Earthquake early warning information tamper-proofing method based on quantum encryption communication

CN122802257APending Publication Date: 2026-09-22YUNNAN SEISMOLOGICAL BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611165108.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-03
Publication Date
2026-09-22

Smart Images

  • Figure CN122802257A_ABST
    Figure CN122802257A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of identity authentication, and discloses a tamper-proofing method for earthquake warning information based on quantum encryption communication, which comprises: key distribution between a main station, a backup station and a warning command center of earthquake warning, and generation of basic quantum key clusters representing core keys of quantum encryption communication; the technical solution shares the same set of basic quantum key clusters by the main station, the backup station and the warning command center, and generates unique identification keys by using differential quantum coding, so that the main station and the backup station have unforgeable identity credentials; when the main station and the backup station are switched, the backup station generates station switching verification information, the warning command center receives and verifies the identity legality and information integrity, and only when both are matched, the earthquake warning information is output, otherwise, it is blocked and an alarm is given; the present application effectively prevents attackers from disguising as backup stations during the switching window period, and improves the tamper-proofing ability and security of mountainous earthquake warning in data communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity verification technology, specifically to a method for preventing tampering of earthquake early warning information based on quantum encrypted communication. Background Technology

[0002] Currently, the anti-tampering scheme for earthquake early warning information based on quantum encrypted communication mainly adopts the following approach: an unconditionally secure shared key is generated between the sending and receiving ends of the early warning information through a quantum key distribution mechanism, and the early warning information payload is encrypted and protected based on a one-time pad or near one-time pad symmetric encryption algorithm. On this basis, a two-way authentication mechanism between the sending and receiving ends is combined to confirm the legitimacy of the entities of the two communicating parties, thereby effectively resisting attacks such as eavesdropping, tampering and forgery during the transmission of earthquake early warning information through classical channels. However, the above-mentioned anti-tampering methods still have the following drawbacks: In mountainous earthquake monitoring, the front-end monitoring stations need to transmit real-time early warning information to the early warning command center located in the city through quantum encrypted communication links. In particular, the mountainous environment is complex and the probability of equipment failure is high. Therefore, a main and backup station switching mechanism is usually designed. That is, when the main station cannot work due to communication interruption, equipment abnormality or power failure, it will automatically switch to the backup station, and the backup station will continue to send early warning information. However, since the authentication process of the backup station is exactly the same as that of the primary station, that is, both use the same type of authentication, this method makes it easy for attackers to take advantage of the switching window caused by the failure of the primary station to impersonate the backup station and send tampered earthquake early warning information to the command center. Since the command center cannot distinguish the legitimacy of the legitimate backup station from the malicious forged node during the verification process, it is unable to quickly identify the forged identity, which easily makes the anti-tampering mechanism fail. Summary of the Invention

[0003] To address the shortcomings of existing technologies, this invention provides a method for preventing tampering of earthquake early warning information based on quantum encrypted communication, thus solving the aforementioned problems.

[0004] The above-mentioned technical objective of the present invention is achieved through the following technical solution: Methods for preventing tampering of earthquake early warning information based on quantum encrypted communication include: Step S1: Key distribution is performed between the primary and backup earthquake early warning stations and the early warning command center to generate a basic quantum key cluster representing the core key of quantum encrypted communication. Step S2: Obtain the station codes of the primary station and the backup station respectively. Based on the basic quantum key cluster, generate identification keys representing the unique identity of the primary station and the backup station respectively using differentiated quantum coding method. After encrypting the station codes through the basic quantum key cluster, the encrypted station codes are obtained. Step S3: When the main station is working normally, it collects earthquake early warning information, encrypts the early warning information with the basic quantum key cluster and the identification key of the main station, generates encrypted early warning information, and performs quantum operations on the encrypted early warning information, the identification key of the main station and the basic quantum key cluster to generate a tamper-proof verification code that represents the integrity of the information. Step S4: When the primary station fails and triggers the primary / standby switchover, the standby station uses its own identification key and the encrypted warning information to be sent to sign its identity and generate station switchover verification information representing the switchover authorization certificate. In step S5, after receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts the information using the basic quantum key cluster and performs identity verification based on the station switching verification information to generate verification indicators representing the legality of the backup station's identity and the integrity of the early warning information.

[0005] Furthermore, key distribution is performed between the primary and backup earthquake early warning stations and the early warning command center to generate a basic quantum key set representing the core key of quantum encrypted communication, including: Key distribution is performed between the primary station, backup station, and early warning command center to generate encoded quantum states; The encoded quantum state is modified to generate a basic quantum key cluster representing the core key of quantum encrypted communication. The basic quantum key cluster is the same set of basic quantum key clusters held by the primary station, the backup station and the early warning and command center.

[0006] Furthermore, based on the fundamental quantum key cluster, differentiated quantum coding methods are used to generate unique identification keys for the primary and backup stations, representing their respective identities, including: Differentiated mapping is performed on the basic quantum key cluster to generate key encoding offsets that represent the differentiating identities of the corresponding stations; Differentiated encoding is applied to the key encoding offset and station encoding to generate unique identification keys for the primary station and the backup station.

[0007] Furthermore, after encrypting the station code using a basic quantum key cluster, the encrypted station code is obtained, including: The station code is encrypted using the basic quantum key cluster to obtain the encrypted station code.

