A key replenishment device and its working method

CN122578149APending Publication Date: 2026-08-14MATRICTIME DIGITAL TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-11
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

这种方式虽然将监控功能从量子安全设备转移到了外部机构,但频繁的询问操作会大量占用通信带宽,尤其在设备数量众多或网络环境受限的场景下,带宽消耗问题尤为突出

Benefits of technology

[0034]1、密钥余量的监控与阈值判断由独立的密钥补充装置完成,量子安全设备无需分配额外计算资源进行实时监控,可专注于密钥生成、协商及加解密等核心业务,从而提升整体处理效率;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122578149A_ABST
    Figure CN122578149A_ABST
Patent Text Reader

Abstract

This application discloses a key replenishment device and its operating method. The method includes: a quantum-safe network management device generating a business information index table and sending it to the key replenishment device; the quantum-safe device pre-registering with the quantum-safe network management device and reporting its total key quantity; the quantum-safe network management device sending the total key quantity to the key replenishment device; the quantum-safe network management device notifying the key replenishment device to calculate the key balance locally based on the business service call request of the quantum-safe device; and the key replenishment device determining whether to generate a key replenishment instruction based on the key balance calculation result, and executing a key replenishment operation according to the generated key replenishment instruction. This invention only performs unified key balance monitoring on authenticated devices, has the ability to accurately correspond business data with devices, and flexibly performs key replenishment for different devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of key management technology, and in particular to a key replenishment device and its working method. Background Technology

[0002] In quantum-secure communication systems, quantum-secure devices (such as quantum key distribution terminals and quantum key management machines) need to maintain a certain number of available keys to ensure continuous operation. When the remaining key quantity in the device drops to a certain threshold, key replenishment needs to be performed promptly. Currently, the two most common key replenishment methods are as follows.

[0003] One approach involves the quantum-safe device itself monitoring its internal key reserves in real time. This method requires the device to continuously monitor and calculate the current key consumption and remaining amount. Once the key quantity reaches a preset replenishment threshold, the device proactively initiates a replenishment request to an external key management node or key replenishment organization. However, quantum-safe devices often have limited computing power. While undertaking core tasks such as key generation, negotiation, encryption, and decryption, they also need to allocate additional computing resources for real-time monitoring of key reserves and threshold judgment. This further increases the burden on the device and reduces the overall business processing efficiency. Moreover, this method is essentially a passive replenishment—the device only issues a request when keys are insufficient, and cannot predict and schedule replenishment in advance based on business dynamics.

[0004] Another approach involves an external key replenishment organization proactively sending query commands to each quantum-safe device, polling or periodically obtaining the remaining key quantity for each device, and then determining whether key replenishment is needed based on the feedback. While this method shifts the monitoring function from the quantum-safe devices to an external organization, the frequent query operations consume significant communication bandwidth, especially in scenarios with a large number of devices or limited network environments. Furthermore, the external organization needs to maintain the interaction state with all devices, increasing system complexity and signaling overhead.

[0005] Therefore, how to achieve efficient and timely key replenishment without significantly consuming the computing power of quantum-safe devices or excessively occupying communication bandwidth has become a technical problem that urgently needs to be solved in this field. Summary of the Invention

[0006] Purpose of the invention: This application provides a key replenishment device and its working method to solve the problems mentioned in the background art.

[0007] Technical solution: The present invention provides a key replenishment device, including a data interface module, a data storage module, a data statistics module, an instruction generation module, a key pool, and a configuration module, wherein the data interface module, data storage module, data statistics module, instruction generation module, and key pool are sequentially and communicatively connected, the data interface module is also communicatively connected to the key pool, and the instruction generation module is communicatively connected to the configuration module.

[0008] The data interface module is used to interact with the quantum-safe network management device and transmit data;

[0009] The data storage module is used to record the storage service information index table from the quantum security network management device and the device serial number and corresponding total number of keys of each quantum security device;

[0010] The data statistics module is used to count the key usage and calculate the key balance of each quantum security device under the jurisdiction of the quantum security network management device at the current time node.

[0011] The instruction generation module is used to generate key supplementation instructions based on the key supplementation threshold in the configuration module and the key balance in the data statistics module.

[0012] The configuration module is used to receive and store the key supplementation threshold configured by the user for the business service data of each quantum security device.

[0013] The key pool is used to perform key replenishment operations according to key replenishment instructions to generate replenishment keys.

[0014] As an improvement of the present invention, a temporary link is established between the data statistics module and the configuration module.

[0015] As an improvement of the present invention, the key replenishment device is either independent of the quantum secure network management device or integrated into the quantum secure network management device.

