Quantum key distribution method, gateway device, terminal device, and storage medium
Through the encryption and decryption module in the gateway device working in concert with the cryptographic module, the wireless key is obtained and the quantum key is encrypted, which solves the problem of mobile terminals in distribution of quantum keys, and achieves wireless distribution and efficient utilization.
Patent Information
- Application Number
- PCT/CN2024/136520
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-06
- Filing Date
- 2024-12-03
- Publication Date
- 2025-06-12
AI Technical Summary
In the existing quantum key distribution methods, the application requirements of mobile terminals for quantum keys are difficult to meet, resulting in users having to frequently carry equipment to specific service sites to add, causing inconvenience and high system construction requirements to users and operation service providers.
Through the first encryption and decryption module in the gateway device working in concert with the first cryptographic module, the wireless key is obtained and the quantum key is encrypted, and the serial number corresponding to the encrypted quantum key and the wireless key is generated, and sent to the terminal device, so that it can obtain the original quantum key.
The wireless distribution of quantum keys is realized, which avoids the limitation of offline filling, extends applicable scenarios, and improves the utilization rate of quantum key distribution infrastructure.
Smart Images

Figure CN2024136520_12062025_PF_FP_ABST
Abstract
Description
A quantum key distribution method, gateway device, terminal device and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This disclosure is based on and claims the priority of Chinese patent application with application number 2023116627375 and application date December 6, 2023. The entire content of this Chinese patent application is hereby incorporated into this disclosure as a reference. Technical Field
[0003] The present disclosure relates to the field of information security technology, and in particular to a quantum key distribution method, a gateway device, a terminal device, and a storage medium. Background Art
[0004] Regarding the current quantum key distribution methods, most in the industry are based on wired quantum key distribution (QKD) networks to reach both ends of the device or the key center. Then, in order to meet the application needs of mobile terminals for quantum keys, the current main method is to use offline filling to inject a certain amount of pre-generated quantum keys into terminal security media such as Universal Subscriber Identity Module (USIM) cards and external memory (Trans-flash, TF) password cards, and distribute them to mobile terminal users for use.
[0005] However, the storage space reserved for quantum-related services on terminal security media is limited. When users run low on quantum keys, they must bring their devices to specific service locations for refilling. This frequent refilling is inconvenient for users and places high demands on the system development of quantum key operators. Therefore, offline secure refilling can only be used as a small-scale, short-term solution, limiting its application scenarios and reducing the utilization rate of quantum key distribution infrastructure. Summary of the Invention
[0006] The embodiments of the present disclosure provide a quantum key distribution method and a gateway device, a terminal device, and a storage medium, which can expand applicable scenarios and thereby improve the utilization rate of quantum key distribution infrastructure.
[0007] The technical solution of the embodiment of the present disclosure is implemented as follows:
[0008] In a first aspect, an embodiment of the present disclosure provides a quantum key distribution method, which is applied to a gateway device, the gateway device including a first distribution system, a first encryption and decryption module, and a first password module, the method comprising:
[0009] The first encryption and decryption module sends a wireless key acquisition request to the first password module;
[0010] The first cryptographic module sends a wireless key acquisition response message to the first encryption / decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key;
[0011] The first encryption / decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key;
[0012] The first distribution system sends a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0013] In a second aspect, an embodiment of the present disclosure provides a quantum key distribution method, which is applied to a terminal device, wherein the terminal device includes a second distribution system and a second encryption and decryption module, and the method includes:
[0014] The second distribution system receives a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key;
[0015] The second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key;
[0016] The second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0017] In a third aspect, an embodiment of the present disclosure provides a gateway device, the gateway device comprising: a first encryption and decryption module, a first password module, and a first distribution system;
[0018] The first encryption and decryption module is used to send a wireless key acquisition request to the first password module;
[0019] The first cryptographic module is configured to send a wireless key acquisition response message to the first encryption / decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key;
[0020] The first encryption and decryption module is further configured to encrypt the quantum key based on the wireless key to obtain an encrypted quantum key;
[0021] The first distribution system is used to send a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0022] In a fourth aspect, an embodiment of the present disclosure provides a gateway device, the gateway device comprising: a first processor and a first memory; wherein,
[0023] The first memory is used to store a computer program that can be run on the processor;
[0024] The first processor is configured to execute the quantum key distribution method described above when running the computer program.
[0025] In a fifth aspect, an embodiment of the present disclosure provides a terminal device, the terminal device comprising: a second encryption and decryption module, a second distribution system;
[0026] The second distribution system is configured to receive a data transmission request, wherein the data transmission request includes the encrypted quantum key and a serial number corresponding to the wireless key;
[0027] The second distribution system is further configured to send a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and a serial number corresponding to the wireless key;
[0028] The second encryption and decryption module is used to determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0029] In a sixth aspect, an embodiment of the present disclosure provides a terminal device, comprising: a second processor and a second memory; wherein,
[0030] The second memory is used to store a computer program that can be run on the processor;
[0031] The second processor is configured to execute the quantum key distribution method described above when running the computer program.
[0032] In the seventh aspect, an embodiment of the present disclosure provides a computer-readable storage medium, characterized in that computer program code is stored on the storage medium, and when the computer program code is executed by a computer, the quantum key distribution method as described above is implemented.
[0033] Embodiments of the present disclosure provide a quantum key distribution method, a gateway device, a terminal device, and a storage medium. The gateway device includes a first distribution system, a first encryption / decryption module, and a first cryptographic module. The first encryption / decryption module sends a wireless key acquisition request to the first cryptographic module. The first cryptographic module sends a wireless key acquisition response message to the first encryption / decryption module. The wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key. The first encryption / decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key. The first distribution system sends a data transmission request to the terminal device. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains an original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. The terminal device includes a second distribution system and a second encryption / decryption module. The second distribution system receives the data transmission request. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key. The second distribution system sends a quantum key decryption request message to the second encryption / decryption module. The quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key. The second encryption / decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. It can be seen that the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first password module, and then encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present disclosure can realize the wireless distribution of quantum keys based on the gateway device without the need for offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] FIG1 is a schematic diagram of a quantum key distribution method according to an embodiment of the present disclosure;
[0035] FIG2 is a second schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure;
[0036] FIG3 is a third schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure;
[0037] FIG4 is a fourth schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure;
[0038] FIG5 is a fifth schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure;
[0039] FIG6 is a schematic diagram of wireless channel key negotiation proposed in an embodiment of the present disclosure;
[0040] FIG7 is a schematic diagram of a physical layer key generation process proposed in an embodiment of the present disclosure;
[0041] FIG8 is a schematic diagram of a quantum key wireless distribution system proposed in an embodiment of the present disclosure;
[0042] FIG9 is a schematic diagram of a wireless key usage interface flow according to an embodiment of the present disclosure;
[0043] FIG10 is a schematic diagram of a first process of wireless key encryption and decryption quantum key according to an embodiment of the present disclosure;
[0044] FIG11 is a second schematic diagram of a wireless key encryption and decryption quantum key process according to an embodiment of the present disclosure;
[0045] FIG12 is a schematic diagram of a wireless key generation process according to an embodiment of the present disclosure;
[0046] FIG13 is a schematic diagram of a key status query process according to an embodiment of the present disclosure;
[0047] FIG14 is a schematic diagram of a key generation triggering process proposed in an embodiment of the present disclosure;
[0048] FIG15 is a schematic diagram of a wireless key storage process according to an embodiment of the present disclosure;
[0049] FIG16 is a schematic diagram of a wireless key destruction process according to an embodiment of the present disclosure;
[0050] FIG17 is a schematic diagram of the structure of a quantum key wireless distribution system proposed in an embodiment of the present disclosure;
[0051] FIG18 is a schematic diagram of a software architecture proposed in an embodiment of the present disclosure;
[0052] FIG19 is a schematic diagram of core business functions proposed in an embodiment of the present disclosure;
[0053] FIG20 is a schematic diagram of a hardware system architecture proposed in an embodiment of the present disclosure;
[0054] FIG21 is a schematic diagram of a quantum wireless gateway and a quantum security terminal proposed in an embodiment of the present disclosure;
[0055] FIG22 is a schematic diagram of the first structure of a gateway device according to an embodiment of the present disclosure;
[0056] FIG23 is a second schematic diagram of the structure of the gateway device proposed in an embodiment of the present disclosure;
[0057] FIG24 is a first schematic diagram of the structure of a terminal device according to an embodiment of the present disclosure;
[0058] FIG25 is a second schematic diagram of the composition structure of the terminal device proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0059] To make the objectives, technical solutions, and advantages of this disclosure more clear, the technical solutions of this disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this disclosure, not all of them. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments of this disclosure without creative effort shall fall within the scope of protection of this disclosure.
[0060] Current quantum key distribution methods in the industry are mostly based on wired QKD networks reaching both devices or key centers. To meet the application needs of quantum keys on mobile terminals, offline keying is currently used. A certain amount of pre-generated quantum keys are injected into secure terminal media such as USIM cards, TF cards, and SoftKeys, and then distributed to mobile terminal users. The entire offline keying operation is performed in a secure physical environment to ensure the security of the quantum key distribution process.
[0061] Because the terminal security media has limited storage space reserved for quantum-related services, the amount of keys that can be loaded in a single refill is also limited, typically a few hundred kilobits. Therefore, after the pre-installed keys are consumed, quantum mobile users are typically required to bring their terminal security media to a designated service provider's location to connect to the quantum key refill equipment and refill the quantum keys. While this offline refill solution meets the needs of quantum key terminal users, it requires users to carry their devices to specific service locations for refilling when the quantum keys are insufficient. This frequent refilling creates inconvenience for users and places high system construction requirements on quantum key operators. Therefore, the offline secure refill method can only be used as a small-scale, short-term solution. Current technical solutions face the challenge of deploying and transmitting quantum keys over the "last mile" at the terminal, severely limiting the terminal service scope of quantum cryptography systems.
[0062] In order to solve the problem that the current applicable scenarios are limited, thereby reducing the utilization rate of quantum key distribution infrastructure, the embodiments of the present disclosure provide a quantum key distribution method, a gateway device, a terminal device and a storage medium, the gateway device includes a first distribution system, a first encryption and decryption module, and a first password module; the first encryption and decryption module sends a wireless key acquisition request to the first password module; the first password module sends a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain the encrypted quantum key; the first distribution system sends the data transmission request to the first password module; the first password module sends a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain the encrypted quantum key; the first distribution system sends the data transmission request to the first password module; the first password module sends the wireless key acquisition response message to the first encryption and decryption module; ... The invention relates to a method for transmitting a quantum key to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key; the terminal device includes a second distribution system and a second encryption and decryption module; the second distribution system receives the data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; the second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; the second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. Thus, the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first cryptographic module, and then can encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present invention can realize wireless distribution of quantum keys based on the gateway device without the need for offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure.
[0063] The technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present disclosure.
[0064] The present disclosure provides a quantum key distribution method, which is applied to a gateway device. The gateway device includes a first distribution system, a first encryption and decryption module, and a first password module. FIG1 is a schematic diagram of the quantum key distribution method proposed in the present disclosure. As shown in FIG1 , the quantum key distribution method may include the following steps:
[0065] Step 101: The first encryption / decryption module sends a wireless key acquisition request to the first password module.
[0066] In an embodiment of the present disclosure, the first encryption and decryption module in the gateway device may send a wireless key acquisition request to the first password module.
[0067] It should be noted that, in the embodiments of the present disclosure, the gateway device may include a first distribution system, a first encryption and decryption module, and a first password module. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0068] It should be noted that, in the embodiment of the present disclosure, FIG2 is a second schematic diagram of the quantum key distribution method proposed in the embodiment of the present disclosure. As shown in FIG2 , before the first encryption and decryption module sends the wireless key acquisition request to the first cryptographic module, that is, before step 101, the following steps may also be included:
[0069] Step 105: The first encryption and decryption module receives a quantum key encryption request sent by the first distribution system; wherein the quantum key encryption request carries a service type and a quantum key.