[0008] Furthermore, after encrypting the warning information using the basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity, including: The basic quantum key cluster and the identification key of the master station are mixed and encrypted to generate an encryption control factor for adjusting the encryption strength and uniqueness of the early warning information; Based on the encryption control factor, combined with the basic quantum key cluster and the identification key of the primary station, the earthquake early warning information is encrypted to generate encrypted early warning information.

[0009] Furthermore, after encrypting the warning information using the basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity. This also includes: Based on the encrypted early warning information, its quantum encryption features are extracted and combined with the basic quantum key cluster and the identification key of the main station to generate a verification feature value for associating the encrypted early warning information with the identity identifier. The verification feature value, encrypted early warning information, the identification key of the main station, and the basic quantum key cluster are used to perform collaborative operations to generate a tamper-proof verification code that represents proof of information integrity.

[0010] Furthermore, when a primary station failure triggers a switchover, the backup station uses its own identification key and the encrypted warning information to be sent to sign its identity, generating station switchover verification information representing the switchover authorization credential, including: When the primary station is detected to switch to the backup station, the backup station calls its own identification key and combines it with the basic quantum key cluster to sign, generating a signature control factor used to regulate the uniqueness and security of the identity signature. Based on the signature control factor and the identifier key of the backup station, the encrypted station code of the backup station is identity-signed to generate station identity signature information used to prove the legitimate identity of the backup station.

[0011] Furthermore, when a primary station failure triggers a primary / standby switchover, the standby station uses its own identification key and the encrypted warning information to be sent to perform an identity signature, generating station switchover verification information representing the switchover authorization credential, which also includes: The anti-tampering verification code, station identity signature information and encrypted early warning information are quantum-linked and bound to generate a signature association verification value for associating identity signature and early warning information. Based on the signature-related verification value, the identification key and tamper-proof verification code of the backup station are quantum encrypted to generate station handover verification information representing the handover authorization certificate.

[0012] Furthermore, after receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts them using a basic quantum key cluster and performs identity verification based on the station switching verification information, generating verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information, including: After receiving the station switching verification information and encrypted early warning information, the early warning command center calls the basic quantum key cluster to perform layered decryption processing and generate a verification calibration factor used to regulate the accuracy of identity comparison and verification code verification.

[0013] Furthermore, after receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts them using a basic quantum key cluster and performs identity verification based on the station switching verification information. This generates verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information, including: Based on the verification calibration factor, the backup station identification key is compared with the encrypted station code of the backup station, and the consistency between the anti-tampering verification code and the encrypted early warning information is verified to generate a verification index representing the legality of the backup station's identity and the integrity of the early warning information. When the verification indicator passes, an earthquake early warning message is output; when the verification indicator fails, the transmission of the earthquake early warning message is immediately blocked and an alarm is triggered.

[0014] In summary, the present invention has the following main beneficial effects: By sharing the same basic quantum key set among the primary and backup stations and the early warning command center, and using differentiated quantum encoding methods to generate unique identification keys for each station, the primary and backup stations possess distinct and unforgeable identity credentials. Secondly, when the primary station is operating normally, the early warning information is strongly encrypted and its integrity protected through encryption control factors and tamper-proof verification codes. When the primary station fails and triggers a switchover, the backup station generates station switchover verification information and quantum-binds the identification key, encrypted station code, tamper-proof verification code, and early warning information. Upon receiving this information, the early warning command center generates a verification calibration factor through layered decryption and simultaneously compares the identity legitimacy and verifies the information integrity. Only when both the identity comparison value and the integrity verification value match the verification calibration factor is the earthquake early warning information output; otherwise, it is immediately blocked and an alarm is triggered. This ensures that attackers cannot exploit the switchover window to impersonate a legitimate backup station, thus improving the tamper-proof capability and security of earthquake early warning information transmission in mountainous areas. Attached Figure Description

[0015] Figure 1 This is a flowchart illustrating the steps of the earthquake early warning information anti-tampering method based on quantum encrypted communication of the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0017] refer to Figure 1 A method for preventing tampering of earthquake early warning information based on quantum encrypted communication includes: Step S1: Key distribution is performed between the primary and backup earthquake early warning stations and the early warning command center to generate a basic quantum key cluster representing the core key of quantum encrypted communication. Step S2: Obtain the station codes of the primary station and the backup station respectively. Based on the basic quantum key cluster, generate identification keys representing the unique identity of the primary station and the backup station respectively using differentiated quantum coding method. After encrypting the station codes through the basic quantum key cluster, the encrypted station codes are obtained. The station codes are either the station ID or the station number. Step S3: When the main station is working normally, it collects earthquake early warning information, encrypts the early warning information with the basic quantum key cluster and the identification key of the main station, generates encrypted early warning information, and performs quantum operations on the encrypted early warning information, the identification key of the main station and the basic quantum key cluster to generate a tamper-proof verification code that represents the integrity of the information. Step S4: When the primary station fails and triggers the primary / standby switchover, the standby station uses its own identification key and the encrypted warning information to be sent to sign its identity and generate station switchover verification information representing the switchover authorization certificate. In step S5, after receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts the information using the basic quantum key cluster and performs identity verification based on the station switching verification information to generate verification indicators representing the legality of the backup station's identity and the integrity of the early warning information.

