext bits, block / stream encryption consumes the key length required for key swapping, and message authentication consumes the MAC key / one-time random value). The role of r2 is as follows: When using consumable encryption methods such as One-Time Password (OTP), it forces the condition r1(W) ≤ α·r2(W) (α∈(0,1] is the security margin coefficient, taking into account link fluctuations and statistical errors) to avoid security degradation caused by key reuse and insufficient keys; when r1(W) ≥ α·r2(W) is detected or it is predicted that the threshold will be exceeded in the next window, the system triggers encryption policy adjustment and service hierarchical scheduling, including but not limited to: Prioritize the supply of the control plane key Kctrl, and satisfy the control plane derivation first with KQKD(Tslot); For high-volume data services, switch from OTP to a low-key-consumption mode (e.g., symmetric encryption combined with periodic key swapping / post-quantum key exchange, or use OTP only for sensitive fields and conventional encryption for the rest). Low-priority services are rate-limited, queued, or delayed until the next time slot for processing. Triggering idxQKD incremental key replenishment, shortening Δt, or adjusting δ to improve the available stable range, etc. For example, if Δt=1s, statistical window W=10s, statistically obtained r2(W)=1Mbit / s, α=0.8, then the allowed key consumption limit is 0.8Mbit / s; when the business OTP demand reaches 0.9Mbit / s (i.e. r1(W)=0.9Mbit / s≥0.8Mbit / s), the system will continue to use OTP or strong authentication encryption in the control plane, while switching the data plane to symmetric encryption and setting the key exchange period to derive Kdata once every 1s, thereby ensuring business continuity and sustainable use of key resources while meeting security constraints.
[0064] The system can configure a threshold set {ρ_th,NB_th,L_th,U_th}.
[0065] Where ρ(W)=r1(W) / (α·r2(W)) characterizes the key consumption pressure: when ρ(W) is close to or exceeds 1, it means that the key consumption is approaching the sustainable supply limit; NB(W) represents the remaining noise budget margin of the homomorphic ciphertext, which can be given by the NoiseMargin returned by the homomorphic library or an equivalent metric. L(W) can be statistically analyzed based on the requested end-to-end round-trip time or critical link P95 / P99 latency. U(W) can be obtained by combining load indicators such as CPU / memory / queue depth.
[0066] When any triggering condition is met, the system will adjust its strategy according to the principle of "control plane priority, business plane hierarchy": (1) Prioritize the derivation and use of the control plane Kctrl to ensure that token issuance, hidden field pre-encryption and authentication are not downgraded; (2) Introduce an upper limit θ_otp for the proportion of OTP usage to the business plane, and migrate high-volume services to symmetric / post-quantum solutions or use OTP only for sensitive fields; (3) When NB(W) is too low, reduce the comparison rounds / depth of the set membership calculation or adopt phased calculation (first coarse screening and then fine calculation), and migrate the calculation to edge / cloud nodes with lower load if necessary; (4) When L(W) or U(W) exceeds the threshold and continues to meet the threshold for more than τ seconds or is triggered more than N times, the session is interrupted and an alarm is triggered. At the same time, the access token associated with the session is revoked or frozen.
[0067] For example, a quantum site sends entangled photon pairs to a cloud data center, edge nodes, and the operational core network. Each node uses its local clock to time-stamp the arriving photons, forming a time-stamped sequence. Nodes exchange partial time-stamped data through classical channels, execute synchronization algorithms to estimate time offsets and clock drift, and perform compensation until the synchronization accuracy meets preset requirements.
[0068] Subsequently, the system divides the continuous time axis into several time slots according to a preset slot length, assigning a time slot marker and synchronization precision parameters to each time slot. Within each time slot, the quantum site and the target node collaboratively run the quantum key distribution protocol to generate the corresponding quantum key block. The quantum key block is divided into control plane key sub-blocks and service plane key sub-blocks according to their purpose. The former is used for time-binding pseudo-identifier generation, access token construction, and pre-encryption of hidden policy fields, while the latter is used for one-time cipherbook encryption of control signaling and some service data.
[0069] The system monitors the quantum key generation rate and usage rate in each time slot. When the usage rate approaches the upper limit of the generation rate, it dynamically adjusts the encryption method of different services. For example, it migrates some high-volume services from one-time password book encryption to post-quantum secure symmetric encryption to avoid the key pool being exhausted.
[0070] Step 2: On the terminal side, a time-bound pseudo-identifier is generated based on the combination of permanent device identifier, time slot marker, and quantum key block, and homomorphically encrypted to obtain pseudo-identifier ciphertext; on the operation node side, a private set membership protocol is executed on the pseudo-identifier ciphertext to obtain the set membership result; When a terminal device initiates network access or cloud resource access, the terminal obtains the current time slot marker and its corresponding control key from the network side. The terminal inputs the permanent device identifier, the current time slot marker, and the control key into a one-way operation module such as a pseudo-random function or hash function to generate a time-bound pseudo-identifier.
[0071] When a terminal device initiates network access or cloud resource access, the terminal synchronously obtains the current time slot marker Tslot (such as a combination of the slot number and epochID calculated from a unified time reference, or its digest) and the control key Kctrl strictly corresponding to that time slot (which can be derived from the quantum key distribution base key via KDF) from the network side. The terminal uses the permanent device identifier PEI as the binding object and generates a time-binding pseudo-identifier TB_PEI using a one-time pseudo-identifier generation function F with a key. This ensures that TB_PEI can be legally verified within the same time slot, but is statistically independent and unlinkable between different time slots. Preferably, the function F is implemented using a key hash / key derivation structure, as shown in the following example: TB_PEI=TruncL(HMAC(Kctrl,PEI‖Tslot‖Ctr‖Nonce)), HMAC(·) is a keyed hash function, TruncL(·) represents truncating L bits / characters as a pseudo-identifier output; Ctr is a time slot counter (used to distinguish different sessions when multiple accesses occur within the same time slot), and Nonce is a random number generated by the terminal (used to enhance unpredictability and avoid replays and collisions). After generating TB_PEI, the terminal sends {TB_PEI, Tslot, Ctr, Nonce} as a pseudo-identifier payload to the authentication / access control module; the network side (or cloud-side authentication service) locates the corresponding control key Kctrl based on the same time slot marker Tslot, and recalculates TB_PEI′ on the received {PEI, Tslot, Ctr, Nonce}. When TB_PEI′ matches TB_PEI, it is determined that the terminal's identity binding is valid within the current time slot, thereby completing access authentication or access authorization. To avoid exposing the PEI, the preferred implementation is as follows: the terminal does not send the PEI directly in plaintext, and the network locates the PEI through the "registration state mapping table" or "protected index", or associates the protected representation of the PEI (such as Enc / Hash(PEI)) with the terminal during the registration phase, so as to complete the equivalent recalculation during the verification phase.