[0070] It should be noted that in the embodiments of the present disclosure, the quantum key encryption request can carry the business type and the data information to be encrypted and decrypted. For example, if the business type is quantum key security distribution, then the corresponding data information to be encrypted and decrypted can be a quantum key. The present disclosure does not specifically limit the business type and the type of data information to be encrypted and decrypted.
[0071] Step 102: The first password module sends a wireless key acquisition response message to the first encryption / decryption module; wherein the wireless key acquisition response message includes the wireless key and the serial number corresponding to the wireless key.
[0072] In an embodiment of the present disclosure, after the first encryption and decryption module sends a wireless key acquisition request to the first password module, the first password module may send a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes the wireless key and the serial number corresponding to the wireless key.
[0073] It should be noted that, in the embodiment of the present disclosure, the serial number corresponding to the wireless key is used to represent the unique identifier of the wireless key.
[0074] It should be noted that, in the embodiment of the present disclosure, the gateway device may further include a first key status query module and a first key usage interface. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0075] It should be noted that, in an embodiment of the present disclosure, the status query process of the wireless key may include: the first distribution system sends a wireless key query request message to the first password module through the first key status query module; or, the first distribution system sends a wireless key query request message to the first password module through the first key usage interface; the first password module queries the currently stored wireless key status information, and forwards the wireless key query response message to the first distribution system through the first key status query module; wherein, the wireless key query response message carries the wireless key status information.
[0076] Furthermore, in an embodiment of the present disclosure, the gateway device may also include a first key generation trigger module, which may determine whether the current wireless key meets the first preset condition based on the wireless key status information, key generation strategy, and application requirement information; if the current wireless key does not meet the first preset condition, the wireless key generation mechanism is triggered.
[0077] It should be noted that in the embodiment of the present disclosure, the gateway device also includes a first management and control module, a first transmission module, a first generation module and a first channel detection module. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0078] It should be noted that, in an embodiment of the present disclosure, when the current wireless key does not meet the first preset condition, after the wireless key generation mechanism is triggered, the first management and control module can receive a request to generate a wireless key and send a request to obtain channel status information to the first channel detection module; then the first channel detection module can obtain the first channel status information and the first serial number information corresponding to the first channel status information; and then can send a channel detection request to the second channel detection module in the terminal device; wherein the channel detection request includes the first channel status information and the first serial number information; and receive a channel detection response message sent by the second channel detection module; wherein the channel detection response message carries the second channel status information and the second serial number information corresponding to the second channel status information.
[0079] It should be noted that, in the embodiment of the present disclosure, the first channel state information may be channel state information (CSI) obtained by detection by a first channel detection module on the gateway device side.
[0080] It should be noted that in an embodiment of the present disclosure, after receiving the channel detection response message sent by the second channel detection module, the first channel detection module can obtain the second channel state information and the second sequence number information, and send an acknowledgement message (Acknowledgement, ACK) or a negative acknowledgement message (Negative Acknowledgment, NAK) to the second channel detection module; when the first sequence number information and the second sequence number information are the same, the first channel detection module can send the first channel state information and the first sequence number information to the first management and control module, so that the first management and control module stores the first channel state and the first sequence number information.
[0081] It should be noted that, in an embodiment of the present disclosure, after the first channel detection module sends the first channel state information and the first sequence number information to the first management and control module, the first management and control module may send a reconciliation information request to the first generation module; wherein the reconciliation information request includes the first channel state information and the first sequence number information; then the first generation module may quantize the first channel state information, thereby obtaining the first wireless key and determining the first reconciliation information corresponding to the first wireless key.
[0082] It should be noted that, in the embodiment of the present disclosure, the first wireless key may be an original wireless key.
[0083] It should be noted that, in an embodiment of the present disclosure, after the first management and control module receives the reconciliation response information sent by the first generation module, the first transmission module can send a key consistency reconciliation request to the second transmission module in the terminal device; wherein, the key consistency reconciliation request includes the first reconciliation information; the first transmission module can receive the key consistency reconciliation response information sent by the second transmission module; wherein, the key consistency reconciliation response information includes the first reconciliation result; after receiving the key consistency reconciliation response information forwarded by the first transmission module, the first management and control module can send a wireless key acquisition request to the first generation module; wherein, the wireless key acquisition request carries the first reconciliation result.
[0084] Furthermore, in an embodiment of the present disclosure, after sending a wireless key acquisition request to the first generation module, the first generation module can determine whether the reconciliation is successful based on the first reconciliation result; if the first reconciliation result is successful, the first generation module can perform privacy amplification processing on the first wireless key to obtain a second wireless key; and then the first generation module can send a wireless key acquisition response message to the first management and control module; wherein the wireless key acquisition response message includes the key generation result.
[0085] Furthermore, in an embodiment of the present disclosure, after obtaining the second wireless key, the first generation module may send a storage key request message to the first password module; wherein the storage key request message carries the second wireless key; then the first password module may encrypt the second wireless key based on the first algorithm; and store the encrypted second wireless key, the serial number information corresponding to the encrypted second wireless key, and the validity period corresponding to the encrypted second wireless key, and then send a storage wireless key response message to the first generation module, the wireless key response message carrying a storage success flag or a storage failure flag.
[0086] It should be noted that, in the embodiments of the present disclosure, the first algorithm may be the national secret SM4 block cipher algorithm (SM4 algorithm), and the present disclosure does not specifically limit the type of the first algorithm.
[0087] That is to say, in an embodiment of the present disclosure, after receiving a wireless key acquisition request, the first cryptographic module can query the status of the wireless key. If the current wireless key does not meet the first preset condition, the wireless key generation mechanism can be triggered, and then the generated wireless key and the validity period corresponding to the wireless key can be stored.
[0088] Step 103: The first encryption / decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key.
[0089] In an embodiment of the present disclosure, after the first cryptographic module sends the wireless key acquisition response information to the first encryption and decryption module, the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain the encrypted quantum key.
[0090] Furthermore, in an embodiment of the present disclosure, FIG3 is a third schematic diagram of a quantum key distribution method proposed in an embodiment of the present disclosure. As shown in FIG3 , after the first encryption / decryption module encrypts the quantum key based on the wireless key, that is, after step 103, the following steps may also be included:
[0091] Step 106: The first encryption and decryption module sends a quantum key encryption response message to the first distribution system; wherein the quantum key response message carries an encryption success flag or an encryption failure flag, the encrypted quantum key, and a serial number corresponding to the wireless key.
[0092] Step 107: The first encryption / decryption module triggers a destruction mechanism corresponding to the wireless key.
[0093] It should be noted that, in an embodiment of the present disclosure, after the first encryption and decryption module triggers the destruction mechanism corresponding to the wireless key, the first encryption and decryption module may send a key destruction request; wherein the key destruction request carries the serial number corresponding to the wireless key; the first cryptographic module destroys the wireless key corresponding to the serial number; or, the first cryptographic module destroys the wireless key based on the valid period corresponding to the wireless key; the first cryptographic module sends a key destruction response message to the first encryption and decryption module, and the key destruction response message carries a destruction success flag or a destruction failure flag.
[0094] It should be noted that in the embodiments of the present disclosure, the gateway device may include not only the first distribution system, the first encryption and decryption module, and the first password module, but also the first module group. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0095] Furthermore, in an embodiment of the present disclosure, after the first encryption / decryption module encrypts the quantum key based on the wireless key, the first encryption / decryption module may also send a data transmission request to the first module; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; the first module may then send a data transmission request to the second module in the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0096] It should be noted that, in an embodiment of the present disclosure, the first module can receive a data transmission response message sent by the second module; wherein the data transmission response message carries a quantum key reception success flag or a reception failure flag; the first module can then forward the data transmission response message to the first distribution system through the first encryption and decryption module; the first encryption and decryption module can trigger the destruction mechanism corresponding to the wireless key.
[0097] Step 104: The first distribution system sends a data transmission request to the terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0098] In an embodiment of the present disclosure, the first encryption and decryption module encrypts the quantum key based on the wireless key. After obtaining the encrypted quantum key, the first distribution system sends a data transmission request to the terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0099] To sum up, the first encryption and decryption module in the gateway device can encrypt the quantum key based on the wireless key to obtain the encrypted quantum key, thereby ensuring the secure transmission of the quantum key. The encrypted quantum key and the serial number corresponding to the wireless key can then be sent to the terminal device, so that the terminal device can obtain the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. This solves the problem of transmission and distribution of quantum keys in the "last mile" at mobile terminals, and is of great significance for promoting the development of the quantum communication industry. It is conducive to improving the utilization rate of QKD infrastructure and achieving cost-sharing and efficiency improvement.
[0100] An embodiment of the present disclosure provides a quantum key distribution method, which is applied to a gateway device. The gateway device includes a first distribution system, a first encryption and decryption module, and a first cryptographic module; the first encryption and decryption module sends a wireless key acquisition request to the first cryptographic module; the first cryptographic module sends wireless key acquisition response information to the first encryption and decryption module; wherein the wireless key acquisition response information includes a wireless key and a serial number corresponding to the wireless key; the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key; the first distribution system sends a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. It can be seen that the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first password module, and then encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present disclosure can realize the wireless distribution of quantum keys based on the gateway device without the need for offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure.
[0101] Based on the above embodiment, another embodiment of the present disclosure provides a quantum key distribution method, which is applied to a terminal device. The terminal device includes a second distribution system and a second encryption and decryption module. FIG4 is a fourth schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure. As shown in FIG4, the quantum key distribution method may include the following steps:
[0102] Step 201: The second distribution system receives a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key.
[0103] In an embodiment of the present disclosure, the second distribution system on the terminal device side can receive a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key.
[0104] It should be noted that, in the embodiments of the present disclosure, the terminal device may further include a second module, and the present disclosure does not specifically limit the number and type of modules included in the terminal device.
[0105] It should be noted that, in an embodiment of the present disclosure, the second module may also receive a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; the second module may then send the data transmission request to the second encryption / decryption module, so that the second encryption / decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0106] Step 202: The second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key.
[0107] In an embodiment of the present disclosure, after the second distribution system receives the data transmission request, the second distribution system can send a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key.
[0108] Step 203: The second encryption / decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0109] In an embodiment of the present disclosure, after the second distribution system sends a quantum key decryption request message to the second encryption and decryption module, the second encryption and decryption module can determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0110] It should be noted that, in the embodiment of the present disclosure, the terminal device further includes a second password module and a second encryption and decryption module. The present disclosure does not specifically limit the number and type of modules included in the terminal device.
[0111] It should be noted that, in an embodiment of the present disclosure, when the terminal device determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key, the second encryption and decryption module can send a wireless key acquisition request message to the second cryptographic module; wherein the wireless key acquisition request message carries the serial number corresponding to the wireless key; then the second cryptographic module can determine the corresponding wireless key based on the serial number corresponding to the wireless key, and send a wireless key acquisition response message to the second encryption and decryption module, the wireless key acquisition response message carrying the wireless key; and then the second encryption and decryption module can decrypt the encrypted quantum key based on the wireless key to obtain the original quantum key.
[0112] Furthermore, in an embodiment of the present disclosure, after the second encryption and decryption module decrypts the encrypted quantum key based on the wireless key, the second cryptographic module may destroy the wireless key corresponding to the serial number; or, the second cryptographic module destroys the wireless key based on the validity period corresponding to the wireless key.
[0113] It should be noted that, in the embodiments of the present disclosure, the terminal device may further include a second management and control module, a second transmission module, a second generation module and a second detection module. The present disclosure does not specifically limit the number and type of modules included in the terminal device.
