Quantum key distribution system terminal based on zero trust
By using a zero-trust-based quantum key distribution system terminal, Alice (the sender) and Bob (the receiver) are authenticated through an identity authentication and key management server. This solves the problems of insufficient network security and trustworthiness in existing technologies, and improves the security and flexibility of the QKD network.
Patent Information
- Application Number
- CN202423283560.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2034-12-30
AI Technical Summary
Existing network security defense models cannot meet the current complex and ever-changing network environment, and it is difficult to ensure the security and reliability of each node and the communication between nodes in a quantum key distribution network.
The system employs a zero-trust quantum key distribution terminal, which uses an identity authentication server to authenticate the Alice sender and Bob receiver. Combined with a key management server, it enables continuous verification and monitoring to prevent malicious operations and data leakage.
It improves the security and reliability of individual nodes and communication between nodes in the QKD network, effectively prevents network attacks and data leakage, supports dynamic deployment of key resources, and is flexible and convenient to operate.
Smart Images

Figure CN223613349U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to quantum communication equipment and quantum network password cloud technical field, concretely relates to a quantum key distribution system terminal based on zero trust. BACKGROUND
[0002] Quantum key distribution (QKD) is a research focus in the field of quantum communication. Based on the characteristics of quantum mechanics, quantum communication is theoretically absolutely secure, and both parties can maintain secure communication and obtain absolutely secure information even if there is an attempt to eavesdrop. The eavesdropper cannot obtain the communication content.
[0003] Traditional network security models rely on firewalls to establish an internal network, assuming that the internal network is completely trusted. However, with the rapid development of emerging technologies such as cloud computing, big data, and the Internet of Things, the traditional security boundary is gradually collapsing, leading to a blurred boundary between the internal and external networks, and network security is facing more complex and widespread threats. Zero trust is a security model whose core philosophy is "never trust, always verify". It abandons the trust model based on network boundaries in traditional network security strategies, i.e., every access request needs to go through a strict authentication, authorization, and auditing process.
[0004] Therefore, the existing network security defense model cannot meet the current complex and changing network environment, and it is difficult to ensure the security and credibility of each node and communication between nodes in the QKD network. New security defense concepts and technical means are needed to address these challenges. SUMMARY
[0005] The utility model discloses a quantum key distribution system terminal based on zero trust to solve the problem that the existing network security defense model cannot meet the current complex and changing network environment.
[0006] To achieve the above-mentioned purpose, the technical scheme adopted by the utility model is as follows:
[0007] A quantum key distribution system terminal based on zero trust includes an Alice sending end, a Bob receiving end, and a zero trust server.
[0008] The zero trust server includes an identity authentication server and a key management server.
[0009] The output end of the Alice sending end is connected to the input end of the Bob receiving end, the identity authentication server and the key management server are connected to each other, the identity authentication server is connected to the Alice sending end and the Bob receiving end, and the key management server is connected to the Alice sending end and the Bob receiving end.
[0010] In the above scheme, the identity authentication server respectively authenticates the Alice sending end and the Bob receiving end, prevents malicious impersonation, access to resources, data leakage and other malicious operations, realizes continuous verification and monitoring of users, devices and systems, effectively protects the security of data in QKD network nodes and communication between nodes, effectively prevents various network attacks and data leakage risks, and improves the security and credibility of network communication.
[0011] Preferably, the Alice sending end comprises a laser, a polarization modulator and a first controller.
[0012] The output end of the laser and the output end of the first controller are respectively connected with different input ends of the polarization modulator, and the output end of the polarization modulator is connected with the input end of the Bob receiving end.
[0013] Preferably, the Alice sending end further comprises an attenuator, and the output end of the laser is connected with an input end of the polarization modulator through the attenuator.
[0014] Preferably, the Bob receiving end comprises a detection module and a second controller.
[0015] The output end of the Alice sending end and the output end of the second controller are respectively connected with different input ends of the detection module, and the second controller is respectively connected with the identity authentication server and the key management server.
[0016] Preferably, the detection module comprises a beam splitting element, a first detector and a second detector.