[0016] As an improvement to the present invention, a method for operating the key replenishment device is also provided, applied to the key replenishment device described above. The participants in the method include a quantum-safe network management device, a key replenishment device, a quantum-safe device, and a service server, wherein the quantum-safe network management device is connected to the key replenishment device, the quantum-safe device, and the service server, respectively. The method includes the following steps:

[0017] Step 1: The business server applies for business service registration with the quantum secure network management device. The quantum secure network management device generates a business information index table and sends it to the key replenishment device. The quantum secure device registers itself in advance with the quantum secure network management device and reports its total key count. The quantum secure network management device renumbers the quantum secure device and sends the corresponding total key count to the key replenishment device.

[0018] Step 2: The quantum-safe device initiates a service call request to the quantum-safe network management device, and the quantum-safe network management device notifies the key replenishment device to calculate the key balance locally based on the service call request;

[0019] Step 3: The key replenishment device determines whether to generate a key replenishment instruction based on the calculation result of the key balance, and performs the key replenishment operation according to the generated key replenishment instruction.

[0020] As an improvement of the present invention, in step 1, the specific process of the quantum secure network management device generating a service information index table and sending it to the key replenishment device includes:

[0021] After the business service registration is completed, the quantum secure network management system stores the business services provided by each business server, the content of the business services, the length of the business data and their corresponding data processing objects. Based on the one-to-one correspondence between the business services provided by each business server and the length of the business data L, a business information index table is generated and sent to the key supplementation device. The key supplementation device stores the business information index table in the data storage module of the key supplementation device.

[0022] As an improvement of the present invention, in step 1, the specific process of the quantum secure network management device re-numbering the quantum secure devices and sending the corresponding total key quantity to the key replenishment device includes:

[0023] The quantum-safe network management device renumbers the quantum-safe devices, obtains the device serial number of each quantum-safe device, stores it locally, and establishes a one-to-one correspondence between each device serial number and the total key of the corresponding quantum-safe device. This correspondence is then forwarded to the key replenishment device, which stores each device serial number and its corresponding total key in its data storage module.

[0024] As an improvement to the present invention, the specific process of step 2 includes:

[0025] The service call request includes the identity information of the quantum security device and the service that the quantum security device needs to call; the quantum security network management device performs identity authentication operation on the quantum security device based on the identity information of the quantum security device, retrieves the device serial number of the quantum security device that has passed the identity authentication operation locally, and sends the device serial number and the called service to the key replenishment device.

[0026] The data storage module of the key replenishment device retrieves the total key quantity (totalkey) of the quantum security device based on the device serial number, and retrieves the business data length (L) of the business service based on the business service in the business information index table.

[0027] The data storage module sends the business data length L, device serial number, and total key (totalkey) to the data statistics module of the key replenishment device. The data statistics module calculates the key remaining key (remainkey) after the business processing is completed based on the encryption strategy, total key (totalkey), and business data length L. The key remaining key value is then sent to the instruction generation module of the key replenishment device.

[0028] As an improvement to the present invention, step 2 further includes:

[0029] The data statistics module establishes a temporary link with the configuration module of the key replenishment device. Based on the device serial number, it reads the corresponding key replenishment threshold Krt and its setting format from the configuration module, stores the setting format in correspondence with the device serial number of the quantum security device, and converts the value of the key remainkey according to the setting format.

[0030] As an improvement to the present invention, the specific process of step 3 includes:

[0031] The instruction generation module obtains the key replenishment threshold Krt from the configuration module and compares it with the key balance remainkey: if remainkey≤Krt, a key replenishment instruction is generated and sent to the key pool of the key replenishment device; otherwise, no processing is performed.

[0032] The key pool performs a key replenishment operation according to the key replenishment instruction: generating a replenishment key Krep, which is then sent to the quantum-safe network management device via the data interface module.

[0033] Beneficial effects:

[0034] 1. The monitoring and threshold judgment of key balance are completed by an independent key replenishment device. Quantum security devices do not need to allocate additional computing resources for real-time monitoring, and can focus on core businesses such as key generation, negotiation and encryption / decryption, thereby improving overall processing efficiency.

[0035] 2. The key replenishment device of this invention only monitors the key balance of quantum-safe devices that have been certified by the quantum-safe network management device, and does not monitor devices that have not been certified. This mechanism not only ensures the timely replenishment of keys for legitimate devices, but also avoids invalid devices occupying monitoring resources, thus significantly improving the system's working efficiency.

[0036] 3. The key replenishment device of the present invention can establish a one-to-one correspondence between business service data and quantum security devices, and accurately perform key balance monitoring based on the specific business data processed by different quantum security devices; when the key balance reaches the replenishment threshold, it can promptly trigger a key replenishment operation for a specific quantum security device, thereby meeting differentiated business needs and making the system more flexible.