[0114] It should be noted that, in an embodiment of the present disclosure, the second channel detection module can receive a channel detection request sent by the first channel detection module, wherein the channel detection request includes first channel state information and first sequence number information, and send a channel detection response message to the first channel detection module; wherein the channel detection response message carries second channel state information and second sequence number information corresponding to the second channel state information; when the second channel detection module receives the ACK sent by the first channel detection module, the second channel state information and the second sequence number information corresponding to the second channel state information can be sent to the second management and control module.
[0115] It should be noted that, in the embodiment of the application, the second channel state information may be CSI detected and obtained by the second channel detection module on the terminal device side.
[0116] Furthermore, in an embodiment of the present disclosure, after sending the second channel state information and the second serial number information corresponding to the second channel state information to the second management and control module, the second management and control module may send a request to obtain a wireless key to the second generation module; wherein the request to obtain a wireless key includes the second channel state information and the second serial number information; and then the second generation module may quantize the second channel state information to obtain a third wireless key.
[0117] It should be noted that, in the embodiment of the present disclosure, the third wireless key may be the original wireless key.
[0118] Furthermore, in an embodiment of the present disclosure, after the second generation module quantizes the second channel state information and obtains the third wireless key, the second transmission module can receive a key consistency reconciliation request sent by the first management and control module; wherein the key consistency reconciliation request includes first reconciliation information; then the second generation module can reconcile the first reconciliation information based on the third wireless key and determine the first reconciliation result; if the first reconciliation result is a successful reconciliation, the second generation module can perform privacy amplification processing on the third wireless key to obtain a fourth wireless key; and then the second generation module can forward the key consistency reconciliation response information to the first transmission module through the second transmission module; wherein the key consistency reconciliation response information includes the first reconciliation result.
[0119] It should be noted that, in an embodiment of the present disclosure, after obtaining the fourth wireless key, the second generation module may send a storage key request message to the second cryptographic module; wherein the storage key request message carries the fourth wireless key; the second cryptographic module may encrypt the fourth wireless key based on the second algorithm; the second cryptographic module stores the encrypted fourth wireless key, the serial number information corresponding to the encrypted fourth wireless key, and the valid period corresponding to the encrypted fourth wireless key, and sends a storage wireless key response message to the second generation module, and the wireless key response message carries a storage success flag or a storage failure flag.
[0120] It should be noted that, in the embodiment of the present disclosure, the second algorithm may be an SM4 block cipher algorithm, and the present disclosure does not specifically limit the type of the second algorithm.
[0121] To sum up, after the terminal device receives the encrypted quantum key and the serial number corresponding to the wireless key, the second encryption and decryption module can determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, there is no need to go to the designated outlets of the service operator to recharge the quantum key, and the quantum key can be received wirelessly, which solves the deployment and transmission problem of the quantum key in the "last mile" at the terminal and expands the terminal service range of the quantum cryptography system.
[0122] The disclosed embodiment provides a quantum key distribution method, which is applied to a terminal device, wherein the terminal device includes a second distribution system and a second encryption and decryption module, wherein the second distribution system receives a data transmission request; wherein the data transmission request includes an encrypted quantum key and a serial number corresponding to a wireless key; the second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; and the second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. It can be seen that the second distribution system on the terminal device side can send a quantum key decryption request message to the second encryption and decryption module, wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key, and then the second encryption and decryption module can determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, there is no need to perform offline filling of the quantum key, and the quantum key can be received wirelessly, which solves the deployment and transmission problem of the "last mile" of the quantum key at the terminal and expands the terminal service range of the quantum cryptography system.
[0123] Based on the above embodiments, another embodiment of the present disclosure provides a quantum key distribution method, which is applied to a gateway device and a terminal device. The gateway device includes a first distribution system, a first encryption and decryption module, and a first password module; the terminal device includes a second distribution system and a second encryption and decryption module. FIG5 is a fifth schematic diagram of the quantum key distribution method proposed in an embodiment of the present disclosure. As shown in FIG5, the quantum key distribution method may include the following steps:
[0124] Step 301: The first encryption / decryption module on the gateway device side sends a wireless key acquisition request to the first password module.
[0125] It should be noted that, in an embodiment of the present disclosure, before the first encryption and decryption module sends a wireless key acquisition request to the first password module, the first encryption and decryption module can receive a quantum key encryption request sent by the first distribution system; wherein the quantum key encryption request carries the service type and the quantum key.
[0126] It should be noted that in the embodiments of the present disclosure, the quantum key encryption request can carry the business type and the data information to be encrypted and decrypted. For example, if the business type is quantum key security distribution, then the corresponding data information to be encrypted and decrypted can be a quantum key. The present disclosure does not specifically limit the business type and the type of data information to be encrypted and decrypted.
[0127] Step 302: The first cryptographic module on the gateway device side sends wireless key acquisition response information to the first encryption / decryption module; wherein the wireless key acquisition response information includes the wireless key and the serial number corresponding to the wireless key.
[0128] It should be noted that, in the embodiment of the present disclosure, the serial number corresponding to the wireless key is used to represent the unique identifier of the wireless key.
[0129] It should be noted that, in the embodiment of the present disclosure, the gateway device may further include a first key status query module and a first key usage interface. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0130] It should be noted that, in an embodiment of the present disclosure, the status query process of the wireless key may include: the first distribution system sends a wireless key query request message to the first password module through the first key status query module; or, the first distribution system sends a wireless key query request message to the first password module through the first key usage interface; the first password module queries the currently stored wireless key status information, and forwards the wireless key query response message to the first distribution system through the first key status query module; wherein, the wireless key query response message carries the wireless key status information.
[0131] Furthermore, in an embodiment of the present disclosure, the gateway device may also include a first key generation trigger module, which may determine whether the current wireless key meets the first preset condition based on the wireless key status information, key generation strategy, and application requirement information; if the current wireless key does not meet the first preset condition, the wireless key generation mechanism is triggered.
[0132] It should be noted that in the embodiment of the present disclosure, the gateway device also includes a first management and control module, a first transmission module, a first generation module and a first channel detection module. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0133] It should be noted that, in an embodiment of the present disclosure, when the current wireless key does not meet the first preset condition, after the wireless key generation mechanism is triggered, the first management and control module can receive a request to generate a wireless key and send a request to obtain channel status information to the first channel detection module; then the first channel detection module can obtain the first channel status information and the first serial number information corresponding to the first channel status information; and then can send a channel detection request to the second channel detection module in the terminal device; wherein the channel detection request includes the first channel status information and the first serial number information; and receive a channel detection response message sent by the second channel detection module; wherein the channel detection response message carries the second channel status information and the second serial number information corresponding to the second channel status information.
[0134] It should be noted that in an embodiment of the present disclosure, after receiving the channel detection response message sent by the second channel detection module, the first channel detection module can obtain the second channel state information and the second sequence number information, and send ACK or NAK to the second channel detection module; when the first sequence number information and the second sequence number information are the same, the first channel detection module can send the first channel state information and the first sequence number information to the first management and control module, so that the first management and control module stores the first channel state and the first sequence number information.
[0135] It should be noted that, in an embodiment of the present disclosure, after the first channel detection module sends the first channel state information and the first sequence number information to the first management and control module, the first management and control module may send a reconciliation information request to the first generation module; wherein the reconciliation information request includes the first channel state information and the first sequence number information; then the first generation module may quantize the first channel state information, thereby obtaining the first wireless key and determining the first reconciliation information corresponding to the first wireless key.
[0136] It should be noted that, in the embodiment of the present disclosure, the first wireless key may be an original wireless key.
[0137] It should be noted that, in an embodiment of the present disclosure, after the first management and control module receives the reconciliation response information sent by the first generation module, the first transmission module can send a key consistency reconciliation request to the second transmission module in the terminal device; wherein, the key consistency reconciliation request includes the first reconciliation information; the first transmission module can receive the key consistency reconciliation response information sent by the second transmission module; wherein, the key consistency reconciliation response information includes the first reconciliation result; after receiving the key consistency reconciliation response information forwarded by the first transmission module, the first management and control module can send a wireless key acquisition request to the first generation module; wherein, the wireless key acquisition request carries the first reconciliation result.
[0138] Furthermore, in an embodiment of the present disclosure, after sending a wireless key acquisition request to the first generation module, the first generation module can determine whether the reconciliation is successful based on the first reconciliation result; if the first reconciliation result is successful, the first generation module can perform privacy amplification processing on the first wireless key to obtain a second wireless key; and then the first generation module can send a wireless key acquisition response message to the first management and control module; wherein the wireless key acquisition response message includes the key generation result.
[0139] Furthermore, in an embodiment of the present disclosure, after obtaining the second wireless key, the first generation module may send a storage key request message to the first password module; wherein the storage key request message carries the second wireless key; then the first password module may encrypt the second wireless key based on the first algorithm; and store the encrypted second wireless key, the serial number information corresponding to the encrypted second wireless key, and the validity period corresponding to the encrypted second wireless key, and then send a storage wireless key response message to the first generation module, the wireless key response message carrying a storage success flag or a storage failure flag.
[0140] That is to say, in an embodiment of the present disclosure, after receiving a wireless key acquisition request, the first cryptographic module can query the status of the wireless key. If the current wireless key does not meet the first preset condition, the wireless key generation mechanism can be triggered, and then the generated wireless key and the validity period corresponding to the wireless key can be stored.
[0141] Step 303: The first encryption and decryption module on the gateway device encrypts the quantum key based on the wireless key to obtain an encrypted quantum key.
[0142] Furthermore, in an embodiment of the present disclosure, after the first encryption and decryption module encrypts the quantum key based on the wireless key, the first encryption and decryption module may send a quantum key encryption response message to the first distribution system; wherein the quantum key response message carries an encryption success flag or an encryption failure flag, the encrypted quantum key, and a serial number corresponding to the wireless key.
[0143] It should be noted that, in the embodiment of the present disclosure, the first encryption and decryption module can trigger a destruction mechanism corresponding to the wireless key.
[0144] It should be noted that, in an embodiment of the present disclosure, after the first encryption and decryption module triggers the destruction mechanism corresponding to the wireless key, the first encryption and decryption module may send a key destruction request; wherein the key destruction request carries the serial number corresponding to the wireless key; the first cryptographic module destroys the wireless key corresponding to the serial number; or, the first cryptographic module destroys the wireless key based on the valid period corresponding to the wireless key; the first cryptographic module sends a key destruction response message to the first encryption and decryption module, and the key destruction response message carries a destruction success flag or a destruction failure flag.
[0145] It should be noted that in the embodiments of the present disclosure, the gateway device may include not only the first distribution system, the first encryption and decryption module, and the first password module, but also the first module group. The present disclosure does not specifically limit the number and type of modules included in the gateway device.
[0146] Furthermore, in an embodiment of the present disclosure, after the first encryption / decryption module encrypts the quantum key based on the wireless key, the first encryption / decryption module may also send a data transmission request to the first module; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; the first module may then send a data transmission request to the second module in the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0147] It should be noted that, in an embodiment of the present disclosure, the first module can receive a data transmission response message sent by the second module; wherein the data transmission response message carries a quantum key reception success flag or a reception failure flag; the first module can then forward the data transmission response message to the first distribution system through the first encryption and decryption module; the first encryption and decryption module can trigger the destruction mechanism corresponding to the wireless key.
[0148] Step 304: The first distribution system on the gateway device side sends a data transmission request to the terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0149] Step 305: The second distribution system on the terminal device side sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key.
[0150] Step 306: The second encryption / decryption module on the terminal device side determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0151] It should be noted that, in the embodiment of the present disclosure, the terminal device further includes a second password module and a second encryption and decryption module. The present disclosure does not specifically limit the number and type of modules included in the terminal device.
[0152] It should be noted that, in an embodiment of the present disclosure, when the terminal device determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key, the second encryption and decryption module can send a wireless key acquisition request message to the second cryptographic module; wherein the wireless key acquisition request message carries the serial number corresponding to the wireless key; then the second cryptographic module can determine the corresponding wireless key based on the serial number corresponding to the wireless key, and send a wireless key acquisition response message to the second encryption and decryption module, the wireless key acquisition response message carrying the wireless key; and then the second encryption and decryption module can decrypt the encrypted quantum key based on the wireless key to obtain the original quantum key.
