Quantum security block chain system
By introducing a quantum-safe blockchain system and quantum communication encryption technology into the blockchain system, generating quantum-safe key information and building a decentralized network, the security problem of the blockchain system under quantum computing attacks is solved, achieving higher security and convenient system upgrades.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2026-04-03
AI Technical Summary
Existing blockchain systems lack effective protection against quantum computing attacks, and traditional encryption algorithms are easily cracked, resulting in insufficient security of transaction data and encrypted information.
A quantum-safe blockchain system is introduced, which combines quantum communication encryption technology. A quantum-safe key information is generated through a quantum key management subsystem, and a decentralized topological network structure is established between blockchain node terminals using a quantum-safe gateway for encrypted communication.
This improves the blockchain system's ability to resist quantum computing attacks, enhances security, and reduces the cost of modifying blockchain node terminals, making it easier for traditional node terminals to access the quantum-safe blockchain system.
Smart Images

Figure CN224083546U_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of blockchain technology, and more specifically, to a quantum-safe blockchain system. Background Technology
[0002] Blockchain is a distributed ledger technology that records and verifies transaction data in a decentralized, transparent, and secure manner. It is a chain-like structure composed of blocks, each containing a batch of verified transaction records. The design of blockchain ensures that the data is immutable and enables reliable transaction verification and information transmission, making it promising for a wide range of applications.
[0003] Current encryption algorithms, such as RSA and elliptic curve cryptography, are based on mathematical problems that are difficult for traditional computers to solve. However, the advent of quantum computing could potentially break these algorithms, as quantum computers can use quantum algorithms such as Shor's algorithm to quickly factor large integers and solve discrete logarithm problems. This could lead to the breach of current blockchain encryption mechanisms, making previous transaction data and encrypted information vulnerable to attack. Therefore, upgrading traditional blockchain systems to be quantum-resistant is of great significance. Utility Model Content
[0004] The purpose of this disclosure is to provide a quantum-safe blockchain system that combines quantum communication encryption technology with blockchain technology, enabling the blockchain system to resist quantum computing attacks.
[0005] To achieve the above objectives, this disclosure provides a quantum-safe blockchain system, including a quantum key management subsystem and multiple quantum-safe blockchain node components. Each quantum-safe blockchain node component includes a blockchain node terminal and a quantum-safe gateway communicatively connected to the blockchain node terminal, wherein:
[0006] The quantum key management subsystem is communicatively connected to the quantum security gateway. The quantum key management subsystem is used to generate quantum security key information and send the quantum security key information to the quantum security gateway in the quantum security blockchain node component.
[0007] Multiple quantum-secure gateways establish communication connections with each other to form a decentralized topological network structure; the quantum-secure gateway is used to encrypt the session information of the blockchain node terminal into encrypted information using the quantum-secure key information, and send the encrypted information to other quantum-secure gateways.
[0008] Optionally, the quantum key management subsystem includes:
[0009] A quantum key generation and management component for generating single-point quantum keys and symmetric quantum keys;
[0010] A quantum encryption and storage component is communicatively connected to the quantum security gateway and the quantum key generation and management component, respectively, and is used to encrypt and encapsulate the symmetric quantum key using the single-point quantum key to obtain the quantum security key information, and to store the quantum security key information;
[0011] A quantum key management server, which is communicatively connected to the quantum encryption and storage component, is used to invoke the quantum encryption and storage component to send the quantum secure key information to the quantum secure gateway in the quantum secure blockchain node component.
[0012] Optionally, the quantum key generation and management component includes:
[0013] A quantum random number generator is used to generate single-point quantum keys;
[0014] A quantum key distribution device used to generate symmetric quantum keys;
[0015] The data acquisition switch is communicatively connected to the quantum random number generator and the quantum key distribution device. The data acquisition switch is used to acquire the single-point quantum key generated by the quantum random number generator and the symmetric quantum key generated by the quantum key distribution device. The data acquisition switch is also communicatively connected to the quantum encryption and storage component.
[0016] A cryptographic exchange machine is communicatively connected to the data acquisition switch. The cryptographic exchange machine is used to receive and store the single-point quantum key and the symmetric quantum key sent by the data acquisition switch.
