Quantum key distribution method and quantum cryptography system implemented by bidirectional key pool

By introducing a two-way key pool in the quantum key distribution system, the key is dynamically allocated according to the user's master-called relationship, the problem of long key distribution time and inappropriate application in the prior art is solved, and the immediate issuance and efficient allocation of keys are realized.

WO2025123881A1PCT designated stage expired Publication Date: 2025-06-19CHINA TELECOM QUANTUM TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/122316
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-09-29
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing quantum key distribution technology is difficult to distribute keys trustworthyly in user networks, especially in large-scale user scenarios, which leads to the long time of key distribution, which cannot meet user needs immediately, and fails to effectively distinguish the user's master called relationship, resulting in the inability to adapt to large-scale applications.

Method used

The two-way key pool is used to realize the quantum key distribution method. Through the interaction between the service terminal and the quantum key management platform, the working key corresponding to the communication direction is obtained from the two-way fixed key pool according to the master-called relationship, realizing the instant issuance and adaptive allocation of the key.

Benefits of technology

Through the use of two-way key pools, the problem of key direction is solved, realizing the instant issuance of key requests during user communication, alleviating the pressure of key distribution in quantum key links, enhancing the user experience, and adapting to the needs of large-scale user scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122316_19062025_PF_FP_ABST
    Figure CN2024122316_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a quantum key distribution method and quantum cryptography system implemented by a bidirectional key pool. The method comprises exchanging service information with a service terminal at a peer end, and determining a caller-receiver relationship; requesting to obtain addresses of quantum key management platforms respectively corresponding to a caller and a receiver from a service management platform; requesting a working key from the quantum key management platform corresponding to a service terminal at a local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from a bidirectional fixed key pool on the basis of the caller-receiver relationship; and receiving the working key issued by the corresponding quantum key management platform, and using the working key to encrypt the exchanged service information to communicate with the service terminal at the peer end. The present application implements key streams distinguishing user communication directions, and implements instant issuing of key requests during user communication.
Need to check novelty before this filing date? Find Prior Art

Description

Quantum key distribution method and cryptographic system based on bidirectional key pool

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 15, 2023, with application number 2023117396310, and invention name “Quantum key distribution method and quantum cryptography system implemented by bidirectional key pool”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of quantum secure communication technology, and in particular to a quantum key distribution method and a quantum cryptography system using a bidirectional key pool. Background Art

[0003] Quantum technology is most widely and maturely applied in quantum communications. Quantum key distribution (QKD) allows for the secure, real-time distribution of quantum keys. This quantum key encryption technology uses a one-time pad (OTP) method to ensure the security of information transmission. Currently, the mainstream application of quantum keys involves storing the distributed quantum keys within terminals, enabling symmetric encrypted communication between terminals. Therefore, reliably storing the quantum keys generated by QKD within terminals within user networks is crucial.

[0004] To date, in the field of quantum key distribution, due to the high cost of direct key distribution schemes based on quantum key distribution devices and the difficulty of practical implementation, various key distribution methods have been derived from this basis, such as multi-level sharded key pools. For example, the patent application document with publication number CN114024666A proposes a key distribution method, namely, to achieve key distribution in a multi-node situation by vertically slicing the key pool and issuing it. Vertical slicing means that after the key is distributed between the first QKD, a portion of the key pool slice is distributed to the next level (this level is no longer quantum key distribution, but traditional communication methods). The key pool of each level of nodes is a subset of the nodes in the previous level. The QKDs are paired with each other, and the key pool contains all one-to-one corresponding keys. This solution aims to solve the problem of how nodes without key distribution devices can obtain keys, but it does not address the security protection of the key slicing distribution process, nor does it consider the direction of key distribution by the quantum key distribution device. The patent application document with publication number CN112887086A describes a key synchronization method for multiple communication nodes, in which the key pool is managed and synchronized through a unified key synchronization management server; this scheme uses a unified key synchronization management server to solve the key synchronization problem of multiple communication nodes, but does not involve the use of a cryptographic system. At the same time, the key pool involved in this scheme is a single key pool between nodes, and the direction problem of quantum key distribution is not considered.

