Quantum encryption communication data protection method, gateway, and system
By using quantum encryption to protect communication data in the public-specialized converged cluster intercom gateway, and using the quantum SDK and key management platform to generate session keys, the problem of lack of end-to-end encryption of the public-specialized converged cluster intercom gateway in the existing technology is solved, and high-security data transmission from the private network intercom terminal to the public network intercom terminal is realized.
Patent Information
- Application Number
- PCT/CN2024/120175
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-07
- Filing Date
- 2024-09-20
- Publication Date
- 2025-06-12
AI Technical Summary
The existing public-specialized integrated cluster intercom gateway lacks end-to-end encryption when intercom is intercom between private network intercom and public network intercom, resulting in a high risk of data leakage.
The method of protecting communication data by quantum encryption is adopted, and the quantum SDK is called through the public-specialized converged cluster intercom gateway, initialize and network-entry authentication to the key management platform, generate session keys, and use the keys in the prefabricated key store for encryption and decryption to ensure end-to-end encryption of the data during transmission.
End-to-end encryption from a private network intercom terminal to a public network intercom terminal is realized, reducing the risk of data leakage and improving the security of communication data.
Smart Images

Figure CN2024120175_12062025_PF_FP_ABST
Abstract
Description
Method, gateway and system for protecting communication data through quantum encryption
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 7, 2023, with application number 202311693484.8 and invention name “Method, gateway and system for quantum encryption protection of communication data”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of network security communication technology, and mainly to a method for obtaining and transmitting quantum keys for public network intercoms and private network intercoms based on a public-private integrated cluster intercom gateway. Background Art
[0003] Currently, mainstream trunking intercom systems in my country include private network digital trunking DMR (Digital Mobile Radio), PDT (Police Digital Trunking), TETRA (Trans European Trunked Radio), and public network intercom POC (Push-to-Talk Over Cellular). These systems are relatively independent, and the communication distance of private network digital trunking relies on its own communication coverage capabilities. With the development of 4G / 5G mobile internet, the public network-based POC intercom trunking system has become a supplement and backup for private network trunking intercom systems due to its low construction cost, wide coverage distance, and rich functionality.
[0004] Both public network trunking intercom and private network trunking intercom are relatively closed systems, using a variety of formats, standards, and protocols.
[0005] By deploying a cluster intercom gateway and dedicated custom cables, such as the public network intercom and private network intercom intercommunication gateway device disclosed in patent application publication number CN105682259A, and the method, gateway device and system for integrating private network intercom and public network intercom intercommunication disclosed in patent application publication number CN 111866761, interconnection between cluster intercom systems such as analog cluster, digital cluster (DMR), PDT, TETRA, and public network intercom (POC) can be achieved.
[0006] Regarding the interoperability security of public and private network trunking intercoms, currently available public-private converged trunking intercom gateways do not implement end-to-end encryption for intercom data from the gateway to the public network intercom group, typically transmitting it in plain text at the link layer. This presents a significant risk of data leakage for organizations using private network intercoms (DMR, PDT, TETRA, etc.) that wish to interoperate with public network intercoms.
[0007] Summary of the Invention
[0008] The technical problem to be solved by this application is how to realize data encryption when private network intercom and public network intercom are interconnected.
[0009] This application solves the above technical problems through the following technical means:
[0010] In the first aspect, this application proposes a method for quantum encryption protection of communication data in a public-private network converged communication system, which is applicable to a public-private converged cluster intercom gateway, including the following methods:
[0011] The public-private integrated cluster intercom gateway analyzes the intercom data from the private network intercom terminal a, converts the intercom data from analog signals into public network digital signals, and then converts them into public network intercom data;
[0012] The public-private integrated cluster intercom gateway calls the quantum SDK to perform initial authentication with the key management platform for identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication with the key management platform;
[0013] Receive the network authentication success and token validity period returned by the key management platform to complete identity authentication;
[0014] The public-private fusion cluster intercom gateway sends an encrypted intercom request to the intercom service platform, and receives a session ID generated by the intercom service platform based on the encrypted intercom request;
[0015] The public-private integrated cluster intercom gateway carries the device ID, session ID, and group ID and calls the Quantum SDK to send a key negotiation request to the key management platform;
[0016] The public-private integrated cluster intercom gateway receives the session key ciphertext and the corresponding encryption key serial number returned by the key management platform. The public-private integrated cluster intercom gateway obtains the same protection key from the built-in quantum security chip through the encryption key serial number, decrypts the obtained session key ciphertext to obtain the session key M;
[0017] After obtaining the session key M, the public-private integrated cluster intercom gateway encrypts and protects the parsed and transcoded public network intercom data obtained from the private network intercom terminal a. The public-private integrated cluster intercom gateway transmits the encrypted public network intercom data to other public network intercom terminals in the group through the intercom group and intercom platform.