[0018] In one embodiment, key distribution is performed between the primary earthquake early warning station, the backup earthquake early warning station, and the early warning command center to generate a basic quantum key set representing the core key of quantum encrypted communication, including: Key distribution is performed between the primary station, backup station, and early warning command center to generate encoded quantum states. Specifically, this includes: establishing a distribution link between the primary station, backup station, and early warning command center; generating an initial key seed based on a quantum random number generator; and encoding the initial key seed into a quantum state: mapping the binary information of the initial key seed into the corresponding quantum state to achieve the quantization conversion of the key information, thereby generating the encoded quantum state.

[0019] The encoded quantum state is modified to generate a basic quantum key cluster representing the core key of quantum encrypted communication. The basic quantum key cluster is the same set of basic quantum key clusters held by the primary station, backup station, and early warning command center. Specifically, this includes: compensating for and deleting the encoded quantum state. Compensation mainly compensates for phase shifts and amplitude attenuation during quantum state transmission, while deletion removes erroneous keys and invalid keys generated during transmission. The basic quantum key cluster is a 128-bit binary key.

[0020] By distributing the same basic quantum key set among the primary station, backup station, and early warning command center, and ensuring unconditional security of the quantum key, the risk of forgery attacks caused by identical authentication processes in existing primary / backup switching mechanisms is resolved. When the primary station switches to the backup station due to a mountainous environment malfunction, the backup station can directly use the same basic quantum key set as the primary station for two-way authentication and encryption of early warning information with the early warning command center. Even if an attacker takes advantage of the switching window to impersonate the backup station, their forged authentication request will be quickly identified and rejected by the early warning command center because they cannot obtain the shared basic quantum key set. At the same time, the initial key seed generated by the quantum random number generator undergoes encoding, compensation, and deletion correction processes to ensure high fidelity and low error rate of the basic quantum key set, thereby effectively resisting eavesdropping, tampering, and forgery during channel transmission and improving the anti-tampering capability of earthquake early warning information transmission in mountainous areas.

[0021] In one embodiment, based on the basic quantum key cluster, differentiated quantum coding is used to generate unique identification keys for the primary station and the backup station, representing their respective identities, including: Differentiated mapping is performed on the basic quantum key cluster to generate key encoding offsets that represent the different identities of the corresponding stations. Specifically, the first 8 bits of the basic quantum key cluster are used as the mapping reference. Unique reference coefficients are assigned to the primary station and the backup station respectively. The reference coefficient for the primary station is set to 17 and that for the backup station is set to 29. The mapping reference is then calculated with the reference coefficient of the corresponding station. During the calculation, the mapping reference is first converted to a decimal value, then added to the reference coefficient, and divided by 16. The remainder is taken as the key encoding offset of the corresponding station. The key encoding offset is mainly used to represent the different identities of the stations. The range of the key encoding offset is 1-16. During the calculation, if the result is 0, the key encoding offset is corrected to 16 to ensure that the key encoding offset is unique and non-zero. The selection of a primary station reference coefficient of 17, a backup station reference coefficient of 29, and a remainder after division by 16 is intended to ensure, under the premise of uniformly using the first 8 bits of the basic quantum key cluster as the mapping reference, that when the primary and backup stations are added together after dividing by 16, a fixed, non-repeating key encoding offset distributed within the range of 1-16 is obtained. At the same time, using 16 as the modulus can both constrain the operation result to a reasonable range of bits suitable for the subsequent 32-bit station encoding shift operation and ensure that the offset does not exceed the effective number of bits of the shift operation. This avoids the problems of duplicate station identity identifiers and encryption logic conflicts caused by excessive offsets or identical primary and backup offsets, thereby effectively realizing differentiated quantum encoding of primary and backup station identities.

[0022] Differentiated encoding is performed on the key encoding offset and station encoding, generating unique identification keys for the primary station and the backup station respectively. Specifically, the station encoding adopts 8-bit decimal encoding, which is first converted into 32-bit binary encoding, and the middle 32 bits of the 128-bit basic quantum key cluster are extracted as the encoding base. Different shift operations are used for the primary station and the backup station. Specifically, the primary station shifts its 32-bit binary station code to the left according to its corresponding key code offset, that is, shifts the entire 32-bit binary code to the left by the number of bits corresponding to the key code offset, and fills the empty bits with 0. The backup station shifts its 32-bit binary station code to the right according to its corresponding key code offset, that is, shifts the entire 32-bit binary code to the right by the number of bits corresponding to the offset, and fills the empty bits with 0. For the primary station and the backup station, the shifted station code is XORed with the 32-bit code base, and the result is then extended to 32 bits. Any missing bits are padded with 0s and concatenated with the key code offset to generate a 64-bit binary identification key. Thus, the primary station and the backup station each have their own unique identification key.

[0023] Using the first 8 bits of the basic quantum key cluster as a mapping benchmark, and combining the primary station benchmark coefficient and the backup station benchmark coefficient, fixed and non-repeating key encoding offsets are obtained. Then, through differentiated shift operations (left shift of the primary station and right shift of the backup station) and bitwise XOR and concatenation operations, an identification key strongly correlated with the station encoding is generated. Since attackers cannot know the basic quantum key cluster, nor can they simultaneously obtain the correct key encoding offset and shift direction, even if a switchover window occurs due to a primary station failure, attackers cannot impersonate the backup station to send tampered information to the early warning command center. The early warning command center can quickly distinguish between legitimate backup stations and malicious forged nodes through the pre-stored identification key, solving the problem in the existing scheme where the same primary and backup authentication process cannot identify forged identities, and enhancing the anti-tampering capability of earthquake early warning information transmission in mountainous areas.