[0072] Because the generation of TB_PEI depends on both Kctrl and Tslot, which vary with the time slot, and introduces Nonce and Ctr, the following advantages are achieved: First, without knowing Kctrl, attackers cannot deduce PEI from TB_PEI in polynomial time (one-wayness); second, different Kctrls for different time slots result in statistically nearly independent distributions of TB_PEIs generated in different time slots, making it difficult to associate them with the same terminal across slots; third, even with multiple accesses within the same time slot, different TB_PEIs can be generated through Ctr / Nonce, avoiding the exposure of fixed identifiers at the session level. The system can further set the validity period of TB_PEI to the current time slot interval or its sub-intervals, and reject authentication when the validity period expires, Tslots do not match, Ctr is repeated, or Nonce is replayed, triggering a re-retrieval of Tslot / Kctrl or entering a downgraded authentication process, thereby improving anti-replay and anti-association capabilities while ensuring availability.
[0073] To reduce network-side state maintenance overhead, the terminal can encapsulate TB_PEI along with Nonce and Ctr into an authentication token, and then calculate the message authentication code MAC = HMAC(Kctrl,Token) for the token before sending it. The network side only needs to locate Kctrl based on Tslot and verify the MAC to confirm that the token has not been tampered with and belongs to the current time slot. Furthermore, the output of TB_PEI can be Base32 / Base64 URL encoded and its length limited (e.g., 16-32 characters). When a collision occurs with a very low probability, the TB_PEI can be regenerated by adding L or introducing a session random salt Salt (Salt = H(Nonce)) to eliminate the collision.
[0074] When a terminal device initiates network access or cloud resource access, it first synchronously obtains the current time slot marker (Tslot) and its strictly corresponding control plane quantum key block (KQKD) from the network side. Then, using a pre-set one-way trapdoor function or pseudo-random function (F), the terminal performs a mixed operation on the permanent device identifier (PEI) with the dynamically changing Tslot and KQKD to generate a time-bound pseudo-identifier (TB_PEI=F(PEI,KQKD,Tslot)). Based on the true randomness of quantum keys and the one-way avalanche effect of functions, there is no polynomial-time reverse derivation path between the generated pseudo-identifier and the original identifier; furthermore, as the time slot and key are updated, the pseudo-identifiers generated at different times exhibit a statistically independent distribution in the ciphertext space, fundamentally eliminating the possibility of piecing together a complete device behavior trajectory through feature matching in the long term.
[0075] The terminal then uses the public key parameters issued by the operator to encode the time-bound pseudo-identifier into an encrypted form, obtaining the pseudo-identifier ciphertext. The encryption form can be homomorphic ciphertext, secure multi-party computation input ciphertext, or other ciphertext forms that support privacy-preserving computation.
[0076] The "privacy-protected set membership calculation / ciphertext domain matching" described in this invention is a general term that can be implemented using techniques such as homomorphic encryption, OPRF, or secure multi-party computation. To balance efficiency and deployment complexity, the OPRF set membership verification protocol is preferred for implementing "equivalence matching within the protected input domain." In another optional embodiment, homomorphic encryption ciphertext domain calculation can also be used to determine membership. Both embodiments satisfy the requirement that blacklist / greylist membership determination is completed without the operator restoring the terminal's plaintext PEI or obtaining the plaintext TB_PEI.
[0077] The ciphertext of the fake identifier is sent to the core network of the operations department or the cloud-side security node. The operations department maintains a set of device lists, which includes at least a blacklist and / or a graylist. The elements in the sets are fake identifiers or fake identifier digests obtained by processing them in the same way as the terminals.
[0078] After the ciphertext of the pseudo-identifier is sent to the core network of the operation or the cloud-side security node, the operation side performs a privacy-preserving set membership calculation to determine whether the terminal belongs to the device list set (at least including the blacklist set / greylist set) without restoring the plaintext of the terminal's permanent device identifier (PEI) or obtaining the plaintext of the terminal's time-bound pseudo-identifier (TB_PEI). Preferably, a set membership verification protocol based on an unintentional pseudo-random function is used to implement "matching within the encrypted domain," and the specific steps are as follows: (1) Set preprocessing: The operation side maintains protected element values for each list entry. The element values are constructed from inputs consistent with those of the terminal. For example, for each device entry i in the list, Xi = PEI_i‖Tslot‖epochID (or its equivalent protected representation) is constructed, and the token Ti = OPRF_k(Xi) is calculated using the operation side's private key k. {Ti,ListType} is written into the list index structure (ListType∈{blacklist,greylist}), where the output of OPRF_k(·) is an irreversible and unpredictable pseudo-random token, and Xi or PEI_i cannot be deduced from Ti when k is unknown. To adapt to the rolling of time slots, the operation side can generate Ti for the current time slot and adjacent buffer time slots (e.g., n−1, n, n+1) and maintain short-term validity periods.
[0079] (2) Terminal blinding request: When the terminal initiates access, it forms its own input X=TB_PEI‖Tslot‖epochID (or X=protected representation of PEI‖Tslot‖epochID) and generates a random blinding factor r. The terminal performs blinding on X to obtain X*. The terminal only sends {X*,Tslot,epochID,Nonce,Ctr} to the operator, where Nonce / Ctr is used for anti-replay and session differentiation.
[0080] (3) Operation side blind evaluation: The operation side uses the private key k to calculate the blinded output Y*=OPRF_k(X*) on the blinded input X* and returns it to the terminal; the operation side does not obtain the plaintext content of X throughout the process.
[0081] (4) Terminal deblinding to obtain token: The terminal uses the deblinding factor r to deblind Y* to obtain Y=OPRF_k(X), and sends Y (or its digest value H(Y)) along with {Tslot,epochID,Nonce,Ctr} to the operation-side security node as a "matchable token".
[0082] (5) Matching and Condition Determination: The operations side performs equality matching in the list index structure (e.g., hash table / Bloom filter / sorted set lookup): if there exists a blacklist token set T_black such that Y∈T_black, then it is determined that "the blacklist condition is met"; if there is no blacklist match but there exists a graylist token set T_gray such that Y∈T_gray, then it is determined that "the graylist condition is met"; if neither matches, then it is determined that "it is not in the list". The determination rule for "matching" is: tokens are completely equal (Y==Ti) which means that the set membership relationship is established; at the same time, the validity period verification of Tslot / epochID can be combined (e.g., only Ti in [validFrom, validTo] participates in the matching) to prevent cross-time slot association and expired replay.
[0083] (6) Minimal Result Leakage Return: The operation side performs result masking / randomization processing on the judgment result Res∈{BLACK,GRAY,NONE} (e.g., returning MaskedRes=Enc(Ksrv,Res‖Rand) or Res⊕PRG(Ksrv,Rand)), and the terminal only obtains the uninterpretable intermediate return packet; the real list status is only restored locally on the operation side for subsequent policy decisions: BLACK→reject access / block access; GRAY→trigger enhanced authentication / restricted access / increase risk control level; NONE→allow access according to the normal policy.
