Method and system for achieving zero-packet-loss ipsec sa key exchange through quantum key integration, and gateway
By integrating quantum key technology in the IPsec SA key replacement process, quantum SA is generated and synchronous switching is solved, and packet loss caused by IPsec SA key replacement in traditional IPsec networks is achieved, and zero packet loss and higher security network communication is achieved.
Patent Information
- Application Number
- PCT/CN2024/120819
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-23
- Filing Date
- 2024-09-24
- Publication Date
- 2025-05-30
AI Technical Summary
In traditional IPsec networks, the key replacement process of IPsec SA may lead to packet loss and service interruption in data transmission.
By integrating quantum key technology, the method of zero packet loss for IPsec SA key exchange includes the initiator and responder generating quantum SA when the first IPsec SA is aged, and synchronously switching to the quantum SA and the second IPsec SA through a timer.
This method can resist the cracking of quantum computers, improve data transmission security, avoid packet loss and service interruption during IPsec SA key replacement, and provide more efficient and secure network communication.
Smart Images

Figure CN2024120819_30052025_PF_FP_ABST
Abstract
Description
Method, gateway, and system for integrating quantum key to achieve zero packet loss in IPsec SA key exchange
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 23, 2023, with application number: 202311576770.6 and application name: "Method, gateway, and system for integrating quantum keys to achieve IPsec SA key change with zero packet loss", the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The technical field of the present application relates to the field of network security communications, and in particular to a method, gateway, and system for integrating quantum keys to achieve zero packet loss in IPsec SA key exchange. Background Art
[0003] IPsec protocol: As a key technology, IPsec provides security functions such as encryption, integrity verification, and identity authentication for IP data.
[0004] Security Association (SA) Management: SA management refers to the creation, maintenance, and update of SAs. SAs are data structures that store security parameters, including encryption algorithms, keys, and other information.
[0005] Quantum key distribution: Using quantum key distribution devices, a shared secure key is created by sending and receiving quantum states.
[0006] In traditional IPsec (Internet Protocol Security) networks, the key change process of the Security Association (SA) may cause packet loss and service interruption during data transmission.
[0007] To maintain security during IPsec communications, IPsec SAs are designed with update and aging mechanisms, including flow aging and time aging. With flow aging, IPsec SAs are updated when traffic reaches a certain limit. With time aging, IPsec SAs are also updated after a certain period of time. Currently, a common update method is to initiate renegotiation of the IPsec SA when the initiator's traffic or time limit reaches a limit, sending a renegotiation message. The responder then receives the message and responds. However, when both the initiator and responder update the SA, a problem arises: after the initiator updates the SA, the renegotiation message sent by the responder may be delayed in the network and not reach the responder in time. Consequently, the responder may not be able to decrypt data encrypted by the initiator using the new SA before the SA is updated, resulting in message discard.
[0008] Patent document CN112910893A discloses a method for preventing packet loss after IPsec SA aging, comprising: S1, establishing an IPsec channel with a peer device and generating a first IPsec SA; S2, upon receiving a key exchange message from the peer device or when the first IPsec SA reaches the aging requirement, sending a key exchange message to the peer device, renegotiating the key with the peer device, creating a second IPsec SA, and retaining the first IPsec SA; S3, starting a timer and, before the timer expires, encrypting encrypted messages sent to the peer device using the first IPsec SA; S4, after the timer expires, determining whether the encrypted messages sent by the peer device are encrypted using the second IPsec SA; S5, if the encrypted messages sent by the peer device are encrypted using the second IPsec SA after the timer expires, deleting the first IPsec SA; otherwise, repeating steps S3 to S4. This application solves the current problem of frequent packet loss after SA aging. This patent document does not incorporate quantum keys and has the following defects: 1) It cannot resist cracking by quantum computers and has low data transmission security; 2) The negotiation efficiency is low and it is prone to aging, resulting in packet loss problems.
[0009] Summary of the Invention
[0010] The technical problem to be solved by this application is how to avoid packet loss and service interruption in data transmission caused by the IPsec SA key replacement process.