[0017] Optionally, the data acquisition switch is model S5720-52P-EI-AC, the quantum key distribution device is model QKDM-POL40A-S-24G1, the quantum random number generator is model QRNG-100E-1012, and the exchange cryptographic machine is model MODULE-SJJ1963-AC.
[0018] Optionally, the quantum key generation and management component further includes a quantum key injector that is communicatively connected to the data acquisition switch. The quantum key injector is used to inject the single-point quantum key into a quantum-safe U-shield and / or a quantum-safe TF card. The quantum-safe gateway is also provided with an interface for connecting the quantum-safe U-shield and the quantum-safe TF card.
[0019] Optionally, the number of quantum key generation and management components and the number of quantum encryption and storage components in the quantum key management subsystem are both less than the number of quantum secure blockchain node components, and at least one of the quantum encryption and storage components is communicatively connected to multiple quantum secure gateways.
[0020] Optionally, all of the quantum key generation and management components and the quantum encryption and storage components are located in the same secure and trusted communication environment.
[0021] Optionally, the number of quantum key generation and management components and the number of quantum encryption and storage components in the quantum key management subsystem are the same as the number of quantum secure blockchain node components. Each quantum encryption and storage component is communicatively connected to a quantum secure gateway and a quantum key generation and management component, and multiple quantum key generation and management components establish communication connections with each other to form the decentralized topological network structure.
[0022] Optionally, the quantum encryption and storage component and the quantum key generation and management component, which are interconnected, are located in the same secure and trusted communication environment.
[0023] Optionally, the quantum encryption and storage component includes a quantum encryption unit and a storage unit.
[0024] Through the above technical solution, the quantum-safe blockchain system includes a quantum key management subsystem and multiple quantum-safe blockchain node components. The quantum key management subsystem provides quantum-safe key information. The quantum-safe blockchain node components include blockchain node terminals and quantum-safe gateways, which communicate and connect with each other to form a decentralized topological network structure. This allows the blockchain node terminals to form the blockchain system through the quantum-safe gateways. The quantum-safe gateways use quantum-safe key information to encrypt the session information between the blockchain node terminals, applying quantum communication encryption technology to improve the quantum-safe blockchain system's resistance to quantum computing attacks and enhance its security. Furthermore, using quantum-safe gateways reduces the cost of modifying blockchain node terminals, making it easier for traditional blockchain node terminals to connect to the quantum-safe blockchain system.
[0025] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description
[0026] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the following detailed description to explain the present disclosure, but do not constitute a limitation thereof. In the drawings:
[0027] Figure 1This is a schematic diagram illustrating a quantum-secure blockchain system according to an exemplary embodiment.
[0028] Figure 2 This is a block diagram illustrating a quantum key management subsystem according to an exemplary embodiment.
[0029] Figure 3 This is a block diagram illustrating a quantum key generation and management component according to an exemplary embodiment.
[0030] Figure 4 This is another block diagram illustrating a quantum key generation and management component according to an exemplary embodiment.
[0031] Figure 5 This is another schematic diagram illustrating a quantum-secure blockchain system according to an exemplary embodiment.
[0032] Figure 6 This is another schematic diagram illustrating a quantum-secure blockchain system according to an exemplary embodiment.
[0033] Explanation of reference numerals in the attached figures
[0034] 510, 610: Quantum key management server; 520, 621-624: Quantum encryption and storage components; 531, 532, 631-634: Quantum key generation and management components; 541-544, 641-644: Quantum secure blockchain node components. Detailed Implementation
[0035] The specific embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit this disclosure.
[0036] Quantum communication technology is a communication technology that uses quantum keys to encrypt communication information. One of its core aspects is quantum key distribution, which uses the principles of quantum mechanics to distribute keys in order to improve the security of communication by leveraging the inherent properties of quantum mechanics.
[0037] For existing blockchains, if quantum communication technology can be used to encrypt session communication between blockchain nodes, the security of the blockchain system will be greatly improved. Based on this, a quantum-safe blockchain system is proposed.
[0038] Figure 1 This is a schematic diagram illustrating a quantum-safe blockchain system according to an exemplary embodiment. See also: Figure 1The quantum-safe blockchain system includes a quantum key management subsystem and multiple quantum-safe blockchain node components. Each quantum-safe blockchain node component includes a blockchain node terminal and a quantum-safe gateway communicatively connected to the blockchain node terminal.