[0153] Furthermore, in an embodiment of the present disclosure, after the second encryption and decryption module decrypts the encrypted quantum key based on the wireless key, the second cryptographic module may destroy the wireless key corresponding to the serial number; or, the second cryptographic module destroys the wireless key based on the validity period corresponding to the wireless key.
[0154] It should be noted that, in the embodiments of the present disclosure, the terminal device may further include a second management and control module, a second transmission module, a second generation module and a second detection module. The present disclosure does not specifically limit the number and type of modules included in the terminal device.
[0155] It should be noted that, in an embodiment of the present disclosure, the second channel detection module can receive a channel detection request sent by the first channel detection module, wherein the channel detection request includes first channel state information and first sequence number information, and send a channel detection response message to the first channel detection module; wherein the channel detection response message carries second channel state information and second sequence number information corresponding to the second channel state information; when the second channel detection module receives the ACK sent by the first channel detection module, the second channel state information and the second sequence number information corresponding to the second channel state information can be sent to the second management and control module.
[0156] It should be noted that, in the embodiment of the application, the second channel state information may be CSI detected and obtained by the second channel detection module on the terminal device side.
[0157] Furthermore, in an embodiment of the present disclosure, after sending the second channel state information and the second serial number information corresponding to the second channel state information to the second management and control module, the second management and control module may send a request to obtain a wireless key to the second generation module; wherein the request to obtain a wireless key includes the second channel state information and the second serial number information; and then the second generation module may quantize the second channel state information to obtain a third wireless key.
[0158] It should be noted that, in the embodiment of the present disclosure, the third wireless key may be the original wireless key.
[0159] Furthermore, in an embodiment of the present disclosure, after the second generation module quantizes the second channel state information and obtains the third wireless key, the second transmission module can receive a key consistency reconciliation request sent by the first management and control module; wherein the key consistency reconciliation request includes first reconciliation information; then the second generation module can reconcile the first reconciliation information based on the third wireless key and determine the first reconciliation result; if the first reconciliation result is a successful reconciliation, the second generation module can perform privacy amplification processing on the third wireless key to obtain a fourth wireless key; and then the second generation module can forward the key consistency reconciliation response information to the first transmission module through the second transmission module; wherein the key consistency reconciliation response information includes the first reconciliation result.
[0160] It should be noted that, in an embodiment of the present disclosure, after obtaining the fourth wireless key, the second generation module may send a storage key request message to the second cryptographic module; wherein the storage key request message carries the fourth wireless key; the second cryptographic module may encrypt the fourth wireless key based on the second algorithm; the second cryptographic module stores the encrypted fourth wireless key, the serial number information corresponding to the encrypted fourth wireless key, and the valid period corresponding to the encrypted fourth wireless key, and sends a storage wireless key response message to the second generation module, and the wireless key response message carries a storage success flag or a storage failure flag.
[0161] It should be noted that, in the embodiment of the present disclosure, the second algorithm may be an SM4 block cipher algorithm, and the present disclosure does not specifically limit the type of the second algorithm.
[0162] To sum up, the first encryption and decryption module in the gateway device can encrypt the quantum key based on the wireless key to obtain the encrypted quantum key, thereby ensuring the secure transmission of the quantum key. The encrypted quantum key and the serial number corresponding to the wireless key can then be sent to the terminal device, so that the terminal device can obtain the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. This solves the problem of transmission and distribution of quantum keys in the "last mile" at mobile terminals, and is of great significance for promoting the development of the quantum communication industry. It is conducive to improving the utilization rate of QKD infrastructure and achieving cost-sharing and efficiency improvement.
[0163] An embodiment of the present disclosure provides a quantum key distribution method, which is applied to a gateway device and a terminal device. The gateway device includes a first distribution system, a first encryption and decryption module, and a first cryptographic module. The first encryption and decryption module sends a wireless key acquisition request to the first cryptographic module. The first cryptographic module sends a wireless key acquisition response message to the first encryption and decryption module. The wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key. The first encryption and decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key. The first distribution system sends a data transmission request to the terminal device. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains an original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. The terminal device includes a second distribution system and a second encryption and decryption module. The second distribution system receives the data transmission request. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key. The second distribution system sends a quantum key decryption request message to the second encryption and decryption module. The quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key. The second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. It can be seen that the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first password module, and then encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present disclosure can realize the wireless distribution of quantum keys based on the gateway device without the need for offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure.
[0164] Based on the above embodiments, another embodiment of the present disclosure provides a quantum key distribution method. For the quantum key wireless distribution method, the present disclosure provides a specific method for using a wireless physical layer key (wireless key), including a wireless key usage interface process and a wireless key encryption and decryption quantum key process. The corresponding process is designed and integrated with the communication process to realize wireless distribution of quantum keys based on physical layer keys (wireless keys). The quantum key distribution method is described in detail below.
[0165] It should be noted that in the embodiments of the present disclosure, FIG6 is a schematic diagram of wireless channel key negotiation proposed in the embodiments of the present disclosure. As shown in FIG6, in the research on the physical layer security of wireless communication, the channels of the two communicating parties have good short-term reciprocity. Similar channel characteristics can be extracted from the wireless channel and a unique identifier can be generated. The natural randomness of the wireless channel can be used to generate a symmetric key for the wireless communication system in real time and uniquely identify the two communicating users. The wireless channel key method is different from the traditional key generation method that relies on complex mathematical algorithms. This method can extract the unique channel characteristic information of the two communicating parties as the data source of the key. At the same time, it can use the volatile nature of the wireless channel characteristics to change the key in a short time and even realize the "one-time one-pad" function. It has higher security and makes it more difficult to crack the key. In the communication system, the wireless channel has short-term reciprocity within the coherence time. The wireless signals sent by the two communicating parties experience the same channel fading, so the measured channel characteristics are extremely similar. It is highly feasible to extract channel state information from the channel characteristics and then generate a symmetric key. The wireless signal monitored by a third-party eavesdropper cannot extract the same channel characteristics as the legitimate receiver because it experiences different channel fading. As shown in Figure 6, wireless channel characterization technology mainly generates the negotiated key through steps such as channel measurement, channel estimation, quantization coding, information reconciliation, and privacy amplification.
[0166] It should be noted that, in the embodiment of the present disclosure, FIG7 is a schematic diagram of the physical layer key generation process proposed in the embodiment of the present disclosure. As shown in FIG7, the physical layer key (wireless key) generation (PKG) technology generally relies on four stages, including channel detection, quantization, information coordination and privacy amplification. FIG7 describes these four stages. Alice and Bob first perform channel detection. The channel detection process is bidirectional, and obtain measurement results X respectively. A and X B , then the measurement result X can be A and X B Converted to binary, that is and get and Afterwards, due to and There may be mismatched bits between them, so information coordination must be used to adjust the mismatched bits. Then Alice and Bob will each get a matching and Finally, in order to prevent attackers from using the information exchanged through the public channel in the information coordination step to deduce the key, it is usually necessary to use privacy amplification technology to match the same and Processing to obtain the almost completely confidential symmetric key K A and K B .
[0167] It should be noted that, in the embodiment of the present disclosure, Figure 8 is a schematic diagram of the quantum key wireless distribution system proposed in the embodiment of the present disclosure. As shown in Figure 8, the quantum key wireless distribution system, as shown in Figure 8, obtains the quantum key by the quantum cryptography security service center (wireless distribution management module), transmits the quantum key to the wireless local area network (WLAN) through the Internet Protocol (IP) network, develops a wireless security communication module on the WLAN quantum wireless gateway (gateway device), generates and manages wireless keys, and securely transmits the quantum key on the wireless gateway to the quantum security terminal (terminal device) through the generated wireless key; develops a wireless security communication module on the quantum security terminal, generates and manages wireless keys, and receives the quantum key transmitted by the wireless gateway (gateway device) through the generated wireless key, thereby realizing wireless security distribution of quantum keys and meeting the needs of quantum security communication.
[0168] It should be noted that in the embodiments of the present disclosure, for the quantum key wireless distribution method and system based on physical layer keys (wireless keys) and their corresponding gateways and terminals, the present disclosure designs and provides a wireless physical layer key (wireless key) generation method process, a wireless key usage interface process, a wireless key encryption and decryption quantum key process, a wireless key management process (including a key status query process, a key generation trigger process, a wireless key storage process, and a wireless key destruction process), the software architecture and core business functions of the quantum key wireless distribution system, the core business function implementation of the quantum key wireless distribution gateway and terminal, and its hardware system architecture, etc.
[0169] Furthermore, in an embodiment of the present disclosure, FIG9 is a schematic diagram of a wireless key usage interface process proposed in an embodiment of the present disclosure. As shown in FIG9 , the wireless key usage interface process includes the following steps: 1. Before transmitting the quantum key, the quantum key security distribution subsystem (first distribution system) needs to first query the WLAN wireless security transmission subsystem whether there is an available wireless key. The quantum key security distribution subsystem (first distribution system) sends a wireless key query request message to the key usage interface module (first key usage interface), and the message carries an indication of the query wireless key status; 2. After receiving the wireless key query request message, the key usage interface module (first key usage interface) sends the message to the cryptographic module (first cryptographic module); 3. The cryptographic module queries whether there is a valid wireless key; 4. The cryptographic module (first cryptographic module) returns a wireless key query response message to the key usage interface module (first key usage interface), and the message carries an indication of the presence or absence of a valid wireless key; 5. The key usage interface module returns a wireless key query response message to the quantum key security distribution subsystem to determine whether there is a valid wireless key in the cryptographic module; 6. .The quantum key security distribution subsystem sends a quantum key security transmission request message to the key usage interface module based on the returned wireless key query result. When it finds that there is an available wireless key, the message carries the service type and the data to be encrypted and decrypted. Here, for the quantum security distribution service, (service type, data to be encrypted and decrypted) is (quantum security distribution, quantum key). The specific service type, data to be encrypted and decrypted, etc. carried here can be expanded accordingly according to the service in the future; 7. After receiving the quantum key security transmission request message, the key usage interface module sends the message to the encryption and decryption module; 8. After receiving the quantum key security transmission request message, the encryption and decryption module triggers the encryption and decryption process; the encryption and decryption module returns a quantum key security transmission response message to the key usage interface module based on the encryption and decryption processing result. The message carries a reception success or failure flag; 9. After receiving the quantum key security transmission response message returned by the encryption and decryption module, the key usage interface module returns the message to the quantum key security distribution subsystem, and the quantum key security distribution subsystem determines the subsequent processing based on the success or failure flag carried in the response message.
