Secure communication method, device and equipment based on quantum random number pre-distribution
Patent Information
- Application Number
- CN202611247742.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-18
- Publication Date
- 2026-09-22
AI Technical Summary
[0005]有鉴于此,本申请提供了一种基于量子随机数预分发的安全通信方法、装置及设备,主要目的在于解决现有技术在密钥安全性、管理复杂度、加密强度和抗篡改能力等方面均存在显著不足的问题
[0010]By employing the above technical solutions, this application provides a secure communication method, apparatus, and device based on quantum random number pre-distribution. Compared with existing secure communication technologies, this application constructs a trusted relay secure communication architecture based on quantum true random number pre-distribution by pre-configuring and synchronously writing a large number of quantum random numbers into a storage device in the communication terminal and data center. This allows the sending and receiving terminals to complete encrypted communication without relying on a real-time quantum key distribution link, effectively overcoming the problems of strong dependence on real-time quantum channels and high networking costs in traditional quantum key distribution networks. Regarding key security, using true random numbers generated based on the uncertainty principle of quantum mechanics as the one-time pad encryption key fundamentally eliminates the risk of key predictability. Even against a quantum computer, the key sequence cannot be derived, enabling the encryption scheme to reach the information theory security level. In terms of key management, by pre-distributing quantum random numbers and writing them into the storage device once and maintaining pre-synchronization, the online transmission and frequent updates of the key during communication are avoided. This eliminates the risk of key transmission being stolen and supports secure data exchange in offline or weak network environments, significantly simplifying the complexity of key management. Meanwhile, the data center uses pre-synchronized quantum random numbers to decrypt and re-encrypt data during relay forwarding. While ensuring the true randomness and unpredictability of the key materials throughout the process, it achieves efficient and secure interaction between the two communicating parties, improving the scenario adaptability and engineering practicality of quantum secure communication.
Smart Images

Figure CN122802152A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of secure communication technology, and in particular to a secure communication method, apparatus and device based on quantum random number pre-distribution. Background Technology
[0002] With the rapid development of information technology and the widespread adoption of the internet, secure data communication has become one of the most pressing issues in modern society. From personal privacy protection to the transmission of trade secrets, from military communication security to financial transaction safeguards, the need for secure data communication is ubiquitous, and it becomes increasingly urgent as digitalization deepens. In the current communication environment, users generate massive amounts of sensitive data daily, which faces various security threats during transmission, including theft, tampering, and replay attacks. In particular, with the rapid development of quantum computing technology, traditional encryption systems based on mathematical problems face the risk of being cracked, posing unprecedented challenges to secure communication technology.
[0003] In traditional secure communication technology systems, symmetric and asymmetric encryption are the two most common encryption methods. Symmetric encryption uses the same key to encrypt and decrypt data, offering high efficiency and speed, making it suitable for encrypting large amounts of data. Asymmetric encryption uses public and private keys for encryption and decryption, solving part of the key distribution problem; users can publicly share their public keys, while their private keys must be kept strictly confidential. Hash functions and digital signatures are important components of secure communication systems. Hash functions generate fixed-length digests of data, primarily used for data integrity verification and password storage. Digital signatures combine hash functions and asymmetric encryption to ensure data integrity, authenticity, and non-repudiation. Regarding key management, traditional Public Key Infrastructure (PKI) systems provide a complete public key management solution, requiring digital certificates to be issued and managed by trusted Certificate Authorities (CAs).
[0004] A comprehensive analysis of existing technical solutions reveals the following main problems and shortcomings of traditional secure communication systems. First, insufficient key security is a fundamental issue. Traditional encryption systems typically generate keys using pseudo-random number generators. Pseudo-random numbers, based on deterministic algorithms, can be predicted using a seed value, making them vulnerable to cracking. This risk is further exacerbated in the era of quantum computing. Second, complex key management is another prominent problem. Traditional encryption systems require secure storage and transmission of keys. Key distribution, updates, and revocation necessitate complex key management protocols and infrastructure support, a problem particularly acute in environments with massive user bases. Third, encryption strength is limited by computational power. The security of traditional encryption algorithms relies on the assumption of computational complexity, but with the improvement of computing power, especially the development of quantum computing, this assumption becomes increasingly unreliable. Finally, weak resistance to tampering is a common problem in traditional security systems. Traditional encryption systems are usually not tied to specific hardware devices, making them easily copied or ported to other devices. In conclusion, existing technologies have significant shortcomings in key security, management complexity, encryption strength, and resistance to tampering. Summary of the Invention
[0005] In view of this, this application provides a secure communication method, apparatus and device based on quantum random number pre-distribution, the main purpose of which is to solve the problems that existing technologies have significant shortcomings in terms of key security, management complexity, encryption strength and anti-tampering ability.
[0006] The first aspect provides a secure communication method based on quantum random number pre-distribution, the method including: A quantum random number storage device is configured in a communication terminal and a data center. A large number of quantum random numbers are pre-written in the quantum random number storage device. The communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random numbers in the quantum random number storage device are pre-synchronized between the transmitting terminal, the receiving terminal, and the data center. In response to a communication command from the transmitting terminal, the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet; The first encrypted data packet is sent to the data center, which decrypts the first encrypted data packet using the same quantum random number stored in its quantum random number storage device as the key of the sending terminal to obtain the original information; the data center then selects an unused quantum random number from the quantum random number storage device corresponding to the receiving terminal as the key to encrypt the original information a second time to obtain the second encrypted data packet. The second encrypted data packet is sent to the corresponding receiving terminal, which decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the key, and obtains the original information.
[0007] Secondly, a secure communication device based on quantum random number pre-distribution is provided, the device comprising: A configuration unit is used to configure a quantum random number storage device to a communication terminal and a data center. The quantum random number storage device is pre-written with a large number of quantum random numbers. The communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random numbers in the quantum random number storage device are pre-synchronized between the transmitting terminal, the receiving terminal, and the data center. An encryption unit is used to respond to a communication command from a transmitting terminal, wherein the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet; A sending unit is configured to send the first encrypted data packet to a data center, wherein the data center decrypts the first encrypted data packet using a quantum random number stored in its quantum random number storage device that is the same as that of the sending terminal as a key, to obtain the original information; the data center then selects an unused quantum random number from the quantum random number storage device corresponding to the receiving terminal as a key to perform secondary encryption on the original information, thereby obtaining a second encrypted data packet. The decryption unit is used to send the second encrypted data packet to the corresponding receiving terminal, which decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the same quantum random number as the data center as the key, and obtains the original information.
[0008] Thirdly, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the program to implement the above-described secure communication method based on quantum random number pre-distribution.
[0009] Fourthly, a computer storage medium is provided on which a computer program is stored, which, when executed by a processor, implements the above-described secure communication method based on quantum random number pre-distribution.
[0010] By employing the above technical solutions, this application provides a secure communication method, apparatus, and device based on quantum random number pre-distribution. Compared with existing secure communication technologies, this application constructs a trusted relay secure communication architecture based on quantum true random number pre-distribution by pre-configuring and synchronously writing a large number of quantum random numbers into a storage device in the communication terminal and data center. This allows the sending and receiving terminals to complete encrypted communication without relying on a real-time quantum key distribution link, effectively overcoming the problems of strong dependence on real-time quantum channels and high networking costs in traditional quantum key distribution networks. Regarding key security, using true random numbers generated based on the uncertainty principle of quantum mechanics as the one-time pad encryption key fundamentally eliminates the risk of key predictability. Even against a quantum computer, the key sequence cannot be derived, enabling the encryption scheme to reach the information theory security level. In terms of key management, by pre-distributing quantum random numbers and writing them into the storage device once and maintaining pre-synchronization, the online transmission and frequent updates of the key during communication are avoided. This eliminates the risk of key transmission being stolen and supports secure data exchange in offline or weak network environments, significantly simplifying the complexity of key management. Meanwhile, the data center uses pre-synchronized quantum random numbers to decrypt and re-encrypt data during relay forwarding. While ensuring the true randomness and unpredictability of the key materials throughout the process, it achieves efficient and secure interaction between the two communicating parties, improving the scenario adaptability and engineering practicality of quantum secure communication.