[0018] As a further optimized technical solution, the private network intercom terminal a is connected to the public-private integrated cluster intercom gateway via an audio cable.
[0019] As a further optimized technical solution, the protection key of the public-private integrated cluster intercom gateway and the protection key of each public network intercom terminal in the intercom group and the protection key of the key management platform are symmetric keys, which are pre-filled keys.
[0020] In a second aspect, the present application also provides a method for quantum encryption protection of communication data in a public-private network converged communication system, which is applicable when a private network intercom terminal communicates with a public network intercom terminal, comprising the following steps:
[0021] A private network intercom terminal a is connected to the public-private integrated cluster intercom gateway. This private network intercom terminal a obtains private network communication data transmitted by other private network intercom terminals in the same intercom frequency band through the private network. Private network intercom terminal a establishes an intercom request to the public-private integrated cluster intercom gateway and transmits the obtained non-encrypted intercom data to the public-private integrated cluster intercom gateway.
[0022] The public-private integrated cluster intercom gateway analyzes the intercom data from the private network intercom terminal a, converts the intercom data from analog signals into public network digital signals, and then converts them into public network intercom data;
[0023] The public-private integrated cluster intercom gateway calls the quantum SDK to perform initial authentication with the key management platform for identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication with the key management platform;
[0024] The key management platform checks the login token and validity period of the public-private integrated cluster intercom gateway. If the verification is correct, the key management platform returns the network access authentication success and token validity period to the public-private integrated cluster intercom gateway, completing the identity authentication;
[0025] The public-private integrated cluster intercom gateway sends an encrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the encrypted intercom request, and synchronously returns the session ID to the public-private integrated cluster intercom gateway and other public network intercom terminals in the intercom group.
[0026] The public-private converged cluster intercom gateway carries the device ID, session ID, and group ID and calls the Quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and encrypts it using the protection keys of each public network intercom terminal in the group to obtain the session key ciphertext.
[0027] The key management platform sends the session key ciphertext and the corresponding encryption key serial number to each public network intercom terminal communicating in the intercom group, so that each public network intercom terminal in the group uses the key pre-filled in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information;
[0028] The public-private integrated cluster intercom gateway receives the session key ciphertext and the corresponding encryption key serial number returned by the key management platform. The public-private integrated cluster intercom gateway obtains the same protection key from the built-in quantum security chip through the encryption key serial number, decrypts the obtained session key ciphertext to obtain the session key M;
[0029] After the public-private integrated cluster intercom gateway obtains the session key M, it encrypts and protects the parsed and transcoded public network intercom data obtained from the private network intercom terminal a. The public-private integrated cluster intercom gateway transmits the encrypted public network intercom data to other public network intercom terminals in the group through the intercom group and the intercom platform. Each public network intercom terminal in the group can use the session key obtained in step S4 to decrypt the encrypted public network intercom data, and obtain the plaintext intercom data after decryption.
[0030] As a further optimized technical solution, in step S1, the private network intercom terminal a is connected to the public-private integrated cluster intercom gateway via an audio cable.
[0031] As a further optimized technical solution, in step S1, when the private network intercom terminal a obtains the private network communication data transmitted by other private network intercom terminals, if the received private network communication data uses the encryption method within the private network, the private network intercom terminal a needs to decrypt it accordingly.
[0032] As a further optimized technical solution, in step S3, the protection key of the public-private integrated cluster intercom gateway and the protection keys of each public network intercom terminal in the intercom group and the protection key of the key management platform are symmetric keys, which are pre-filled keys.
[0033] In a third aspect, the present application also provides a method for quantum encryption protection of communication data in a public-private network converged communication system, which is applicable when a public network intercom terminal communicates with a private network intercom terminal, comprising the following steps:
[0034] The public network intercom terminal b in the group transmits the encrypted intercom data to the public-private integrated cluster intercom gateway through the intercom group. The public-private integrated cluster intercom gateway converts the public network communication data from the public network intercom terminal b from digital signals to analog signals and converts them into private network intercom data.