[0039] The quantum key management subsystem is communicatively connected to the quantum security gateway. The quantum key management subsystem is used to generate quantum security key information and send the quantum security key information to the quantum security gateway in the quantum security blockchain node component.
[0040] Multiple quantum-secure gateways establish communication connections with each other to form a decentralized topological network structure; the quantum-secure gateway is used to encrypt the session information of the blockchain node terminal into encrypted information using the quantum-secure key information, and send the encrypted information to other quantum-secure gateways.
[0041] The communication connection described in this disclosure refers to the establishment of a communication channel between two hardware devices via wired or wireless communication, and the transmission of data through this communication channel. Taking the communication connection between the quantum key management subsystem and the quantum security gateway as an example, the two can achieve a communication connection through a wired optical fiber connection, or through wireless communication methods such as 4G or 5G. For communication connections between other components, terminals, and other hardware, please refer to this description; further details are omitted here.
[0042] Specifically, to implement and maintain a blockchain, multiple blockchain node terminals need to communicate and connect with each other to form a decentralized topological network structure. Blockchain node terminals can be, for example, electronic computers, servers, etc., which run the software required to maintain the operation of the blockchain network and can perform functions such as data storage, transaction verification, block creation, mining, and data propagation.
[0043] A quantum-secure gateway is a transmission security device based on modern cryptographic technology. It is a hardware device with physical security protection measures and an autonomous key management mechanism, enabling the encryption and decryption process based on quantum keys to be completed internally. Various quantum-secure gateway products on the market can use quantum keys to encrypt and decrypt information; their encryption and decryption can be implemented based on existing encryption and decryption algorithms, which will not be elaborated upon in this disclosure.
[0044] A quantum-safe gateway and a blockchain node terminal communicate with each other to form a quantum-safe blockchain node component. In order to form a decentralized topological network structure, multiple quantum-safe gateways in multiple quantum-safe blockchain node components communicate with each other. That is, a communication connection is established between every two quantum-safe gateways. In turn, blockchain node terminals can communicate with each other through quantum-safe gateways to form a decentralized topological network structure, which facilitates the construction and maintenance of blockchain by blockchain node terminals.
[0045] The quantum key management subsystem is used to generate and manage quantum-secure key information. Quantum-secure key information contains quantum keys, such as single-point quantum keys, symmetric quantum keys, or information encrypted with symmetric quantum keys. The quantum key management subsystem can be implemented based on products such as quantum key management systems, quantum key management service systems, and quantum key service centers provided by relevant companies, or it can be implemented through devices such as quantum key distribution equipment and quantum key generation and management components.
[0046] The quantum key management subsystem communicates with a quantum-safe gateway to send the generated quantum-safe key information to the gateway. The gateway then uses this quantum-safe key information to encrypt session information between blockchain nodes. This session information refers to the communication information needed to build and maintain the blockchain; it can be, for example, broadcast messages. For instance, if the quantum-safe key is a symmetric quantum key, the gateway can directly encrypt the session information using it. If the key is an encrypted key obtained from a symmetric quantum key, the gateway first decrypts it to obtain the symmetric quantum key, and then uses this key to encrypt the session information. After obtaining the encrypted information, the gateway sends it to other quantum-safe gateways that need to receive it. These gateways then decrypt the encrypted information to obtain the required session information and send it to the blockchain nodes they are connected to to implement the corresponding blockchain operation process.
[0047] Through the above technical solution, the quantum-safe blockchain system includes a quantum key management subsystem and multiple quantum-safe blockchain node components. The quantum key management subsystem provides quantum-safe key information. The quantum-safe blockchain node components include blockchain node terminals and quantum-safe gateways, which communicate and connect with each other to form a decentralized topological network structure. This allows the blockchain node terminals to form the blockchain system through the quantum-safe gateways. The quantum-safe gateways use quantum-safe key information to encrypt the session information between the blockchain node terminals, applying quantum communication encryption technology to improve the quantum-safe blockchain system's resistance to quantum computing attacks and enhance its security. Furthermore, using quantum-safe gateways reduces the cost of modifying blockchain node terminals, making it easier for traditional blockchain node terminals to connect to the quantum-safe blockchain system.