[0011] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0012] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a flowchart of a secure communication method based on quantum random number pre-distribution in one embodiment of this application; Figure 2 This is a flowchart of a secure communication method based on quantum random number pre-distribution in another embodiment of this application; Figure 3 yes Figure 2 A flowchart of a specific implementation method for step 202; Figure 4 yes Figure 3 A flowchart of a specific implementation method for step 302; Figure 5 yes Figure 3 A flowchart of a specific implementation method for step 303; Figure 6 This is a flowchart of a secure communication method based on a pre-distributed key secure communication system according to an embodiment of this application; Figure 7 This is a schematic diagram of the pre-distribution process of a pre-distribution key secure communication system according to an embodiment of this application; Figure 8 This is a flowchart of the signature generation and verification process in one embodiment of this application; Figure 9 This is a flowchart of a secure message relay distribution based on a quantum random number key library in one embodiment of this application; Figure 10 This is a structural block diagram of a secure communication device based on quantum random number pre-distribution in one embodiment of this application; Figure 11 This is a schematic diagram of the device structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0013] The present application will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the embodiments of the present application can be combined with each other.
[0014] In traditional secure communication technology systems, symmetric and asymmetric encryption are the two most common encryption methods. Symmetric encryption uses the same key to encrypt and decrypt data, offering high efficiency and speed, making it suitable for encrypting large amounts of data. Asymmetric encryption uses public and private keys for encryption and decryption, solving part of the key distribution problem; users can publicly share their public keys, while their private keys must be kept strictly confidential. However, a comprehensive analysis of existing technologies reveals significant shortcomings in traditional secure communication systems regarding key security, management complexity, encryption strength, and tamper resistance.
[0015] To address this issue, this embodiment provides a secure communication method based on quantum random number pre-distribution, such as... Figure 1 As shown, it includes the following steps: 101. Configure quantum random number storage devices in communication terminals and data centers.
[0016] In this embodiment, the communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random number storage device is configured in the transmitting terminal, the receiving terminal, and the data center, respectively. As a key carrier of the secure communication system, the quantum random number storage device is pre-written with a large number of quantum random numbers. These random numbers are generated by a quantum random number generator based on the uncertainty principle of quantum mechanics, and their output has true randomness, maintaining security even against attackers with quantum computers.
[0017] After the quantum random number storage device is deployed, the quantum random numbers in the storage device are pre-synchronized among the sending terminal, receiving terminal, and data center. Pre-synchronization refers to ensuring that the quantum random number sequences in the three storage devices are completely consistent in content and order through a secure initialization process before formal communication begins. Specifically, during system initialization, the system writes quantum random numbers generated in the same batch to the storage devices of each terminal and records a unified starting index and total quantity information. Subsequently, each terminal maintains an independent usage state pointer locally, eliminating the need to renegotiate or transmit keys during each communication, thus avoiding the security risks associated with online key distribution.
[0018] 102. In response to a communication command from the transmitting terminal, the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet.
[0019] In this embodiment, when the sending terminal receives a communication command from a user or upper-layer application, it first parses the command to determine the original information to be transmitted and its target receiving terminal. Then, the sending terminal reads an unused quantum random number from its locally configured quantum random number storage device as the key for this encryption operation. This selection process follows a sequential usage principle, automatically locating the next available random number segment through an internally maintained usage status pointer, ensuring that each quantum random number segment is used only once, satisfying the one-time pad requirement for key uniqueness and non-repeatability.
[0020] After obtaining the key, the sending terminal immediately performs an encryption operation on the original information. This encryption operation uses a quantum random number of the same length as the original information as the key stream, and completes the encryption process through bit-by-bit XOR or other information-theoretically secure symmetric encryption algorithms to generate the first encrypted data packet. Since the key length is equal to the plaintext length and is completely random and used only once, this encryption process theoretically achieves an information-theoretically secure level. Even if an attacker possesses unlimited computing power or a quantum computer, they cannot extract any deterministic content about the original information from the ciphertext. After encryption is complete, the sending terminal synchronously updates the usage status flag in its local quantum random number storage device, marking the used key segment as unusable to prevent subsequent communications from misusing the same key and ensuring the secure continuity of the entire key sequence.
[0021] The generated first encrypted data packet is then sent to the data center. Throughout the encryption and transmission process, the key remains internally stored in the quantum random number storage device of the sending terminal, never leaving the hardware in plaintext form, nor being transmitted over the network, thus completely avoiding the risk of the key being stolen or leaked during generation, use, and transmission. Furthermore, since the encryption operation relies entirely on locally pre-stored quantum random numbers, there is no need for real-time connection to a quantum key distribution network or online key negotiation. This allows the sending terminal to independently complete high-security encryption tasks offline or in environments with unstable networks, significantly improving the system's adaptability and engineering practicality.
[0022] 103. The first encrypted data packet is sent to the data center, which decrypts the first encrypted data packet using the same quantum random number stored in its quantum random number storage device as the key of the sending terminal to obtain the original information; the data center selects an unused quantum random number as the key from the quantum random number storage device corresponding to the receiving terminal to encrypt the original information a second time to obtain the second encrypted data packet.
[0023] In this embodiment, after the sending terminal completes one encryption, it sends the generated first encrypted data packet to the data center. Upon receiving the data packet, the data center locates a quantum random number that is completely identical to that of the sending terminal as the decryption key based on a pre-synchronization mechanism. Since the quantum random number storage devices of the sending terminal, receiving terminal, and data center have completed the synchronization of content and order during the initialization phase, and each independently maintains the same usage state pointer, the data center can accurately obtain the corresponding true random key without any real-time key negotiation or transmission with the sending terminal. After decrypting the first encrypted data packet using this key, the data center completely restores the original information. Throughout the entire process, the key remains in the local storage device without any form of online interaction, fundamentally eliminating the risk of the key being intercepted or tampered with during transmission.
[0024] After successfully obtaining the original information, the data center immediately initiates a secondary encryption process for the receiving terminal. Based on the receiving terminal identifier specified in the communication instructions, the next unused quantum random number is selected from a quantum random number storage device pre-synchronized with that terminal as the new key. This selection process also follows the principles of sequential use and one-time use, ensuring that the key used for secondary encryption is completely different from all previously used keys and is used only in this forwarding. Subsequently, the data center uses this new key to perform a one-pad encryption on the original information again, generating a second encrypted data packet. Because both encryptions use independent true random keys, and each encryption satisfies information-theoretic security conditions, even if an attacker intercepts both the first and second encrypted data packets simultaneously, they cannot deduce the original content or the key material at either end through correlation analysis.
[0025] The entire relay forwarding process relies entirely on pre-distributed quantum true random numbers to achieve secure end-to-end transmission. The data center neither undertakes key generation tasks nor participates in the key negotiation protocol; it only acts as a trusted relay node to perform decryption and re-encryption operations based on locally pre-stored keys. This design allows the system to maintain a full information-theoretic security level without deploying a real-time quantum key distribution link, while significantly reducing its dependence on network bandwidth and real-time performance. Furthermore, since all key operations are completed within dedicated hardware, and the key usage status is autonomously and synchronously updated by each end, the system naturally supports secure communication in offline or weak network environments, significantly improving the engineering feasibility and operational stability in large-scale networking scenarios.
[0026] 104. The second encrypted data packet is sent to the corresponding receiving terminal. The receiving terminal decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the key as the data center, and obtains the original information.
[0027] In this embodiment, after the data center completes secondary encryption to generate the second encrypted data packet, it sends it to the receiving terminal. Upon receiving the second encrypted data packet, the receiving terminal reads a quantum random number from its local quantum random number storage device that is completely identical to that of the data center, using it as the decryption key according to the pre-synchronization mechanism. Since the receiving terminal and the data center's quantum random number storage device have completed strict synchronization of content and order during the system initialization phase, and both independently maintain the same usage state pointer, the receiving terminal can accurately locate and obtain the corresponding true random key without any real-time key negotiation or online transmission with the data center. After using this key to decrypt the second encrypted data packet, the receiving terminal completely restores the original information. Throughout the entire decryption process, the key remains within the local dedicated hardware, without any form of network interaction, completely eliminating the security risk of the key being stolen or leaked at the receiving end.
[0028] While decrypting to obtain the original information, the receiving terminal synchronously updates the usage status flag in its quantum random number storage device, marking the used key segment as unusable. This ensures that subsequent communications will not reuse the same key, maintaining the integrity of the one-time pad system and the information theory security level. Since the quantum random number used for decryption is completely identical to the key used for encryption in the data center and is used only once, the decryption result is absolutely accurate, eliminating the risk of errors or failures due to key synchronization issues. Furthermore, the entire decryption operation relies entirely on locally pre-stored quantum true random numbers, without depending on external network connections or real-time key distribution services. This allows the receiving terminal to reliably restore information even offline, in weak network, or high-interference environments, significantly enhancing the system's robustness and availability in complex real-world scenarios.