[0011] This application solves the above technical problems through the following technical means: a method for integrating quantum keys to achieve zero packet loss in IPsec SA key change, including the following steps:
[0012] The initiator initiates key negotiation to establish an IPsec tunnel with the responder and generates the first IPsec SA.
[0013] When the first IPsec SA reaches the aging requirement, the initiator in the renegotiation first generates a quantum SA based on the SPI in the IKE_SA, sends a key exchange message to the responder, and starts the initiator's first timer;
[0014] After receiving the key exchange message, the responder also uses the SPI in IKE_SA to generate a quantum SA and starts the responder's first timer.
[0015] When the first timer of both parties reaches the predetermined time, they will switch from the first IPsec SA to the quantum SA synchronously.
[0016] After the re-key negotiation is completed, both parties start the second timer;
[0017] When the second timer of both parties reaches the predetermined time, they will synchronously switch from the quantum SA to the second IPsec SA.
[0018] As a further specific technical solution, step S1 includes the following contents:
[0019] The local device initiates an IKE negotiation request.
[0020] After receiving the request, the peer device responds, and the two parties negotiate based on the configuration parameters to establish an IKE SA.
[0021] After the IKE SA is generated, both parties initiate IPSec negotiation. The two parties negotiate through the key negotiation module based on the configured parameters, thus generating the first IPSec SA.
[0022] After the IPSec SA between the two parties reaches the ESTABLISHED state, the two parties transmit data based on the IPSec SA.
[0023] As a further specific technical solution, step S2 includes the following contents:
[0024] The initiator of the renegotiation obtains the corresponding two sets of quantum keys from the QT secure SIM card module according to initiator_spi and responder_spi in IKE_SA;
[0025] The quantum key is decrypted using the SM4 algorithm in the preset cryptographic component module using CBC encryption to obtain two sets of quantum key plaintexts;
[0026] The two sets of quantum key plaintexts are derived into a 32-byte SM3 key and a 16-byte SM4 key respectively;
[0027] The initiator uses the SA generated by initiator_spi as the outbound direction and the SA generated by responder_spi as the inbound direction.
[0028] The initiator quantum SA generated by the two sets of quantum keys is sent to the kernel via netlink, and the timer module is used to simultaneously start the initiator first timer, whose time is set before the hard expiration of the first IPSec SA.
[0029] As a further specific technical solution, step S3 includes the following contents:
[0030] After receiving the first re-key negotiation packet, the initiator_spi and responder_spi in the IKE_SA can be obtained from the message. The same method as step S2 is used to generate two SAs. The quantum SA generated by the initiator_spi is used as the in direction, and the quantum SA generated by the responder_spi is used as the out direction. At the same time, the timer module is used to start the first timer of the responder. The expiration time of the first timer of the responder is synchronized with the expiration time of the first timer of the initiator.
[0031] As one of the further specific technical solutions, step S5 includes the following content: once the re-key negotiation is completed, that is, both parties have successfully obtained the new key and have a second IPsec SA, a timer will be started to switch the SA. After starting the second timer, the devices of both parties perform the corresponding SA switching operation according to a predetermined time interval.
[0032] The present application also provides a quantum gateway that executes the method of integrating quantum keys to achieve IPsec SA key change with zero packet loss as described in any of the above schemes, including: a QT secure SIM card module, a preset password component module, a key negotiation module, and a timer.
[0033] This application also provides a system for implementing zero-packet-loss IPsec SA key rekeying by integrating quantum keys, including the following modules:
[0034] A first IPsec SA module, configured for an initiator to initiate key negotiation with a responder to establish an IPsec channel and generate a first IPsec SA;
[0035] The initiator's first timer start module is configured to, when the first IPsec SA reaches the aging requirement, generate a quantum SA according to the SPI in the IKE_SA during renegotiation, send a key exchange message to the responder, and start the initiator's first timer.