[0048] Furthermore, the quantum blockchain network, composed of quantum-safe blockchain node components, is independent of the quantum key management subsystem. Its traditional blockchain operating mechanisms, such as data on-chaining and user decision-making, are unaffected, and the decentralized topology is preserved.
[0049] Figure 2 This is a block diagram of a quantum key management subsystem according to an exemplary embodiment. Optionally, see [link to example diagram]. Figure 2 The quantum key management subsystem includes:
[0050] A quantum key generation and management component for generating single-point quantum keys and symmetric quantum keys;
[0051] A quantum encryption and storage component is communicatively connected to the quantum security gateway and the quantum key generation and management component, respectively, and is used to encrypt and encapsulate the symmetric quantum key using the single-point quantum key to obtain the quantum security key information, and to store the quantum security key information;
[0052] A quantum key management server, which is communicatively connected to the quantum encryption and storage component, is used to invoke the quantum encryption and storage component to send the quantum secure key information to the quantum secure gateway in the quantum secure blockchain node component.
[0053] Specifically, a single-point quantum key is a truly random number sequence that can be generated by a quantum random number generator based on the principles of quantum mechanics. It possesses high randomness and can be used as a quantum secure key. A symmetric quantum key, on the other hand, is a pair of keys generated based on quantum key distribution protocols such as BB84, which can be used for symmetric encryption. It should be noted that, for ease of illustration, Figure 2 The connection between the quantum encryption and storage components and the quantum security gateway is not shown in the diagram.
[0054] By setting up quantum encryption and storage components to encrypt symmetric quantum keys using single-point quantum keys, quantum-secure encrypted transmission of symmetric quantum keys is ensured during transmission to quantum-safe blockchain node components. This improves the security of the transmission process and allows symmetric quantum keys to be stored in ciphertext form, reducing the requirements for the physical security of the storage location and broadening the scope of application.
[0055] Optionally, see Figure 3 In one possible implementation, the quantum key generation and management component includes:
[0056] A quantum random number generator is used to generate single-point quantum keys;
[0057] A quantum key distribution device used to generate symmetric quantum keys;
[0058] The data acquisition switch is communicatively connected to the quantum random number generator and the quantum key distribution device. The data acquisition switch is used to acquire the single-point quantum key generated by the quantum random number generator and the symmetric quantum key generated by the quantum key distribution device. The data acquisition switch is also communicatively connected to the quantum encryption and storage component.
[0059] A cryptographic exchange machine is communicatively connected to the data acquisition switch. The cryptographic exchange machine is used to receive and store the single-point quantum key and the symmetric quantum key sent by the data acquisition switch.
[0060] Specifically, the cipher machine is mainly used for key storage and output. The data acquisition switch is mainly used for data acquisition and exchange, and can serve as the control center for the quantum key generation and management components to manage single-point quantum keys and symmetric quantum keys. For example, the data acquisition switch can acquire single-point quantum keys generated by a quantum random number generator and symmetric quantum keys generated by a quantum key distribution device, and send both types of keys to the cipher machine for storage. Furthermore, the data acquisition switch can also respond to requests from the quantum key management subsystem, acquire the two types of keys from the cipher machine, and send them to the quantum encryption and storage components with established communication connections. It should be noted that, for ease of illustration, Figure 3 The connection between the data acquisition switch and the quantum encryption and storage components is not shown in the diagram.
[0061] Quantum key distribution devices and quantum random number generators can generate a large number of symmetric quantum keys and single-point quantum keys at once and store them in a cryptographic exchange machine via a data acquisition switch. The symmetric quantum keys and single-point quantum keys required by the quantum encryption and storage components can be obtained from the cryptographic exchange machine without waiting for the quantum key distribution device and quantum random number generator to generate them in real time. On the one hand, this can improve the efficiency of obtaining symmetric quantum keys and single-point quantum keys. On the other hand, the process of generating corresponding quantum keys by the quantum key distribution device and quantum random number generator, as well as the process of quantum encryption and storage components, quantum security gateways and other related hardware devices using quantum keys for quantum encrypted communication, can be carried out asynchronously, which facilitates the maintenance and management of the equipment. For example, when the quantum key distribution device and quantum random number generator are out of service due to failure or maintenance, the quantum encryption and storage components can still obtain the corresponding quantum keys from the cryptographic exchange machine.