[0029] At this point, the end-to-end secure communication process from the sending terminal to the receiving terminal is complete. All encryption and decryption operations are based on pre-distributed and pre-synchronized quantum true random numbers. The key is never transmitted in the network, nor exposed in plaintext at any intermediate node. The data center, acting as a trusted relay, only performs decryption and re-encryption based on its locally pre-stored key, ensuring both forwarding efficiency and maintaining information-theoretic security properties. The receiving terminal, as the final information recipient, has its decryption capability entirely determined by the pre-synchronization state of its local quantum random number storage device, requiring no additional authentication or key exchange protocols, significantly simplifying the security management complexity on the terminal side.
[0030] The secure communication method based on quantum random number pre-distribution provided in this application, compared with existing secure communication technologies, constructs a trusted relay secure communication architecture based on quantum true random number pre-distribution by pre-configuring and synchronously writing a large number of quantum random numbers into storage devices in communication terminals and data centers. This allows the sending and receiving terminals to complete encrypted communication without relying on real-time quantum key distribution links, effectively overcoming the problems of strong dependence on real-time quantum channels and high networking costs in traditional quantum key distribution networks. Regarding key security, using true random numbers generated based on the uncertainty principle of quantum mechanics as one-time pad encryption keys fundamentally eliminates the risk of key predictability. Even against quantum computers, the key sequence cannot be derived, achieving an information-theoretic security level for the encryption scheme. In terms of key management, by pre-distributing quantum random numbers and keeping them pre-synchronized, online transmission and frequent updates of keys during communication are avoided. This eliminates the risk of key transmission being stolen and supports secure data exchange in offline or weak network environments, significantly simplifying key management complexity. Meanwhile, the data center uses pre-synchronized quantum random numbers to decrypt and re-encrypt data during relay forwarding. While ensuring the true randomness and unpredictability of the key materials throughout the process, it achieves efficient and secure interaction between the two communicating parties, improving the scenario adaptability and engineering practicality of quantum secure communication.
[0031] In practical applications, the aforementioned secure communication method based on quantum random number pre-distribution can be applied to a pre-distributed key security system. This system includes a quantum random number generation center, a key distribution server, a data center, and user terminal equipment, specifically deployed within enterprise networks requiring secure communication. While maintaining compatibility with existing communication infrastructure, it also offers advantages such as high security, scalability, low latency, and ease of use. In one embodiment, the system can be deployed on various enterprise office equipment, mobile terminals, servers, and other devices, providing enterprises with one-time pad secure communication capabilities based on quantum random numbers. This design allows enterprises to quickly obtain communication security against future quantum computing attacks without large-scale modifications to their existing network architecture, significantly reducing deployment costs and technical barriers.
[0032] The quantum random number generation center is primarily responsible for generating truly random number sequences. This center employs a photon polarization-based quantum random number generator, based on the uncertainty principle of quantum mechanics. A single-photon source emits a single photon; a polarizer randomly selects either horizontal or vertical polarization; a detector measures the photon's polarization state; and random bits are generated based on the measurement results. The generated quantum random numbers undergo rigorous statistical testing to ensure the sequence exhibits good randomness. The random number sequences generated by the quantum random number generation center are stored in secure storage devices for subsequent key distribution, providing the entire system with an unpredictable and uncopyable truly random key source.
[0033] The key distribution server is responsible for distributing the random number sequences generated by the quantum random number generation center to the universal serial bus flash drives of user terminal devices. During the initialization phase, the key distribution server obtains a certain number of quantum random numbers from the quantum random number generator, generates a key library, and writes the encrypted key library to the user's universal serial bus flash drive. Simultaneously, the key distribution server is also responsible for generating the user's post-quantum cryptographic key pair, encrypting the private key and storing it on the universal serial bus flash drive, while transferring the public key to the data center for storage. This process ensures that each user possesses exclusive, hardware-protected key materials before first use, and that the private key always exists in encrypted form, effectively preventing the risk of key leakage during the initialization phase.
[0034] The data center is the core hub of the entire system, responsible for storing all users' public keys and quantum random number libraries, implementing user authentication, and routing and forwarding encrypted communication data. The data center's storage system employs a distributed architecture, capable of supporting key data storage for millions of users. Furthermore, through user classification and management, top-secret users should have their data stored on dedicated hardware, and should not share different partitions of the same storage medium with other users. This hierarchical isolation strategy ensures efficient access for ordinary users while providing additional physical protection for highly sensitive users, meeting the enterprise's differentiated management needs for data with different security levels.
[0035] The user terminal device includes a quantum random number universal serial bus flash drive and a secure communication application. The quantum random number universal serial bus flash drive serves as the hardware carrier for user authentication and key storage, incorporating a secure storage chip and a microcontroller. The secure storage chip securely stores the quantum random number keys, user private keys, and authentication credentials, providing security features such as read resistance, copy resistance, and tamper resistance. The microcontroller manages the various functions of the universal serial bus flash drive, including encryption operations and secure storage access. The device is initialized by the manufacturer at the factory, pre-writing a large number of quantum random number keys and unique post-quantum cryptographic private keys. The secure communication application provides a user interface, implements encryption and decryption functions, and supports multiple platforms including Apple mobile operating systems, Android operating systems, Windows operating systems, and Apple desktop operating systems. The application's encryption functions utilize the hardware interface of the universal serial bus flash drive, ensuring that key operations are performed in a secure hardware environment and eliminating the possibility of keys being stolen from host memory or at the operating system level.
[0036] While pre-synchronized quantum random numbers can ensure information security during data transmission, the system still needs to guard against man-in-the-middle attacks or the risk of unauthorized terminals impersonating legitimate nodes to access the network. If communication relies solely on pre-stored random numbers, an attacker who physically obtains or clones a terminal's storage device could impersonate a legitimate user to initiate or receive encrypted data. Therefore, a strong authentication system independent of the quantum random number transmission channel must be established. Furthermore, such as... Figure 2 As shown, after step 101 above, the method further includes the following steps: 201. Generate a corresponding post-quantum cryptographic key pair for each quantum random number storage device.
[0037] 202. Before the sending terminal communicates with the data center, two-way authentication is performed using the post-quantum cryptography key pair.
[0038] In this embodiment, the post-quantum cryptography key pair includes a public key and a private key. To ensure the absolute security of the private key, it is not stored in plaintext but is encrypted using the user-set password and then stored in the corresponding quantum random number storage device. This design ensures that even if the storage device is lost or illegally dismantled, attackers cannot extract or use the private key without knowing the user's password, thus achieving a strong binding between the private key and the user's identity. Simultaneously, the public key is stored in the data center through a pre-established encrypted transmission channel as the base credential for subsequent authentication. Since the public key itself is not sensitive, its transmission and storage process focuses on integrity and availability, ensuring that the data center can reliably obtain the identity of each legitimate terminal.
[0039] Before the transmitting terminal and the data center conduct encrypted communication based on quantum random numbers, both parties must perform a two-way authentication process using the aforementioned post-quantum cryptography key pair. The transmitting terminal first signs a specific challenge message using its locally decrypted private key and sends the signature to the data center. The data center verifies the validity of the signature using its pre-stored corresponding public key, thus confirming that the transmitting terminal possesses a legitimate private key and that it has not been tampered with. Simultaneously, the data center also returns a response message signed by its own private key to the transmitting terminal, which also verifies the signature using the data center's public key, thereby confirming that the other party is indeed a trusted data center and not a forged node. Only after both-way verifications are successful can the subsequent quantum random number selection and encrypted communication process begin. This mechanism ensures that mutual trust is established between the communicating parties before entering the high-security data transmission phase, effectively preventing unauthorized access and identity spoofing, and enabling the entire system to maintain information security while possessing authentication capabilities resistant to quantum computing attacks.
[0040] Specifically, such as Figure 3 As shown, step 202 above includes the following steps: 301. In response to a user login request from the sending terminal, the sending terminal sends the username and password to the data center so that the password can be verified by the data center.
[0041] 302. After the password verification is successful, the sending terminal obtains a quantum random number from its quantum random number storage device as a mask generation seed, performs a signature generation operation based on the mask generation seed, and generates user signature data containing a response, signature challenge, and prompt.