[0036] The responder first timer start module is used for the responder to receive the key exchange message and also use the SPI in the IKE_SA to generate the quantum SA and start the responder first timer;
[0037] A first switching module is configured to synchronously switch from the first IPsec SA to the quantum SA when the first timer of both parties reaches a predetermined time;
[0038] The second timer starts the module, and after the re-key negotiation is completed, both parties start the second timer;
[0039] In the second switching module, when the second timers of both parties reach a predetermined time, the quantum SA is synchronously switched to the second IPsec SA.
[0040] As a further specific technical solution, the first IPsec SA module includes the following contents:
[0041] IKE negotiation request unit, used by the local device to initiate an IKE negotiation request;
[0042] The IKE SA generation unit is used to respond to the request from the peer device, and the two parties negotiate based on the configuration parameters to generate the IKE SA;
[0043] The first IPSec SA generation unit is used to initiate IPSec negotiation between the two parties after the IKE SA is generated. The two parties negotiate through the key negotiation module based on the configuration parameters to generate the first IPSec SA.
[0044] The data transmission unit is used for data transmission between the two parties according to the IPSec SA after the IPSec SA reaches the ESTABLISHED state.
[0045] As one further specific technical solution, the initiator's first timer starting module includes the following contents:
[0046] The quantum key acquisition unit is used for the renegotiation initiator to obtain the corresponding two sets of quantum keys from the QT secure SIM card module according to the initiator_spi and responder_spi in IKE_SA;
[0047] A quantum key plaintext acquisition unit is used to decrypt the quantum key using the SM4 algorithm in the preset cryptographic component module using the CBC encryption method to obtain two sets of quantum key plaintexts;
[0048] The spi acquisition unit in the SA is used to derive the two sets of quantum key plaintexts into a 32-byte SM3 key and a 16-byte SM4 key respectively;
[0049] Direction determination unit, used by the initiator to use the SA generated by initiator_spi as the out direction and the SA generated by responder_spi as the in direction;
[0050] The first timer starting unit sends the initiator quantum SA for generating two sets of quantum keys to the kernel through netlink, and uses the timer module to simultaneously start the initiator first timer, whose time is set before the hard expiration of the first IPSec SA.
[0051] The present application proposes a computing and processing device, which includes: a memory storing computer-readable code; and one or more processors. When the computer-readable code is executed by one or more processors, the computing and processing device executes the method proposed above for achieving zero packet loss by fusing quantum keys to IPsec SA key exchange.
[0052] The present application proposes a computer program, including computer-readable code. When the computer-readable code is executed on a computing processing device, the computing processing device is caused to execute the method proposed above for fusing quantum keys to achieve IPsec SA key change with zero packet loss.
[0053] The present application proposes a computer-readable medium in which the computer program proposed above is stored.
[0054] The advantages of this application are:
[0055] Compared with the existing technology, this application can resist the cracking of quantum computers and improve the security of data transmission by integrating quantum key technology;
[0056] It is applied to the IPsec SA key replacement process, using the SPI of the initiator and responder in the traditional IPsec SA to directly obtain it in the quantum SIM card. In terms of acquisition method, acquisition speed, and transmission security, this application obtains the second IPsec SA from the local machine, which is faster and more secure. The second IPsec SA is a quantum SA, which has stronger resistance to quantum computers and higher security, and effectively solves the packet loss problem caused by aging.
[0057] Compared with the patent application with publication number CN112910893A, in the patent application with publication number CN112910893A, the generation of the second IPSec SA is completed by IKE negotiation. In the present application, the generation of the second IPSec SA is completed by quantum SA. The generation speed of the second IPSec SA in the patent application CN112910893A is not as fast as the generation speed of the quantum SA in the present application, and the security of the second IPSec SA in the patent application CN112910893A is not as high as the security of the quantum SA in the present application.
[0058] This innovative method, device, and equipment not only provides a higher level of cybersecurity protection but also defends against possible future quantum computing attacks. It provides stable and reliable protection for data communications, ensuring the confidentiality and integrity of information, and has significant application value in the field of cybersecurity.