[0062] In one possible implementation, the data acquisition switch is model S5720-52P-EI-AC, the quantum key distribution device is model QKDM-POL40A-S-24G1, the quantum random number generator is model QRNG-100E-1012, and the cipher machine is model MODULE-SJJ1963-AC. Testing of different hardware models revealed that these models can cooperate well.
[0063] Specifically, the quantum encryption and storage component establishes communication connections with both the quantum security gateway and the quantum key generation and management component. The quantum encryption and storage component can encrypt the symmetric key using the received single-point quantum key to obtain quantum-secure key information. Since the quantum-secure blockchain node component and the quantum key management subsystem are often not deployed in the same secure and trusted environment, encrypting the symmetric quantum key through the quantum encryption and storage component can improve the security of subsequent transmission of the symmetric quantum key.
[0064] Optionally, the quantum encryption and storage component includes quantum encryption units and storage units that are communicatively connected. For example, the quantum encryption unit can be a quantum encryption chip or an encryption server, or it can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to encrypt and encapsulate the symmetric quantum key using a single-point quantum key to obtain quantum secure key information.
[0065] The storage unit can be a key storage server, static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. Optionally, the quantum encryption unit can be communicatively connected to a quantum key generation and management component and a quantum key management server.
[0066] Furthermore, the quantum encryption unit and storage unit can reside in the same device. For example, the quantum encryption and storage component can be a proxy server or a key server, capable of both encryption and storage functions. Its quantum encryption unit and storage unit are implemented by the processor and storage medium, respectively. It should be noted that using a single-point quantum key to encrypt a symmetric quantum key is a key-to-key encryption method. This can be achieved by treating the key to be encrypted as plaintext and using existing encryption algorithms. It is existing technology and not an improvement upon this disclosure. For example, the Key Encapsulation Mechanism (KEM) demonstrates a key-to-key encryption method.
[0067] The quantum key management server is communicatively connected to the quantum key encryption and storage component. In response to requests from the quantum-safe blockchain node component, it can send quantum-safe key information to the quantum-safe gateway within that node component. The quantum key management server is a key management server capable of managing and scheduling key information. It should be noted that the control process for calling and forwarding quantum-safe key information implemented by the quantum key management server described in this disclosure is essentially a scheduling process for information; it belongs to existing technology and is not an improvement upon this disclosure, and will not be elaborated upon further.
[0068] Optionally, see Figure 4 In one possible implementation, in Figure 3 Based on the quantum key generation and management component shown, the quantum key generation and management component also includes a quantum key injector that is communicatively connected to the data acquisition switch. The quantum key injector is used to inject the single-point quantum key into the quantum security U-shield and / or the quantum security TF card. The quantum security gateway is also provided with an interface for connecting the quantum security U-shield and the quantum security TF card.
[0069] Specifically, see Figure 4 The quantum key generation and management component includes:
[0070] A quantum random number generator is used to generate single-point quantum keys;
[0071] A quantum key distribution device used to generate symmetric quantum keys;
[0072] The data acquisition switch is communicatively connected to the quantum random number generator and the quantum key distribution device. The data acquisition switch is used to acquire the single-point quantum key generated by the quantum random number generator and the symmetric quantum key generated by the quantum key distribution device. The data acquisition switch is also communicatively connected to the quantum encryption and storage component.
[0073] A cryptographic exchange machine is communicatively connected to the data acquisition switch. The cryptographic exchange machine is used to receive and store the single-point quantum key and the symmetric quantum key sent by the data acquisition switch.
[0074] A quantum key filling machine, which is communicatively connected to the data acquisition switch, is used to fill the single-point quantum key into a quantum-safe U-shield and / or a quantum-safe TF card.