[0170] Further, in an embodiment of the present disclosure, FIG10 is a schematic diagram of a wireless key encryption and decryption quantum key process proposed in an embodiment of the present disclosure. As shown in FIG10 , the wireless key encryption and decryption quantum key process includes the following steps: 1. The quantum key security distribution subsystem (first distribution system) on the gateway side sends a quantum key security transmission request message to the encryption and decryption module (first encryption and decryption module) on the gateway side, carrying information such as the service type and the data to be encrypted and decrypted. Here, for the quantum security distribution service, (service type, information on the data to be encrypted and decrypted) is (quantum security distribution, quantum key). The specific service type, information such as the data to be encrypted and decrypted carried here can be expanded accordingly according to the service in the future; 2. Encryption and decryption on the gateway side The module (first encryption and decryption module) sends a wireless key acquisition request message to the password module (first password module) on this side; 3. After the password module (first password module) on the gateway side obtains the wireless key, it returns a wireless key acquisition response message to the encryption and decryption module on this side. The message carries the wireless key and the unique identification number of the wireless key (the serial number corresponding to the wireless key); 4. The encryption and decryption module on the gateway side uses the wireless key to encrypt the quantum key. The encryption algorithm (first algorithm) here can adopt the XOR algorithm, the national secret SM4 algorithm and other encryption algorithms; 5. The encryption and decryption module on the gateway side sends a wireless key encrypted data transmission request message to the WIFI6 module (first module) on this side. The message carries the message type identifier, the encrypted 6. The WIFI6 module (first module) on the gateway side performs WIFI6 data transmission to the WIFI6 module (second module) on the terminal side; 7. After the WIFI6 module (second module) on the terminal side identifies the message type, it sends a wireless key encrypted data transmission request message to the encryption and decryption module (second encryption and decryption module) on this side, and the message carries the encrypted quantum key and the unique identification number of the wireless key; 8. The encryption and decryption module (second encryption and decryption module) on the terminal side sends a wireless key acquisition request message to the password module (second password module) on this side, and the message carries the unique identification number of the wireless key; 9. The password module (second password module) on the terminal side obtains the wireless key. After receiving the key, the terminal returns a wireless key acquisition response message to the encryption and decryption module (second encryption and decryption module) on the terminal side, which carries the wireless key. 10. The encryption and decryption module on the terminal side uses the wireless key to decrypt the quantum key. The decryption algorithm (second algorithm) here can adopt a decryption algorithm such as the XOR algorithm and the national secret SM4 algorithm. 11. The encryption and decryption module on the terminal side sends a quantum key transmission request message to the quantum key security distribution subsystem (second distribution system) on the terminal side, which carries the quantum key. 12. The quantum key security distribution subsystem (second distribution system) on the terminal side returns a quantum key transmission response message to the encryption and decryption module (second encryption and decryption module) on the terminal side, which carries an indication of success or failure of the reception. 13.The encryption and decryption module on the terminal side executes step 13-1 and step 13-2 simultaneously. Specifically, step 13-1 and step 13-2 are as follows. In addition, step 14, step 15, step 16-1, and step 16-2 may also be performed after step 13-1.
[0171] Further, in an embodiment of the present disclosure, as shown in FIG10 , step 13-1. The encryption and decryption module (second encryption and decryption module) on the terminal side sends a wireless key encrypted data transmission response message to the WIFI6 module (second module) on this side, and the message carries an identification of successful or failed reception; step 13-2. The encryption and decryption module on the terminal side triggers the wireless key destruction process; step 14. The WIFI6 module (second module) on the terminal side performs WIFI6 data transmission to the WIFI6 module (first module) on the gateway side; step 15. The WIFI on the gateway side Module 6 (the first module) returns a wireless key encrypted data transmission response message to the encryption and decryption module on this side, and the message carries an identification of successful or failed reception; step 16. The encryption and decryption module on the gateway side simultaneously executes steps 16-1 and 16-2; specifically, steps 16-1 and 16-2 are as follows: 16-1. The encryption and decryption module on the gateway side returns a quantum key secure transmission response message to the quantum key secure distribution subsystem on the gateway side, carrying an identification of successful or failed reception; 16-2. The encryption and decryption module on the gateway side triggers the wireless key destruction process.
[0172] Further, in an embodiment of the present disclosure, FIG11 is a schematic diagram of the second wireless key encryption and decryption quantum key process proposed in an embodiment of the present disclosure. As shown in FIG11, the wireless key encryption and decryption quantum key process also includes the following steps: 1. The quantum key security distribution subsystem (first distribution system) on the gateway side sends a quantum key security encryption request message to the encryption and decryption module (first encryption and decryption module) on the gateway side, carrying information such as the service type and the data to be encrypted and decrypted. Here, for the quantum security distribution service, (service type, information on the data to be encrypted and decrypted) is (quantum security distribution, quantum key). The specific service type, information such as the data to be encrypted and decrypted carried here can be expanded accordingly according to the service later; 2. The gateway side The encryption and decryption module (first encryption and decryption module) sends a wireless key acquisition request message to the password module on this side; 3. After the password module on the gateway side obtains the wireless key, it returns a wireless key acquisition response message to the encryption and decryption module on this side, and the message carries the wireless key and the unique identification serial number of the wireless key; 4. The encryption and decryption module on the gateway side uses the wireless key to encrypt the quantum key. The encryption algorithm here can adopt an XOR algorithm, a national secret SM4 algorithm, and other encryption algorithms; 5. The encryption and decryption module on the gateway side executes steps 5-1 and 5-2 at the same time. Specifically, steps 5-1 and 5-2 are as follows; in addition, after step 5-1, steps 6, 7-1, 7-2, 8, 9, and 10 will also be performed. 10. Step 11-1, Step 11-2; 5-1. The encryption and decryption module on the gateway side (the first encryption and decryption module) returns a quantum key security encryption response message to the quantum key security distribution subsystem (the first distribution system) on the gateway side, which carries the encryption success / failure flag, the encrypted quantum key, and the unique identification number of the wireless key; 5-2. The encryption and decryption module on the gateway side triggers the wireless key destruction process; 6. The quantum key security distribution subsystem (the first distribution system) on the gateway side transmits data to the quantum key security distribution subsystem (the second distribution system) on the terminal side, and sends a quantum key encryption data transmission request message, which carries the encrypted quantum key and the unique identification number of the wireless key; 7. The terminal The quantum key security distribution subsystem (second distribution system) on the terminal side simultaneously executes steps 7-1 and 7-2. Specifically, steps 7-1 and 7-2 are as follows. In addition, steps 8, 9, 10, 11-1, and 11-2 will be performed after step 7-2. 7-1. The quantum key security distribution subsystem (second distribution system) on the terminal side returns a quantum key encrypted data transmission response message to the quantum key security distribution subsystem on the gateway side, which carries a reception success / failure indicator. 7-2. The quantum key security distribution subsystem on the terminal side sends a quantum key security decryption request message to the encryption / decryption module, which carries the unique identification serial number of the encrypted quantum key and wireless key. 8.The terminal's encryption and decryption module (second encryption and decryption module) sends a wireless key acquisition request message to the local cryptographic module (second cryptographic module), which carries the wireless key's unique identification number. 9. After acquiring the wireless key, the terminal's cryptographic module (second cryptographic module) returns a wireless key acquisition response message to the local encryption and decryption module, which also carries the wireless key. 10. The terminal's encryption and decryption module uses the wireless key to decrypt the quantum key. The decryption algorithm used here can be an XOR algorithm, the national secret SM4 algorithm, or other decryption algorithms. 11. The terminal's encryption and decryption module simultaneously executes steps 11-1 and 11-2. Specifically, steps 11-1 and 11-2 are as follows: 11-1. The terminal's encryption and decryption module returns a quantum key security decryption response message to the terminal's quantum key security distribution subsystem, which carries a decryption success / failure indicator and the quantum key. 11-2. The terminal's encryption and decryption module triggers the wireless key destruction process.
[0173] It should be noted that, in the embodiment of the present disclosure, FIG12 is a schematic diagram of the wireless key generation process proposed in the embodiment of the present disclosure. As shown in FIG12, the wireless key generation process includes the following steps: 1. After the state management and control module (first management and control module) receives the request to generate a wireless key, 2. Send a CSI request message (first channel state information) to the channel detection module (first channel detection module) to obtain (channel state information), and call the channel detection module to start wireless channel detection; 3. The gateway side channel detection module (first channel detection module) sends a custom channel detection request media access control (Media Access Control) to the terminal side channel detection module (second channel detection module) Control, MAC) frame; 4. The terminal side channel detection module (second channel detection module) extracts the CSI (first channel state information) and the CSI sequence number information it carries in the channel detection request message, and temporarily stores it in its own channel detection module; 5. After the terminal confirms that the message is correctly received and the CSI (first channel state information) is successfully obtained, the channel detection module (second channel detection module) returns a custom channel detection response MAC frame to the gateway channel detection module (first channel detection module), and carries the CSI sequence number information (second channel state information) in the response message; 6. The gateway channel detection module obtains the CSI (second channel state information) and the CSI sequence number information carried according to the returned channel detection response message, and temporarily stores it in its own channel detection module; 7. After the gateway confirms that the message is correctly received and the corresponding CSI is successfully obtained, the gateway channel detection module sends a custom channel detection ACK / NAK to the terminal channel detection module MAC frame to inform the terminal of the response message reception status and CSI acquisition status; 8. After the gateway channel detection module confirms that the channel detection ACK / NAK is correctly received by the terminal, it returns the CSI acquisition response message to the status management and control module (first management and control module), and sends the CSI and corresponding sequence number temporarily stored in the channel detection module to the local status management and control module (in the case of correct CSI acquisition) or discards the CSI and corresponding sequence number obtained this time (in the case of an abnormality); 8-1. After receiving the channel detection ACK / NAK message, the terminal determines whether the other party has successfully acquired the CSI and whether the sequence numbers correspond. If so (the first sequence number information and the second sequence number information are the same), the CSI and corresponding sequence number temporarily stored in the channel detection module are sent to the local status management and control module. If not (the first sequence number information and the second sequence number information are different), the CSI and corresponding sequence number obtained this time are discarded; 9. The gateway status management and control module (first management and control module) calls the local wireless key generation module (first generation module) by sending a reconciliation information acquisition request message; 10.The wireless key generation module (first generation module) quantizes the CSI to generate an original wireless key (first wireless key). The original wireless key mentioned here refers to the binary bit sequence obtained after the CSI is quantized. At the same time, the wireless key generation module (first generation module) on the gateway side calculates the information required to reconcile the original wireless key. It should be noted that the wireless key may be a group of wireless keys generated by processing multiple CSI combinations. 9-1. The terminal side status management and control module (second management and control module) calls the wireless key generation module (second generation module) by sending a request message to generate an original wireless key. 10-1. The second generation module quantizes the CSI to generate an original wireless key ( The third wireless key), the original wireless key mentioned here also refers to the binary bit sequence obtained after the CSI is quantized; 11. The wireless key generation module (first generation module) obtains the reconciliation information response message and feeds back the reconciliation information to the state management and control module (first management and control module); 12. The state management and control module (first management and control module) sends a key consistency reconciliation request message to the reconciliation information module, thereby calling the reconciliation information transmission module to transmit the reconciliation information; 13. The gateway side reconciliation information transmission module (first transmission module) uses the custom key consistency reconciliation request MAC frame to transmit the reconciliation information to the terminal side reconciliation information transmission module (second transmission module); 14. The terminal The terminal-side reconciliation information transmission module (second transmission module) sends the parsed reconciliation information to the state management and control module (second management and control module) in the form of a key consistency reconciliation request message; 15. The terminal-side state management and control module calls the wireless key generation module (second generation module) by sending a key consistency reconciliation request message and transmits the reconciliation information at the same time; 16. After receiving the request message, the wireless key generation module (second generation module) uses the original wireless key of the terminal to process the reconciliation information to obtain the reconciliation result of this group of wireless keys; 17. If this group of keys is successfully reconciled, the wireless key generation module (second generation module) performs subsequent processing (such as privacy amplification) to generate the final reconciled wireless key. The wireless key generation module (second generation module) generates the online key and stores it in the cryptographic module. If key reconciliation fails, the wireless key generation module discards the key. 18. The wireless key generation module (second generation module) notifies the state management and control module (second management and control module) of the reconciliation result in the form of a key consistency reconciliation response message. 19. The state management and control module (second management and control module) transmits the reconciliation result by sending a key consistency reconciliation response message to the reconciliation information transmission module (second transmission module). 20. The terminal-side reconciliation information transmission module (second transmission module) uses a custom key consistency reconciliation response MAC frame to feed back the reconciliation result to the gateway-side reconciliation information transmission module (first transmission module). 21.The reconciliation information transmission module (first transmission module) feeds back the reconciliation result to the state management and control module (first management and control module) by returning a key consistency reconciliation response message. 22. The state management and control module (first management and control module) sends a request to obtain a wireless key to the wireless key generation module (first generation module), invoking the wireless key generation module and transmitting the reconciliation result. 23. The wireless key generation module (first generation module) chooses to store or discard the wireless key set based on the key reconciliation result (same as step 17). 24. The wireless key generation module notifies the state management and control module of the wireless key generation result in the form of a obtain wireless key response message. 25. The state management and control module notifies the key generation trigger module of the generation result by returning a generate wireless key response message.