[0084] Throughout the list verification process, the operations side does not restore the plaintext of the terminal's permanent device identifier and time-bound pseudo-identifier; it only obtains the flag results related to the set's membership relationships. To prevent the terminal from inferring its own state from the return value, the operations side can perform random masking or noise perturbation on the calculation results. The terminal only receives uninterpretable intermediate results, and the true list state is restored locally on the operations side by combining the mask information for subsequent access strategy decisions.
[0085] For example, when a terminal device initiates an access or cloud access request, it obtains the current time slot marker and necessary parameters from the network side. Using the control plane quantum key sub-block corresponding to the current time slot, it combines the locally stored permanent device identifier with the time slot marker to generate a time-bound pseudo-identifier. Specific operations may include pseudo-random functions, hash functions, and masking, making it difficult to find a feasible reverse derivation path between the time-bound pseudo-identifier and the original device identifier.
[0086] The terminal device encodes the time-bound pseudo-identifier into ciphertext using a homomorphic encryption public key and sends this ciphertext to the core network. The core network maintains blacklist and graylist sets indexed by time slots, where each set element is a digest of the pseudo-identifier processed in the same way. Within the homomorphically encrypted ciphertext domain, the core network executes a private set membership protocol to determine whether the terminal is on the blacklist or graylist without recovering the plaintext. To prevent the terminal from inferring its own state from the output, the core network applies a random mask to the calculation result, only internally recovering the true state for subsequent access decisions.
[0087] Step 3: When the terminal identity authentication is successful and the set membership result meets the preset access policy, the access control node generates a quantum time-stamped access token based on the time slot marker, quantum key index, set membership result and predefined cloud access policy, including public access field, hidden policy field, time slot marker, quantum key index and integrity verification information; When terminal authentication is successful and the list verification result conforms to the access policy, the access control node generates a session access token based on the current time slot marker, session key, list verification result, and predefined cloud access policy. The session access token includes at least the following two types of fields: Public access fields are used for routine access control and include at least information such as session identifier, authorized resource scope, service quality level, session validity period, and access initiator identifier. They can be read and used by network nodes participating in the session without additional authorization. Hidden policy fields are used for risk control, auditing, and law enforcement purposes, and include at least information such as summary information corresponding to time-bound pseudo-identifiers, blacklist / greylist status, risk level, audit policy identifier, law enforcement policy identifier, and internal tags related to session behavior.
[0088] Session access tokens are bound to time slot markers and terminal session identifiers when they are generated, so that various operations of the same session can be associated in subsequent audits through tokens and time slot markers.
[0089] Step 4: Based on the quantum time-stamped access token, perform pre-encryption on the access control node to obtain the pre-encrypted hidden field; based on the quantum deformation encryption scheme, generate a single access token ciphertext; To encapsulate both the public access field and the hidden policy field within a single ciphertext and to achieve differentiated visibility across different authorization levels, the access control node performs encrypted encapsulation on the session access token. Specifically, the access control node pre-encrypts the hidden policy field using the control key corresponding to the current time slot, ensuring it remains encrypted even during internal transmission. Subsequently, the access control node inputs the public access field and the pre-encrypted hidden policy field together into the encryption encapsulation module, generating the access token ciphertext through an encryption structure with multi-level decryption capabilities.
[0090] The generated access token ciphertext must meet at least the following conditions: the access token is encapsulated into TokenCT using a multi-level decryption structure, ensuring that different authorization levels can only decrypt information of different granularities. Specifically, "first decryption information" refers to the key material or decryption credential required for the first-level decryption (denoted as DK1), used to recover public access fields and information related to regular access control; "second decryption information" refers to the key material or decryption credential required for the second-level decryption (denoted as DK2), used to recover hidden policy fields when preset authorization conditions are met.
[0091] Specifically, the access control node divides the access token field into a public access field Pub (e.g., resource identifier, request type, time slot marker Tslot, token version number, random number Nonce, signature / verification digest, etc.) and a hidden policy field Hid (e.g., fine-grained policy, audit switch, risk label, anonymization level, additional authentication challenge parameters, etc.). The access control node first pre-encrypts Hid using the control key Kctrl corresponding to the current time slot to obtain HidCT, for example, HidCT=AEAD_Enc(Kctrl,Hid,AD=Pub) or HidCT=Enc(Kctrl,Hid), and binds Pub as the associated data AD. Subsequently, Pub and HidCT are jointly encapsulated into the first-layer ciphertext TokenCT1=AEAD_Enc(K1,Pub‖HidCT,AD=meta), where K1 is the first-layer encapsulation key. DK1 is used to derive or obtain K1, thereby completing the first-layer decryption to obtain Pub and HidCT, but HidCT cannot be decrypted without DK2.
[0092] The DK1 can be obtained in any one or a combination of the following ways: (1) Role / domain based distribution: The operation-side key management service (KMS) distributes the first-level encapsulated key K1 (or its key handle) to the access control node according to the role or system domain, and stores and uses it through the hardware security module HSM / Trusted Execution Environment (TEE); (2) Derivation based on time slot: K1 is derived from the time slot marker Tslot and the session control key Kctrl through KDF, for example K1=KDF(Kctrl,“L1”‖Tslot‖AlgID‖Len1); at this time, DK1 is equivalent to the ability to “hold the Kctrl of the corresponding time slot and obtain K1 through KDF”. (3) Certificate-based decapsulation: K1 is encapsulated by a key encapsulation mechanism (KEM) and given to an access control node with a specific certificate. The node uses its private key to decapsulate and obtain K1.
[0093] The "Second Decryption Information" (DK2) is used to decrypt the pre-encrypted ciphertext HidCT containing the hidden policy field. Its acquisition methods include at least: key material bound to the time slot marker Tslot, dedicated key material bound to the audit / supervisory entity, and challenge proof material bound to the authorization conditions. Preferably, DK2 consists of one or a combination of the following elements: (1) Time slot key factor: provided by the control key Kctrl of the current time slot or its derived key K2=KDF(Kctrl,“L2”‖Tslot‖AlgID‖Len2); (2) Role / Audit Entity Factor: Provided by the audit entity’s private key K_audit (which can be stored in the audit side HSM / TEE), or obtained by decapsulating the private key corresponding to the audit entity’s certificate; (3) Authorization condition proof: The authorization ticket AuthZ output by the strategy engine (e.g., a signature assertion that satisfies multi-factor authentication / risk threshold / work order approval) participates in the derivation as part of the decryption gating condition.
[0094] In implementation, the decryption key for Hid can be defined as KH = KDF(Kctrl‖K_audit,“HID”‖Tslot‖RoleID‖Hash(AuthZ)‖LenH). KH can only be calculated and HidCT decrypted when both the key factor and authorization ticket required by DK2 are available. This achieves the following: with only DK1, only Pub and regular access control information can be recovered; with both DK2 and preset authorization conditions met, Hid can be recovered; in the absence of DK2, even statistical analysis of TokenCT makes it difficult to distinguish whether it contains a hidden policy field, thus achieving differentiated visibility and indistinguishability of the hidden policy.