[0035] The public-private integrated cluster intercom gateway calls the quantum SDK, performs initial authentication with the key management platform to complete identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication with the key management platform;
[0036] The public-private fusion cluster intercom gateway sends a decrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the decrypted intercom request, and synchronously returns the session ID to the public-private fusion cluster intercom gateway and the private network intercom terminal a;
[0037] The public-private converged cluster intercom gateway carries the device ID, session ID, and group ID and calls the Quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and encrypts it with the protection key b' of the public network intercom terminal b to obtain the session key ciphertext MB.
[0038] The key management platform sends the session key ciphertext MB and the corresponding encryption key serial number to the private network intercom terminal a, so that the private network intercom terminal a uses the key pre-filled in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information;
[0039] After the public-private integrated cluster intercom gateway obtains the session key M, the gateway encrypts and protects the private network intercom data parsed from the public network intercom terminal b side, and transmits the encrypted private network intercom data to the private network intercom terminal a. The private network intercom terminal a decrypts the encrypted intercom data using the session key M obtained in step S40, and obtains the plaintext intercom data after decryption.
[0040] As a further optimized technical solution, the protection key of the public-private integrated cluster intercom gateway and the protection key of each public network intercom terminal in the intercom group and the protection key of the key management platform are symmetric keys, which are pre-filled keys.
[0041] In a fourth aspect, the present application also provides a public-private integrated cluster intercom gateway, which adopts the above-mentioned method of quantum encryption to protect communication data in the public-private network integrated communication system applicable to the public-private integrated cluster intercom gateway.
[0042] In the fifth aspect, the present application also provides a public-private network converged communication system, which adopts the above-mentioned method of quantum encryption to protect communication data in the public-private network converged communication system suitable for private network intercom terminals to communicate with public network intercom terminals and suitable for public network intercom terminals to communicate with private network intercom terminals, including public network intercom terminals, private network intercom terminals, public-private converged cluster intercom gateways, intercom service platforms and key management platforms.
[0043] In the sixth aspect, the present application proposes a computing and processing device, which includes: a memory storing computer-readable code; and one or more processors. When the computer-readable code is executed by one or more processors, the computing and processing device executes the method for quantum encryption protection of communication data in the public-private network converged communication system proposed in the first and second aspects above.
[0044] In the seventh aspect, the present application proposes a computer program, including a computer-readable code. When the computer-readable code runs on a computing processing device, it causes the computing processing device to execute the method of quantum encryption for protecting communication data in the public-private network integrated communication system proposed in the first and second aspects above.
[0045] In an eighth aspect, the present application proposes a computer-readable medium in which the computer program proposed in the sixth aspect is stored.
[0046] The advantages of this application are:
[0047] (1) This application utilizes a key management platform to generate session keys actually used for work in real time, and uses the keys pre-filled in the pre-made key libraries of the two parties to the call as protection keys to encrypt the session keys, and generates key ciphertexts that are sent to the two parties to the call. Compared with the direct use of pre-made shared key libraries, this application improves security, solves the problem of key reuse in intercom handheld terminals, and realizes the one-time key negotiation and one-time key function.
[0048] (2) This application realizes the combination of quantum key storage media and key transmission SDK encryption and decryption interface through the public-private integrated cluster intercom gateway, which can realize voice analysis and transcoding from the private network intercom terminal to the public-private integrated gateway side, and encrypted transmission of corresponding data from the public-private integrated gateway side to the public network intercom terminal, thereby ensuring the end-to-end security from the gateway to the intercom and the channel side of the transmission link.