[0024] In one embodiment, the station code is encrypted using a basic quantum key cluster to obtain an encrypted station code, including: The station code is encrypted using the basic quantum key cluster to obtain the encrypted station code. Specifically, this involves converting the 8-bit decimal station code into a 32-bit binary code, using the last 32 bits of the 128-bit basic quantum key cluster as the encryption key, and then performing a bitwise XOR operation between the 32-bit binary station code and the encryption key. The bitwise XOR operation compares corresponding bits of the 32-bit binary station code and the 32-bit encryption key one by one. If the corresponding two bits have the same binary value (e.g., both are 0 or both are 1), the result of the bitwise operation is 0; if the corresponding two bits have different binary values ​​(e.g., one is 0 and the other is 1), the result of the bitwise operation is 1. After all the corresponding 32 bits have been processed, a 32-bit intermediate encryption result is obtained. Then, the intermediate encryption result is added to the mapping base that has been diffused to 32 bits and padded with 0s where necessary. The last 32 bits of the calculation result are used as the final encrypted station code.

[0025] By converting the station code into 32-bit binary, the last 32 bits of the basic quantum key cluster are used as the encryption key for bitwise XOR operation. The result is then added to the 32-bit mapping reference to obtain the encrypted station code. This encryption process strongly correlates the station code with the basic quantum key cluster, and each encryption relies on the shared quantum key. Attackers cannot forge or tamper with the encrypted station code without mastering the basic quantum key cluster. When the primary station fails and switches to the backup station, the early warning and command center can first decrypt the received encrypted station code and quickly compare whether the decrypted station code matches the preset station identity, thereby effectively distinguishing between legitimate backup stations and malicious forged nodes. Because the encrypted station code has quantum-level confidentiality during transmission, attackers cannot use the switching window to spoof their identity, solving the problem of the anti-tampering mechanism failing due to the identical primary and backup authentication processes in existing solutions.

[0026] In one embodiment, after encrypting the warning information using a basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity, including: The basic quantum key cluster and the identification key of the main station are mixed and encrypted to generate an encryption control factor for adjusting the encryption strength and uniqueness of the early warning information. Specifically, for the first 64 bits and the last 32 bits of the basic quantum key cluster, the first 64 bits are used as the first encryption segment and the last 32 bits are used as the auxiliary control segment. The identification key of the primary station is divided into two segments: the first 32 bits and the last 32 bits. First, the first 32 bits of the identification key are padded with zeros to extend it to 64 bits. Then, the first encrypted segment is XORed with the extended identification key to obtain a 64-bit first operation result. Next, the auxiliary control segment is XORed with the last 32 bits of the identification key to obtain a 32-bit second operation result. The second operation result is padded with zeros to extend it to 64 bits. Perform a bitwise XOR operation on the two results to obtain a 64-bit hybrid core result. Convert the 64-bit hybrid core result into a decimal value. Add the decimal value of the first 8 bits of the basic quantum key cluster mapping benchmark to the main station key encoding offset. Then add the units digit and the tens digit of the sum to obtain the exclusive control coefficient. The transformed hybrid core result is multiplied by the first 8 bits of the basic quantum key cluster mapping benchmark, then divided by the dedicated control coefficient, rounded down to obtain an integer, and then converted into a 64-bit binary number, which is the encryption control factor used to control the encryption strength and uniqueness of the early warning information.

[0027] Based on the encryption control factor, combined with the basic quantum key cluster and the identification key of the main station, the earthquake early warning information is encrypted to generate encrypted early warning information. Specifically, the earthquake early warning information is in the form of a combination of text and numbers. First, it is converted into a string using UTF-8 encoding. Then, each character of the string is converted into an 8-bit binary number. After concatenation, it is padded to 256 bits of binary data and then divided into four 64-bit early warning data segments. The first 64 bits, the middle 32 bits, and the last 32 bits of the 128-bit basic quantum key cluster are used as the first auxiliary key, the second auxiliary key, and the third auxiliary key, respectively. The last two 32-bit auxiliary keys are padded with zeros to expand to 64 bits. For the encryption control factor, the four warning data segments are segmented and controlled according to its decimal value. That is, the first segment is the warning data segment plus the encryption control factor and the remainder is taken after dividing by 8; the second segment is the warning data segment plus the encryption control factor and the remainder is taken after dividing by 12; the third segment is the warning data segment plus the encryption control factor and the remainder is taken after dividing by 16; and the fourth segment is the warning data segment plus the encryption control factor and the remainder is taken after dividing by 20. Each warning data segment is first XORed with the corresponding auxiliary key, and then cyclically shifted XORed with the master station identification key: the identification key is cyclically shifted left according to the number of bits corresponding to the remainder result of the segment, and then the cyclically shifted identification key is XORed with the XORed warning data segment to obtain a 64-bit encrypted segment. Finally, the four processed data segments are concatenated in order to obtain an encrypted warning message of 256 bits of binary data. The modulo 8, modulo 12, modulo 16, and modulo 20 mentioned above refer to performing remainder operations on the warning data segments. Specifically, the decimal value corresponding to each 64-bit warning data segment is first added to the decimal value of the control factor, and then divided by 8, 12, 16, and 20 respectively, retaining only the final remainder. The purpose is to use four sequentially increasing and distinct moduli to form differentiated cyclic shift control values ​​for the four warning data segments, so that each warning information segment uses a different number of shift bits when it is processed with the main station identification key, avoiding insufficient security due to repetitive encryption rules.