[0042] 303. The user signature data is sent to the data center, which looks up the corresponding public key matrix based on the username and performs a signature verification operation based on the public key matrix to verify the user signature data.
[0043] 304. After the user signature data is verified, the identity of the sending terminal is confirmed to be legitimate. The data center returns a verification pass response containing an authentication tag to the sending terminal. The sending terminal uses the pre-stored data center public key to verify the authentication tag.
[0044] 305. After the authentication label is verified, the identity of the data center is confirmed to be legitimate.
[0045] In this embodiment, the two-way authentication process is first triggered by a user login request from the sending terminal. When a user attempts to access the system, the sending terminal sends the username and password to the data center, which performs preliminary verification of the password. This step, as a basic identity screening mechanism, can quickly filter out unauthorized or incorrect access attempts. Only after the password verification is successful will the system enter the strong authentication phase based on post-quantum cryptography.
[0046] After successful password verification, the sending terminal retrieves a quantum random number from its quantum random number storage device as a mask generation seed. This seed is not an ordinary pseudo-random number, but rather originates from pre-distributed truly random key material, possessing unpredictability and information-theoretic security properties. Based on this mask generation seed, the sending terminal performs a signature generation operation, constructing user signature data containing the response, signature challenge, and hints. Because the signature process incorporates quantum true randomness as a mask, even if an attacker intercepts the signature data, they cannot deduce the private key or replay the signature through reverse engineering, effectively resisting side-channel attacks and replay attacks, ensuring the uniqueness and timeliness of the signature data.
[0047] Subsequently, the sending terminal transmits the generated user signature data to the data center. The data center looks up the corresponding public key matrix based on the received username and performs a signature verification operation based on this matrix to verify the user signature data. The public key matrix is a core verification parameter in post-quantum cryptography; its structure is resistant to quantum computing attacks, ensuring long-term security of identity authentication in a quantum computing environment. Only when signature verification is successful can the data center confirm that the sending terminal possesses a legitimate private key that has not been tampered with, thus determining its legitimacy.
[0048] After verifying the legitimacy of the sending terminal, the data center returns a verification success response containing an authentication tag. This authentication tag, generated by the data center using its own private key, proves that the response indeed originates from a trusted data center and is not a forged node. Upon receiving the response, the sending terminal verifies the authentication tag using its pre-stored data center public key. If the verification succeeds, the data center's legitimacy is confirmed, and the two-way authentication process is successfully completed. At this point, both communicating parties have established mutual trust. The entire verification process requires no transmission of private keys, and all sensitive operations are performed within local secure hardware, fully demonstrating the system's balanced design between quantum security and engineering practicality.
[0049] Specifically, such as Figure 4 As shown, step 302 above includes the following steps: 401. Generate a repeated sampling random mask vector based on the mask generation seed, and calculate the commitment value based on the public key matrix of the sending terminal.
[0050] 402. Take the high-order bits of the commitment value to obtain the high-order commitment value, and use a random oracle to generate a signature challenge as a sparse polynomial based on the high-order commitment value.
[0051] 403. Calculate the response based on the repeated sampling random mask vector, the signature challenge, and the private key. If the response does not meet the preset norm constraint, regenerate the repeated sampling random mask vector and repeat the above calculation until the response meets the preset norm constraint.
[0052] 404. Based on the response that meets the conditions and the signature challenge, a hint is generated through a hint function.
[0053] 405. Construct user signature data based on the response, the signature challenge, and the prompt.
[0054] In practice, the sending terminal first generates a repeatedly sampled random mask vector based on a mask generation seed obtained from a quantum random number storage device, and calculates the commitment value using its own public key matrix. Then, it extracts the high-order bits of the commitment value to obtain the high-order commitment value, and uses a random oracle to map this high-order commitment value into a sparse polynomial form signature challenge. This design compresses the high-entropy commitment value into structured challenge parameters, reducing communication overhead while maintaining sufficient security strength. Because the high-order commitment value originates from a quantum true random seed, its collision resistance and anti-prediction capabilities far exceed those of traditional methods, effectively enhancing the overall security of the signature protocol.
[0055] After receiving the signature challenge, the response value is calculated based on the repeated sampling random mask vector, the signature challenge, and the local private key. If the response does not meet the preset norm constraint, the current result is immediately discarded, a new repeated sampling random mask vector is generated, and the above calculation process is repeated until a response that meets the conditions is obtained. Since the mask seed comes from pre-distributed quantum true random numbers, the mask used in each retry has true independence, further improving the security boundary of rejection sampling.
[0056] Upon receiving a response that satisfies the norm constraint, a hint is generated by combining the response with the signature challenge using a hint function. The hint assists the verifier in efficiently reconstructing the commitment value, avoiding repeated complex calculations during verification, and concealing any sensitive intermediate states. Finally, the satisfying response, signature challenge, and hint are combined to construct the complete user signature data. This signature data structure is compact, verification is efficient, and the entire process relies on quantum true random numbers to drive key random parameters. This gives the entire signature generation process both information-theoretic security properties and post-quantum computation resistance, providing a solid and reliable cryptographic foundation for subsequent two-way authentication.
[0057] Specifically, such as Figure 5 As shown, step 303 above includes the following steps: 501. Based on the public key matrix and the response, reconstruct the commitment value, and use the prompt to recover the high-order commitment value from the reconstructed commitment value.
[0058] 502. Recalculate the signature challenge based on the recovered high-level commitment value.
[0059] 503. If the recalculated signature challenge is consistent with the signature challenge in the user signature data and the response satisfies the preset norm constraint, then the user signature data is determined to have passed verification.
[0060] 504. The authentication tag contained in the verification response returned by the data center is generated by the data center signing the verification result digest based on its private key; the sending terminal uses the pre-stored data center public key to verify the authentication tag.
[0061] In the specific verification process, the data center first reconstructs the original commitment value using the response and public key matrix from the user signature data, and then recovers the high-order commitment value from it using the prompt information. Since the prompt only contains the auxiliary information needed to recover the high-order commitment without revealing the complete commitment, this design ensures verification efficiency while avoiding the exposure of sensitive intermediate data. Subsequently, the signature challenge is recalculated based on the recovered high-order commitment value and compared with the signature challenge carried in the user signature data. Only when the two are completely identical and the response meets the preset norm constraint is the signature verification considered successful. This dual verification mechanism ensures that the signature is indeed generated by a legitimate private key and has not been tampered with or replayed, fully guaranteeing the authenticity and integrity of the sending terminal's identity.
[0062] After confirming the user's signature data verification is successful, the data center generates a verification success response containing an authentication tag. This authentication tag is generated by the data center using its own private key to sign the verification result digest. Since the verification result digest contains crucial contextual information such as username, timestamp, and verification status, signing it effectively prevents the authentication response from being replaced or reused in other sessions. Upon receiving the response, the sending terminal verifies the authentication tag using the data center's public key. If the verification is successful, the authentication tag is confirmed as verified, thus completing the verification of the data center's identity.
[0063] The entire verification process forms a symmetrical structure with the aforementioned signature data generation process. All calculations are performed based on public parameters and the received signature data, without involving any private key operations. Furthermore, since the reconstruction of the signature challenge relies on high-bit commitment values derived from a quantum true random seed, its collision resistance and anti-prediction capabilities are guaranteed at the information theory level, making the verification process itself capable of resisting future quantum computing attacks. The introduction of authentication tags extends post-quantum security attributes to the entire two-way authentication chain, ensuring that not only is the user's identity trustworthy, but the server's identity also withstands the test of the quantum era.
[0064] In practical applications, although the system employs a one-time pad encryption scheme based on quantum random numbers to ensure the confidentiality and unpredictability of single communication content, attackers may still intercept legitimate encrypted data packets and resend them in subsequent periods if time constraints are lacking. Therefore, by embedding the absolute timestamp of message transmission into the data packet and having the data center perform real-time comparison upon receipt, abnormal data packets exceeding the reasonable transmission delay range can be effectively identified and discarded. This adds a layer of temporal security protection on top of cryptographic security, forming a defense-in-depth system. Furthermore, the first encrypted data packet contains the absolute timestamp of message transmission. After step 103, the method further includes the following steps: The data center calculates the time difference between the current time and the absolute timestamp; If the time difference is within a preset time window, then the first encrypted data packet is confirmed to be valid; If the time difference is not within the preset time window, the first encrypted data packet is determined to be an expired data packet or a replay attack data packet, and the first encrypted data packet is refused to be processed.