[0059] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0061] FIG1 is an interactive flow chart of a method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key according to an embodiment of the present application;
[0062] FIG2 is a flow chart of a method for implementing zero packet loss for IPsec SA key exchange by integrating quantum key according to an embodiment of the present application;
[0063] FIG3 is a block diagram of the composition principle of a quantum gateway proposed in an embodiment of the present application;
[0064] FIG4 is a schematic diagram of the structure of a computing and processing device for implementing a method for implementing IPsec SA key exchange with zero packet loss by integrating quantum keys, as proposed in another embodiment of the present application;
[0065] FIG5 is a schematic diagram of the structure of a computer program for implementing a method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key, as proposed in another embodiment of the present application. Specific embodiments
[0066] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0067] To address the issues of packet loss and service interruption during data transmission caused by the IPsec SA key rekeying process and improve communication security, this application proposes a method for achieving zero packet loss in IPsec SA key rekeying by integrating quantum keys. This method combines quantum key distribution (QKD) technology with the IPsec protocol. Quantum key distribution technology uses the principles of quantum physics to achieve secure key exchange and can provide unconditional security, that is, security that is not limited by computing power. The IPsec protocol is used to protect the confidentiality, integrity, and identity authentication of data communications.
[0068] Example 1
[0069] Referring to Figures 1 and 2 , this application integrates quantum keys to solve the current problem of packet loss during IPsec key changes, including the following steps:
[0070] S1. The initiator initiates key negotiation to establish an IPsec channel with the responder and generates the first IPsec SA.
[0071] S2. When the first IPsec SA reaches the aging requirement, the initiator in the renegotiation first generates a quantum SA based on the SPI in the IKE_SA, sends a key exchange message to the responder, and starts the initiator's first timer.
[0072] S3. The responder receives the key exchange message and generates a quantum SA using the SPI in the IKE_SA, and starts the responder's first timer.
[0073] S4. When the first timer of both parties reaches the predetermined time, they simultaneously switch from the first IPsec SA to the quantum SA.
[0074] S5. The two parties complete the re-key negotiation and both start the second timer.
[0075] S6. When the second timer of both parties reaches the predetermined time, they synchronously switch from the quantum SA to the second IPsec SA.
[0076] The initiator and responder are corresponding quantum gateways, as shown in Figure 3, including:
[0077] QT secure SIM card module: also known as quantum SIM card, is a new type of SIM card based on quantum technology. It uses the principles of quantum communication and quantum encryption to provide a higher level of security and privacy protection;
[0078] Preset password component module: provides the calculation method of the preset algorithm SM4 / SM3 to complete the encryption and decryption of data;
[0079] Key negotiation module: completes the negotiation of the first IPSec SA and the second IPSec SA;
[0080] Timer: A timer is used to execute scheduled tasks, such as synchronously switching from the first IPsec SA to the quantum SA, or synchronously switching from the quantum SA to the second IPsec SA.
[0081] The specific execution process of the above steps is as follows:
[0082] S1. The initiator initiates key negotiation to establish an IPsec channel with the responder and generates the first IPsec SA.
[0083] IPSec (Internet Protocol Security) is an open standard framework used to ensure the confidentiality and security of communications on Internet Protocol (IP) networks by using encrypted security services. SA (Security Association) is used to record the policies and policy parameters of each IP security channel. The Security Association is the foundation of IPSec and is an agreement established by the communicating parties. It determines the protocols used to protect data packets, transcoding methods, keys, and key validity periods. When communicating, the two parties of IPSec have established a connection and the IPSec SA of both parties has been successfully negotiated, so messages can be transmitted normally. Specifically, step S1 includes the following:
[0084] 1. The local device (Gateway A in Figure 1) initiates an IKE (Internet Key Exchange) negotiation request.
[0085] 2. The peer device (Gateway B in Figure 1) responds to the request, and both parties negotiate based on the configuration parameters to establish an IKE SA.