[0028] In one embodiment, after encrypting the warning information using a basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity. The method further includes: Based on the encrypted early warning information, its quantum encryption features are extracted and combined with the basic quantum key cluster and the identification key of the main station to generate a verification feature value for associating the encrypted early warning information with the identity identifier. Specifically, the 256-bit encrypted early warning information is divided into four 64-bit segments. For the binary numbers of the 1st, 16th, 32nd, 48th and 64th bits of each segment, they are concatenated to form a 20-bit quantum encryption feature. The first and last 32 bits of the 128-bit basic quantum key cluster are concatenated to form a 64-bit key feature, while the 64-bit master station identification key remains unchanged. The 20-bit quantum encryption feature is padded with zeros to expand it to 64 bits. It is then subjected to a bitwise XOR operation with the 64-bit key feature and the 64-bit identification key to obtain a 64-bit intermediate verification sequence. The intermediate verification sequence is then split into groups of two bits each, and the first bit of each group is taken to form a new sequence, resulting in a 32-bit temporary sequence. This temporary sequence is then subjected to a bitwise XOR operation with the first 32 bits of the encryption control factor to obtain a 32-bit result. This result is then concatenated with the last 32 bits of the encryption control factor to finally generate a 64-bit verification feature value used to associate encrypted warning information with identity identification.

[0029] The verification feature value, encrypted early warning information, identification key of the main station, and basic quantum key cluster are used in a collaborative operation to generate an anti-tampering verification code that represents the proof of information integrity. Specifically, the basic quantum key cluster is split into groups of 16 bits each, and the sum of the odd and even bits of each group after splitting is used as its weight coefficient. The identification key of the main station is also divided into 8 8-bit segments. The 8 sets of weight coefficients are sequentially matched with the 8 8-bit segments of the identification key. Each set of weight coefficients is multiplied by each bit of the corresponding 8-bit segment. The product results of each segment are added together. The resulting 8 8-bit fusion results are concatenated into a 64-bit weighted fusion result. The encrypted warning information is then divided into 32 byte segments, with each byte consisting of 8 bits. Each byte segment is matched with the corresponding two bits of the 64-bit check feature value. That is, the byte segment is converted to decimal, the corresponding two bits of the check feature value are converted to decimal, and the difference between the two is taken to obtain 32 decimal difference values. The absolute value of each difference is taken and modulo 256. That is, for each difference, the absolute value of the difference is divided by 256 and the remainder is taken to obtain a value between 0 and 255. Then, it is converted into 8 bits of binary. The 32 differences result in a 256-bit binary sequence. The first 64 bits of the binary sequence are used as a binary string. The first 32 bits of the binary string are XORed with the first 32 bits of the basic quantum key cluster. The last 32 bits of the binary string are XORed with the last 32 bits of the basic quantum key cluster to obtain a 64-bit bidirectional XOR result. The 64-bit weighted fusion result is added to the 64-bit bidirectional XOR result, converted to decimal, and the decimal number is multiplied by the first 8 bits of the mapping benchmark of the basic quantum key cluster to obtain the mapping product result. The binary values ​​of each of the first 8 bits of the mapping base of the basic quantum key cluster are added together, that is, each bit is either 0 or 1, to obtain an integer sum between 0 and 8. Then, the sum is divided by 8 and rounded down to obtain the adjustment coefficient. If the adjustment coefficient is 0, it is set to 1. Finally, the mapping product is divided by the adjustment coefficient, and the last 64 bits of the quotient are taken as the tamper-proof verification code representing the information integrity proof.

[0030] By generating encryption control factors using a basic quantum key cluster and the primary station's identification key, and combining this with segmented differentiated modular arithmetic to perform multi-level encryption on the early warning information, a tamper-proof verification code is further generated. This achieves a strong association between the encrypted early warning information and the station's identity. When the primary station fails and switches over, the backup station holds the same basic quantum key cluster but has a different identification key. The early warning command center can quickly distinguish between legitimate backup stations and malicious forged nodes through the decrypted encrypted early warning information and the tamper-proof verification code. Since the encryption control factors, verification feature values, and tamper-proof verification codes all depend on the basic quantum key cluster and the corresponding station's unique identification key, attackers find it difficult to forge or tamper with early warning information without mastering all key parameters. Furthermore, the tamper-proof verification code can prove the integrity of the information; any tampering with the information will cause the verification code to become invalid. This solves the defect in the existing primary / backup switching mechanism that cannot identify forged identities due to the same identity verification process, and improves the tamper-proof capability of earthquake early warning information transmission in mountainous areas.