[0095] Step 5: When transmitting business data between terminal devices, edge computing nodes and cloud data centers, access requests are authorized and controlled according to the single access token ciphertext, and a data encryption method is selected. During the process of processing access requests and forwarding data, each node records the access token identifier, time slot marker and key operation results in the security log. During the session, the terminal device sends a resource access request to the edge computing node or cloud data center, carrying an encrypted access token. The receiving node first verifies the integrity and validity of the encrypted access token and uses the first decryption information to recover the public access field. Based on information such as the authorized resource scope, service quality level, session validity period, and risk level in the public access field, the receiving node performs access control, resource authorization, and rate limiting on the access request.
[0096] For business data requiring encryption protection, the receiving node selects the data key corresponding to the current time slot or other post-quantum secure encryption algorithms to encrypt and decrypt the data based on the public access fields and preset security policies. For sensitive signaling or metadata related to the control plane, the data key can be directly used for one-time encryption, thereby enhancing protection against replay and tampering. All critical access operations are accompanied by time slot markers and session identifiers and written to the security log to provide basic data for subsequent auditing.
[0097] For example, when the terminal completes identity authentication and the time-bound pseudo-identity verification result meets the access policy, the access control node reads data such as the current time slot marker, quantum key index, user or device identity information, and access request characteristics, performs risk assessment, and obtains the risk level and the corresponding policy number.
[0098] The access control node constructs a quantum time-stamped access token based on the above information. The token uses the time slot marker, quantum key index, session identifier, authorized resource scope, and service quality level as public access fields, and the time-bound pseudo-identifier digest, blacklist / greylist status, risk level, audit policy identifier, and enforcement policy identifier as hidden policy fields. These hidden policy fields are pre-encrypted using the control plane quantum key sub-block corresponding to the current time slot, ensuring they remain encrypted throughout subsequent steps.
[0099] Subsequently, the access control node invokes the quantum warp encryption module to encapsulate the public access field and the pre-encrypted hiding policy field together into a single access token ciphertext. This ensures that decryption with a regular key can only recover the public access field, while the existence and content of the hiding policy field remain invisible to unauthorized entities. Finally, the access token ciphertext is bound to a session identifier and distributed to terminals, edge nodes, and cloud data centers for access control and data encryption / decryption in subsequent sessions.
[0100] Step 6: Upon detecting a security incident, being hit on a gray list, or receiving an audit and enforcement instruction, the audit entity audits and collects evidence on the target session based on quantum time stamps, generating a chain of evidence with quantum time stamps.
[0101] Upon detecting suspected attacks, devices being added to a gray list, or audit or enforcement instructions issued by higher authorities, the audit entity first restores the unified timeline for the target time period based on the Quantum Time service to locate the relevant time slots and sessions. After obtaining the appropriate authorization, the audit entity retrieves the relevant access token ciphertext and security log records from the log system or storage system, and uses the control key corresponding to the time slot and the second decryption information to decrypt the access token ciphertext and restore the hidden policy fields.
[0102] The audit entity combines the risk level recorded in the hidden policy fields, device list status, audit policy identifier, and time-series operation records in the security logs to perform backtracking analysis on suspicious sessions, reconstructing access paths and behavioral sequences to form a complete chain of evidence. Throughout the process, operational nodes and cloud service nodes during normal business operations do not need to access the plaintext of the hidden policy fields and permanent device identifiers, thereby ensuring traceability while reducing the risk of privacy leaks.
[0103] For example, after a terminal device completes access authentication and obtains an access token on the mobile communication access network side, it attaches the access token to the request when accessing edge services or cloud resources. Edge nodes and cloud data centers first verify the integrity and validity of the access token, and then decide whether to allow, rate-limit, or reject the request based on the permission settings, risk level, and service quality requirements in the publicly accessible access fields. For different types of data streams, the system selects protection methods such as one-time passwords, post-quantum symmetric encryption, or homomorphic encryption according to its policies.
[0104] During the session, each node records the time slot marker, access token identifier, access target, and important operation results in the security log. When abnormal behavior occurs, a gray list is hit, or an audit instruction is received, the audit entity restores the unified timeline within the relevant time period based on the quantum time service, extracts the corresponding access token ciphertext and security log, and, under authorized conditions, uses the quantum key block and transformed key corresponding to the time slot to deseal the access token, restore the hidden policy field, and combines the log to trace and analyze the session behavior, forming a credible chain of evidence.
[0105] Preferably, the process of performing entangled photon time transfer and time synchronization, dividing the continuous time axis into multiple time slots, running a quantum key distribution protocol to generate quantum key blocks within each time slot, and establishing a mapping relationship between time slot markers, quantum key blocks, and quantum key indices to form a quantum key pool organized by time slots includes: Quantum-secure time transfer is achieved by using quantum signals. Single-photon detection events are time-stamped at each node to form a time-stamped sequence. Each node includes cloud data centers, edge computing nodes, and mobile communication network operation nodes. Each node receives quantum signals on the quantum channel and generates a time stamp record for each detection event. The time stamp record includes at least the node identifier, the running cycle identifier, the detection event sequence number, the local arrival time, the detection channel or detector identifier, and the validity flag. Each node preprocesses the timestamp records, removes invalid events, and aggregates them according to time windows to obtain a local timestamp sequence; Each node sends a time stamp reporting message through a classic channel. The time stamp reporting message includes at least a node identifier, a running cycle identifier, a start and end time window, a number of records, a time stamp sequence, a digest value, and integrity verification information. The integrity verification information includes a message authentication code (MAC) and / or a digital signature to ensure the integrity and non-repudiation of the time stamp data during the exchange process. A synchronization algorithm is used to estimate and compensate for time offset and clock drift between nodes to obtain a unified time reference with a predetermined accuracy; the continuous running time is divided into multiple time slots, and each time slot corresponds to a unique time slot marker. Within a preset matching window, time-stamped records of different nodes are paired to obtain a set of paired events; The initial value of the time offset between nodes is calculated based on the set of paired events, and the clock drift parameter is obtained by regression estimation or equivalent estimation. The initial value of the time offset between nodes and the clock drift parameter are filtered and smoothed to obtain the compensation parameter that is updated over time. Each node converts its local time into a unified time reference according to the formula: unified time = local time - compensation parameter. When the synchronization error meets the preset threshold, the continuous time axis is divided into multiple time slots, and each time slot corresponds to a time slot mark. A quantum key distribution protocol is run within each time slot to generate quantum key blocks that correspond one-to-one with the time slot markers, and a quantum key index is assigned to each quantum key block to form a quantum key pool organized by time slots. The quantum key blocks corresponding to each time slot are divided into control plane quantum key sub-blocks and service plane quantum key sub-blocks. The control plane quantum key sub-blocks are used for time-binding pseudo-identifier generation, access token construction, and pre-encryption of hidden policy fields. The service plane quantum key blocks are used for one-time encryption of control signaling, access control related data, and some service data. Constrain the rate of quantum key usage to not exceed the rate of quantum key generation, and configure quantum key usage strategies according to different business types.