[0049] (3) This application also supports reverse data transmission from public network intercom terminals to private network intercom terminals. The public network intercom terminals in the group can pass the encrypted intercom data to the public-private integrated cluster intercom gateway through the intercom group. The gateway can also call the key negotiation SDK to apply for the encrypted session key from the key management platform. The gateway uses the key in the quantum TF card to decrypt the session key, and then uses the session key to decrypt the encrypted intercom data in the group. After the public-private integrated cluster intercom gateway obtains the public network digital intercom data, the gateway can convert the digital signal into an analog signal and pass the analog signal corresponding to the intercom data to the private network intercom terminal connected to the gateway audio line. The private network intercom terminal will perform encryption or transmission processing of the analog signal in the private network. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0051] FIG1 is a schematic diagram of a private network intercom interconnection connection method proposed in an embodiment of the present application through a public-private fusion cluster intercom gateway and a public network intercom terminal;
[0052] FIG2 is a flow chart of a method for negotiating and distributing keys between a public-private fusion cluster intercom gateway and a public network intercom terminal according to an embodiment of the present application;
[0053] FIG3 is a schematic diagram of the structure of a computing and processing device for a method of quantum encryption protection of communication data in a public-private network converged communication system proposed in another embodiment of the present application;
[0054] FIG4 is a schematic diagram of the structure of a computer program for a method of quantum encryption for protecting communication data in a public-private network converged communication system proposed in another embodiment of the present application. DETAILED DESCRIPTION
[0055] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0056] As shown in Figure 1, the first embodiment of the present application proposes a method for quantum encryption protection of communication data in a public and private network converged communication service system, which is applied to a public and private network converged communication service system. The public and private network converged communication service system includes a public network intercom terminal, a private network intercom terminal, a public-private converged cluster intercom gateway, an intercom service platform, and a key management platform.
[0057] in:
[0058] The public network intercom terminal integrates a quantum security chip, which can be a quantum SIM card or a quantum TF card. The software integrates the quantum SDK (Software Development Kit) and key transmission SDK to realize the application, transmission, and encryption and decryption functions of quantum keys.
[0059] The private network intercom terminal establishes communication with the public-private integrated cluster intercom gateway, and transmits the data and requests obtained by other private network intercom devices that need to communicate with the public network intercom terminal to the public-private integrated cluster intercom gateway side.
[0060] The public-private integrated cluster intercom gateway hardware integrates a quantum security chip, which is a SIM card or quantum TF card. The software integrates quantum SDK and key transmission SDK to realize the application, transmission, encryption and decryption functions of quantum keys.
[0061] The intercom service platform generates and maintains a session ID based on the encrypted intercom request sent by the public-private converged cluster intercom gateway, and synchronously returns the session ID to the public-private converged cluster intercom gateway and other public network intercom terminals in the intercom group.
[0062] The key management platform accepts applications from public intercom terminals or public-private converged cluster intercom gateways and provides quantum keys to them. The key management platform maintains the binding relationship between the public-private converged cluster intercom gateway and the quantum security chip, as well as the validity period of the public-private converged cluster intercom gateway's network access authentication. It also provides trusted identity authentication and identity authentication validity period functions.
[0063] The quantum security chip is a storage medium pre-filled with quantum keys through a key management platform. The pre-filled key and the key management platform's protection key are symmetric keys. After the public network intercom terminal and the public-private integrated cluster intercom gateway apply for the quantum session key from the key management platform through the quantum SDK interface, they need to use the pre-filled key in the quantum security chip to decrypt the session key.
[0064] The quantum SDK provides network access authentication and quantum session key application interfaces, which are used for authentication and authorization of public network intercom terminals and public-private integrated cluster intercom gateways on the key management platform and for applying for quantum session key functions.
[0065] Key transmission SDK is used for key negotiation and transmission between public network intercom terminals and public-private integrated cluster intercom gateways.
[0066] Before the public network and private network integrated communication service system conducts confidential communication, the public-private integrated cluster intercom gateway and the public network intercom terminal need to be in an intercom group. The intercom group is specially set up for the frequency band of the private network intercom and is specifically connected to the private network intercom communication within the frequency band. The intercom service platform has issued a group ID to the public-private integrated cluster intercom gateway.
[0067] When a private network intercom terminal communicates with a public network intercom terminal, the method for quantum encryption protection of communication data in the public and private network integrated communication service system includes the following steps:
[0068] S1. A private network intercom terminal a is connected to the public-private integrated cluster intercom gateway via an audio cable. This private network intercom terminal a obtains private network communication data transmitted by other private network intercom terminals (such as private network intercom terminal b) in the same intercom frequency band through the private network. If the received private network communication data uses the encryption method within the private network, the private network intercom terminal a needs to decrypt it accordingly to obtain the intercom data. Private network intercom terminal a establishes an intercom request to the public-private integrated cluster intercom gateway and transmits the non-encrypted intercom data in the same intercom frequency band obtained from private network intercom device b to the public-private integrated cluster intercom gateway side;
[0069] The public-private fusion cluster intercom gateway analyzes the intercom data from the private network intercom terminal a, converts the intercom data from analog signals into public network digital signals, and converts them into public network intercom data;
[0070] The public-private integrated cluster intercom gateway calls the quantum SDK to perform initial authentication with the key management platform for identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication with the key management platform;
[0071] The key management platform checks the login token and validity period on the public-private integrated cluster intercom gateway side, and the binding relationship between the application account and the key medium TF card on the secret service platform. If the verification is correct, the key management platform returns the network access authentication success and token validity period to the public-private integrated cluster intercom gateway to complete the identity authentication.