[0017] The output end of the Alice sending end and the output end of the second controller are respectively connected with different input ends of the beam splitting element, and the input end of the first detector and the input end of the second detector are respectively connected with different output ends of the beam splitting element.
[0018] Preferably, the beam splitting element is a polarization beam splitter.
[0019] Preferably, the zero trust server further comprises a database, and the database is connected with the identity authentication server.
[0020] Preferably, the first controller is internally provided with a first quantum random number generator.
[0021] Preferably, the first controller is internally provided with a second quantum random number generator.
[0022] The beneficial technical effects of the utility model are as follows:
[0023] The utility model provides a quantum key distribution system terminal based on zero trust, through identity authentication server respectively to Alice sending end and Bob receiving end carries out identity authentication, effectively prevents user malicious impersonation, accesses resources, data leakage and so on malicious operation, realizes to user, device and the sustained authentication and monitoring of system, can satisfy current complex and changeable network environment, improves each node in QKD network and the security and credibility of communication between nodes.
[0024] In addition, the utility model still supports the dynamic deployment of resources such as keys in the quantum key distribution system, ensuring data security, unrestricted user operation, and very convenient and flexible use. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 It is the module connection schematic drawing of the utility model;
[0026] Figure 2 It is the communication step flow chart in the utility model;
[0027] Wherein: 1, Alice sending end;11, laser;12, polarization modulator;13, first controller;14, attenuator;2, Bob receiving end;20, second controller;21, beam splitting element;22, first probe;23, second probe;3, zero trust server;31, identity authentication server;32, key management server;33, database. DETAILED DESCRIPTION
[0028] In order to make the purpose, technical scheme and advantage of the utility model more clearly, the following combines embodiment and carries out further detailed explanation to the utility model, but the scope of protection of the utility model is not limited to the following specific embodiment.
[0029] Embodiment 1
[0030] As Figure 1 Shown, a quantum key distribution system terminal based on zero trust, including Alice sending end 1, Bob receiving end 2 and zero trust server 3;
[0031] The zero trust server 3 includes identity authentication server 31 and key management server 32;
[0032] The output of Alice sending end 1 is connected with the input of Bob receiving end 2, identity authentication server 31 and key management server 32 are connected with each other, identity authentication server 31 is connected with each other with Alice sending end 1, Bob receiving end 2 respectively, key management server 32 is connected with each other with Alice sending end 1, Bob receiving end 2 respectively.
[0033] In the specific implementation process, the identity authentication server 31 respectively performs identity authentication on the Alice sending end 1 and the Bob receiving end 2, prevents malicious impersonation, access to resources, data leakage and other malicious operations, realizes continuous verification and monitoring of users, devices and systems, effectively protects the security of data in each node and communication between nodes in the QKD network, effectively prevents various network attacks and data leakage risks, and improves the security and credibility of network communication.
[0034] Embodiment 2
[0035] A quantum key distribution system terminal based on zero trust includes an Alice sending end 1, a Bob receiving end 2 and a zero trust server 3.
[0036] The zero trust server 3 includes an identity authentication server 31 and a key management server 32.
[0037] In the specific implementation process, the Alice sending end 1 is configured to send a communication application and identity information to the identity authentication server 31 to obtain a communication identifier, send a key application to the key management server 32 according to the identity information and the communication identifier to obtain key information, and perform a quantum key distribution process with the Bob receiving end 2 using the key information.
[0038] The Bob receiving end 2 is configured to perform identity authentication according to a request of the identity authentication server 31 to obtain a corresponding communication identifier, and perform a quantum key distribution process with the Alice sending end 1 according to the communication identifier.
[0039] The identity authentication server 31 is configured to perform identity authentication on the Alice sending end 1 and the Bob receiving end 2 according to the communication application, and return a communication identifier after the authentication is passed, and query identity authentication records according to an instruction of the key management server 32.
[0040] The key management server 32 is configured to initiate an identity authentication record query to the identity authentication server 31 according to a key application of the Alice sending end 1, and generate key information after the query is passed.