[0065] In its implementation, the first encrypted data packet contains an absolute timestamp of the message transmission during the construction phase. An absolute timestamp is a time stamp generated based on a unified global time base, such as Coordinated Universal Time (UTC) or GPS timestamps. It is independent of local time zone settings and possesses global uniqueness and monotonically increasing properties. Upon receiving the first encrypted data packet, the data center immediately obtains its current system time and calculates the time difference between it and the absolute timestamp carried in the data packet. This time difference reflects the actual transmission time experienced by the data packet from sending to receiving, and also implicitly contains information about the degree of clock synchronization between the sending and receiving ends. The system presets a reasonable time window that comprehensively considers factors such as maximum network transmission latency, device clock drift tolerance, and service processing buffers. This avoids misjudging legitimate packets due to normal network jitter while promptly intercepting suspicious data with significant delays.
[0066] If the calculated time difference falls within a preset time window, the data center confirms the first encrypted data packet as a valid packet and allows it to proceed with subsequent decryption and business processing. This indicates that the data packet arrived within the expected time, conforms to normal communication behavior characteristics, and can be considered a fresh and tamper-proof legitimate request. Conversely, if the time difference exceeds the preset window range, whether it is earlier than the lower limit or later than the upper limit, the data center determines the data packet as an expired packet or a replay attack packet and immediately rejects its processing.
[0067] In pre-distributed key secure communication systems, while relying solely on time window verification can defend against most replay attacks, boundary risks still exist. For example, when network latency is exactly at the critical value of the time window, or when an attacker intercepts and immediately retransmits data packets within a very short time, a simple timestamp mechanism may not be able to completely identify duplicate requests. Therefore, introducing a deduplication mechanism based on monotonically increasing sequence numbers as a second line of defense after time window verification can prevent the repeated processing of the same data packet from the logical order level. Furthermore, the first encrypted data packet is configured with a unique sequence number that monotonically increases, and the data center maintains a list of sequence numbers successfully processed by each communication terminal; after confirming the validity of the first encrypted data packet, the method further includes: In practice, each sending terminal assigns a globally unique sequence number when constructing its first encrypted data packet. This sequence number is generated strictly according to a monotonically increasing rule, ensuring that the sequence numbers of subsequent data packets are always greater than all previously sent packets. The data center maintains an independent list of successfully processed sequence numbers for each registered communication terminal. This list records the sequence numbers of all data packets that the terminal has historically received and executed. After the data center completes the time window validity verification and determines that the data packet has not expired, it immediately extracts the sequence number from the data packet and compares it with the maximum value in the corresponding terminal's sequence number list. If the current sequence number is less than or equal to the maximum value recorded in the list, it means that the data packet is either an old packet that has been successfully processed before, or a historical packet that arrived out of order but has actually been overwritten. The system immediately classifies it as a duplicate data packet and refuses to process it.
[0068] The design of this sequence number deduplication mechanism fully considers the balance between efficiency and security in engineering implementation. Since the sequence number monotonically increases, the data center does not need to store all historical sequence numbers; it only needs to retain the current maximum value to quickly determine whether a newly arrived data packet is a duplicate, greatly reducing memory overhead and query complexity. Simultaneously, the sequence number, as metadata in the packet header, participates in integrity protection before encryption, preventing attackers from tampering with the sequence number to bypass checks. More importantly, this mechanism inherently supports breakpoint resumption and out-of-order tolerance: as long as the sequence number is greater than the current maximum value, even if there are missing sequence numbers in the middle, the system can still receive the packet and update the maximum value, avoiding session interruption due to temporary packet loss.
[0069] Furthermore, as a specific implementation of the above method, this application provides a secure communication system based on quantum random number pre-distribution keys. It achieves high-security end-to-end communication through a three-layer architecture consisting of a user device layer, a data transmission layer, and a data center layer. The user terminal uses a dedicated quantum random number storage device integrating a security chip and a microcontroller as a hardware root of trust. It internally pre-stores a massive amount of truly random keys and consumes them using a one-time pad mechanism, combined with a post-quantum cryptographic digital signature algorithm to complete identity authentication and data protection. The data center, as the core hub, uses a distributed architecture to store public keys for millions of users and a synchronized quantum random number library. It undertakes key functions such as two-way authentication, message routing and forwarding, and key lifecycle management, ensuring high efficiency and security in large-scale concurrent scenarios.
[0070] In terms of identity authentication and key management, the system utilizes post-quantum cryptographic signature technology to achieve two-way trust between users and the data center. During login, the system verifies user identity by signing challenge data with the private key, while the server returns the signature for terminal verification to prevent man-in-the-middle attacks. The quantum random number storage device employs partitioned management, physically isolating firmware, user credentials, keystore, and audit logs. The keystore is used in strict order according to index numbers, prompting for replacement or updating when exhausted. Private keys are encrypted with user passwords and stored locally, while public keys are securely uploaded to the data center, preventing the plaintext exposure of sensitive information throughout the process. Furthermore, all hash and signature operations use quantum-resistant algorithms, fundamentally resisting future computing threats.
[0071] The communication process strictly adheres to one-time pad encryption and multiple layers of replay protection. The sending terminal selects an unused quantum random number from its local keystore to encrypt the message, with the data packet carrying an absolute timestamp and a monotonically increasing sequence number. The data center first verifies the validity of the time window, then compares the maximum sequence number to eliminate duplicate or expired requests. Only after confirming legitimacy does it use the synchronization key to decrypt the original message and re-select an independent key for each receiving terminal to encrypt and forward it. The receiving terminal also needs to complete two-way authentication before decrypting and obtaining the plaintext. This mechanism combines one-time key consumption, time sequence verification, sequence number deduplication, and reception confirmation—four lines of defense—to completely block replay attacks and key reuse risks, ensuring the confidentiality, integrity, and freshness of each message.
[0072] To support a user base of millions, the system has undergone deep engineering optimization. The data center employs distributed storage and high-speed intranet interconnection, using public and private keys combined with hash tables and tree structures to achieve millisecond-level lookups. Message processing incorporates multi-threading and asynchronous input / output technologies, effectively improving concurrency throughput. A key synchronization mechanism ensures that user devices and the data center always hold completely identical copies of quantum random numbers, and automatically triggers a secure update process when key consumption reaches a threshold. The overall solution organically integrates information-theoretic one-time pad cryptography with post-quantum cryptography without relying on online key negotiation, balancing theoretical security, engineering feasibility, and large-scale deployment practicality, providing a future-proof secure communication infrastructure for highly sensitive scenarios.
[0073] Specifically, when a user needs to send a message to another user, the complete communication process begins with local authentication and message encryption preparation. The sending terminal first inserts the quantum random number storage device into the terminal and starts the secure communication application. After logging in by entering a username and password, the system enters a ready state after confirming the user's identity. The user then composes the message content in the application and specifies one or more receiving terminals. After clicking send, the application automatically selects a pair of unused quantum random numbers from the storage device's keystore as the encryption key, encrypts the original message, and generates an encrypted data packet containing the ciphertext and key index.
[0074] Before sending the data packet, the sending terminal must establish a secure connection with the data center and complete two-way authentication. Both parties verify each other's identity based on post-quantum cryptography private and public keys to ensure that both ends of the communication link are legitimate entities. After successful authentication, the sending terminal uploads the encrypted data packet to the data center via the wireless network. Upon receiving the data packet, the data center first performs a timestamp validity check to determine whether the message is within a preset time window to rule out the risk of replay attacks. After successful verification, it then uses the key index in the data packet to precisely extract the matching quantum random number key from the quantum random number library partition corresponding to the user, and uses this key to decrypt the encrypted content, restoring the original message.
[0075] After obtaining the original message, the data center selects a unique quantum random number key for each designated receiving terminal to re-encrypt the same original message, generating an independent ciphertext data packet corresponding to each receiving terminal. This design ensures that even if multiple users receive the same content, the ciphertext they receive will be completely different, and each key used is only valid in the current communication. Subsequently, the data center pushes these ciphertext data packets to the corresponding receiving terminals. Upon receiving the data packet, each receiving terminal must first complete two-way quantum cryptographic authentication with the data center to confirm the trustworthiness of the data source. After successful authentication, it then extracts the quantum random number key matching the data packet index from its own quantum random number storage device to decrypt the ciphertext, ultimately securely obtaining the original message.