[0174] It should be noted that, in an embodiment of the present disclosure, Figure 13 is a schematic diagram of the key status query process proposed in an embodiment of the present disclosure. As shown in Figure 13, the key status query process may include the following steps: 1. When the quantum key security distribution subsystem has a need to transmit a quantum key or when the status query module of the management subsystem needs to query the wireless key status, a wireless key query request message is sent to the key status query module (first key status query module) through the key usage interface (first key usage interface); 2. The key status query module sends a wireless key query request message to the cryptographic module; 3. The cryptographic module queries all stored wireless key status information; 4. The cryptographic module returns a wireless key query response message to the key status query module, and the message carries wireless key status statistics (such as the number of available wireless keys); 5. The key status query module returns a wireless key query response message to the quantum key security distribution subsystem or the management subsystem, and the message carries wireless key status statistics (such as the number of available wireless keys).
[0175] It should be noted that, in an embodiment of the present disclosure, Figure 14 is a schematic diagram of the key generation trigger process proposed in an embodiment of the present disclosure. As shown in Figure 14, the key generation trigger process may include the following steps: 1. According to local cryptographic application requirements (for example, the user has business needs), key generation strategies (for example, when and under what circumstances to generate keys (the gateway detects that a terminal has successfully accessed)), etc., combined with the number of local wireless physical layer keys (for example, whether there are sufficient and fresh keys locally for application use), determine whether to trigger the wireless physical layer key generation mechanism and control the start and stop of the key generation component; 2. After receiving the request message, the wireless key generation component starts the wireless key generation process; 3. The wireless key generation component returns the wireless key generation response message to the key generation trigger module, and the message carries a key generation success / failure identifier.
[0176] It should be noted that, in an embodiment of the present disclosure, Figure 15 is a schematic diagram of the wireless key storage process proposed in an embodiment of the present disclosure. As shown in Figure 15, the wireless key storage process may include the following steps: 1. The wireless key generation module sends a wireless key storage request message to the password module, and the message carries the wireless key generated by the wireless key generation module; 2. The password module encrypts the wireless key with the SM4 national secret algorithm and stores it. When storing, a serial number that uniquely identifies the wireless key should be generated, and the time when the wireless key is generated and the expiration period of the key should be stored at the same time (such as the expiration time defaults to 5 minutes, then the expiration period of the key is 300 seconds, and the expiration time can be set through application management); 3. The password module returns a wireless key storage response message to the wireless key generation module, and the message carries a success or failure indication for storing the wireless key.
[0177] It should be noted that, in an embodiment of the present disclosure, FIG16 is a schematic diagram of a wireless key destruction process proposed in an embodiment of the present disclosure. As shown in FIG16 , the wireless key destruction process may include an active destruction process and an automatic destruction process. The active destruction process may include the following steps: 1. The wireless key usage component sends a wireless key destruction request message to the cryptographic module, the message carrying the wireless key serial number to be destroyed; 2. The cryptographic module destroys the corresponding wireless key according to the wireless key serial number carried in the message; 3. The cryptographic module returns a wireless key destruction response message to the wireless key usage component, the message carrying a success or failure indicator of wireless key destruction; The automatic destruction process may include the following steps: 1. The cryptographic module periodically monitors whether the stored wireless keys have exceeded their usage period. If any expired unused wireless keys exist, they are directly destroyed.
[0178] Furthermore, in an embodiment of the present disclosure, FIG17 is a schematic diagram of the structure of the quantum key wireless distribution system proposed in an embodiment of the present disclosure. As shown in FIG17, according to the core business logic and functional scope of the quantum key wireless distribution system based on the physical layer key (wireless key), the system is divided into: WLAN wireless secure transmission subsystem, quantum key security distribution subsystem and management subsystem; the WLAN wireless secure transmission subsystem includes: wireless key generation, wireless key management and wireless key usage functions, which can also be called components, wherein the wireless key generation function is composed of a state management and control module, a channel detection module, a wireless key generation module and a reconciliation information transmission module; the wireless key management function is composed of a key state query module, a key generation trigger module, a wireless key storage module and a wireless key destruction module; the wireless key usage function is composed of an encryption and decryption module and a key usage interface module; the WLAN wireless secure transmission subsystem is embodied in the form of a wireless secure communication module on the WLAN quantum wireless gateway and the quantum security terminal device; the quantum key security distribution subsystem includes a quantum key The wireless transmission / distribution function is mainly composed of a quantum key acquisition module, a quantum key storage module, a quantum key transmission module and a quantum key receiving module; the quantum key security distribution subsystem is embodied in the form of a quantum key wireless transmission component on the WLAN quantum wireless gateway device and in the form of a quantum key wireless distribution component on the quantum security terminal device; the management subsystem includes five functional modules: user management, device management, system configuration, status query, and log management; the management subsystem must be embodied in both the WLAN quantum wireless gateway and the quantum security terminal devices, among which the WLAN quantum wireless gateway device must have all functional modules, and the quantum security terminal must have basic system configuration, status query, and log management functions; among the above core business functions, the WLAN wireless security transmission subsystem and the management subsystem are provided with relevant software and hardware system architecture design and wireless key-related business process design by the WLAN quantum wireless gateway equipment vendor and the quantum security terminal equipment vendor, and the quantum key security distribution subsystem is provided with relevant design and business process implementation by the quantum key security service provider.
[0179] Furthermore, in an embodiment of the present disclosure, FIG18 is a schematic diagram of the software architecture proposed in an embodiment of the present disclosure. As shown in FIG18 , the software system adopts a three-layer architecture design, including an application management system, a quantum key wireless distribution system, and a hardware and interface system; the application management system is mainly responsible for the management of WLAN quantum wireless gateways (gateway devices) and quantum security terminal devices (terminal devices), and its main functions are user management, device management, system configuration, status query, and log management; the quantum key wireless distribution system is mainly responsible for the management of quantum keys and wireless keys, and is divided into a WLAN wireless security transmission subsystem and a quantum key security distribution subsystem; the WLAN wireless security transmission subsystem is mainly used for wireless key generation, management, and use, and the quantum key security distribution subsystem is mainly used for quantum key wireless transmission and distribution; the hardware and interface system mainly includes a wireless fidelity (WiFi) key enhancement interface, a WiFi transmission interface, and a microprocessor (Advanced RISC Machine, ARM), WiFi6 module, cryptographic module, TF card; the underlying operating system runs in the ARM main control, serving as the operating environment for the software system; the system adopts a multi-threaded task scheduling mechanism: allocating computing power to the wireless key generation algorithm and quantum key distribution function, while allocating computing power and memory to the smooth operation of each component in the management subsystem, which is the basis for the stable operation of the system.
[0180] Furthermore, in an embodiment of the present disclosure, Figure 19 is a schematic diagram of the core business functions proposed in the embodiment of the present disclosure. As shown in Figure 19, the quantum key security distribution / transmission component runs in the ARM main control as a process; the wireless key usage component and the wireless key management component run in the ARM main control as a process; the wireless key generation module in the wireless key generation component runs in the ARM main control as a process, the state management and control module runs in the ARM main control as a process, and the channel detection module and the coordination information transmission module run in the WiFi6 module of a specific chip.
[0181] It should be noted that, in the embodiment of the present disclosure, Figure 20 is a schematic diagram of the hardware system architecture proposed in the embodiment of the present disclosure. As shown in Figure 20, the gateway and terminal hardware are mainly composed of a WiFi6 module, an ARM, a TF card interface, a cryptographic module, a WiFi4 module, an Ethernet (ETH) interface, a Universal Serial Bus (USB) interface and a power interface; the WiFi6 module must support the WiFi6 protocol and can spit out CSI information through the hardware pin. The spitted CSI information can be directly transmitted to the wireless key generation module to generate a wireless key used to encrypt and transmit quantum key data; the channel detection module and the reconciliation information transmission module related to the wireless key generation function in the WLAN wireless security transmission subsystem are mainly implemented by the WiFi6 module, and can trigger ECR6630 to spit out CSI information and transmit reconciliation with a custom MAC frame; the main control chip can choose the ARM architecture Rockchip RK3568 chip, which has a 4-core 2G main frequency, 4GB of fourth-generation double data rate synchronous dynamic random access memory (DDR4) dual-channel memory, and a 16GB embedded flash memory card (eMMC The main control chip is mainly responsible for communication between the input / output (I / O) bus, used to load and run the operating system, and supports the complex operations of the wireless key generation algorithm; the wireless key usage function, wireless key generation function module, wireless key management function, quantum key security distribution subsystem, and management subsystem of the WLAN wireless security transmission subsystem all run on the ARM main control; the cryptographic module uses the LKT4305 chip, which supports national secret algorithms such as SM1 / SM2 / SM3 / SM4 / SM7; the bus is encrypted and has a metal shielding protection layer. After detecting an external attack, the internal data self-destructs; the cryptographic module is used to achieve secure storage of wireless keys; the TF card product adopts the Secure Digital (SD) architecture design, is compatible with the standard SD protocol interface, reads and writes data through the SD protocol interface, and can be used to securely store quantum keys in this system.
[0182] It should be noted that, in the embodiment of the present disclosure, FIG21 is a schematic diagram of the quantum wireless gateway and quantum security terminal proposed in the embodiment of the present disclosure. As shown in FIG21, a wireless security communication module can be constructed on the WLAN quantum wireless gateway to generate and manage wireless keys and to perform wireless security transmission of quantum keys; on the quantum security terminal, the quantum keys can be wirelessly and securely distributed through the wireless security communication module to achieve quantum security communication; the following is a detailed introduction. The functional components of the WLAN quantum wireless gateway include 5 parts, namely, a wireless key generation component, a wireless key management component, a quantum key wireless transmission component, an operation management component, and a WLAN module component; specifically as follows: (1) Wireless key generation component: including a communication module Block interface module, channel detection module, quantization module, information coordination module, privacy amplification module, key storage interface module, wireless key management interface module, including: 1) Communication module interface module: used for the interface with the WLAN wireless communication module to realize data information transmission through WiFi; 2) Channel detection module: used for sending and receiving wireless channel detection request and response special frames, realizing wireless channel detection information interaction, obtaining CSI channel state information through channel estimation, used to generate keys, and should support continuous detection of wireless channels and continuous output of CSI; 3) Quantization module: used for quantizing CSI information and generating original key bit sequence; 4) Information coordination module: used for consistency of quantized original key information Coordination processing, including: supporting the implementation of consistency coordination algorithm and the sending and receiving of consistency coordination information; 5) Privacy amplification module: used to perform privacy amplification processing on the key bit information after consistency coordination to generate the final available wireless key; 6) Key storage interface module: used for secure access to the password module to achieve secure storage of the wireless key in the password module; 7) Wireless key management interface module: used to establish a command channel with the wireless key management module to control the start and stop of the wireless key generation function; (2) The wireless key management component includes a wireless key generation interface module, a password module interface module, a key generation startup module, a key use module, a key destruction module, a key query module, and a quantum key wireless transmission interface module; Among them, 1) Wireless 1) Key Generation Interface Module: used to establish a command channel with the wireless key generation module and control the start and stop of the wireless key generation function; 2) Cryptographic Module Interface Module: realizes the call of the cryptographic module and securely stores, uses, queries, and destroys the wireless key; 3) Key Generation Startup Module: used to control the generation of wireless keys and control the startup method, frequency, time, etc.; 4) Key Use Module: used to call the use of wireless keys; 5) Key Destruction Module: used to delete expired keys; 6) Key Query Module: used to query the status of wireless keys; 7) Quantum Key Wireless Transmission Interface Module: used for the quantum key wireless transmission component to call the interface service of the corresponding function in the wireless key management to realize the wireless secure transmission of quantum keys;(3) Quantum key wireless transmission component includes component integration module, quantum key wireless security transmission module, and communication module interface module; wherein, 1) component integration module: can integrate quantum key wireless transmission component; 2) quantum key wireless security transmission module: can use wireless key to encrypt quantum key and realize quantum key security transmission; 3) communication module interface module: used for interface with WLAN wireless communication module, realizing data information transmission through WiFi; (4) operation management component: realizes user identity authentication, system log management, authority management, device management, system configuration, status query, user interface and other functions; (5) WLAN module component: can realize WLAN protocol, gateway transceiver and other functions; at the same time, supports wireless key generation, wireless key management, quantum key wireless transmission and other functions for calling related communication modules in WLAN module; MAC layer supports wireless channel detection mechanism and wireless physical layer key consistency negotiation information transmission mechanism.