[0086] 3. After the IKE SA is generated, both parties initiate IPSec negotiation. Based on the configured parameters, the two parties negotiate through the key negotiation module, thus generating the first IPSec SA.
[0087] 4. After the IPSec SA between the two parties reaches the ESTABLISHED state, the two parties can transmit data based on the IPSec SA;
[0088] The above is the specific process of IPSec communication. In this process, IKE negotiation generates an IKE SA, and then IPSec negotiation generates the first IPSec SA. Once the IPSec SAs of both parties reach the ESTABLISHED state, both parties can transmit data based on these SAs.
[0089] S2. When the first IPsec SA reaches the aging requirement, the initiator in the renegotiation first generates a quantum SA based on the SPI in the IKE_SA, sends a key exchange message to the responder, and starts the initiator's first timer.
[0090] In this example, after the local device and the remote device have negotiated an IPsec SA, when the traffic or time limit of one party is reached, the IPsec SA renegotiation will be triggered. The initiator of the renegotiation will first generate a quantum SA. The generation steps are as follows:
[0091] 1. The initiator of the renegotiation (the party that reaches the traffic or time limit first) obtains the corresponding two sets of quantum keys from the QT secure SIM card module according to the initiator_spi and responder_spi in IKE_SA;
[0092] 2. Use the SM4 algorithm in the preset cryptographic component module to decrypt the quantum key using CBC encryption to obtain two sets of quantum key plaintexts;
[0093] 3. Derive the two sets of quantum key plaintexts into a 32-byte SM3 key and a 16-byte SM4 key respectively;
[0094] 4. The initiator uses the SA generated by initiator_spi as the outbound direction and the SA generated by responder_spi as the inbound direction.
[0095] 5. The initiator's quantum SA generated by the two sets of quantum keys is sent to the kernel via netlink, and the timer module is used to simultaneously start the initiator's first timer, whose time is set before the hard expiration of the first IPSec SA.
[0096] After the initiator generates the quantum SA in the above steps, it sends a re-negotiated IPsec SA message (also called a key exchange message).
[0097] S3. The responder receives the key exchange message and also uses the SPI in IKE_SA to generate a quantum SA. The timer module is used to start the first timer of the responder.
[0098] After receiving the first rekey negotiation packet, the initiator_spi and responder_spi in the IKE_SA are obtained from the message. Two SAs are generated using the same method as in step S2. The quantum SA generated by the initiator_spi is used as the inbound direction, and the quantum SA generated by the responder_spi is used as the outbound direction. The timer module is used to start the responder's first timer, and the expiration time of the responder's first timer is synchronized with the initiator's first timer.
[0099] S4: When the first timer of both parties expires, they simultaneously switch from the first IPsec SA to the quantum SA.
[0100] When the first timer of both parties reaches the time, they can switch from the first IPsec SA (security association) to the quantum SA (security association) through synchronization.
[0101] In an IPsec VPN, an SA is a set of security parameters used to encrypt and authenticate IP packets. When an SA needs to be changed or updated, quantum SA technology can be used to achieve a smooth switchover. Once the switchover is complete, both devices should verify that the new SA is working properly and ensure continued communication.
[0102] S5. The two parties complete the re-key negotiation and both start the second timer.
[0103] Once the rekey negotiation is complete, meaning both parties have completed the rekey and established the second IPsec SA, a timer will start to switch the SA. After the second timer starts, both devices will switch SAs at predetermined intervals to ensure the stability and security of data encryption and decryption.
[0104] S6: When the second timer of both parties expires, they synchronously switch from the quantum SA to the second IPsec SA.
[0105] When the second timer on both sides expires, both devices will first terminate the current quantum SA and stop using the encryption protocol. This means that subsequent data transmission will no longer be encrypted using the quantum encryption algorithm, and both devices will start a new IPsec SA for encryption and decryption.
[0106] In this application, the switching between the first IPSec SA and the second IPSec SA is not only completed by traditional key negotiation, but a quantum SA is added during the negotiation process to avoid data packet loss in the middle.