[0076] Furthermore, as a specific implementation of the above method, this embodiment of the invention provides a secure communication method based on a pre-distributed key secure communication system. This method mainly includes four parts: manufacturer initialization, user initialization, user authentication, and secure communication. The overall process is as follows: Figure 6 As shown. It includes the following steps: During the manufacturer's initialization phase: The manufacturer is responsible for designing and building a quantum random number generation center and data center, and pre-distributing post-quantum cryptography keys and quantum random number libraries to user storage devices and data center databases.
[0077] In the manufacturer's initialization process, the manufacturer designs and builds a quantum random number generation center and a data center, pre-distributing post-quantum cryptography keys and quantum random number libraries to user storage devices and data center databases. The quantum random number generator can be based on three types: random photon polarization, vacuum fluctuations, or radioactive decay. It generates random numbers by measuring the polarization state of a single photon, the quantum fluctuations in the vacuum state, or the time interval of radioactive atomic nucleus decay, respectively. The randomness is ensured through rigorous statistical tests, including the NIST SP800-22 test suite, the ENT test, and the Diehard test.
[0078] The manufacturer divides users into multiple security levels based on their security needs and access privileges. High-level users have 2 million pairs of quantum random number keys pre-installed on each storage device, mid-level users have 1 million pairs, and ordinary users have 500,000 pairs. Different user levels have different configurations in terms of storage partitions, communication permissions, and audit log retention times. Subsequently, a quantum cryptography algorithm is used to generate a digital signature key for each storage device. Taking the quantum cryptography algorithm as an example, the key generation software requests a random array as a seed from the quantum random number generator. Through hash expansion, central binomial distribution sampling, and high-bit compression, a public key and a private key are obtained. The private key is stored in the user's storage device, and the public key is stored in the user identity data area of the data center. Combined with... Figure 7The system architecture shown in this embodiment of the invention, and the pre-distribution process of the pre-distribution key secure communication system, can be described in detail as follows: like Figure 7 As shown, the entire pre-distribution system consists of a data center, a quantum random number generation center, user storage devices (USB flash drive A and USB flash drive B), and corresponding communication devices (user A's smartphone and user B's desktop computer). The quantum random number generation center, as the infrastructure, has a built-in highly reliable quantum random number generator responsible for batch generating quantum random number sequences with true randomness and unpredictability, and constructing two independent quantum random number libraries, denoted as... and It is used to serve different user groups or communication counterparts.
[0079] During the pre-distribution phase, the quantum random number generation center first synchronously outputs two sets of post-quantum cryptographic public keys to the data center: Public Key and The public key is generated by a post-quantum signature algorithm, and its private key... and The data is then written to the corresponding user storage devices, USB flash drive A and USB flash drive B, respectively, to achieve the security principle of private keys not leaving the devices and public keys being centrally managed. Meanwhile, the quantum random number library... Fully pre-installed on USB drive A, quantum random number library The entire system is pre-installed on USB drive B, with each library containing a number of key pairs configured according to user permission levels. All key pairs are stored in encrypted form in a dedicated secure area of the USB drive and can only be accessed by a trusted execution environment after local account and password verification.
[0080] USB flash drives A and B are physically distributed to users A and B, respectively. Users connect them to their respective terminal devices (such as mobile phones or computers). The system automatically recognizes and initiates the initialization process, completing the username and password settings, thereby binding the user's identity, local private key, and hardware carrier. During subsequent communication, users A and B do not need to negotiate keys online; they only need to perform a one-time one-pad encryption based on a pre-distributed quantum random number library, combined with a post-quantum digital signature, to achieve strong authentication and message integrity assurance.
[0081] In conclusion, Figure 7 It clearly demonstrates the process of deploying key materials synchronously to user terminal devices and data centers, starting from the quantum random number generation center and through a dual-track pre-distribution path of keys and random numbers.
[0082] During the user initialization process, after receiving a quantum random number USB drive from the quantum random number generation center, the user performs an initial account and password setup. The user inserts the USB drive into the USB port of their computer or mobile device, and the system automatically detects the USB drive and starts the initialization program. The user needs to set a username and password. The username is used to uniquely identify the user in the system, and the password is used to protect the security of the private key and password stored on the USB drive. The username and password are hashed using a hash algorithm and then stored in the user area of the USB drive.
[0083] In the user authentication process, the user and the data center authenticate each other using a combination of account-based cryptography and post-quantum cryptography key pairs. When logging in, the user enters their username and password. After verifying the password's correctness, the system uses the user's private key stored in the storage device to sign random challenge data, generating signature data. The system then sends the username and signature data to the data center. The data center uses the username to look up the corresponding public key to verify the signature's correctness. If the verification is successful, it confirms that the user possesses the correct private key. Simultaneously, the data center generates server-side signature data and returns it to the user's device. The user's device uses the data center's public key to verify the signature, confirming the data center's identity, effectively preventing man-in-the-middle attacks and identity forgery attacks. Figure 8 The flowchart shown illustrates the signature generation and verification process during the user authentication phase in this embodiment of the invention, which can be specifically described as follows: Figure 8 The complete interaction process of algorithm-based post-quantum digital signature between the user (User A) and the data center is clearly presented. It is divided into the user-side signature generation module on the left and the data center verification module on the right. The two are represented by dashed arrows to indicate the data transmission and feedback mechanism, and together they form a closed-loop two-way authentication process.
[0084] In the user-side signature generation module on the left, after user A completes account and password verification, they invoke the locally stored post-quantum private key to initiate the signature process. The system first generates a random mask vector by repeatedly sampling from the central binomial distribution. Then, the commitment is calculated based on the pre-shared public key matrix A. ,right Get the high bit Then, a challenge is generated using a random oracle. Calculate the response vector ,in, This is the secret vector. The system then checks whether the condition is met. If so, then regenerate the random mask vector. until the condition is met, after passing through the function Generate prompts ,in, This is the secret vector. The final output contains the response. ,challenge and prompts User signature And send it to the data center.
[0085] In the data center verification module on the right, the system receives the signature. After the username, retrieve the corresponding user's public key matrix A and public key. First, based on the response in the signature... With tips And recalculate the challenge vector from the public key matrix A. And based on this, rebuild the commitment Then, two key verifications are performed: first, to confirm whether the conditions are met. Secondly, to verify the commitments made during the reconstruction. Whether it matches the commitment calculated on the user's end. If both verifications are true, the challenge is considered successful and the identity verification is passed; otherwise, the challenge is considered to have failed and the verification result is fed back to the user's end.
[0086] In the secure communication process, after successful user authentication, one-to-one or one-to-many secure communication can commence. The sender composes a message and designates recipients. The application then selects a pair of quantum random numbers from its storage device's keystore as the encryption key to encrypt the message and generate an encrypted data packet. After completing two-way quantum cryptography authentication with the data center, the data packet is sent to the data center via the wireless network. The data center verifies the timestamp's validity to rule out replay attacks. Based on the key index, it searches for the key in the corresponding quantum random number library partition and decrypts the message to obtain the original text. Then, it selects the corresponding quantum random number key for each recipient to re-encrypt and generate ciphertext data packets, which are then sent separately. Upon receiving the ciphertext data packet, each recipient completes two-way quantum cryptography authentication with the data center, decrypts the ciphertext using the corresponding quantum random number from its own storage device, and obtains the original message, completing the end-to-end secure communication loop.
[0087] For details on the secure message relay distribution process based on quantum random number key libraries, please refer to... Figure 9 As shown, the overall architecture consists of three parts: the sending end (user A) on the left, the central data center, and the receiving ends (users B and C) on the right. The relationships between these modules are represented by dashed arrows, forming a complete and reliable message distribution loop.
[0088] At User A's sending end, the device first selects a pair of unused quantum random number keys from a quantum random number key library stored on a local USB flash drive. Then, using these keys, it performs a one-pad encryption operation on the original plaintext message, generating an encrypted data packet containing the sender's identifier, receiver's identifier, timestamp, sequence number, key index, encrypted content, and message authentication code. After establishing a secure connection with the data center, User A's device sends this encrypted data packet to the data center.
[0089] Upon receiving the encrypted data packet, the data center first verifies the validity of the timestamp and checks the sequence number to rule out the risk of replay attacks or expired messages. After successful verification, the data center uses the key index in the data packet to precisely locate and extract the one-time key used for this communication from the quantum random number library partition corresponding to user A. This key is then used to decrypt the encrypted content, restoring the original message.