[0183] Furthermore, in an embodiment of the present disclosure, the quantum security terminal based on wireless keys may include five functional components, namely a wireless key generation component, a wireless key management component, a quantum key wireless distribution component, an operation management component, and a terminal component; wherein, (1) the wireless key generation component includes a communication module interface module, a channel detection module, a quantization module, an information coordination module, a privacy amplification module, a key storage interface module, and a wireless key management interface module; wherein, 1) the communication module interface module: is used for interfacing with the WLAN wireless communication module to realize data information transmission through WiFi; 2) the channel detection module: is used for sending and receiving wireless channel detection request and response special frames to realize wireless channel detection Information interaction, obtain CSI channel state information through channel estimation, used to generate keys, should support continuous detection of wireless channels, and continuously output CSI; 3) Quantization module: used to quantize CSI information and generate original key bit sequence; 4) Information coordination module: used to coordinate the consistency of the quantized original key information, including: supporting the implementation of the consistency coordination algorithm and the transmission and reception of consistency coordination information; 5) Privacy amplification module: used to amplify the privacy of the key bit information after consistency coordination to generate the final usable wireless key; 6) Key storage interface module: used for secure access to the cryptographic module to achieve secure storage of the wireless key in the cryptographic module; 7) Wireless key management interface module: used for secure access to the cryptographic module to achieve secure storage of the wireless key in the cryptographic module; (1) The wireless key generation interface module is used to establish a command channel with the wireless key management module and control the start and stop of the wireless key generation function; (2) The wireless key management component includes a wireless key generation interface module, a cryptographic module interface module, a key generation start module, a key use module, a key destruction module, a key query module, and a quantum key wireless distribution interface module; wherein, 1) The wireless key generation interface module is used to establish a command channel with the wireless key generation module and control the start and stop of the wireless key generation function; 2) The cryptographic module interface module is used to call the cryptographic module and securely store, use, query, and destroy the wireless key; 3) The key generation start module is used to control the generation of the wireless key and control the start method, frequency, and time, etc. ; 4) Key usage module: used for calling the use of wireless keys; 5) Key destruction module: used for deleting expired keys; 6) Key query module: used for querying the status of wireless keys; 7) Quantum key wireless distribution interface module: used for the quantum key wireless distribution component to call the interface service of the corresponding function in the wireless key management to realize the wireless security distribution of quantum keys; (3) The quantum key wireless distribution component may include a component integration module, a quantum key wireless security distribution module, and a communication module interface module; wherein, 1) the component integration module: can integrate the quantum key wireless distribution component; 2) the quantum key wireless security distribution module: can use the wireless key to decrypt the quantum key to realize the quantum key security distribution;3) Communication module interface module: used to interface with the WLAN wireless communication module and realize data information transmission through WiFi; (4) Operation management component can realize user identity authentication, system log management, authority management, device management, system configuration, status query, user interface and other functions; (5) Terminal component can realize WiFi, mobile terminal and other functions; at the same time, it supports wireless key generation, wireless key management, quantum key wireless distribution and other functions of calling related communication modules in the terminal; MAC layer supports wireless channel detection mechanism and wireless physical layer key consistency negotiation information transmission mechanism.
[0184] To sum up, the first encryption and decryption module in the gateway device can encrypt the quantum key based on the wireless key to obtain the encrypted quantum key, thereby ensuring the secure transmission of the quantum key. The encrypted quantum key and the serial number corresponding to the wireless key can then be sent to the terminal device, so that the terminal device can obtain the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. This solves the problem of transmission and distribution of quantum keys in the "last mile" at mobile terminals, and is of great significance for promoting the development of the quantum communication industry. It is conducive to improving the utilization rate of QKD infrastructure and achieving cost-sharing and efficiency improvement.
[0185] An embodiment of the present disclosure provides a quantum key distribution method, which is applied to a gateway device and a terminal device. The gateway device includes a first distribution system, a first encryption and decryption module, and a first cryptographic module. The first encryption and decryption module sends a wireless key acquisition request to the first cryptographic module. The first cryptographic module sends a wireless key acquisition response message to the first encryption and decryption module. The wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key. The first encryption and decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key. The first distribution system sends a data transmission request to the terminal device. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains an original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. The terminal device includes a second distribution system and a second encryption and decryption module. The second distribution system receives the data transmission request. The data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key. The second distribution system sends a quantum key decryption request message to the second encryption and decryption module. The quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key. The second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. It can be seen that the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first password module, and then encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present disclosure can realize the wireless distribution of quantum keys based on the gateway device without the need for offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure.
[0186] Based on the above embodiments, the present disclosure provides a gateway device. FIG22 is a schematic diagram of the composition structure of the gateway device. As shown in FIG22 , the gateway device 10 includes: a first encryption and decryption module 11, a first password module 12, and a first distribution system 13;
[0187] The first encryption and decryption module 11 is used to send a wireless key acquisition request to the first password module;
[0188] The first cryptographic module 12 is configured to send a wireless key acquisition response message to the first encryption / decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key;
[0189] The first encryption and decryption module 11 is further configured to encrypt the quantum key based on the wireless key to obtain an encrypted quantum key;
[0190] The first distribution system 13 is used to send a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0191] In an embodiment of the present disclosure, further, Figure 23 is a second schematic diagram of the composition structure of the gateway device. As shown in Figure 23, the gateway device 10 proposed in the embodiment of the present disclosure may also include a first processor 14, a first memory 15 storing executable instructions of the first processor 14, and further, the gateway device 10 may also include a first communication interface 16, and a first bus 17 for connecting the first processor 14, the first memory 15 and the first communication interface 16.
[0192] In an embodiment of the present disclosure, the first processor 14 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understandable that for different devices, the electronic device used to implement the above-mentioned processor function may also be other, and the embodiment of the present disclosure is not specifically limited. The gateway device 10 may also include a first memory 15, which may be connected to the first processor 14, wherein the first memory 15 is used to store executable program code, the program code including computer operating instructions, and the first memory 15 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0193] In the embodiment of the present disclosure, the first bus 17 is used to connect the first communication interface 16 , the first processor 14 , and the first memory 15 , as well as to facilitate mutual communication between these devices.
[0194] In the embodiment of the present disclosure, the first memory 15 is used to store instructions and data.
[0195] Furthermore, in an embodiment of the present disclosure, the above-mentioned first processor 14 is used for the first encryption and decryption module to send a wireless key acquisition request to the first cryptographic module; the first cryptographic module sends a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key; the first distribution system sends a data transmission request to the terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0196] In practical applications, the first memory 15 may be a volatile memory, such as a random-access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the first processor 14.
[0197] The embodiment of the present disclosure provides a gateway device, which includes a first distribution system, a first encryption and decryption module, and a first cryptographic module; the first encryption and decryption module sends a wireless key acquisition request to the first cryptographic module; the first cryptographic module sends a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; the first encryption and decryption module encrypts the quantum key based on the wireless key to obtain the encrypted quantum key; the first distribution system sends a data transmission request to the terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. Therefore, it can be seen that the first encryption and decryption module on the gateway device side can obtain the wireless key and the serial number corresponding to the wireless key through the first cryptographic module, and then can encrypt the quantum key based on the wireless key, and send the encrypted quantum key and the serial number corresponding to the wireless key to the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. That is, the present disclosure can realize wireless distribution of quantum keys based on the gateway device without offline filling of quantum keys, thereby expanding the applicable scenarios and improving the utilization rate of quantum key distribution infrastructure.
[0198] An embodiment of the present disclosure provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the quantum key distribution method as described above.
[0199] Specifically, the program instructions corresponding to a quantum key distribution method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When the program instructions corresponding to a quantum key distribution method in the storage medium are read or executed by an electronic device, the following steps are included:
[0200] The first encryption and decryption module sends a wireless key acquisition request to the first password module;
[0201] The first cryptographic module sends a wireless key acquisition response message to the first encryption / decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key;
[0202] The first encryption / decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key;
[0203] The first distribution system sends a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0204] In the embodiment of the present disclosure, further, FIG24 is a schematic diagram of the composition structure of the terminal device. As shown in FIG24 , the terminal device 20 includes: a second encryption and decryption module 21, a second distribution system 22;
[0205] The second distribution system 22 is configured to receive a data transmission request, wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key;
[0206] The second distribution system 22 is further configured to send a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key;
[0207] The second encryption and decryption module 21 is configured to determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0208] In an embodiment of the present disclosure, further, Figure 25 is a second schematic diagram of the composition structure of the terminal device. As shown in Figure 25, the terminal device 20 proposed in the embodiment of the present disclosure may also include a second processor 23, and a second memory 24 storing executable instructions of the second processor 23. Further, the terminal device 20 may also include a second communication interface 25, and a second bus 26 for connecting the second processor 23, the second memory 24 and the second communication interface 25.
[0209] In an embodiment of the present disclosure, the second processor 23 may be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It is understandable that for different devices, the electronic device used to implement the above-mentioned processor function may also be other, and the embodiment of the present disclosure is not specifically limited. The terminal device 20 may also include a second memory 24, which may be connected to the second processor 23, wherein the second memory 24 is used to store executable program code, the program code including computer operating instructions, and the second memory 24 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0210] In the embodiment of the present disclosure, the second bus 26 is used to connect the second communication interface 25, the second processor 23, and the second memory 24, and to facilitate mutual communication between these devices.
[0211] In the embodiment of the present disclosure, the second memory 24 is used to store instructions and data.
[0212] Furthermore, in an embodiment of the present disclosure, the second processor 23 is configured to receive a data transmission request from the second distribution system; wherein the data transmission request includes the encrypted quantum key and a serial number corresponding to the wireless key;
[0213] The second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; and the second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0214] In actual applications, the above-mentioned second memory 24 can be a volatile memory (volatile memory), such as random-access memory (RAM); or a non-volatile memory (non-volatile memory), such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the second processor 23.
[0215] The disclosed embodiment provides a terminal device, which includes a second distribution system and a second encryption and decryption module. The second distribution system receives a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; the second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; and the second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key. Thus, the second distribution system on the terminal device side can send a quantum key decryption request message to the second encryption and decryption module, wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key, and then the second encryption and decryption module can determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key, that is, there is no need to perform offline filling of the quantum key, and the quantum key can be received wirelessly, which solves the deployment and transmission problem of the "last mile" of the quantum key at the terminal and expands the terminal service range of the quantum cryptography system.
[0216] An embodiment of the present disclosure provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the quantum key distribution method as described above.
[0217] Specifically, the program instructions corresponding to a quantum key distribution method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When the program instructions corresponding to a quantum key distribution method in the storage medium are read or executed by an electronic device, the following steps are included:
[0218] The second distribution system receives a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key;
[0219] The second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key;
[0220] The second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
[0221] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) containing computer-usable program code.