[0106] Preferably, the step of generating a time-bound pseudo-identifier on the terminal side based on the combination of a permanent device identifier, a time slot marker, and a quantum key block, and then performing homomorphic encryption encoding to obtain pseudo-identifier ciphertext; and executing a private set membership protocol on the pseudo-identifier ciphertext on the operation node side to obtain the set membership result includes: When a terminal device initiates network access or cloud resource access, it obtains the permanent device identifier, time slot marker and quantum key block of the current terminal device and inputs them into a predetermined pseudo-random function to generate a time-bound pseudo-identifier TB_PEI. The pseudo-random function F is a combination of key-based pseudo-random functions or cryptographic hash functions, TB_PEI=F(PEI,KQKD(Tslot),Tslot), where PEI represents the permanent device identifier, KQKD(Tslot) represents the quantum key block, and Tslot represents the time slot marker; The time-binding pseudo-identifier satisfies the following properties: given a time-binding pseudo-identifier, it is difficult to recover the permanent device identifier within feasible computational complexity; the time-binding pseudo-identifiers generated for different time slot markers are statistically independent of each other; when the quantum key block is updated or invalidated, the historical time-binding pseudo-identifier can no longer be verified. The terminal device performs homomorphic encryption encoding on the time-bound pseudo-identifier based on the homomorphic encryption public key to obtain the pseudo-identifier ciphertext; The mobile communication network operator performs a private set membership protocol on the pseudo-identifier ciphertext based on a pre-built blacklist set and graylist set. Within the homomorphically encrypted ciphertext domain, it determines whether the time-bound pseudo-identifier belongs to the blacklist set or the graylist set, and obtains the set membership result without restoring the plaintext value of the permanent device identifier or the time-bound pseudo-identifier. After obtaining an internal determination result by executing a private set membership protocol, the mobile communication network operator node generates a one-time random number and uses the operator's confidential key to mask the internal determination result to obtain the return value MaskedRes to the terminal. The masking process includes at least encrypted encapsulation or pseudo-random mapping. The operation node generates risk control context internally based on internal judgment results for access decisions, and only returns MaskedRes to the terminal. The length of the returned message and the error code / response type are consistent to avoid the terminal inferring the blacklist or graylist hit status based on the feedback.
[0107] Preferably, the quantum time-stamped access token includes a public access field, which includes at least one or more of the following: session identifier, accessible resource range, quality of service level, and session validity period. The quantum time-stamped access token includes a hidden policy field, which includes at least one or more of the following information: risk level associated with the time-bound pseudo-identifier, blacklist or graylist status, audit policy identifier, and enforcement policy identifier; The quantum time-stamped access token also includes a time slot stamp, a quantum key index, and integrity verification information; The quantum time-stamped access token is universally applicable in the cloud-edge-mobile network integrated environment. On the mobile communication access network side, the access token is used to control terminal device access, network slice selection, and edge service authorization. On the cloud data center side, the access token is used to control tenant resource access, data download, management interface calls, and cross-regional access authorization. The lifecycle of the access token is jointly limited by the time slot length and the cloud access policy. When the time slot expires or the access policy changes, the access token automatically becomes invalid and triggers a new round of time synchronization and key negotiation process.
[0108] Preferably, the access control node is pre-encrypted based on the quantum time-stamped access token to obtain a pre-encrypted hidden field; the single access token ciphertext is generated based on the quantum warp encryption scheme, including: The hidden policy field is pre-encrypted using the control plane quantum key sub-block corresponding to the current time slot mark to obtain the pre-encrypted hidden field. Based on the quantum deformation encryption scheme, the public access field, the pre-encrypted hidden field, and the metadata of the time slot marker and the quantum key index are all encapsulated into a single access token ciphertext. The quantum deformation encryption scheme includes at least the following: When decrypting a single access token ciphertext using a regular decryption key, only the public access field and the encrypted encapsulated data related to the hidden field are output, and the plaintext of the hiding policy field is not output. Under audit or enforcement authorization, when the auditing entity possesses the modified key and is authorized to obtain the quantum key block corresponding to the time slot or its derived control key, it performs secondary desealing on the encrypted data to restore the hidden policy field.
[0109] The "quantum warp encryption" described in this invention refers to a two-layer visibility encryption encapsulation mechanism for access tokens: for the same access token ciphertext `C_QAE`, with only the regular decryption key `DK1`, the receiver can only obtain the public access field `Ppub` (and the encrypted encapsulation data related to the hidden field), but cannot obtain the plaintext of the hidden policy field `Phid`; under audit or law enforcement authorization, the auditing entity can further decapsulate and recover `Phid` only when it simultaneously possesses the warp key `DK2` and is authorized to obtain the quantum key material corresponding to the current time slot `Tslot` (e.g., the control key derived from `KQKD(Tslot)`).
[0110] 1) Key materials and derivation relationships In step (1), the system has established a mapping and divided control / service sub-blocks according to their purpose.
[0111] The control key `Kctrl` can be derived from the quantum key block of the current time slot, for example: The standard encapsulation key `K1` (corresponding to the standard decryption key `DK1`) can be obtained through time slot derivation, certificate decapsulation, role-based distribution, or equivalent methods. The variant key system consists of a pair of keys or equivalent credentials: the variant encapsulation parameter `PK_def`: can be publicly disclosed / distributed, used to encapsulate the "variation factor" during the token generation phase; the variant key `SK_def` (i.e., one of the core components of `DK2`): held by the audit entity in a controlled environment, used to decapsulate the "variation factor".
[0112] 2) "Modified Pre-encryption" of Hidden Fields The access control node generates a one-time deformation factor (random seed) and encapsulates it with deformation encapsulation parameters to obtain a deformation capsule; Subsequently, the access control node derives the hidden field encryption key `Khid` based on the control key `Kctrl` and the transformation factor `s`, and performs Authentication Encryption with Associated Data (AEAD) on the hidden policy field to obtain the pre-encrypted hidden field: The `meta` part must include at least `{Tslot,idxQKD,TokenID,Exp,AlgID}`, where `TokenID` is the token identifier, `Exp` is the validity period or valid time slot range, and `AlgID` is the algorithm identifier.
[0113] 3) Generation of the ciphertext C_QAE for the access token The access control node constructs the payload to be encapsulated and performs first-level AEAD encapsulation using the regular encapsulation key `K1` to obtain the access token ciphertext. To enhance tamper resistance and non-repudiation, the access control node can also generate a signature or message authentication code for `(C_QAE||meta)` and distribute it together with `C_QAE`.
[0114] 4) Two-level reopening and information view Regular decryption (DK1 only): Edge nodes / cloud nodes decrypt `C_QAE` to obtain `Ppub`, `meta` and encrypted data `HidCT` and `D_caps` when they only have `DK1(=K1)`. However, due to the lack of `s` and / or the lack of `Kctrl`, the plaintext `Phid` cannot be recovered.