[0107] The quantum SA in this application is based on the charging of quantum SIM cards. It has a huge number of keys, and each set of keys has a unique ID corresponding to it.
[0108] The SPIs of the initiator and responder of the first IPSec SA negotiated in this application have been uniquely guaranteed by the key negotiation module;
[0109] In this application, SPI calculation can quickly obtain a unique key ID from a large number of quantum keys;
[0110] In this application, after the first timer expires, the encryption direction will be encrypted through the quantum SA, and the decryption direction will first be verified through the first IPSEC SA for data integrity. If successful, the data will be forwarded normally. If it fails, the data integrity will be verified again through the quantum SA to avoid packet loss caused by the time difference between the initiator and the responder due to the timer expiration;
[0111] In this application, after the second timer expires, the encryption method will be encrypted through the second IPSec SA, and the decryption direction will first be verified through the quantum SA for data integrity. If successful, the data will be forwarded normally. If it fails, the data integrity will be verified through the second IPSEC SA to avoid packet loss caused by the time difference between the initiator and the responder due to the expiration of the timer.
[0112] Example 2
[0113] This embodiment provides a system for implementing zero-packet-loss IPsec SA key rekeying by integrating quantum keys, corresponding to the first embodiment described above, including the following modules:
[0114] A first IPsec SA module, configured for an initiator to initiate key negotiation with a responder to establish an IPsec channel and generate a first IPsec SA;
[0115] The initiator's first timer start module is configured to, when the first IPsec SA reaches the aging requirement, generate a quantum SA according to the SPI in the IKE_SA during renegotiation, send a key exchange message to the responder, and start the initiator's first timer.
[0116] The responder first timer start module is used for the responder to receive the key exchange message and also use the SPI in the IKE_SA to generate the quantum SA and start the responder first timer;
[0117] A first switching module is configured to synchronously switch from the first IPsec SA to the quantum SA when the first timer of both parties reaches a predetermined time;
[0118] The second timer starts the module, and after the re-key negotiation is completed, both parties start the second timer;
[0119] In the second switching module, when the second timers of both parties reach a predetermined time, the quantum SA is synchronously switched to the second IPsec SA.
[0120] The first IPsec SA module includes the following:
[0121] IKE negotiation request unit, used by the local device to initiate an IKE negotiation request;
[0122] The IKE SA generation unit is used to respond to the request from the peer device, and the two parties negotiate based on the configuration parameters to generate the IKE SA;
[0123] The first IPSec SA generation unit is used to initiate IPSec negotiation between the two parties after the IKE SA is generated. The two parties negotiate through the key negotiation module based on the configuration parameters to generate the first IPSec SA.
[0124] The data transmission unit is used by both parties to transmit data according to the IPSec SA after the IPSec SA reaches the ESTABLISHED state.
[0125] The initiator's first timer starting module includes the following contents:
[0126] The quantum key acquisition unit is used for the renegotiation initiator to obtain the corresponding two sets of quantum keys from the QT secure SIM card module according to the initiator_spi and responder_spi in IKE_SA;
[0127] A quantum key plaintext acquisition unit is used to decrypt the quantum key using the SM4 algorithm in the preset cryptographic component module using the CBC encryption method to obtain two sets of quantum key plaintexts;
[0128] The spi acquisition unit in the SA is used to derive the two sets of quantum key plaintexts into a 32-byte SM3 key and a 16-byte SM4 key respectively;
[0129] Direction determination unit, used by the initiator to use the SA generated by initiator_spi as the out direction and the SA generated by responder_spi as the in direction;
[0130] The first timer starting unit sends the initiator quantum SA for generating two sets of quantum keys to the kernel through netlink, and uses the timer module to simultaneously start the initiator first timer, whose time is set before the hard expiration of the first IPSec SA.