[0031] In one embodiment, when a primary station failure triggers a switchover, the backup station uses its own identification key and the encrypted warning information to be sent to perform an identity signature, generating station switchover verification information representing the switchover authorization credential, including: When the primary station is detected to switch to the backup station, the backup station calls its own identification key and combines it with the basic quantum key cluster to sign, generating a signature control factor used to regulate the uniqueness and security of the identity signature. Specifically, it includes: forming a 64-bit odd key segment from the odd-numbered bits of the basic quantum key cluster and forming a 64-bit even key segment from the even-numbered bits of the basic quantum key cluster. The first 32 bits of the backup station identification key are XORed with the first 32 bits of the odd key segment to obtain a 32-bit first intermediate result. The last 32 bits of the backup station identification key are inverted with the last 32 bits of the even key segment and then XORed, i.e., the corresponding bits of the even key segment are inverted and then XORed with the corresponding bits of the identification key to obtain a 32-bit second intermediate result. The control number is obtained by adding the mapping reference to the key encoding offset of the backup station; The two intermediate results are then concatenated in a staggered manner. The first 32-bit intermediate result is cyclically shifted left by a number of bits equal to the key encoding offset of the backup station. The cyclically shifted 32-bit result is then directly concatenated with the second 32-bit intermediate result, with the first intermediate result first and the second intermediate result last, forming a 64-bit data. After concatenation, the data is converted to decimal and multiplied by the square of the first 8 bits of the mapping benchmark of the basic quantum key cluster. Then, it is divided by the control number, rounded down, and converted to a 64-bit binary number, which is the signature control factor used to control the uniqueness and security of the identity signature.

[0032] Based on the signature control factor and the backup station's identification key, an identity signature is performed on the encrypted station code of the backup station to generate station identity signature information proving the legitimate identity of the backup station. Specifically, this includes: padding the encrypted station code with zeros to extend it to 64 bits; interleaving the first 32 bits of the signature control factor with the first 32 bits of the backup station's identification key bit by bit, i.e., taking the first bit from the first position of the control factor, the second bit from the first position of the identification key, and so on, to obtain a 64-bit interleaved sequence; and then combining this 64-bit interleaved sequence with the extended encrypted station code. Performing a bitwise modulo summation involves summing each corresponding bit of the binary number, dividing by 3, and taking the remainder as the result of the operation for that bit, resulting in a 64-bit summation sequence. Each element in the summation sequence is multiplied by the signature weight value to obtain 64 products. Each product is then converted to 8 bits by taking the modulo of 256. Finally, all 8-bit binary segments are concatenated in order, and the first 64 bits are used as the station identity signature information to prove the legitimate identity of the backup station. The signature weight value is the decimal value corresponding to the first 8 bits of the mapping benchmark of the basic quantum key cluster.

[0033] In one embodiment, when a primary station failure triggers a primary / standby switchover, the standby station uses its own identification key and the encrypted warning information to be sent to perform an identity signature, generating station switchover verification information representing the switchover authorization credential, which also includes: The anti-tampering verification code, station identity signature information and encrypted early warning information are quantum-linked and bound to generate a signature association verification value for associating the identity signature and early warning information. Specifically, this includes concatenating the 16th bit of the encrypted early warning information into groups of 32 bits to form an 8-bit association base code. Then, the anti-tampering verification code and the station identity signature information are split bit by bit, that is, each is split into 64 1-bit segments, and then spliced ​​together into a 128-bit fusion sequence according to the 1-bit verification code + 1-bit signature information. For the first 8 bits of the basic quantum key cluster mapping reference, sum them with the offset of the backup station key encoding to obtain the correlation coefficient. Then, repeatedly concatenate the fusion sequence with the correlation reference code until the total length reaches 256 bits. Take the difference between the 256 bits and the encrypted warning information bit by bit, that is, subtract the corresponding binary after converting to decimal. If the difference is negative, take the absolute value to obtain a 256-bit difference sequence. Sum the difference sequence in groups of 4 bits, concatenate the binary forms of each group of sums, and truncate the last 64 bits, which is the signature association verification value used to associate the identity signature with the warning information.

[0034] Based on the signature association verification value, the identification key and anti-tamper verification code of the backup station are quantum encrypted to generate station switching verification information representing the switching authorization certificate. Specifically, this includes: using the middle 32 bits of the basic quantum key cluster as the encryption base and the last 32 bits as the auxiliary encryption key; and fusing the identification key and anti-tamper verification code of the backup station bit by bit, that is, taking the identification key as the first bit and the anti-tamper verification code as the second bit, and so on, to obtain a 128-bit fused key verification sequence. The signature-associated verification value is converted to decimal and multiplied by the key encoding offset of the backup station to obtain the encryption coefficient. Then, the encryption coefficient is summed with the first 8 bits of the mapping benchmark of the basic quantum key cluster to obtain the final encryption weight. The fusion key verification sequence is sequentially subjected to bitwise modulo operations with the encryption base and the auxiliary encryption key. That is, the 32-bit encryption base is padded with zeros to expand to 128 bits, and the 32-bit auxiliary encryption key is also padded with zeros to expand to 128 bits. Then, the fusion key verification sequence is operated bit by bit with the expanded 128-bit encryption base. For each bit, the corresponding two binary numbers are converted to decimal, added together, and then divided by the final encryption weight. The remainder is taken as the result of the first step operation for that bit. The above operation is repeated bit by bit with the expanded auxiliary encryption key. For each bit, the sum is divided by the encryption weight and the remainder is taken to obtain the 128-bit encryption sequence. The encrypted sequence is concatenated with the station identity signature information and the encrypted station code extended to 64 bits with zero padding. The first 256 bits of binary data are extracted to obtain the station switching verification information representing the switching authorization credential.