[0075] Specifically, the data acquisition switch can collect single-point quantum keys from the cryptographic machine and send them to the quantum key injection machine. The quantum key injection machine then injects the single-point quantum keys into at least one of a quantum-secure U-shield (Ukey) and a quantum-secure TF card. The quantum-secure gateway is equipped with an interface for connecting the quantum-secure U-shield and the quantum-secure TF card. By inserting the quantum-secure U-shield and / or the quantum-secure TF card, which are injected with the single-point quantum keys, into the corresponding interface, the single-point quantum keys can be transmitted to the quantum-secure gateway through at least one of the two devices, thus improving the security of the transmission.
[0076] Of course, in other possible implementations, single-point quantum keys can also be transmitted and filled in other ways. For example, single-point quantum keys can be transmitted through a secure and reliable dedicated line, or single-point quantum keys can be filled into a quantum-safe U-shield or a quantum-safe TF card through a cryptographic exchange machine with filling function. This disclosure does not impose any specific limitations on this.
[0077] Optionally, see Figure 5 In one possible implementation, the number of quantum key generation and management components and the number of quantum encryption and storage components in the quantum key management subsystem are both less than the number of quantum secure blockchain node components, and at least one of the quantum encryption and storage components is communicatively connected to multiple of the quantum secure gateways.
[0078] Specifically, since the number of quantum key generation and management components and the number of quantum encryption and storage components are both less than the number of quantum-safe blockchain node components, at least one quantum encryption and storage component will communicate with multiple quantum-safe gateways, thereby connecting one quantum encryption and storage component with multiple quantum-safe blockchain node components. This reduces the hardware cost of the quantum key management subsystem and also allows for key distribution in the form of group keys across multiple quantum-safe blockchain node components.
[0079] For example in Figure 5 The quantum-secure blockchain system shown includes a quantum key management subsystem comprising one quantum key management server 510, one quantum encryption and storage component 520, and two quantum key generation and management components (quantum key generation and management component 531 and quantum key generation and management component 532, respectively). In addition, the quantum-secure blockchain system also includes four quantum-secure blockchain node components (quantum-secure blockchain node component 541, quantum-secure blockchain node component 542, quantum-secure blockchain node component 543, and quantum-secure blockchain node component 544, respectively).
[0080] See Figure 5The quantum encryption and storage component 520 communicates with the quantum secure blockchain node components 541, 542, 543, and 544 respectively through their respective quantum secure gateways. The quantum encryption and storage component 520 also communicates with the quantum key generation and management components 531 and 532. The quantum key generation and management components 531 and 532 can communicate with each other. The four quantum secure blockchain node components 541-544 communicate with each other, forming a decentralized topological network structure. Thus, the quantum encryption and storage component 520 can distribute quantum-secure key information to the corresponding quantum-secure blockchain node components. For example, in some possible implementations, the same quantum-secure key information is distributed to four quantum-secure blockchain node components 541-544. In some possible implementations, one set of the same quantum-secure key information is distributed to quantum-secure blockchain node components 541 and 542, and another set of the same quantum-secure key information is distributed to quantum-secure blockchain node components 543 and 544.
[0081] Optionally, all the quantum key generation and management components and the quantum encryption and storage components reside in the same secure and trusted communication environment. This allows the quantum key generation and management components and the quantum encryption and storage components to be placed in the same environment, forming a quantum key management center, which facilitates management and maintenance. Furthermore, it can replace a CA (Certificate Authority) and is more lightweight.
[0082] Optionally, see Figure 6 In one possible implementation, the number of quantum key generation and management components and the number of quantum encryption and storage components in the quantum key management subsystem are the same as the number of quantum secure blockchain node components. Each quantum encryption and storage component is communicatively connected to a quantum secure gateway and a quantum key generation and management component, and multiple quantum key generation and management components establish communication connections with each other to form the decentralized topological network structure.
[0083] Specifically, the number of quantum key generation and management components, quantum encryption and storage components, and quantum-safe blockchain node components are the same. Furthermore, each quantum encryption and storage component communicates with only one quantum-safe gateway and one quantum key generation and management component. Thus, each quantum-safe blockchain node component has one quantum key generation and management component and one quantum encryption and storage component to provide it with quantum-safe key information. Each quantum-safe key is used only for communication between a pair of quantum-safe blockchain node components, becoming a point-to-point key. This improves communication security even when blockchain nodes do not trust each other.