[0115] Transformation Unsealing: After obtaining authorization, the auditing entity locates `Tslot`, idxQKD` and obtains `Kctrl` (or an equivalent time slot control key), and uses the transformation key `SK_def` to unseal the transformation capsule, then calculates `Khid` and decrypts `HidCT` to recover `Phid`.
[0116] 5) Safety and Consistency Constraints If the `Tslot` in `meta` has expired, the `TokenID` has been replayed (which can be determined using a blacklist or sliding window cache), or the AEAD verification fails, then unblocking will be refused and an audit log will be recorded.
[0117] The binding of `AD=(Ppub||meta)` ensures the consistency between hidden fields and public fields, timestamps, and indexes, preventing field replacement and splicing attacks.
[0118] Preferably, when transmitting business data between terminal devices, edge computing nodes, and cloud data centers, the specific implementation process of authorizing and controlling access requests based on the single access token ciphertext, selecting a data encryption method, and recording the access token identifier, time slot marker, and key operation results in the security log during the processing of access requests and data forwarding includes: Each node authorizes access requests based on the recoverable public access field in the single access token ciphertext, and selects the appropriate data encryption method based on the security level in the public access field. For control signaling, access control related data and some highly sensitive metadata, use the business plane quantum key sub-block corresponding to the current time slot to encrypt it in a one-time password book manner; For high-volume business data, use symmetric encryption or homomorphic encryption based on post-quantum cryptography algorithms for protection; During the process of handling access requests and forwarding data, each node records the access token identifier, time slot marker, and key operation results in the security log.
[0119] Preferably, the specific implementation process of the audit entity auditing and collecting evidence on the target session based on quantum time stamps and generating an evidence chain with quantum time stamps when a security event, graylist hit, or audit and enforcement instruction is detected includes: Upon detecting a security incident, being hit on a graylist, or receiving an audit and enforcement directive, the audit entity restores a unified timeline within the target time period based on the quantum secure time service and locates the relevant time slot markers. After obtaining authorization, the audit entity obtains the ciphertext of the access token corresponding to the target session and related security logs, and uses the quantum key block corresponding to the time slot and the transformed key to decrypt the ciphertext of the access token and restore the hidden policy field. The audit entity combines the risk level, blacklist or graylist status, audit policy identifier, enforcement policy identifier, and time-series operation records in the hidden policy field to perform retrospective analysis on suspicious session behavior and generate a chain of evidence with quantum time stamps.
[0120] Preferably, the mobile communication network operator does not access the plaintext of the permanent device identifier during the entire time-bound pseudo-identifier generation and privacy verification process, and does not store the plaintext value of the time-bound pseudo-identifier. The behavior-related information is only decrypted by an independent audit or law enforcement entity in a controlled environment under audit or law enforcement authorization. For sessions whose duration exceeds the length of a single time slot, it supports rolling updates of the quantum time stamp access token and its associated time slot stamp and quantum key index across multiple consecutive time slots, and seamless switching between nodes in the cloud-edge-mobile network, balancing the needs of long session services with key security.
[0121] Preferably, during the generation of quantum time slots and quantum key pools, cloud-edge-mobile network collaborative access control, and data encryption / decryption, the system continuously generates a set of monitoring indicators using a sliding statistical window, and triggers adaptive strategy adjustments based on preset thresholds; wherein the set of monitoring indicators includes at least: the quantum key generation rate r1(W) and usage rate r2(W) counted within the sliding statistical window W, and the key pressure coefficient ρ(W) = r1(W) / (α·r2(W)) is calculated, where α is the security margin coefficient; homomorphic encryption noise budget margin; link latency; node computational load; When any of the following triggering conditions are met: the key pressure coefficient is greater than or equal to the pressure coefficient threshold, the homomorphic encryption noise budget margin is less than or equal to the margin threshold, the link latency is greater than the latency threshold, or the node computing load is greater than or equal to the load threshold, a set of actions to dynamically adjust the quantum key usage ratio and access strategy will be executed. The set of actions includes at least one of the following: Key resource priority scheduling includes prioritizing control plane key derivation and consumption, and prioritizing the allocation of quantum key blocks for control plane key sub-blocks; The encryption method can be adaptively switched, including switching at least one type of high-traffic service from one-time key book encryption to low key consumption mode, including symmetric encryption combined with periodic key swapping and / or post-quantum secure key exchange, or using one-time key book encryption only for sensitive fields and conventional encryption for the remaining fields; Homomorphic computation order reduction and resource deload include reducing the circuit depth / comparison rounds of private set membership computation or adjusting homomorphic parameters when the noise budget margin is insufficient or the computational load is too high, and rate limiting, queuing or delaying low-priority requests to the next time slot. Session-level security measures include interrupting the session, revoking / freezing the relevant access token, and triggering a security alarm when the triggering conditions are met for a continuous period of time or reach a preset number of triggers.
[0122] A system for a cloud privacy data access control method using quantum time stamping, the system comprising: The time and key management module is used to establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes and mobile communication network operation nodes, perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers and quantum key blocks and quantum key indexes. The pseudo-identifier processing module is deployed on terminal devices and mobile communication network operation nodes. It is used to generate time-bound pseudo-identifiers by combining permanent device identifiers and time slot markers and quantum key blocks on the terminal side, and to calculate the private set membership relationship with blacklists and graylists on the operation node side based on homomorphic encryption. The access token generation module, deployed on edge computing nodes and cloud data centers, is used to construct quantum time-stamped access tokens based on time slot markers, quantum key indexes, privacy verification results, and access policies, and to complete the issuance, updating, revocation, and storage of access tokens. The encryption encapsulation module is used to perform quantum deformation encryption encapsulation on the public access field and hidden policy field in the quantum time-stamped access token, generate a single access token ciphertext, and manage the regular decryption key and the deformation key, so that different information views are presented under different authorization combinations; The access control module is used to transmit a single access token ciphertext between terminal devices, base stations, edge computing nodes and cloud data centers. It performs access control, network slice selection, cloud resource authorization and encryption / decryption of business data based on the quantum time-stamped access token, and records time slot markers and key operation logs. The auditing and evidence collection module is used to restore a unified timeline based on the quantum time service, decrypt hidden policy fields in the ciphertext of a single access token, and trace back terminal behavior and construct a chain of evidence by combining access logs, under audit or law enforcement authorization conditions. The modules are interconnected through network communication or inter-process communication.