[0090] After decryption, the data center selects new unused quantum random number keys from their respective dedicated quantum random number library partitions for users B and C. The system uses these two independent keys to perform one-pad encryption on the same message plaintext, generating two independent ciphertext data packets. Each data packet contains necessary fields such as the corresponding recipient's identifier, the new key index, a timestamp, and a message authentication code. Finally, the data center sends these two ciphertext data packets to users B and C respectively, achieving fine-grained key isolation for multicast messages.
[0091] After receiving their respective encrypted data packets, users B and C first authenticate with the data center to confirm the trustworthiness of the message source. Once authentication is successful, both parties retrieve the corresponding one-time quantum random number key from their local USB key repository based on the key index in the data packet, and use this key to decrypt the encrypted message to obtain the original message. Simultaneously, the system verifies the message authentication code to ensure that the data has not been tampered with during transmission, ultimately completing end-to-end secure message reception and integrity verification.
[0092] In the secure communication process of this embodiment, the system employs multiple protection strategies to ensure the freshness and uniqueness of data communication. The first layer of protection is a timestamp verification mechanism, where each encrypted data packet contains a Coordinated Universal Time (UTC) timestamp from when the message was sent. Upon receiving a data packet, the data center immediately calculates the difference between this timestamp and the current system time and determines whether it falls within a preset reasonable time window. In this embodiment, this time window is set to five minutes. Any data packet exceeding this window is deemed expired or subject to a replay attack, and the system directly rejects it, thereby effectively resisting replay attacks based on time delays.
[0093] The second layer of protection is a sequence number verification mechanism. The system assigns a globally unique sequence number to each data packet, and this sequence number maintains a monotonically increasing characteristic. The data center maintains a recently processed sequence number list for each user. When a new data packet is received, the system compares the sequence number in the packet with the maximum value recorded in this list. If the received sequence number is less than or equal to the maximum value in the list, the data packet is determined to be old data that has been repeatedly sent, and the system will refuse to process it, thus completely blocking the injection of replay data at the logical level.
[0094] The third layer of protection is the one-time use key mechanism, which is the core element ensuring one-time pad security. The quantum random number key used in each communication is limited to one use only. After encryption, the key is immediately marked as used and permanently removed from the available key store. Even if an attacker intercepts historical ciphertext and attempts to replay it, the attacker cannot decrypt it using the expired key because the recipient's corresponding key has expired or been destroyed, ensuring forward security and replay resistance.
[0095] The fourth layer of protection is the reception confirmation and key update retransmission mechanism. After successfully receiving the data packet from the sender, the data center will return a reception confirmation message to the sender. If the sender does not receive this confirmation message within a specified time limit, the system will trigger the retransmission process. It is important to emphasize that retransmission is not simply resending the original ciphertext, but rather re-encrypting the message with a new quantum random number key before retransmission. This design effectively prevents the reuse of historical ciphertext during network transmission, further enhancing the dynamic security of the communication process.
[0096] The pre-distributed key secure communication system and method proposed in this invention achieves a unified balance of high security, scalability, low latency, and ease of use while remaining compatible with existing communication infrastructure through the synergistic effect of the aforementioned four protection strategies. This system not only meets the stringent requirements of enterprises for data confidentiality, integrity, and resistance to quantum attacks, but also possesses excellent engineering feasibility, making it widely applicable to various enterprise-level secure communication scenarios in government, finance, energy, and defense sectors.
[0097] Furthermore, as a specific implementation of the above method, embodiments of this application provide a secure communication device based on quantum random number pre-distribution, such as... Figure 10 As shown, the device includes: a configuration unit 61, an encryption unit 62, a sending unit 63, and a decryption unit 64.
[0098] Configuration unit 61 is used to configure a quantum random number storage device to a communication terminal and a data center. The quantum random number storage device is pre-written with a large number of quantum random numbers. The communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random numbers in the quantum random number storage device are pre-synchronized between the transmitting terminal, the receiving terminal, and the data center. The encryption unit 62 is used to respond to a communication command from a transmitting terminal, wherein the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet; The sending unit 63 is used to send the first encrypted data packet to the data center, where the data center decrypts the first encrypted data packet using the same quantum random number stored in its quantum random number storage device as the key as the sending terminal to obtain the original information; the data center then selects an unused quantum random number as the key from the quantum random number storage device corresponding to the receiving terminal to encrypt the original information a second time to obtain the second encrypted data packet. The decryption unit 64 is used to send the second encrypted data packet to the corresponding receiving terminal. The receiving terminal decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the key as the data center, and obtains the original information.
[0099] The secure communication device based on quantum random number pre-distribution provided in this invention, compared with existing secure communication technologies, constructs a trusted relay secure communication architecture based on quantum true random number pre-distribution by pre-configuring and synchronously writing a large number of quantum random numbers into a storage device in the communication terminal and data center. This allows the sending and receiving terminals to complete encrypted communication without relying on a real-time quantum key distribution link, effectively overcoming the problems of strong dependence on real-time quantum channels and high networking costs in traditional quantum key distribution networks. Regarding key security, using true random numbers generated based on the uncertainty principle of quantum mechanics as the one-time pad encryption key fundamentally eliminates the risk of key predictability. Even against a quantum computer, the key sequence cannot be derived, achieving an information-theoretic security level for the encryption scheme. In terms of key management, by pre-distributing quantum random numbers and keeping them pre-synchronized, online transmission and frequent updates of the key during communication are avoided. This eliminates the risk of key transmission being stolen and supports secure data exchange in offline or weak network environments, significantly simplifying key management complexity. Meanwhile, the data center uses pre-synchronized quantum random numbers to decrypt and re-encrypt data during relay forwarding. While ensuring the true randomness and unpredictability of the key materials throughout the process, it achieves efficient and secure interaction between the two communicating parties, improving the scenario adaptability and engineering practicality of quantum secure communication.
[0100] In specific application scenarios, the device further includes: The generation unit is configured to generate a corresponding post-quantum cryptographic key pair for each quantum random number storage device after configuring the quantum random number storage device to the communication terminal and the data center. The post-quantum cryptographic key pair includes a public key and a private key. The private key is encrypted using a password set by the user and then stored in the corresponding quantum random number storage device. The public key is stored in the data center through a pre-established encrypted transmission channel. The verification unit is used to perform two-way authentication using the post-quantum cryptography key pair before the sending terminal communicates with the data center.
[0101] In specific application scenarios, the verification unit is specifically used for: In response to a user login request from a sending terminal, the sending terminal sends the username and password to a data center for verification of the password by the data center. After the password verification is successful, the sending terminal obtains a quantum random number from its quantum random number storage device as a mask generation seed, performs a signature generation operation based on the mask generation seed, and generates user signature data containing a response, signature challenge and prompt. The user signature data is sent to the data center, which looks up the corresponding public key matrix based on the username and performs a signature verification operation based on the public key matrix to verify the user signature data. After the user signature data is verified, the identity of the sending terminal is confirmed to be legitimate. The data center returns a verification success response containing an authentication tag to the sending terminal. The sending terminal uses the pre-stored data center public key to verify the authentication tag. The identity of the data center is confirmed to be legitimate after the authentication label is verified.
[0102] In specific application scenarios, the verification unit is further used for: A repeated sampling random mask vector is generated based on the mask generation seed, and the commitment value is calculated based on the public key matrix of the sending terminal. The high-order commitment value is obtained by taking the high-order bits of the commitment value, and a random oracle is used to generate a signature challenge as a sparse polynomial based on the high-order commitment value. Based on the repeated sampling random mask vector, the signature challenge, and the private key, the response is calculated. If the response does not meet the preset norm constraint, the repeated sampling random mask vector is regenerated and the above calculation is repeated until the response meets the preset norm constraint. Hints are generated using a hint function based on responses that meet the conditions and signature challenges; User signature data is constructed based on the response, the signature challenge, and the prompt.
[0103] In specific application scenarios, the verification unit is further used for: Based on the public key matrix and the response, the high-order commitment value is recovered from the reconstructed commitment value using the hint; The signature challenge is recalculated based on the recovered high-level commitment value; If the recalculated signature challenge is consistent with the signature challenge in the user signature data and the response satisfies the preset norm constraint, then the user signature data is determined to have passed verification. The authentication tag included in the verification response returned by the data center is generated by the data center signing the verification result digest based on its private key; the sending terminal verifies the authentication tag using the pre-stored data center public key, specifically including: using the data center public key to verify the authentication tag, and confirming that the authentication tag has been verified when the verification is successful.