[0035] When a primary station failure triggers a switchover, the backup station utilizes its unique identification key and shared basic quantum key cluster to generate unforgeable switchover verification information through multi-layer quantum operations, including signature control factors, station identity signature information, and signature association verification values. This verification information quantum-links the backup station's identity identifier, encrypted station code, tamper-proof verification code, and encrypted early warning information. Upon receiving a switchover request, the early warning command center can quickly distinguish between legitimate backup stations and malicious forged nodes by verifying the correctness of the switchover verification information. This ensures that only backup stations with the correct quantum key materials can successfully take over and send tasks, thus resolving the identity forgery attack problem caused by the identical identity verification process in the existing primary-backup switchover mechanism.

[0036] In one embodiment, after receiving the station handover verification information and the encrypted early warning information, the early warning command center decrypts the information using a basic quantum key cluster and performs identity verification based on the station handover verification information. This generates verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information, including: After receiving the station switching verification information and the encrypted early warning information, the early warning command center calls the basic quantum key cluster to perform layered decryption processing and generate a verification calibration factor used to adjust the accuracy of identity comparison and verification code verification. Specifically, for the first 128 bits of the encrypted sequence of the station switching verification information, the first 64 bits of the basic quantum key cluster are used as the first-level decryption key. This 64-bit decryption key is repeated once to expand it to 128 bits, that is, the first 64 bits are followed by the same content as the last 64 bits. The encrypted sequence is grouped into groups of 8 bits, and the corresponding groups are inverted bit by bit and summed to obtain the 128-bit first-level decryption result. Using the last 64 bits of the basic quantum key cluster as the second-layer decryption key, the first-layer decryption result is XORed with this key bitwise, with the number of bitwise offsets equal to the key encoding offset of the backup station, resulting in a 128-bit second-layer decryption result. The first 8 bits of the basic quantum key cluster mapping reference are multiplied by the reference coefficient 29 of the backup station to obtain the calibration base. The second-layer decryption result is converted to decimal, divided by the calibration base, and the remainder is summed with the mapping reference. This result is then converted to a 64-bit binary number, which is the verification calibration factor used to adjust the accuracy of identity comparison and verification code verification.

[0037] In one embodiment, after receiving the station switching verification information and the encrypted early warning information, the early warning command center decrypts the information using a basic quantum key cluster and performs identity verification based on the station switching verification information. It then generates verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information. The system also includes: Based on the verification calibration factor, the backup station identification key is compared with the encrypted station code of the backup station, and the consistency between the anti-tampering verification code and the encrypted warning information is verified. A verification index representing the legality of the backup station's identity and the integrity of the warning information is generated. Specifically, this includes: extracting the 64-bit backup station identification key, padding the encrypted station code with zeros to extend it to 64 bits, and summing it bit by bit with the backup station identification key to obtain 64 sums. Each sum is converted into a 1-bit binary number according to the following rules: if the sum is ≥ 1, it is converted to 1; if the sum is 0, it is converted to 0. A 64-bit binary number is obtained. This binary number is converted to decimal, divided by the verification calibration factor, and the remainder is taken. The remainder is converted into a 64-bit binary number, and zeros are added where necessary to obtain the identity comparison value. In the encrypted warning information, the first bit of each 32-bit group is concatenated to form an 8-bit group. The anti-tampering verification code is then subjected to a bitwise modulo operation with the 8-bit concatenated value. Specifically, the 8-bit concatenated value is extended to 64 bits by repeating the operation 8 times. Each bit is then processed in turn with the 64-bit anti-tampering verification code. For each bit, the corresponding two binary digits are converted to decimal values. The decimal value of the corresponding bit of the verification code is then divided by the decimal value of the corresponding bit of the extended concatenated value. The remainder is taken as the result of the operation for that bit. If the divisor is 0, the remainder is 0. After all 64 bits have been processed, the resulting 64-bit result is the integrity verification value. The identity comparison value and the integrity verification value are concatenated into 128 bits. The verification calibration factor is expanded to 128 bits again. Then, the two 128-bit values ​​are bitwise XORed. If the result is all 1, it means that the identity is legal and the information is complete, and the verification indicator is verified. Otherwise, it means that the identity is abnormal or the information has been tampered with, and the verification indicator is verified. When the verification indicator passes, an earthquake early warning message is output; when the verification indicator fails, the transmission of the earthquake early warning message is immediately blocked and an alarm is triggered.

[0038] After receiving the station switching verification information and encrypted early warning information, the early warning command center performs layered decryption based on the basic quantum key cluster to generate a verification calibration factor. Based on this factor, it compares the backup station identification key with the encrypted station code to obtain an identity comparison value. It also verifies the consistency between the anti-tampering verification code and the encrypted early warning information to obtain an integrity verification value. Finally, it performs a bitwise XOR operation with the verification calibration factor. Only when all results are 1 is the verification considered successful and the earthquake early warning information is output; otherwise, transmission is immediately blocked and an alarm is triggered. This verification mechanism strongly correlates the legality of the backup station's identity, the integrity of the early warning information, and the quantum key material. Even if an attacker intercepts the switching window data, they cannot simultaneously forge the correct identification key, encrypted station code, and anti-tampering verification code. This solves the problem in existing schemes where the identical primary and backup identity verification processes prevent the identification of forged identities, thus improving the anti-forgery capability of earthquake early warning information transmission in mountainous areas.