[0072] S2. The public-private integrated cluster intercom gateway sends an encrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the encrypted intercom request, and synchronously returns the session ID to the public-private integrated cluster intercom gateway and other public network intercom terminals in the intercom group.
[0073] S3. The public-private integrated cluster intercom gateway carries the device ID, session ID, and group ID and calls the quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and uses the protection keys of each public network intercom terminal in the group. For example, public network intercom terminal A uses protection key A', public network intercom terminal B uses protection key B', and public network intercom terminal C uses protection key C' to encrypt the session key M and obtain the session key ciphertexts MA, MB, and MC.
[0074] The protection key is composed of a charging key in a pre-made key library of each public network intercom terminal in the intercom group, and the charging key and the protection key of the key management platform are symmetric keys.
[0075] The charging keys used to encrypt the session keys are stored in the quantum SIM card / TF card and can only be obtained through the SDK internal interface, effectively ensuring the security of session key transmission.
[0076] The key management platform needs to pre-write the charging key into the quantum security chip (SIM card or quantum TF card) of each public network intercom terminal in the group communication as the protection key to build the pre-made key library. The pre-made key in the quantum security chip is used to implement key negotiation and distribution based on the symmetric key system, realizing a single key per communication.
[0077] The key negotiation request includes the public-private converged cluster intercom gateway identifier (device ID), the session identifier (session ID) for this communication, and the intercom group identifier (group ID). The public-private converged cluster intercom gateway identifier (device ID) is the unique identifier of the public-private converged cluster intercom gateway on the key management platform. This gateway identifier (device ID) enables the association of the key management platform with the public-private converged cluster intercom gateway's own pre-charged key.
[0078] S4. The key management platform sends the session key ciphertext (MA, MB, MC) and the corresponding encryption key serial number to each public network intercom terminal communicating in the intercom group, so that each public network intercom terminal in the group can use the pre-filled key in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information.
[0079] The public-private integrated cluster intercom gateway receives the session key ciphertext such as MA and the corresponding encryption key serial number returned by the key management platform. The public-private integrated cluster intercom gateway obtains the same protection key A' from the quantum security chip through the encryption key serial number, decrypts the obtained session key ciphertext MA to obtain the session key M.
[0080] S5. After obtaining the session key M, the public-private converged cluster intercom gateway encrypts the parsed and transcoded public network intercom data received from private network intercom terminal a. The gateway transmits the encrypted public network intercom data to other public network intercom terminals in the group via the intercom group and the intercom platform. Each public network intercom terminal in the group can decrypt the encrypted intercom data using the obtained session key, obtaining the plaintext intercom data.
[0081] On the contrary, when the public network intercom terminal b communicates with the private network intercom terminal a, confidential communication is performed based on the same principles as steps S1 to S5 above:
[0082] Step S10: The public network intercom terminal b in the group transmits the encrypted intercom data to the public-private integrated cluster intercom gateway through the intercom group. The public-private integrated cluster intercom gateway converts the public network communication data from the public network intercom terminal b from digital signals to analog signals and converts them into private network intercom data.
[0083] The public-private converged cluster intercom gateway calls the Quantum SDK to perform initial authentication with the key management platform to complete identity verification. It then calls the Quantum SDK's network access authentication interface to authenticate with the key management platform. The key management platform checks the login token and expiration date on the public-private converged cluster intercom gateway. If the verification is correct, the key management platform returns a successful network access authentication and the token expiration date to the public-private converged cluster intercom gateway.
[0084] S20. The public-private integrated cluster intercom gateway sends a decrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the decrypted intercom request, and synchronously returns the session ID to the public-private integrated cluster intercom gateway and the private network intercom terminal a.
[0085] S30. The public-private integrated cluster intercom gateway carries the device ID, session ID, and group ID and calls the quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and encrypts the session key M using the protection key b' of the public network intercom terminal b to obtain the session key ciphertext MB.
[0086] The protection key is composed of a charging key in a prefabricated key base of the public network intercom terminal b in the intercom group, and the charging key and the protection key of the key management platform are symmetric keys.