[0037] 4. The key replenishment device of the present invention can be connected to the quantum secure network management device independently of the quantum secure network management device as an external device; or it can be integrated into the quantum secure network management device in a modular manner. The diverse deployment forms enable the present invention to adapt to network environments of different scales, security levels and hardware conditions, reduce system transformation costs and improve the versatility of the technical solution. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 This is a schematic diagram of the key replenishment device for this application;

[0040] Figure 2 This is a schematic diagram of the key replenishment device for this application;

[0041] Figure 3 This is a schematic diagram showing the connections between the participants in the method of this application;

[0042] Figure 4 This is a flowchart illustrating the method described in this application. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0044] Based on the problems mentioned in the background art, the present invention provides a key replenishment device. For example... Figure 1 As shown, the key replenishment device includes a data interface module, a data storage module, a data statistics module, an instruction generation module, a key pool, and a configuration module. The data interface module, data storage module, data statistics module, instruction generation module, and key pool are sequentially and communicatively connected. The data interface module is also communicatively connected to the key pool, and the instruction generation module is communicatively connected to the configuration module. Furthermore, a temporary link can be established between the data statistics module and the configuration module.

[0045] The data interface module is used to interact with the quantum-safe network management device and transmit data;

[0046] The data storage module is used to record the storage service information index table from the quantum security network management device and the device serial number and corresponding total number of keys of each quantum security device;

[0047] The data statistics module is used to statistically analyze the key usage of each quantum security device under the jurisdiction of the quantum security network management device at the current time point, calculate the key surplus, and send the command generation module to the key replenishment device.

[0048] The instruction generation module is used to generate corresponding business service operation instructions, such as key replenishment and key recovery instructions, based on the key replenishment threshold in the configuration module and the key balance in the data statistics module.

[0049] The configuration module is used to receive and store parameters configured by the user for the business service data of each quantum security device, such as key replenishment threshold parameters.

[0050] The key pool is used to perform key replenishment operations according to key replenishment instructions to generate replenishment keys.

[0051] like Figure 2 As shown, the key replenishment device can exist independently of the quantum secure network management device and be connected to the quantum secure network management device as an external device, or the key replenishment device can be integrated into the quantum secure network management device and exist in the quantum secure network management device as a module.

[0052] Based on the above-described key replenishment device, the present invention also provides a method for operating the key replenishment device. For example... Figure 3 As shown, the participants in the method include a quantum-safe network management device, a key replenishment device, a quantum-safe device, and a service server, wherein the quantum-safe network management device is connected to the key replenishment device, the quantum-safe device, and the service server, respectively.

[0053] like Figure 4 As shown, the method includes the following steps:

[0054] Step 1: The business server applies for business service registration with the quantum security network management device and generates a business information index table; the quantum security device pre-registers with the quantum security network management device and reports its total key quantity; the quantum security network management device forwards the business information index table and the total key quantity of the quantum security device to the key replenishment device.

[0055] Specifically, the service servers providing services can register their services within the quantum-safe network management device. The service registration process can be referenced in the patent application number 2025111232180, "A Service Registration and Discovery Method." Specifically, after service registration, the quantum-safe network management system stores the service services provided by each service server, their service content, service data length, and corresponding data processing objects. The service can be a first service, a second service, ..., an nth service. Each service includes a service request content *con*, and each service request content *con* has its own service data length *L*, and a corresponding data processing object *obj*. Obtaining the service data length *L* provides data support for subsequent key balance monitoring. For example, the first service includes a first service request content *con1*, whose length is the service data length *L1*, and the corresponding data processing object *obj1* is the a-th quantum-safe device; the b-th service includes a b-th service request content *conb*, whose length is the service data length *Lb*, and the corresponding data processing object *objb* is the first quantum-safe device.

[0056] The quantum-safe network management system generates a service information index table based on the one-to-one correspondence between the service services provided by each service server and the length L of the service data, and sends it to the key replenishment device. The key replenishment device then stores the service information index table in its data storage module.

[0057] In embodiments of this invention, each quantum-secure device that needs to invoke the service must first register with the quantum-secure network management device and report its total key count, so that the quantum-secure network management device locally stores its own device ID and total key count (totalkey). The quantum-secure network management device re-numbers the quantum-secure devices to obtain a device serial number, stores it locally, and establishes a one-to-one correspondence between each device serial number and its corresponding total key count (totalkey). This is then forwarded to the key replenishment device, which stores each device serial number and its corresponding total key count (totalkey) in its data storage module. This step aims to ensure that the device ID of the quantum-secure device is not exposed to any entity outside the quantum-secure device and the quantum-secure network management device, thereby preventing attackers from interfering with the subsequent authentication process after obtaining the device ID.