[0041] The identity information includes an identity code and a username.
[0042] In an instant communication, the communication identifiers of the Alice sending end 11 and the Bob receiving end 22 are the same and unique.
[0043] More specifically, the Alice sending end 1 includes a laser 11, a polarization modulator 12 and a first controller 13.
[0044] The output end of the laser 11 and the output end of the first controller 13 are connected with different input ends of the polarization modulator 12 respectively, the output end of the polarization modulator 12 is connected with the input end of the Bob receiving end 2, and the first controller 13 is connected with the identity authentication server 31 and the key management server 32 respectively.
[0045] More specifically, the Alice sending end 1 further comprises an attenuator 14, and the output end of the laser 11 is connected with an input end of the polarization modulator 12 through the attenuator 14.
[0046] In the specific implementation process, the laser 11 generates a pulse signal of a specific wavelength, the pulse signal is attenuated in intensity by the attenuator 14, and when the average photon number is less than 1, the light signal can be effectively considered as a safe light signal, and the light signal enters the polarization modulator 12 for polarization modulation.
[0047] The polarization modulator 12 randomly selects whether the base vector is a horizontal-vertical base or a diagonal base according to the control signal of the first controller 13, and selects the polarization direction as horizontal, vertical, 45° or 135° according to the key information.
[0048] More specifically, the Bob receiving end 2 comprises a detection module and a second controller 20.
[0049] More specifically, the detection module comprises a beam splitting element 21, a first detector 22 and a second detector 23.
[0050] The output end of the Alice sending end 1 and the output end of the second controller 20 are connected with different input ends of the beam splitting element 21 respectively, and the input end of the first detector 22 and the input end of the second detector 23 are connected with different output ends of the beam splitting element 21 respectively; and the second controller 20 is connected with the identity authentication server 31 and the key management server 32 respectively.
[0051] More specifically, the beam splitting element 21 is a polarization beam splitter.
[0052] In the specific implementation process, the polarization encoded light signal transmitted by the Alice sending end 1 is split by the polarization beam splitter of the Bob receiving end 2, and different polarization directions under the same base vector are detected by the first detector 22 or the second detector 23.
[0053] The selection of the base vector of the polarization beam splitter of the Bob receiving end 2 is determined by the control signal of the second controller 20.
[0054] The coding mode of the Alice sending end 1 and the Bob receiving end 2 is as follows:
[0055]
[0056] More specifically, the zero-trust server 3 further comprises a database 33, which is interconnected with the identity authentication server 31.
[0057] In the specific implementation, the database 33 is used to store identity information, communication identification and key information.
[0058] More specifically, the first controller 13 is internally provided with a first quantum random number generator.
[0059] In the specific implementation, the control signal of the first controller 13 is randomly generated by the first quantum random number generator.
[0060] More specifically, the first controller 13 is internally provided with a second quantum random number generator.
[0061] In the specific implementation, the control signal of the second controller 20 is randomly generated by the second quantum random number generator.