[0039] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for preventing tampering of earthquake early warning information based on quantum encrypted communication, characterized in that, include: Step S1: Key distribution is performed between the primary and backup earthquake early warning stations and the early warning command center to generate a basic quantum key cluster representing the core key of quantum encrypted communication. Step S2: Obtain the station codes of the primary station and the backup station respectively. Based on the basic quantum key cluster, generate identification keys representing the unique identity of the primary station and the backup station respectively using differentiated quantum coding method. After encrypting the station codes through the basic quantum key cluster, the encrypted station codes are obtained. Step S3: When the main station is working normally, it collects earthquake early warning information, encrypts the early warning information with the basic quantum key cluster and the identification key of the main station, generates encrypted early warning information, and performs quantum operations on the encrypted early warning information, the identification key of the main station and the basic quantum key cluster to generate a tamper-proof verification code that represents the integrity of the information. Step S4: When the primary station fails and triggers the primary / standby switchover, the standby station uses its own identification key and the encrypted warning information to be sent to sign its identity and generate station switchover verification information representing the switchover authorization certificate. In step S5, after receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts the information using the basic quantum key cluster and performs identity verification based on the station switching verification information to generate verification indicators representing the legality of the backup station's identity and the integrity of the early warning information.

2. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 1, characterized in that, Key distribution is performed between the primary and backup earthquake early warning stations and the early warning command center to generate a basic quantum key set representing the core key of quantum encrypted communication, including: Key distribution is performed between the primary station, backup station, and early warning command center to generate encoded quantum states; The encoded quantum state is modified to generate a basic quantum key cluster representing the core key of quantum encrypted communication. The basic quantum key cluster is the same set of basic quantum key clusters held by the primary station, the backup station and the early warning and command center.

3. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 2, characterized in that, Based on the fundamental quantum key set, differentiated quantum coding methods are used to generate unique identification keys for the primary and backup stations, representing their respective identities. These keys include: Differentiated mapping is performed on the basic quantum key cluster to generate key encoding offsets that represent the differentiating identities of the corresponding stations; Differentiated encoding is applied to the key encoding offset and station encoding to generate unique identification keys for the primary station and the backup station, respectively.

4. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 3, characterized in that, After encrypting the station code using a basic quantum key cluster, the encrypted station code is obtained, which includes: The station code is encrypted using the basic quantum key cluster to obtain the encrypted station code.

5. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 4, characterized in that, After encrypting the warning information using a basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity, including: The basic quantum key cluster and the identification key of the master station are mixed and encrypted to generate an encryption control factor for adjusting the encryption strength and uniqueness of the early warning information; Based on the encryption control factor, combined with the basic quantum key cluster and the identification key of the primary station, the earthquake early warning information is encrypted to generate encrypted early warning information.

6. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 5, characterized in that, After encrypting the warning information using a basic quantum key cluster and the identification key of the master station, encrypted warning information is generated. Quantum operations are then performed on the encrypted warning information, the identification key of the master station, and the basic quantum key cluster to generate a tamper-proof verification code representing proof of information integrity. This also includes: Based on the encrypted early warning information, its quantum encryption features are extracted and combined with the basic quantum key cluster and the identification key of the main station to generate a verification feature value for associating the encrypted early warning information with the identity identifier. The verification feature value, encrypted early warning information, the identification key of the main station, and the basic quantum key cluster are used to perform collaborative operations to generate a tamper-proof verification code that represents proof of information integrity.

7. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 6, characterized in that, When a primary station failure triggers a switchover, the backup station uses its own identification key and the encrypted warning information to be sent to sign its identity, generating station switchover verification information representing the switchover authorization credential, including: When the primary station is detected to switch to the backup station, the backup station calls its own identification key and combines it with the basic quantum key cluster to sign, generating a signature control factor used to regulate the uniqueness and security of the identity signature. Based on the signature control factor and the identifier key of the backup station, the encrypted station code of the backup station is identity-signed to generate station identity signature information used to prove the legitimate identity of the backup station.

8. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 7, characterized in that, When a primary station failure triggers a switchover, the backup station uses its own identification key and the encrypted warning information to be sent to sign its identity, generating station switchover verification information representing the switchover authorization credential, which also includes: The anti-tampering verification code, station identity signature information and encrypted early warning information are quantum-linked and bound to generate a signature association verification value used to associate the identity signature and early warning information. Based on the signature-related verification value, the identification key and tamper-proof verification code of the backup station are quantum encrypted to generate station handover verification information representing the handover authorization certificate.

9. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 8, characterized in that, After receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts them using a basic quantum key cluster and performs identity verification based on the station switching verification information. This generates verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information, including: After receiving the station switching verification information and encrypted early warning information, the early warning command center calls the basic quantum key cluster to perform layered decryption processing and generate a verification calibration factor used to regulate the accuracy of identity comparison and verification code verification.

10. The method for preventing tampering of earthquake early warning information based on quantum encrypted communication according to claim 9, characterized in that, After receiving the station switching verification information and encrypted early warning information, the early warning command center decrypts them using a basic quantum key cluster and performs identity verification based on the station switching verification information. It then generates verification indicators representing the legitimacy of the backup station's identity and the integrity of the early warning information, including: Based on the verification calibration factor, the backup station identification key is compared with the encrypted station code of the backup station, and the consistency between the anti-tampering verification code and the encrypted early warning information is verified to generate a verification index representing the legality of the backup station's identity and the integrity of the early warning information. When the verification indicator passes, an earthquake early warning message is output; when the verification indicator fails, the transmission of the earthquake early warning message is immediately blocked and an alarm is triggered.