[0087] The key management platform needs to pre-write the key as the protection key into the quantum security chip (SIM card or quantum TF card) of each public network intercom terminal in the group communication, and build the pre-made key library. The built-in key of the quantum security chip is used to implement key negotiation and distribution based on the symmetric key system, realizing a key per communication.
[0088] The key negotiation request includes the public-private converged cluster intercom gateway identifier (device ID), the session identifier (session ID) for this communication, and the intercom group identifier (group ID). The public-private converged cluster intercom gateway identifier (device ID) is the unique identifier of the public-private converged cluster intercom gateway on the key management platform. This gateway identifier (device ID) enables the association of the key management platform with the public-private converged cluster intercom gateway's own pre-charged key.
[0089] S40. The key management platform sends the session key ciphertext MB and the corresponding encryption key serial number to the private network intercom terminal a, so that the private network intercom terminal a can use the key pre-filled in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information.
[0090] Specifically, when the public-private integrated cluster intercom gateway receives the session key ciphertext MA and the corresponding encryption key serial number returned by the key management platform, the public-private integrated cluster intercom gateway obtains the same protection key a' from the quantum TF card through the encryption key serial number, decrypts the obtained session key ciphertext MA to obtain the session key M.
[0091] S50: After the public-private converged cluster intercom gateway obtains session key M, it encrypts the private network intercom data parsed from public network intercom terminal b. The gateway transmits the encrypted private network intercom data to private network intercom terminal a. Private network intercom terminal a decrypts the encrypted data using session key M, obtaining the plaintext intercom data.
[0092] It should be noted that this embodiment uses the key management platform to generate the session keys actually used for work in real time, and uses the keys pre-filled in the pre-made key libraries of each party to the call as protection keys to encrypt the session keys, and generates key ciphertext and sends it to both parties to the call. Compared with the direct use of the pre-made shared session key library, it improves security, solves the problem of reuse of session keys for public network intercom and public-private integrated cluster intercom gateway, and realizes the function of one key for one call and one key negotiation consuming one key.
[0093] In this embodiment, a key management platform is used to pre-fill keys into the quantum security chips integrated by both communicating parties. Each quantum security chip uses the filled keys to build a prefabricated key library. During key negotiation, the key management platform generates session keys in real time and uses the keys filled in the prefabricated key library as protection keys to encrypt the session keys. The built-in keys of the quantum security chip are used to implement key negotiation and distribution based on a symmetric key system, achieving one key per communication.
[0094] Furthermore, quantum symmetric keys cannot be cracked by large factorization, thus preventing the cracking of public key cryptography algorithms based on large factorization problems. Encrypted transmission using quantum-safe cryptography is theoretically completely secure and reliable, protecting against security threats posed by future quantum computers.
[0095] Moreover, quantum security chips are a feasible technology, and security authentication based on quantum symmetric keys is also a feasible technology. The integration technology of quantum security chips used in intercom terminals is mature and highly secure.
[0096] It solves the security impact of intercom calls in an environment with increasingly severe network attacks, solves the key replacement problem of public-private integrated cluster intercom gateway and public network intercom terminal to key management platform, and solves the problem that private network intercom terminal and public network intercom terminal cannot communicate with each other securely based on the existing network environment.
[0097] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0098] The various component embodiments of the present application can be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing equipment according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0099] For example, FIG3 illustrates a computing device that can implement the methods according to the present application. The computing device typically includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020. Memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or ROM. Memory 1020 has storage space 1030 for program code 1031 for executing any of the method steps described above. For example, storage space 1030 for program code can include individual program codes 1031 for implementing various steps in the method described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units, as described with reference to FIG4 . This storage unit can have storage segments, storage space, and the like arranged similarly to memory 1020 in the computing device of FIG3 . The program code can, for example, be compressed in a suitable form. Typically, the storage unit includes computer-readable codes 1031 ′, ie, codes that can be read by a processor such as 1010 , which, when executed by a computing device, cause the computing device to perform the steps of the method described above.
[0100] References herein to "one embodiment," "an embodiment," or "one or more embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Furthermore, please note that instances of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.
[0101] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.
[0102] In the claims, any reference signs placed between brackets shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.