[0058] After step 1 is completed, the key replenishment device locally stores information such as the business information index table and the total key count (totalkey) of each quantum security device.

[0059] Step 2: The quantum-safe device initiates a service call request to the quantum-safe network management device. Based on the service call request, the quantum-safe network management device notifies the key replenishment device to calculate the key balance locally.

[0060] Specifically, the service call request includes the identity information of the quantum secure device and the service that the quantum secure device needs to call. The quantum secure network management device first needs to perform an identity authentication operation on the quantum secure device based on its identity information. For quantum secure devices that pass the identity authentication operation, the quantum secure network management device retrieves the device serial number locally and sends the device serial number and the called service to the key replenishment device. The identity authentication process can be referenced in the patent application number CN202511784869.4, "An Identity Authentication Method Based on Quantum Security Tokens".

[0061] The data storage module of the key replenishment device retrieves the total key quantity (totalkey) of the quantum security device based on the device serial number, and retrieves the business data length (L) of the business service based on the business information index table.

[0062] The data storage module sends the business data length L, the device serial number, and the total key quantity (totalkey) of the quantum security device to the data statistics module of the key replenishment device. The data statistics module locally stores the encryption strategy. Based on the encryption strategy (e.g., encryption ratio ER), the total key quantity (totalkey), and the business data length L, the data statistics module calculates the remaining key quantity (remainkey) after the business processing is completed. This remaining key quantity (remainkey) is then sent to the instruction generation module of the key replenishment device. The calculation process is, for example: remainkey = totalkey - L × ER.

[0063] It should be noted that the configuration module stores different key replenishment thresholds (Krt) configured for different quantum security devices. Understandably, the configuration module can store each key replenishment threshold Krt according to the device serial number. The value of the key remainkey can be an absolute value or a percentage, and should have the same data format as the key replenishment threshold Krt configured for the corresponding quantum security device in the configuration module.

[0064] Therefore, this step may also include: establishing a temporary link between the data statistics module and the configuration module of the key replenishment device, reading the key replenishment threshold Krt and its setting format from the configuration module according to the device serial number, storing the setting format in correspondence with the device serial number of the quantum security device, and converting the value of the key remainkey according to the setting format.

[0065] The purpose of this step is to address the issue that key balance can be an absolute value or a percentage, and different quantum security devices may be configured with different formats for the key replenishment threshold Krt. Without standardizing the format, direct comparison will lead to errors. By temporarily reading the Krt format from the configuration module and storing it according to the device serial number of the current device, the data statistics module can convert the calculated key balance (remainkey) value into a format (absolute value or percentage) completely consistent with Krt. Only the converted key balance (remainkey) can be accurately compared with Krt. Standardizing the data formats of the key balance (remainkey) and the key replenishment threshold Krt, ensuring their comparability, lays the foundation for correctly determining whether key replenishment has been triggered.

[0066] Step 3: The key replenishment device determines whether to generate a key replenishment instruction based on the calculation result of the key balance, and performs the key replenishment operation according to the generated key replenishment instruction.

[0067] Specifically, the instruction generation module obtains the key replenishment threshold Krt from the configuration module and compares it with the value of the key balance remainkey: if remainkey≤Krt, a key replenishment instruction is generated and sent to the key pool of the key replenishment device; otherwise, no processing is performed.

[0068] The key pool performs a key replenishment operation according to the key replenishment instruction: generating a replenishment key Krep, which is sent to the quantum-safe network management device via the data interface module to ensure that the quantum-safe network management device has sufficient keys to perform business processing operations.

[0069] The key replenishment device and its working method provided by this invention not only avoid occupying the valuable computing power of quantum security devices, but also improve work efficiency by uniformly monitoring the key balance only for certified devices; at the same time, it has the ability to accurately match business data with devices, and can flexibly perform key replenishment for different devices.

Claims

1. A key replenishment device, characterized in that, It includes a data interface module, a data storage module, a data statistics module, an instruction generation module, a key pool, and a configuration module. The data interface module, data storage module, data statistics module, instruction generation module, and key pool are sequentially and communicatively connected. The data interface module is also communicatively connected to the key pool, and the instruction generation module is communicatively connected to the configuration module. The data interface module is used to interact with the quantum-safe network management device and transmit data; The data storage module is used to record the storage service information index table from the quantum security network management device and the device serial number and corresponding total number of keys of each quantum security device; The data statistics module is used to count the key usage and calculate the key balance of each quantum security device under the jurisdiction of the quantum security network management device at the current time node. The instruction generation module is used to generate key supplementation instructions based on the key supplementation threshold in the configuration module and the key balance in the data statistics module. The configuration module is used to receive and store the key supplementation threshold configured by the user for the business service data of each quantum security device. The key pool is used to perform key replenishment operations according to key replenishment instructions to generate replenishment keys.