[0222] The present disclosure is described with reference to the implementation flow diagrams and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flow diagram and / or block diagram can be implemented by computer program instructions, as well as the combination of the processes and / or boxes in the flow diagram and / or block diagram. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flow diagram and / or one or more boxes in the block diagram.
[0223] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in implementing one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0224] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0225] The above description is merely a preferred embodiment of the present disclosure and is not intended to limit the scope of protection of the present disclosure.
Claims
1. A quantum key distribution method, the method is applied to a gateway device, the gateway device includes a first distribution system, a first encryption and decryption module, and a first password module, the method includes: The first encryption and decryption module sends a wireless key acquisition request to the first password module; The first password module sends a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; The first encryption / decryption module encrypts the quantum key based on the wireless key to obtain an encrypted quantum key; The first distribution system sends a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
2. The method according to claim 1, wherein: Before the first encryption / decryption module sends a wireless key acquisition request to the first password module, the method further includes: The first encryption and decryption module receives a quantum key encryption request sent by the first distribution system; wherein the quantum key encryption request carries a service type and the quantum key.
3. The method according to claim 2, wherein: After the first encryption / decryption module encrypts the quantum key based on the wireless key, the method includes: The first encryption and decryption module sends a quantum key encryption response message to the first distribution system; wherein the quantum key response message carries an encryption success flag or an encryption failure flag, the encrypted quantum key, and a serial number corresponding to the wireless key; The first encryption and decryption module triggers a destruction mechanism corresponding to the wireless key.
4. The method according to claim 1, wherein: The gateway device further includes a first module. After the first encryption / decryption module encrypts the quantum key based on the wireless key, the method includes: The first encryption and decryption module sends the data transmission request to the first module; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; The first module sends the data transmission request to the second module in the terminal device, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
5. The method according to claim 4, wherein: The method further comprises: The first module receives a data transmission response message sent by the second module; wherein the data transmission response message carries a quantum key reception success flag or a reception failure flag; The first module forwards the data transmission response message to the first distribution system through the first encryption and decryption module; The first encryption and decryption module triggers a destruction mechanism corresponding to the wireless key.
6. The method according to claim 3 or 5, wherein: After the first encryption / decryption module triggers a destruction mechanism corresponding to the wireless key, the method further includes: The first encryption / decryption module sends a key destruction request; wherein the key destruction request carries a serial number corresponding to the wireless key; The first cryptographic module destroys the wireless key corresponding to the serial number; or the first cryptographic module destroys the wireless key based on the validity period corresponding to the wireless key; The first password module sends a key destruction response message to the first encryption / decryption module, where the key destruction response message carries a destruction success flag or a destruction failure flag.
7. The method according to claim 1, wherein: The gateway device further includes a first key status query module and a first key usage interface, and the method further includes: The first distribution system sends a wireless key query request message to the first password module through the first key status query module; or, The first distribution system sends the wireless key query request message to the first cryptographic module through the first key usage interface; The first cryptographic module queries the currently stored wireless key status information, and forwards a wireless key query response message to the first distribution system through the first key status query module; wherein the wireless key query response message carries the wireless key status information.
8. The method according to claim 7, wherein: The gateway device further includes a first key generation trigger module, and the method further includes: The first key generation trigger module determines whether the current wireless key meets a first preset condition based on the wireless key status information, the key generation strategy, and the application requirement information; When the current wireless key does not meet the first preset condition, a wireless key generation mechanism is triggered.
9. The method according to claim 8, wherein: The gateway device further includes a first management and control module, a first transmission module, a first generation module, and a first channel detection module. When the current wireless key does not meet the first preset condition, after triggering the wireless key generation mechanism, the method further includes: The first management and control module receives a request to generate a wireless key, and sends a request to obtain channel state information to the first channel detection module; The first channel detection module acquires first channel state information and first sequence number information corresponding to the first channel state information; The first channel detection module sends a channel detection request to the second channel detection module in the terminal device; wherein the channel detection request includes the first channel state information and the first sequence number information; Receive a channel detection response message sent by the second channel detection module; wherein the channel detection response message carries second channel state information and second sequence number information corresponding to the second channel state information.
10. The method according to claim 9, wherein: After receiving the channel detection response message sent by the second channel detection module, the method further includes: The first channel detection module obtains the second channel state information and the second sequence number information, and sends an acknowledgement message ACK or a negative acknowledgement message NAK to the second channel detection module; When the first sequence number information and the second sequence number information are the same, the first channel detection module sends the first channel state information and the first sequence number information to the first management and control module, so that the first management and control module stores the first channel state and the first sequence number information.
11. The method according to claim 10, wherein: After the first channel detection module sends the first channel state information and the first sequence number information to the first management and control module, the method further includes: The first management and control module sends a reconciliation information request to the first generation module; wherein the reconciliation information request includes the first channel state information and the first sequence number information; The first generating module performs quantization processing on the first channel state information to obtain a first wireless key, and determines first reconciliation information corresponding to the first wireless key.
12. The method according to claim 11, wherein: The method further comprises: After the first management and control module receives the reconciliation response information sent by the first generation module, the first transmission module sends a key consistency reconciliation request to the second transmission module in the terminal device; wherein the key consistency reconciliation request includes the first reconciliation information; The first transmission module receives the key consistency reconciliation response information sent by the second transmission module; wherein the key consistency reconciliation response information includes a first reconciliation result; After receiving the key consistency reconciliation response information forwarded by the first transmission module, the first management and control module sends a wireless key acquisition request to the first generation module; wherein the wireless key acquisition request carries the first reconciliation result.
13. The method according to claim 12, wherein: After sending the wireless key acquisition request to the first generating module, the method further includes: The first generating module determines whether the blending is successful based on the first blending result; When the first reconciliation result is successful, the first generating module performs privacy amplification processing on the first wireless key to obtain a second wireless key; The first generating module sends wireless key acquisition response information to the first management and control module; wherein the wireless key acquisition response information includes a key generation result.
14. The method according to claim 13, wherein: After obtaining the second wireless key, the method further includes: The first generating module sends a storage key request message to the first password module; wherein the storage key request message carries the second wireless key; The first cryptographic module encrypts the second wireless key based on a first algorithm; The first password module stores the encrypted second wireless key, the serial number information corresponding to the encrypted second wireless key, and the valid period corresponding to the encrypted second wireless key, and sends storage wireless key response information to the first generation module, and the wireless key response information carries a storage success mark or a storage failure mark.
15. A quantum key distribution method, the method being applied to a terminal device, the terminal device comprising a second distribution system and a second encryption and decryption module, the method comprising: The second distribution system receives a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; The second distribution system sends a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; The second encryption / decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
16. The method according to claim 15, wherein: The terminal device further includes a second cryptographic module, and the second cryptographic module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key, including: The second encryption and decryption module sends a wireless key acquisition request message to the second password module; wherein the wireless key acquisition request message carries a serial number corresponding to the wireless key; The second cryptographic module determines the corresponding wireless key based on the serial number corresponding to the wireless key, and sends a wireless key acquisition response message to the second encryption / decryption module, wherein the wireless key acquisition response message carries the wireless key; The second encryption / decryption module decrypts the encrypted quantum key based on the wireless key to obtain the original quantum key.
17. The method according to claim 16, wherein: After the second encryption / decryption module decrypts the encrypted quantum key based on the wireless key, the method further includes: The second cryptographic module destroys the wireless key corresponding to the serial number; or, The second cryptographic module performs destruction processing based on a valid period corresponding to the wireless key.
18. The method according to claim 17, wherein: The terminal device further includes a second module, and the method further includes: The second module receives the data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; The second module sends the data transmission request to the second encryption and decryption module, so that the second encryption and decryption module determines the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
19. The method according to claim 15, wherein: The terminal device further includes a second management and control module, a second transmission module, a second generation module and a second detection module, and the method further includes: The second channel detection module receives a channel detection request sent by the first channel detection module, wherein the channel detection request includes the first channel state information and the first sequence number information, and sends a channel detection response message to the first channel detection module; wherein the channel detection response message carries the second channel state information and the second sequence number information corresponding to the second channel state information; When the second channel detection module receives the confirmation message ACK sent by the first channel detection module, the second channel state information and the second sequence number information corresponding to the second channel state information are sent to the second management and control module.
20. The method according to claim 19, wherein: After sending the second channel state information and the second sequence number information corresponding to the second channel state information to the second management and control module, the method further includes: The second management and control module sends a request for obtaining a wireless key to the second generation module; wherein the request for obtaining a wireless key includes the second channel state information and the second sequence number information; The second generating module performs quantization processing on the second channel state information to obtain a third wireless key.
21. The method according to claim 20, wherein: After the second generating module performs quantization processing on the second channel state information to obtain a third wireless key, the method further includes: The second transmission module receives the key consistency reconciliation request sent by the first management and control module; wherein the key consistency reconciliation request includes first reconciliation information; The second generation module performs a reconciliation process on the first reconciliation information based on the third wireless key, and determines a first reconciliation result; When the first reconciliation result is successful, the second generating module performs privacy amplification processing on the third wireless key to obtain a fourth wireless key; The second generation module forwards key consistency reconciliation response information to the first transmission module through the second transmission module; wherein the key consistency reconciliation response information includes the first reconciliation result.
22. The method according to claim 21, wherein: After obtaining the fourth wireless key, the method further includes: The second generating module sends a storage key request message to the second password module; wherein the storage key request message carries the fourth wireless key; The second cryptographic module encrypts the fourth wireless key based on a second algorithm; The second password module stores the encrypted fourth wireless key, the serial number information corresponding to the encrypted fourth wireless key, and the valid period corresponding to the encrypted fourth wireless key, and sends storage wireless key response information to the second generation module, and the wireless key response information carries a storage success flag or a storage failure flag.
23. A gateway device, comprising: A first encryption and decryption module, a first password module, and a first distribution system; The first encryption and decryption module is used to send a wireless key acquisition request to the first password module; The first password module is used to send a wireless key acquisition response message to the first encryption and decryption module; wherein the wireless key acquisition response message includes a wireless key and a serial number corresponding to the wireless key; The first encryption and decryption module is further used to encrypt the quantum key based on the wireless key to obtain an encrypted quantum key; The first distribution system is used to send a data transmission request to a terminal device; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key, so that the terminal device obtains the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
24. A gateway device, comprising: a first processor and a first memory; wherein, The first memory is used to store a computer program that can be run on the processor; The first processor is configured to execute the method according to any one of claims 1 to 14 when running the computer program.
25. A terminal device, comprising: A second encryption and decryption module and a second distribution system; The second distribution system is used to receive a data transmission request; wherein the data transmission request includes the encrypted quantum key and the serial number corresponding to the wireless key; The second distribution system is further used to send a quantum key decryption request message to the second encryption and decryption module; wherein the quantum key decryption request message carries the encrypted quantum key and the serial number corresponding to the wireless key; The second encryption and decryption module is used to determine the original quantum key based on the encrypted quantum key and the serial number corresponding to the wireless key.
26. A terminal device, comprising: A second processor and a second memory; wherein, The second memory is used to store a computer program that can be run on the processor; The second processor is configured to execute the method according to any one of claims 15 to 22 when running the computer program.
27. A computer-readable storage medium having computer program code stored thereon, wherein when the computer program code is executed by a computer, the method according to any one of claims 1 to 14 or 15 to 22 is performed.
28. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1-14 or 15-22.
Citation Information
Patent Citations
Quantum key distribution method and quantum key distribution system
CN110808834A
Internet of Things wireless terminal quantum key distribution and negotiation method
CN113038468A
Conversation encryption method, key management platform, equipment and medium
CN116709227A
OTN encryption communication method and system based on quantum key distribution
CN116743380A
A removable ventilation window
KR1020240003182A
Cited By
First domain controller and encryption method and system oriented to vehicle-mounted Ethernet physical layer
CN121173582A
Key charging method for quantum local area network
CN121283618A
Quantum key management method, system, device and medium
CN122496205A