[0103] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for quantum encryption protection of communication data in a public-private network fusion communication system, wherein: The method is applied to a public-private fusion cluster intercom gateway, including the following methods: The public-private integrated cluster intercom gateway analyzes the intercom data from the private network intercom terminal a, converts the intercom data from analog signals into public network digital signals, and then converts them into public network intercom data; The public-private integrated cluster intercom gateway calls the quantum SDK, performs initialization authentication to the key management platform for identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication to the key management platform; Receive the network access authentication success and token validity period returned by the key management platform to complete identity authentication; The public-private fusion cluster intercom gateway sends an encrypted intercom request to the intercom service platform, and receives a session ID generated by the intercom service platform based on the encrypted intercom request; The public-private integrated cluster intercom gateway carries the device ID, session ID, and group ID and calls the quantum SDK to send a key negotiation request to the key management platform; The public-private integrated cluster intercom gateway receives the session key ciphertext and the corresponding encryption key serial number returned by the key management platform. The public-private integrated cluster intercom gateway obtains the same protection key from the built-in quantum security chip through the encryption key serial number, and decrypts the obtained session key ciphertext to obtain the session key M; After the public-private integrated cluster intercom gateway obtains the session key M, it encrypts and protects the parsed and transcoded public network intercom data obtained from the private network intercom terminal a. The public-private integrated cluster intercom gateway transmits the encrypted public network intercom data to other public network intercom terminals in the group through the intercom group and the intercom platform.
2. The method for protecting communication data with quantum encryption in a public-private network fusion communication system as claimed in claim 1, wherein: The private network intercom terminal a is connected to the public-private fusion cluster intercom gateway via an audio line.
3. The method for protecting communication data with quantum encryption in a public-private network fusion communication system as claimed in claim 1, wherein: The protection key of the public-private integrated cluster intercom gateway, the protection key of each public network intercom terminal in the intercom group, and the protection key of the key management platform are symmetric keys and are pre-charged keys.
4. A method for protecting communication data with quantum encryption in a public-private network fusion communication system, wherein: When the method is applied to a private network intercom terminal communicating with a public network intercom terminal, it comprises the following steps: S1. A private network intercom terminal a is connected to a public-private integrated cluster intercom gateway. The private network intercom terminal a obtains the private network communication data transmitted by other private network intercom terminals in the same intercom frequency band through the private network. The private network intercom terminal a establishes an intercom request to the public-private integrated cluster intercom gateway and transmits the obtained non-encrypted intercom data to the public-private integrated cluster intercom gateway. The public-private integrated cluster intercom gateway analyzes the intercom data from the private network intercom terminal a, converts the intercom data from analog signals into public network digital signals, and then converts them into public network intercom data; The public-private integrated cluster intercom gateway calls the quantum SDK, performs initialization authentication to the key management platform for identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication to the key management platform; The key management platform checks the login token and validity period of the public-private integrated cluster intercom gateway. If the verification is correct, the key management platform returns the network access authentication success and token validity period to the public-private integrated cluster intercom gateway to complete the identity authentication. S2. The public-private fusion cluster intercom gateway sends an encrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the encrypted intercom request, and synchronously returns the session ID to the public-private fusion cluster intercom gateway and other public network intercom terminals in the intercom group; S3. The public-private integrated cluster intercom gateway carries the device ID, session ID and group ID and calls the quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and encrypts the session key M using the protection keys of each public network intercom terminal in the group to obtain the session key ciphertext. S4, the key management platform sends the session key ciphertext and the corresponding encryption key serial number to each public network intercom terminal communicating in the intercom group, so that each public network intercom terminal in the group uses the key pre-filled in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information; The public-private integrated cluster intercom gateway receives the session key ciphertext and the corresponding encryption key serial number returned by the key management platform. The public-private integrated cluster intercom gateway obtains the same protection key from the built-in quantum security chip through the encryption key serial number and encrypts the obtained session key ciphertext. Decrypt the document to obtain the session key M; S5. After the public-private integrated cluster intercom gateway obtains the session key M, it encrypts and protects the parsed and transcoded public network intercom data obtained from the private network intercom terminal a. The public-private integrated cluster intercom gateway transmits the encrypted public network intercom data to other public network intercom terminals in the group through the intercom group and the intercom platform. Each public network intercom terminal in the group can use the session key obtained in step S4 to decrypt the encrypted public network intercom data, and obtain the plaintext intercom data after decryption.
5. The method for protecting communication data with quantum encryption in a public-private network fusion communication system as claimed in claim 4, wherein: In the step S1, the private network intercom terminal a is connected to the public-private integrated cluster intercom gateway via an audio line.