2. The key replenishment device according to claim 1, characterized in that, A temporary link is established between the data statistics module and the configuration module.

3. The key replenishment device according to claim 1, characterized in that, The key replenishment device is either independent of or integrated into the quantum-safe network management device.

4. A method for operating a key replenishment device, applied to the key replenishment device according to any one of claims 1 to 3, characterized in that, The participants in the method include a quantum-safe network management device, a key replenishment device, a quantum-safe device, and a service server, wherein the quantum-safe network management device is connected to the key replenishment device, the quantum-safe device, and the service server, respectively; the method includes the following steps: Step 1: The business server applies for business service registration with the quantum secure network management device. The quantum secure network management device generates a business information index table and sends it to the key replenishment device. The quantum secure device registers itself in advance with the quantum secure network management device and reports its total key count. The quantum secure network management device renumbers the quantum secure device and sends the corresponding total key count to the key replenishment device. Step 2: The quantum-safe device initiates a service call request to the quantum-safe network management device, and the quantum-safe network management device notifies the key replenishment device to calculate the key balance locally based on the service call request; Step 3: The key replenishment device determines whether to generate a key replenishment instruction based on the calculation result of the key balance, and performs the key replenishment operation according to the generated key replenishment instruction.

5. The operating method of the key replenishment device according to claim 4, characterized in that, In step 1, the specific process by which the quantum-secure network management device generates a service information index table and sends it to the key replenishment device includes: After the business service registration is completed, the quantum secure network management system stores the business services provided by each business server, the content of the business services, the length of the business data and their corresponding data processing objects. Based on the one-to-one correspondence between the business services provided by each business server and the length of the business data L, a business information index table is generated and sent to the key supplementation device. The key supplementation device stores the business information index table in the data storage module of the key supplementation device.

6. The method of operating the key replenishment device according to claim 4, characterized in that, In step 1, the specific process by which the quantum-safe network management device re-numbers the quantum-safe devices and sends the corresponding total number of keys to the key replenishment device includes: The quantum-safe network management device renumbers the quantum-safe devices, obtains the device serial number of each quantum-safe device, stores it locally, and establishes a one-to-one correspondence between each device serial number and the total key of the corresponding quantum-safe device. This correspondence is then forwarded to the key replenishment device, which stores each device serial number and its corresponding total key in its data storage module.

7. The method of operating the key replenishment device according to claim 5 or 6, characterized in that, The specific process of step 2 includes: The service call request includes the identity information of the quantum security device and the service that the quantum security device needs to call; the quantum security network management device performs identity authentication operation on the quantum security device based on the identity information of the quantum security device, retrieves the device serial number of the quantum security device that has passed the identity authentication operation locally, and sends the device serial number and the called service to the key replenishment device. The data storage module of the key replenishment device retrieves the total key quantity (totalkey) of the quantum security device based on the device serial number, and retrieves the business data length (L) of the business service based on the business service in the business information index table. The data storage module sends the business data length L, device serial number, and total key (totalkey) to the data statistics module of the key replenishment device. The data statistics module calculates the key remaining key (remainkey) after the business processing is completed based on the encryption strategy, total key (totalkey), and business data length L. The key remaining key value is then sent to the instruction generation module of the key replenishment device.

8. The method of operating the key replenishment device according to claim 7, characterized in that, Step 2 also includes: The data statistics module establishes a temporary link with the configuration module of the key replenishment device. Based on the device serial number, it reads the corresponding key replenishment threshold Krt and its setting format from the configuration module, stores the setting format in correspondence with the device serial number of the quantum security device, and converts the value of the key remainkey according to the setting format.

9. The method of operating the key replenishment device according to claim 7, characterized in that, The specific process of step 3 includes: The instruction generation module obtains the key replenishment threshold Krt from the configuration module and compares it with the key balance remainkey: if remainkey≤Krt, a key replenishment instruction is generated and sent to the key pool of the key replenishment device; otherwise, no processing is performed. The key pool performs a key replenishment operation according to the key replenishment instruction: generating a replenishment key Krep, which is then sent to the quantum-safe network management device via the data interface module.

Citation Information

Patent Citations

  • Identity authentication method of token based on quantum security

    CN121309198A