[0084] For example, in Figure 6 In the illustrated quantum-secure blockchain system, the quantum key management subsystem includes four quantum key generation and management components (quantum key generation and management components 631, 632, 633, and 634), four quantum encryption and storage components (quantum encryption and storage components 621, 622, 623, and 624), and one quantum key management server 610. These four quantum key generation and management components 631-634 are interconnected, forming a decentralized topological network structure to generate symmetric quantum keys for peer-to-peer encryption. The four quantum encryption and storage components 621-624 can also communicate with each other, forming a decentralized topological network structure. In some implementations, such as when the quantum encryption and storage components act as proxy servers, they can assist in the distribution of symmetric quantum keys. The quantum key management server 610 is communicatively connected to these four quantum encryption and storage components 621-624.
[0085] also, Figure 6 The illustrated quantum-safe blockchain system also includes four quantum-safe blockchain node components (quantum-safe blockchain node component 641, quantum-safe blockchain node component 642, quantum-safe blockchain node component 643, and quantum-safe blockchain node component 644). These four quantum-safe blockchain node components 641-644 are interconnected, forming a decentralized topological network structure. Thus, quantum-safe key information generated by a quantum key generation and management component and a quantum encryption and storage component is only provided to one quantum-safe blockchain node component. For example, the quantum-safe key information generated by quantum key generation and management component 631 and quantum encryption and storage component 621 is only provided to quantum-safe blockchain node component 641, thereby improving the system's communication security.
[0086] Optionally, the quantum encryption and storage component and the quantum key generation and management component, which are interconnected, reside in the same secure and trusted communication environment. This can improve the security of communication between the quantum encryption and storage component and the quantum key generation and management component.
[0087] by Figure 6 Taking the illustrated quantum-secure blockchain system as an example, the quantum key generation and management component 631 and the quantum encryption and storage component 621 can reside in the same secure and trusted communication environment, as can the quantum key generation and management component 632 and the quantum encryption and storage component 622. This enhances the security of communication between the interconnected quantum key generation and management components and the quantum encryption and storage component.
[0088] In one possible implementation, when the quantum encryption and storage component acts as a proxy server, it can adjust the string of quantum-safe key information to an appropriate key file size and save it along with the key ID and the quantum key generation and management component ID. Alternatively, upon request from a quantum-safe blockchain node component, it can provide quantum-safe key information to the quantum-safe blockchain node component in an appropriate format, recording the corresponding symmetric quantum key ID, the quantum-safe blockchain node component ID, and the symmetric quantum key usage date, and send this information to the quantum key management server to ensure key traceability. When the stored quantum-safe key information expires, the quantum key management server can send an instruction to the proxy server to delete the corresponding quantum-safe key information. The quantum key management server can collect quantum key distribution link information from the proxy server, including bit error rate, key rate, and key accumulation, and organize a routing table to provide a secure path to the proxy server.
[0089] In one possible implementation, the quantum key management server can also configure a user admission mechanism for quantum-safe blockchain node components. This configured mechanism can be imported into the quantum key management server, allowing it to determine whether to provide the corresponding quantum-safe blockchain node with symmetric quantum key encryption based on the user admission permissions defined by the preset mechanism. For example, the user admission mechanism can adopt a public blockchain model with application-based approval for decentralized and unorganized management; it can also adopt a user-voting annotation model or a consortium blockchain model; or the decision can be made by a management organization. The quantum key management server can also set unified key update policies and key management cycles for proxy servers to ensure system consistency and coordination.
[0090] Because single-point quantum keys are pre-built keys rather than real-time generated keys, they are unsuitable for session encryption. When communication occurs between nodes in a quantum-safe blockchain, a symmetric quantum key is required as the session key. Therefore, a quantum random number generator and a quantum key distribution device within the quantum key generation and management component generate single-point quantum keys and symmetric quantum keys respectively. The single-point quantum key is used to encrypt the symmetric quantum key, which can then be transmitted using a one-time pad method. The transmission of the symmetric quantum key itself is encrypted into a two-level key using quantum communication, enhancing transmission security and further ensuring the security of encrypted communication using the symmetric quantum key. Both single-point quantum keys and symmetric quantum keys are generated based on quantum physics properties, offering high security. Combined with the use of symmetric encryption and decryption algorithms throughout the process, the quantum-safe blockchain system possesses quantum computing resistance capabilities and improves communication efficiency.