6. The method for protecting communication data with quantum encryption in a public-private network fusion communication system as claimed in claim 4, wherein: In step S1, when private network intercom terminal a obtains private network communication data transmitted by other private network intercom terminals, if the received private network communication data uses the encryption method within the private network, the private network intercom terminal a needs to decrypt it accordingly.
7. The method for protecting communication data with quantum encryption in a public-private network integrated communication system as claimed in claim 4, wherein: In step S3, the protection key of the public-private integrated cluster intercom gateway, the protection key of each public network intercom terminal in the intercom group, and the protection key of the key management platform are symmetric keys, which are pre-filled keys.
8. A method for quantum encryption protection of communication data in a public-private network fusion communication system, wherein: When the method is applied to a public network intercom terminal communicating with a private network intercom terminal, it comprises the following steps: S10, the public network intercom terminal b in the group transmits the encrypted intercom data to the public-private integrated cluster intercom gateway through the intercom group, and the public-private integrated cluster intercom gateway converts the public network communication data from the public network intercom terminal b from digital signals to analog signals and then converts them into private network intercom data; The public-private integrated cluster intercom gateway calls the quantum SDK, performs initialization authentication to the key management platform to complete identity authentication, and calls the network access authentication interface of the quantum SDK to perform network access authentication to the key management platform; S20: The public-private fusion cluster intercom gateway sends a decrypted intercom request to the intercom service platform, so that the intercom service platform generates and maintains a session ID based on the decrypted intercom request, and sends the session ID Synchronously return to the public-private fusion cluster intercom gateway and private network intercom terminal a; S30, the public-private integrated cluster intercom gateway carries the device ID, session ID and group ID and calls the quantum SDK to send a key negotiation request to the key management platform. The key management platform generates a session key M and encrypts the session key M using the protection key b' of the public network intercom terminal b to obtain the session key ciphertext MB; S40, the key management platform sends the session key ciphertext MB and the corresponding encryption key serial number to the private network intercom terminal a, so that the private network intercom terminal a uses the key pre-filled in the prefabricated key library to decrypt the session key ciphertext, obtain the session key M, and synchronize the key acquisition information; S50. After the public-private integrated cluster intercom gateway obtains the session key M, the gateway encrypts and protects the private network intercom data parsed from the public network intercom terminal b side, and transmits the encrypted private network intercom data to the private network intercom terminal a. The private network intercom terminal a decrypts the encrypted intercom data using the session key M obtained in step S40, and obtains the plaintext intercom data after decryption.
9. The method for protecting communication data with quantum encryption in a public-private network integrated communication system as claimed in claim 8, wherein: The protection key of the public-private integrated cluster intercom gateway, the protection key of each public network intercom terminal in the intercom group, and the protection key of the key management platform are symmetric keys and are pre-charged keys.
10. A public-private fusion cluster intercom gateway, wherein: A method for protecting communication data by quantum encryption in a public-private network fusion communication system as described in any one of claims 1 to 3.
11. A public-private network integrated communication system, wherein: The method for protecting communication data with quantum encryption in a public-private network fusion communication system as described in any one of claims 4 to 9 includes a public network intercom terminal, a private network intercom terminal, a public-private fusion cluster intercom gateway, an intercom service platform and a key management platform.
12. A computing device, characterized in that: include: a memory having computer readable code stored therein; One or more processors, when the computer readable code is executed by the one or more processors, the computing processing device executes the method for quantum encryption protection of communication data in the public-private network fusion communication system as described in any one of claims 1-7 or 8-9.
13. A computer program comprising a computer-readable code, which, when executed on a computing processing device, causes the computing processing device to execute the method for quantum encryption protection of communication data in a public-private network converged communication system according to any one of claims 1-7 or 8-9.
14. A computer readable medium having stored therein the computer program according to claim 13.
Citation Information
Patent Citations
Method, gateway device and system for integrated private network intercom and public network intercom intercommunication
CN111866761A
Method and system for realizing cluster encryption of dual-mode interphone based on public network
CN113612608A
Public network interphone encryption communication method
CN115278667A
Method, gateway and system for protecting communication data through quantum encryption
CN117640084A
Systems and methods for a quantum proxy server handover mechanism
US20230232220A1
Cited By
Internet of Things data transmission system and method based on quantum encryption communication
CN121567484A