[0062] Embodiment 3
[0063] As shown in Figure 2 When there is a communication demand between the Alice sending terminal and the Bob receiving terminal, the communication process of the zero-trust-based quantum key distribution system terminal is as follows:
[0064] S1: The Alice sending terminal sends its identity information (identity code) and the username of the Bob receiving terminal which needs to communicate to the identity authentication server to apply for communication;
[0065] S2: The identity authentication server performs identity authentication on the Alice sending terminal according to the identity information of the Alice sending terminal;
[0066] If the authentication is passed, step S3 is performed;
[0067] If the authentication is not passed, the Alice sending terminal is returned an authentication error, and is required to resend the identity information, and step S2 is performed again;
[0068] S3: The identity authentication server initiates an identity authentication request to the Bob receiving terminal, and obtains the identity information (identity code and username) of the Bob receiving terminal to perform identity authentication;
[0069] If the authentication is passed, the Alice sending terminal and the Bob receiving terminal are respectively returned a communication identification, and the identity information and the communication identification of the Alice sending terminal and the Bob receiving terminal are saved;
[0070] If the authentication is not passed, the Bob receiving terminal is returned an authentication error, and step S3 is performed again;
[0071] S4: the Alice sender sends its identity information and communication identifier to the key management server to apply for a key;
[0072] S5: the key management server initiates identity authentication record query to the identity authentication server according to the key application of the Alice sender;
[0073] If the query is passed, the key management server generates key information of a specified length and encrypts the key information together with the identity information (identity code) and the communication identifier of the Alice sender, and then sends the encrypted key information to the Alice sender; and saves the relevant key information and other data in the key management server;
[0074] If the query is not passed, the Alice sender is returned with an application failure, and the process returns to step S4;
[0075] In actual implementation, the database stores the identity information of all legal users, devices and systems in the QKD network, and the identity authentication server compares the information sent by the Alice sender with the information stored in the database to determine whether the information is correct;
[0076] The key generated by the key management server is random;
[0077] If the relevant record is found, the data is correct and can be matched, the query is passed, and the identity authentication server returns an authentication pass to the key management server;
[0078] If no relevant record is found or the data is incorrect and cannot be matched, the query is not passed, and the identity authentication server returns an authentication error to the key management server;
[0079] S6: after the Alice sender processes the encrypted key information to obtain the key information, the Alice sender encrypts the information to be communicated in combination with the communication identifier and the key information, and transmits the encrypted information to the Bob receiver through the quantum channel;
[0080] S7: the Bob receiver decodes the communication identifier to obtain the key information, and completes the quantum key distribution.
[0081] According to the disclosure and teaching of the above description, those skilled in the art of the present application can also make changes and modifications to the above embodiments. Therefore, the present application is not limited to the specific embodiments disclosed and described above, and some modifications and changes of the present application should fall within the protection scope of the claims of the present application. In addition, although some specific terms are used in the present specification, these terms are only for convenience and do not constitute any limitation on the present application.
Claims
1. A zero-trust based quantum key distribution system terminal, characterized by, The Alice sending end, the Bob receiving end and the zero-trust server are included; The zero-trust server includes an identity authentication server and a key management server; The output end of the Alice sending end is connected with the input end of the Bob receiving end, the identity authentication server and the key management server are connected with each other, the identity authentication server is connected with the Alice sending end and the Bob receiving end respectively, and the key management server is connected with the Alice sending end and the Bob receiving end respectively.
2. The zero trust based quantum key distribution system terminal according to claim 1, wherein, The Alice sending end includes a laser, a polarization modulator and a first controller; The output end of the laser and the output end of the first controller are connected with different input ends of the polarization modulator respectively, the output end of the polarization modulator is connected with the input end of the Bob receiving end, and the first controller is connected with the identity authentication server and the key management server respectively.
3. The zero trust based quantum key distribution system terminal according to claim 2, wherein, The Alice sending end further includes an attenuator, and the output end of the laser is connected with an input end of the polarization modulator through the attenuator.
4. The zero trust based quantum key distribution system terminal of claim 1, wherein, The Bob receiving end includes a detection module and a second controller; The output end of the Alice sending end and the output end of the second controller are connected with different input ends of the detection module respectively, and the second controller is connected with the identity authentication server and the key management server respectively.
5. The zero trust based quantum key distribution system terminal according to claim 4, wherein, The detection module includes a beam splitting element, a first detector and a second detector; The output end of the Alice sending end and the output end of the second controller are connected with different input ends of the beam splitting element respectively, and the input end of the first detector and the input end of the second detector are connected with different output ends of the beam splitting element respectively.
6. The zero trust based quantum key distribution system terminal according to claim 5, wherein, The beam splitting element is a polarization beam splitter.
7. The zero trust based quantum key distribution system terminal according to claim 1, wherein, The zero-trust server further includes a database, and the database is connected with the identity authentication server.
8. The zero trust based quantum key distribution system terminal according to claim 2, wherein, The first controller is internally provided with a first quantum random number generator.
9. The zero trust based quantum key distribution system terminal according to claim 8, wherein, The first controller is internally provided with a second quantum random number generator.