[0091] The preferred embodiments of this disclosure have been described in detail above with reference to the accompanying drawings. However, this disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this disclosure, various simple modifications can be made to the technical solutions of this disclosure, and these simple modifications all fall within the protection scope of this disclosure.
[0092] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, this disclosure will not describe the various possible combinations separately.
[0093] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.
Claims
1. A quantum secure blockchain system, characterized in that, The quantum key management subsystem comprises a plurality of quantum secure blockchain node assemblies, each of which comprises a blockchain node terminal and a quantum secure gateway connected in communication with the blockchain node terminal, wherein: The quantum key management subsystem comprises: A quantum key generation and management assembly for generating a single-point quantum key and a symmetric quantum key; A quantum encryption and storage assembly connected in communication with the quantum secure gateway and the quantum key generation and management assembly respectively, for encrypting and packaging the symmetric quantum key with the single-point quantum key to obtain quantum secure key information, and storing the quantum secure key information; A quantum key management server connected in communication with the quantum encryption and storage assembly, for calling the quantum encryption and storage assembly to send the quantum secure key information to the quantum secure gateway in the quantum secure blockchain node assembly; A plurality of quantum secure gateways are connected in communication with each other to form a decentralized topological network structure; the quantum secure gateway is configured to encrypt session information of the blockchain node terminal into encrypted information using the quantum secure key information, and send the encrypted information to other quantum secure gateways.
2. The quantum secure blockchain system of claim 1, wherein, The quantum key generation and management assembly comprises: A quantum random number generator for generating a single-point quantum key; A quantum key distribution device for generating a symmetric quantum key; A data acquisition switch connected in communication with the quantum random number generator and the quantum key distribution device, the data acquisition switch being configured to acquire the single-point quantum key generated by the quantum random number generator and the symmetric quantum key generated by the quantum key distribution device; the data acquisition switch is also connected in communication with the quantum encryption and storage assembly; An exchange cipher machine connected in communication with the data acquisition switch, the exchange cipher machine being configured to receive and store the single-point quantum key and the symmetric quantum key sent by the data acquisition switch.
3. The quantum secure blockchain system of claim 2, wherein, The model of the data acquisition switch is S5720-52P-EI-AC, the model of the quantum key distribution device is QKDM-POL40A-S-24G1, the model of the quantum random number generator is QRNG-100E-1012, and the model of the exchange cipher machine is MODULE-SJJ1963-AC.
4. The quantum secure blockchain system of claim 2, wherein, The quantum key generation and management assembly further comprises a quantum key refilling machine connected in communication with the data acquisition switch, the quantum key refilling machine being configured to refill the single-point quantum key to a quantum secure U disk and / or a quantum secure TF card, and the quantum secure gateway is further provided with an interface for connecting the quantum secure U disk and the quantum secure TF card.
5. The quantum secure blockchain system of claim 1, wherein, The number of quantum key generation and management assemblies and the number of quantum encryption and storage assemblies in the quantum key management subsystem are less than the number of quantum secure blockchain node assemblies, and at least one quantum encryption and storage assembly is connected in communication with a plurality of quantum secure gateways.
6. The quantum secure blockchain system of claim 5, wherein, All the quantum key generation and management assemblies and the quantum encryption and storage assemblies are located in the same secure and trusted communication environment.
7. The quantum secure blockchain system of claim 1, wherein, The number of quantum key generation and management components and the number of quantum encryption and storage components in the quantum key management subsystem are the same as the number of quantum secure blockchain node components, each quantum encryption and storage component is respectively communicatively connected to one quantum secure gateway and one quantum key generation and management component, and a plurality of quantum key generation and management components are communicatively connected to each other to form the decentralized topological network structure.
8. The quantum secure blockchain system of claim 7, wherein, The quantum encryption and storage components and the quantum key generation and management components that are communicatively connected to each other are located in the same secure and trusted communication environment.
9. The quantum secure blockchain system of claim 1, wherein, The quantum encryption and storage component includes a quantum encryption unit and a storage unit that are communicatively connected to each other.