[0131] Among them, in the first timer start module of the responder, upon receiving the first re-key negotiation packet, the initiator_spi and responder_spi in the IKE_SA can be obtained from the message, and two SAs are generated using the same method as the first timer start module of the initiator. The quantum SA generated by the initiator_spi is used as the in direction, and the quantum SA generated by the responder_spi is used as the out direction. At the same time, the timer module is used to start the first timer of the responder, and the expiration time of the first timer of the responder is synchronized with the expiration time of the first timer of the initiator.
[0132] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0133] The various component embodiments of the present application can be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing equipment according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0134] For example, FIG4 illustrates a computing device that can implement the methods according to the present application. The computing device typically includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020. Memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or ROM. Memory 1020 has storage space 1030 for program code 1031 for executing any of the method steps described above. For example, storage space 1030 for program code can include individual program codes 1031 for implementing various steps in the method described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units, as described with reference to FIG5 . This storage unit can have storage segments, storage space, and the like arranged similarly to memory 1020 in the computing device of FIG4 . The program code can, for example, be compressed in a suitable form. Typically, the storage unit includes computer-readable codes 1031 ′, ie, codes that can be read by a processor such as 1010 , which, when executed by a computing device, cause the computing device to perform the steps of the method described above.
[0135] References herein to "one embodiment," "an embodiment," or "one or more embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Furthermore, please note that instances of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.
[0136] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.
[0137] In the claims, any reference signs placed between brackets shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.
[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for implementing zero packet loss for IPsec SA key exchange by integrating quantum key, wherein: The steps include: S1. The initiator initiates key negotiation to establish an IPsec channel with the responder and generates the first IPsec SA. S2. When the first IPsec SA reaches the aging requirement, the initiator in the renegotiation first generates a quantum SA according to the SPI in the IKE_SA, sends a key exchange message to the responder, and starts the first timer of the initiator; S3. The responder receives the key exchange message and generates a quantum SA using the SPI in IKE_SA, and starts the first timer of the responder. S4. When the first timer of both parties reaches the predetermined time, they switch from the first IPsec SA to the quantum SA synchronously. S5. The two parties complete the re-key negotiation and both start the second timer. S6. When the second timer of both parties reaches the preset time, they synchronously switch from the quantum SA to the second IPsec SA.
2. The method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 1, wherein: The step S1 includes the following contents: S11, the local device initiates an IKE negotiation request; S12, the peer device responds after receiving the request, and the two parties negotiate based on the configuration parameters to generate an IKE SA; S13, when the IKE SA is generated, the two parties initiate IPSec negotiation, and the two parties negotiate through the key negotiation module according to the configuration parameters, thereby generating the first IPSec SA; S14: After the IPSec SA of both parties reaches the ESTABLISHED state, both parties transmit data according to the IPSec SA.
3. The method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 1, wherein: The step S2 includes the following contents: S21. The initiator of the renegotiation obtains the corresponding two sets of quantum keys from the QT secure SIM card module according to initiator_spi and responder_spi in IKE_SA; S22, using the SM4 algorithm in the preset cryptographic component module to decrypt the quantum key using the CBC encryption method to obtain two sets of quantum key plaintexts; S23, deriving the two sets of quantum key plaintexts into a 32-byte SM3 key and a 16-byte SM4 key respectively; S24, the initiator uses the SA generated by initiator_spi as the out direction and uses responder_spi The generated SA is used as the in direction; S25. The initiator quantum SA generated by the two sets of quantum keys is sent to the kernel through netlink, and the timer module is used to start the initiator first timer at the same time, and the time is set before the hard expiration of the first IPSec SA.
4. The method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 3, wherein: The step S3 includes the following contents: After receiving the first packet of re-key negotiation, the initiator_spi and responder_spi in IKE_SA can be obtained from the message, and two SAs are generated using the same method as step S2. The quantum SA generated by initiator_spi is used as the in direction, and the quantum SA generated by responder_spi is used as the out direction. At the same time, the timer module is used to start the first timer of the responder, and the expiration time of the first timer of the responder is synchronized with the expiration time of the first timer of the initiator.