[0104] In a specific application scenario, the first encrypted data packet contains an absolute timestamp of message transmission; the device further includes: The calculation unit is configured to, after the first encrypted data packet is sent to the data center, have the data center calculate the time difference between the current time and the absolute timestamp; The confirmation unit is used to confirm that the first encrypted data packet is valid if the time difference is within a preset time window. The confirmation unit is further configured to determine the first encrypted data packet as an expired data packet or a replay attack data packet and refuse to process the first encrypted data packet if the time difference is not within a preset time window.
[0105] In a specific application scenario, the first encrypted data packet is configured with a unique sequence number that monotonically increases, and the data center maintains a list of sequence numbers that have been successfully processed by each communication terminal; the device further includes: The determination unit is configured to, after confirming that the first encrypted data packet is valid, determine that the first encrypted data packet is a duplicate data packet if the sequence number of the first encrypted data packet is less than or equal to the maximum value in the sequence number list, and refuse to process the first encrypted data packet.
[0106] Based on the above-described secure communication method based on quantum random number pre-distribution, this application also provides a storage medium storing a computer program that, when executed by a processor, implements the above-described secure communication method based on quantum random number pre-distribution.
[0107] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.
[0108] Based on the above-described secure communication method based on quantum random number pre-distribution and the corresponding virtual device embodiment, in order to achieve the above objectives, this application embodiment also provides a physical device for secure communication based on quantum random number pre-distribution, which may be a computer, smartphone, tablet computer, smartwatch, server, or network device, etc. The physical device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to implement the above-described secure communication method based on quantum random number pre-distribution.
[0109] Optionally, the physical device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.
[0110] In an exemplary embodiment, see Figure 11 The aforementioned physical device includes a communication bus, a processor, a memory, and a communication interface. It may also include an input / output interface and a display device. The various functional units can communicate with each other via the bus. The memory stores a computer program, and the processor executes the program stored in the memory to perform the secure communication method based on quantum random number pre-distribution described in the above embodiments.
[0111] Those skilled in the art will understand that the physical device structure for secure communication based on quantum random number pre-distribution provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.
[0112] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the physical device for secure communication based on quantum random number pre-distribution, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing physical device.
[0113] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented using software plus necessary general-purpose hardware platforms, or it can be implemented in hardware. By applying the technical solution of this application, compared with the existing methods, this application constructs a trusted relay secure communication architecture based on the pre-distribution of quantum true random numbers by pre-configuring and synchronously writing a large number of quantum random numbers into the storage device in the communication terminal and data center. This enables the sending terminal and the receiving terminal to complete encrypted communication without relying on a real-time quantum key distribution link, effectively overcoming the problems of strong dependence on real-time quantum channels and high networking costs in traditional quantum key distribution networks.
[0114] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.
[0115] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.
Claims
1. A secure communication method based on quantum random number pre-distribution, characterized in that, include: A quantum random number storage device is configured in a communication terminal and a data center. A large number of quantum random numbers are pre-written in the quantum random number storage device. The communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random numbers in the quantum random number storage device are pre-synchronized between the transmitting terminal, the receiving terminal and the data center. In response to a communication command from the transmitting terminal, the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet; The first encrypted data packet is sent to the data center, which decrypts the first encrypted data packet using the same quantum random number stored in its quantum random number storage device as the key of the sending terminal to obtain the original information; the data center then selects an unused quantum random number from the quantum random number storage device corresponding to the receiving terminal as the key to encrypt the original information a second time to obtain the second encrypted data packet. The second encrypted data packet is sent to the corresponding receiving terminal, which decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the key, and obtains the original information.
2. The method according to claim 1, characterized in that, After configuring the quantum random number storage device to the communication terminal and the data center, the method further includes: A corresponding post-quantum cryptographic key pair is generated for each quantum random number storage device. The post-quantum cryptographic key pair includes a public key and a private key. The private key is encrypted using a password set by the user and then stored in the corresponding quantum random number storage device. The public key is stored in the data center through a pre-established encrypted transmission channel. Before the sending terminal communicates with the data center, two-way authentication is performed using the post-quantum cryptography key pair.
3. The method according to claim 2, characterized in that, The two-way authentication using the post-quantum cryptography key pair includes: In response to a user login request from a sending terminal, the sending terminal sends the username and password to a data center for verification of the password by the data center. After the password verification is successful, the sending terminal obtains a quantum random number from its quantum random number storage device as a mask generation seed, performs a signature generation operation based on the mask generation seed, and generates user signature data containing a response, signature challenge and prompt. The user signature data is sent to the data center, which looks up the corresponding public key matrix based on the username and performs a signature verification operation based on the public key matrix to verify the user signature data. After the user signature data is verified, the identity of the sending terminal is confirmed to be legitimate. The data center returns a verification success response containing an authentication tag to the sending terminal. The sending terminal uses the pre-stored data center public key to verify the authentication tag. The identity of the data center is confirmed to be legitimate after the authentication label is verified.
4. The method according to claim 3, characterized in that, The signature generation operation based on the mask seed generates user signature data containing a response, signature challenge, and prompt, including: A repeated sampling random mask vector is generated based on the mask generation seed, and the commitment value is calculated based on the public key matrix of the sending terminal. The high-order commitment value is obtained by taking the high-order bits of the commitment value, and a random oracle is used to generate a signature challenge as a sparse polynomial based on the high-order commitment value. Based on the repeated sampling random mask vector, the signature challenge, and the private key, the response is calculated. If the response does not meet the preset norm constraint, the repeated sampling random mask vector is regenerated and the above calculation is repeated until the response meets the preset norm constraint. Hints are generated using a hint function based on responses that meet the conditions and signature challenges; User signature data is constructed based on the response, the signature challenge, and the prompt.
5. The method according to claim 3, characterized in that, The step of performing a signature verification operation based on the public key matrix to verify the user signature data includes: Based on the public key matrix and the response, the high-order commitment value is recovered from the reconstructed commitment value using the hint; The signature challenge is recalculated based on the recovered high-level commitment value; If the recalculated signature challenge is consistent with the signature challenge in the user signature data and the response satisfies the preset norm constraint, then the user signature data is determined to have passed verification. The authentication tag included in the verification response returned by the data center is generated by the data center signing the verification result digest based on its private key; the sending terminal verifies the authentication tag using the pre-stored data center public key, specifically including: using the data center public key to verify the authentication tag, and confirming that the authentication tag has been verified when the verification is successful.
6. The method according to any one of claims 1-5, characterized in that, The first encrypted data packet contains an absolute timestamp of the message being sent; After sending the first encrypted data packet to the data center, the method further includes: The data center calculates the time difference between the current time and the absolute timestamp; If the time difference is within a preset time window, then the first encrypted data packet is confirmed to be valid; If the time difference is not within the preset time window, the first encrypted data packet is determined to be an expired data packet or a replay attack data packet, and the first encrypted data packet is refused to be processed.
7. The method according to claim 6, characterized in that, The first encrypted data packet is configured with a unique sequence number that monotonically increases, and the data center maintains a list of sequence numbers that have been successfully processed by each communication terminal; after confirming that the first encrypted data packet is valid, the method further includes: If the sequence number of the first encrypted data packet is less than or equal to the maximum value in the sequence number list, the first encrypted data packet is determined to be a duplicate data packet, and the first encrypted data packet is rejected.
8. A secure communication device based on quantum random number pre-distribution, characterized in that, include: A configuration unit is used to configure a quantum random number storage device to a communication terminal and a data center. The quantum random number storage device is pre-written with a large number of quantum random numbers. The communication terminal includes a transmitting terminal and at least one receiving terminal. The quantum random numbers in the quantum random number storage device are pre-synchronized between the transmitting terminal, the receiving terminal, and the data center. An encryption unit is used to respond to a communication command from a transmitting terminal, wherein the transmitting terminal selects an unused quantum random number as a key based on its quantum random number storage device to encrypt the original information once, thereby obtaining a first encrypted data packet; A sending unit is configured to send the first encrypted data packet to a data center, wherein the data center decrypts the first encrypted data packet using a quantum random number stored in its quantum random number storage device that is the same as that of the sending terminal as a key, to obtain the original information; the data center then selects an unused quantum random number from the quantum random number storage device corresponding to the receiving terminal as a key to perform secondary encryption on the original information, thereby obtaining a second encrypted data packet. The decryption unit is used to send the second encrypted data packet to the corresponding receiving terminal, which decrypts the data packet using the same quantum random number stored in its quantum random number storage device as the key, and obtains the original information.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.