[0123] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0124] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A quantum time-stamped cloud privacy data access control method, characterized in that, The method includes the following steps: Establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes, and mobile communication network operation nodes; perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers, quantum key blocks, and quantum key indexes to form a quantum key pool organized by time slots; On the terminal side, a time-bound pseudo-identifier is generated based on the combination of permanent device identifier, time slot marker, and quantum key block, and homomorphic encryption is performed to obtain pseudo-identifier ciphertext; on the operation node side, a private set membership protocol is executed on the pseudo-identifier ciphertext to obtain set membership result; When the terminal identity authentication is successful and the set membership result meets the preset access policy, the access control node generates a quantum time-stamped access token based on the time slot marker, quantum key index, set membership result and predefined cloud access policy, including public access field, hidden policy field, time slot marker, quantum key index and integrity verification information; Based on quantum time-stamped access tokens, pre-encryption is performed on access control nodes to obtain pre-encrypted hidden fields; based on quantum deformation encryption schemes, a single access token ciphertext is generated. When transmitting business data between terminal devices, edge computing nodes and cloud data centers, access requests are authorized and controlled according to the single access token ciphertext, and a data encryption method is selected. During the process of processing access requests and forwarding data, each node records the access token identifier, time slot marker and key operation results in the security log. Upon detecting a security incident, being hit on a greylist, or receiving audit and enforcement instructions, the audit entity audits and collects evidence on the target session based on quantum time stamps, generating a chain of evidence with quantum time stamps.
2. The quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, The process of performing entangled photon time transfer and time synchronization, dividing a continuous time axis into multiple time slots, running a quantum key distribution protocol within each time slot to generate quantum key blocks, and establishing a mapping relationship between time slot markers, quantum key blocks, and quantum key indices to form a quantum key pool organized by time slots includes: Quantum-secure time transfer is achieved by using quantum signals. Single-photon detection events are time-stamped at each node to form a time-stamped sequence. Each node includes cloud data centers, edge computing nodes, and mobile communication network operation nodes. Each node receives quantum signals on the quantum channel and generates a time stamp record for each detection event. The time stamp record includes at least the node identifier, the running cycle identifier, the detection event sequence number, the local arrival time, the detection channel or detector identifier, and the validity flag. Each node preprocesses the timestamp records, removes invalid events, and aggregates them according to time windows to obtain a local timestamp sequence; Each node sends a time stamp reporting message through a classic channel. The time stamp reporting message includes at least a node identifier, a running cycle identifier, a start and end time window, a number of records, a time stamp sequence, a digest value, and integrity verification information. The integrity verification information includes a message authentication code (MAC) and / or a digital signature to ensure the integrity and non-repudiation of the time stamp data during the exchange process. A synchronization algorithm is used to estimate and compensate for time offset and clock drift between nodes to obtain a unified time reference with a predetermined accuracy; the continuous running time is divided into multiple time slots, and each time slot corresponds to a unique time slot marker. Within a preset matching window, time-stamped records of different nodes are paired to obtain a set of paired events; The initial value of the time offset between nodes is calculated based on the set of paired events, and the clock drift parameter is obtained by regression estimation or equivalent estimation. The initial value of the time offset between nodes and the clock drift parameter are filtered and smoothed to obtain the compensation parameter that is updated over time. Each node converts its local time into a unified time reference according to the formula: unified time = local time - compensation parameter. When the synchronization error meets the preset threshold, the continuous time axis is divided into multiple time slots, and each time slot corresponds to a time slot mark. A quantum key distribution protocol is run within each time slot to generate quantum key blocks that correspond one-to-one with the time slot markers, and a quantum key index is assigned to each quantum key block to form a quantum key pool organized by time slots. The quantum key blocks corresponding to each time slot are divided into control plane quantum key sub-blocks and service plane quantum key sub-blocks. The control plane quantum key sub-blocks are used for time-binding pseudo-identifier generation, access token construction, and pre-encryption of hidden policy fields. The service plane quantum key blocks are used for one-time encryption of control signaling, access control related data, and some service data. Constrain the rate of quantum key usage to not exceed the rate of quantum key generation, and configure quantum key usage strategies according to different business types.
3. The quantum time-stamped cloud privacy data access control method according to claim 2, characterized in that, The terminal side generates a time-bound pseudo-identifier based on a combination of a permanent device identifier, a time slot marker, and a quantum key block, and performs homomorphic encryption encoding to obtain the pseudo-identifier ciphertext. On the operation node side, a private set membership protocol is executed on the pseudo-identifier ciphertext to obtain the set membership results, including: When a terminal device initiates network access or cloud resource access, it obtains the permanent device identifier, time slot marker and quantum key block of the current terminal device and inputs them into a predetermined pseudo-random function to generate a time-bound pseudo-identifier TB_PEI. The pseudo-random function F is a combination of key-based pseudo-random functions or cryptographic hash functions, TB_PEI=F(PEI,KQKD(Tslot),Tslot), where PEI represents the permanent device identifier, KQKD(Tslot) represents the quantum key block, and Tslot represents the time slot marker; The time-binding pseudo-identifier satisfies the following properties: given a time-binding pseudo-identifier, it is difficult to recover the permanent device identifier within feasible computational complexity; the time-binding pseudo-identifiers generated for different time slot markers are statistically independent of each other; when the quantum key block is updated or invalidated, the historical time-binding pseudo-identifier can no longer be verified. The terminal device performs homomorphic encryption encoding on the time-bound pseudo-identifier based on the homomorphic encryption public key to obtain the pseudo-identifier ciphertext; The mobile communication network operator performs a private set membership protocol on the pseudo-identifier ciphertext based on a pre-built blacklist set and graylist set. Within the homomorphically encrypted ciphertext domain, it determines whether the time-bound pseudo-identifier belongs to the blacklist set or the graylist set, and obtains the set membership result without restoring the plaintext value of the permanent device identifier or the time-bound pseudo-identifier. After obtaining an internal determination result by executing a private set membership protocol, the mobile communication network operator node generates a one-time random number and uses the operator's confidential key to mask the internal determination result to obtain the return value MaskedRes to the terminal. The masking process includes at least encrypted encapsulation or pseudo-random mapping. The operation node generates risk control context internally based on internal judgment results for access decisions, and only returns MaskedRes to the terminal. The length of the returned message and the error code / response type are consistent to avoid the terminal inferring the blacklist or graylist hit status based on the feedback.
4. The quantum time-stamped cloud privacy data access control method according to claim 3, characterized in that, The quantum time-stamped access token includes a public access field, which includes at least one or more of the following: session identifier, accessible resource range, service quality level, and session validity period. The quantum time-stamped access token includes a hidden policy field, which includes at least one or more of the following information: risk level associated with the time-bound pseudo-identifier, blacklist or graylist status, audit policy identifier, and enforcement policy identifier; The quantum time-stamped access token also includes a time slot stamp, a quantum key index, and integrity verification information; The quantum time-stamped access token is universally applicable in the cloud-edge-mobile network integrated environment. On the mobile communication access network side, the access token is used to control terminal device access, network slice selection, and edge service authorization. On the cloud data center side, the access token is used to control tenant resource access, data download, management interface calls, and cross-regional access authorization. The lifecycle of the access token is jointly limited by the time slot length and the cloud access policy. When the time slot expires or the access policy changes, the access token automatically becomes invalid and triggers a new round of time synchronization and key negotiation process.