5. The method for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 1, wherein: The step S5 includes the following contents: once the re-key negotiation is completed, that is, both parties have successfully obtained the new key and the second IPsec SA, a timer will be started to switch the SA. After starting the second timer, the devices of both parties perform the corresponding SA switching operation according to the predetermined time interval.
6. A quantum gateway for executing the method for implementing IPsec SA key change with zero packet loss by integrating quantum keys as described in any one of claims 1 to 5, wherein: include: QT secure SIM card module, preset password component module, key negotiation module, and timer.
7. A system for implementing zero packet loss for IPsec SA key exchange by integrating quantum key, wherein: Includes the following modules: A first IPsec SA module, used for the initiator to initiate key negotiation to establish an IPsec channel with the responder and generate a first IPsec SA; The initiator first timer start module is used for, when the first IPsec SA reaches the aging requirement, the initiator first generates a quantum SA according to the SPI in the IKE_SA during the renegotiation, sends a key exchange message to the responder, and starts the initiator first timer; The responder first timer start module is used for the responder to receive the key exchange message and also use the SPI in IKE_SA to generate the quantum SA and start the responder first timer; The first switching module is used for synchronously switching from the first IPsec SA to the quantum SA when the first timer of both parties reaches a predetermined time; The second timer starts the module, and after the re-key negotiation is completed, both parties start the second timer; In the second switching module, when the second timers of both parties reach a predetermined time, the quantum SA is synchronously switched to the second IPsec SA.
8. The system for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 7, wherein: The first IPsec SA module includes the following: IKE negotiation request unit, used for the local device to initiate an IKE negotiation request; The IKE SA generation unit is used for the peer device to respond after receiving the request, and the two parties negotiate according to the configuration parameters to generate the IKE SA; The first IPSec SA generating unit is used for initiating IPSec negotiation between the two parties after the IKE SA is generated. The two parties negotiate through the key negotiation module according to the configuration parameters, thereby generating the first IPSec SA. The data transmission unit is used for data transmission between the two parties according to the IPSec SA after the IPSec SA of the two parties reaches the ESTABLISHED state.
9. The system for implementing IPsec SA key exchange with zero packet loss by integrating quantum key as claimed in claim 7, wherein: The initiator's first timer starting module includes the following contents: The quantum key acquisition unit is used for the initiator of the renegotiation to obtain the corresponding two sets of quantum keys from the QT secure SIM card module according to initiator_spi and responder_spi in IKE_SA; A quantum key plaintext acquisition unit is used to decrypt the quantum key using the CBC encryption method using the SM4 algorithm in the preset cryptographic component module to obtain two sets of quantum key plaintexts; The spi acquisition unit in the SA is used to derive two sets of quantum key plaintexts into a 32-byte SM3 key and a 16-byte SM4 key respectively; A direction determination unit, used for the initiator to use the SA generated by initiator_spi as the out direction and the SA generated by responder_spi as the in direction; The first timer starting unit is used to send the initiator quantum SA for generating two sets of quantum keys to the kernel through netlink, and simultaneously start the initiator first timer using the timer module, and the time is set before the hard expiration of the first IPSec SA.
10. A computing device, wherein: include: a memory having computer readable code stored therein; One or more processors, when the computer readable code is executed by the one or more processors, the computing processing device executes the method for achieving zero packet loss for IPsec SA key exchange by fusing quantum key as described in any one of claims 1-5.
11. A computer program, comprising a computer readable code, which, when executed on a computing processing device, causes the computing processing device to execute the method for implementing IPsec SA key exchange with zero packet loss by fusion quantum key according to any one of claims 1 to 5.
12. A computer readable medium having stored therein the computer program according to claim 11.
Citation Information
Patent Citations
IPSec VPN method used for realizing quantum safety
CN107453869A
A method for using a quantum key through IKEv2 negotiation
CN109714164A
Method, device and equipment for preventing packet loss after IPsec SA aging and storage medium
CN112910893A
Method, gateway and system for realizing IPsec SA key change zero packet loss by fusing quantum key
CN117640182A
Protected transmission of data using post-quantum cryptography
EP3562115A1