5. The quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, The access control node is pre-encrypted using the quantum time-stamped access token to obtain a pre-encrypted hidden field. Based on the quantum deformation encryption scheme, the generated single access token ciphertext includes: The hidden policy field is pre-encrypted using the control plane quantum key sub-block corresponding to the current time slot mark to obtain the pre-encrypted hidden field. Based on the quantum deformation encryption scheme, the public access field, the pre-encrypted hidden field, and the metadata of the time slot marker and the quantum key index are all encapsulated into a single access token ciphertext. The quantum deformation encryption scheme includes at least the following: When decrypting a single access token ciphertext using a regular decryption key, only the public access field and the encrypted encapsulated data related to the hidden field are output, and the plaintext of the hiding policy field is not output. Under audit or enforcement authorization, when the auditing entity possesses the modified key and is authorized to obtain the quantum key block corresponding to the time slot or its derived control key, it performs secondary desealing on the encrypted data to restore the hidden policy field.
6. The quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, When transmitting business data between terminal devices, edge computing nodes, and cloud data centers, the specific implementation process of authorizing and controlling access requests based on the single access token ciphertext, selecting a data encryption method, and recording the access token identifier, time slot marker, and key operation results in the security log during the processing of access requests and data forwarding includes: Each node authorizes access requests based on the recoverable public access field in the single access token ciphertext, and selects the appropriate data encryption method based on the security level in the public access field. For control signaling, access control related data and some highly sensitive metadata, use the business plane quantum key sub-block corresponding to the current time slot to encrypt it in a one-time password book manner; For high-volume business data, use symmetric encryption or homomorphic encryption based on post-quantum cryptography algorithms for protection; During the process of handling access requests and forwarding data, each node records the access token identifier, time slot marker, and key operation results in the security log.
7. The quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, The specific implementation process of the audit entity conducting audit and forensics of the target session based on quantum time stamping upon detecting a security incident, graylist hit, or receiving audit and enforcement instructions includes: Upon detecting a security incident, being hit on a graylist, or receiving an audit and enforcement directive, the audit entity restores a unified timeline within the target time period based on the quantum secure time service and locates the relevant time slot markers. After obtaining authorization, the audit entity obtains the ciphertext of the access token corresponding to the target session and related security logs, and uses the quantum key block corresponding to the time slot and the transformed key to decrypt the ciphertext of the access token and restore the hidden policy field. The audit entity combines the risk level, blacklist or graylist status, audit policy identifier, enforcement policy identifier, and time-series operation records in the hidden policy field to perform retrospective analysis on suspicious session behavior and generate a chain of evidence with quantum time stamps.
8. The quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, Mobile communication network operating nodes do not access the plaintext of permanent device identifiers during the entire process of time-bound pseudo-identifier generation and privacy verification, nor do they store the plaintext value of time-bound pseudo-identifiers. Only under audit or law enforcement authorization can independent audit or law enforcement entities decrypt behavior-related information in a controlled environment. For sessions whose duration exceeds the length of a single time slot, it supports rolling updates of the quantum time stamp access token and its associated time slot stamp and quantum key index across multiple consecutive time slots, and seamless switching between nodes in the cloud-edge-mobile network, balancing the needs of long session services with key security.
9. A quantum time-stamped cloud privacy data access control method according to claim 1, characterized in that, During the generation of quantum time slots and quantum key pools, cloud-edge-mobile network collaborative access control and data encryption and decryption, the system continuously generates a set of monitoring indicators with a sliding statistical window and triggers adaptive strategy adjustments based on preset thresholds. The set of monitoring indicators includes at least: the quantum key generation rate r1(W) and usage rate r2(W) statistically analyzed within a sliding statistical window W, and the key pressure coefficient ρ(W) = r1(W) / (α·r2(W)) is calculated, where α is the security margin coefficient; homomorphic encryption noise budget margin; link latency; node computational load; When any of the following triggering conditions are met: the key pressure coefficient is greater than or equal to the pressure coefficient threshold, the homomorphic encryption noise budget margin is less than or equal to the margin threshold, the link latency is greater than the latency threshold, or the node computing load is greater than or equal to the load threshold, a set of actions to dynamically adjust the quantum key usage ratio and access strategy will be executed. The set of actions includes at least one of the following: Key resource priority scheduling includes prioritizing control plane key derivation and consumption, and prioritizing the allocation of quantum key blocks for control plane key sub-blocks; The encryption method can be adaptively switched, including switching at least one type of high-traffic service from one-time key book encryption to low key consumption mode, including symmetric encryption combined with periodic key swapping and / or post-quantum secure key exchange, or using one-time key book encryption only for sensitive fields and conventional encryption for the remaining fields; Homomorphic computation order reduction and resource deload include reducing the circuit depth / comparison rounds of private set membership computation or adjusting homomorphic parameters when the noise budget margin is insufficient or the computational load is too high, and rate limiting, queuing or delaying low-priority requests to the next time slot. Session-level security measures include interrupting the session, revoking / freezing the relevant access token, and triggering a security alarm when the triggering conditions are met for a continuous period of time or reach a preset number of triggers.
10. A system for implementing a quantum time-stamped cloud privacy data access control method according to any one of claims 1-9, characterized in that, The system includes: The time and key management module is used to establish quantum and classical channels between quantum sites and cloud data centers, edge computing nodes and mobile communication network operation nodes, perform entangled photon time transfer and time synchronization, divide the continuous time axis into multiple time slots, run the quantum key distribution protocol in each time slot to generate quantum key blocks, and establish a mapping relationship between time slot markers and quantum key blocks and quantum key indexes. The pseudo-identifier processing module is deployed on terminal devices and mobile communication network operation nodes. It is used to generate time-bound pseudo-identifiers by combining permanent device identifiers and time slot markers and quantum key blocks on the terminal side, and to calculate the private set membership relationship with blacklists and graylists on the operation node side based on homomorphic encryption. The access token generation module, deployed on edge computing nodes and cloud data centers, is used to construct quantum time-stamped access tokens based on time slot markers, quantum key indexes, privacy verification results, and access policies, and to complete the issuance, updating, revocation, and storage of access tokens. The encryption encapsulation module is used to perform quantum deformation encryption encapsulation on the public access field and hidden policy field in the quantum time-stamped access token, generate a single access token ciphertext, and manage the regular decryption key and the deformation key, so that different information views are presented under different authorization combinations; The access control module is used to transmit a single access token ciphertext between terminal devices, base stations, edge computing nodes and cloud data centers. It performs access control, network slice selection, cloud resource authorization and encryption / decryption of business data based on the quantum time-stamped access token, and records time slot markers and key operation logs. The auditing and evidence collection module is used to restore a unified timeline based on the quantum time service under audit or law enforcement authorization conditions, unblock hidden policy fields in the ciphertext of a single access token, and combine access logs to trace back terminal behavior and build a chain of evidence.