[0005] Patent application publication number CN114024670A describes a quantum trusted relay key synchronization method using a bidirectional key pool. This method utilizes a bidirectional key pool in quantum relay nodes, each used for reading and writing, ensuring read / write balance between nodes. However, this method emphasizes the horizontal key relay process and does not address the application of the bidirectional key pool in the overall cryptographic system. Furthermore, the quantum key relay process in this scheme addresses the short distance between QKD key distribution. For example, QKD can only distribute key over distances of 80-120 km. If locations AC are 200 km apart, a relay node B is required to connect them in series, i.e., ABC. Furthermore, the bidirectional key pool is used for key relay. For example, for nodes A, B, and C, B's bidirectional key pool is used for key exchange. This means that the bidirectional key pool interacts with the bidirectional key pool of another node, not with the user's service application.

[0006] In quantum cryptography systems, since quantum key distribution devices are divided into a receiving end and an initiating end, key synchronization communication requests must be initiated by the initiating end. Therefore, in practical applications, key directionality is inevitably a problem. Due to this directionality, key data from different directions exists between two quantum key distribution nodes, but existing methods cannot determine the key data in the specific direction of the symmetric key required by both parties. When users need to obtain keys immediately, due to the low coding rate and slow generation speed of current QKD, and the queueing required for multiple users to interact with the same node, such as in BA / CA, existing quantum key distribution solutions take too long to distribute keys, making it impossible to immediately distribute quantum keys to users through quantum key distribution. Furthermore, when the number of users is very large, one-to-one distribution can cause severe congestion. Furthermore, since users are divided into callers and callees, the methods for obtaining symmetric keys differ significantly during communication. Existing technologies do not take this into account. Key distribution does not distinguish between user communication directions, making it unsuitable for large-scale applications.

[0007] Summary of the Invention

[0008] The technical problem to be solved by this application is how to distinguish between the calling and called users and to achieve the instant issuance of key requests when users communicate.

[0009] This application solves the above technical problems through the following technical means:

[0010] In a first aspect, the present application proposes a method for implementing quantum key distribution using a bidirectional key pool. The method is applied to a service terminal, where the service terminal acts as a calling party or a called party, and includes:

[0011] Exchange business information with the other end's business terminal to determine the calling and called party relationships;

[0012] Request the service management platform to obtain the address of the quantum key management platform corresponding to the calling party and the called party;

[0013] Requesting a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from the bidirectional fixed key pool based on the caller-caller relationship;

[0014] Receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt interactive business information to communicate with the business terminal on the other end.

[0015] Furthermore, requesting a working key from the quantum key management platform corresponding to the service terminal of the local end includes:

[0016] Obtaining the preset key stored in the service terminal of the local end, and sending the preset key sequence and the address of the quantum key management platform corresponding to the service terminal of the opposite end to the quantum key management platform corresponding to the local end, so that the quantum key management platform corresponding to the local end obtains the working key corresponding to the communication direction of the local end from the corresponding fixed key pool according to the caller-caller relationship, and obtains the corresponding symmetric preset key from the preset key pool according to the preset key sequence;

[0017] Receiving a working key ciphertext issued by a corresponding quantum key management platform, where the working key ciphertext is encrypted using a symmetric preset key;

[0018] The working key ciphertext is decrypted using the preset key of the local end to obtain the working key.

[0019] Furthermore, the service terminal includes a quantum security chip, in which a preset key pre-filled by the quantum key management platform to which it belongs is stored.

[0020] Furthermore, the bidirectional fixed key pool stores a key stream corresponding to the user communication direction that is pre-generated by the quantum key distribution node.

[0021] Furthermore, the business management platform is pre-set with a correspondence between the business terminal, the quantum security chip, and the quantum key management platform address.

[0022] In a second aspect, this application proposes a method for implementing quantum key distribution using a bidirectional key pool, which is applied to a quantum key management platform and includes:

[0023] Receiving a working key request message sent by the current service terminal, wherein the working key request message includes a calling and called relationship of the current service terminal and an address of a quantum key management platform to which the current service terminal belongs;

[0024] Based on the calling and called relationship of the current service terminal, the working key corresponding to the communication direction of the current service terminal is obtained from the bidirectional fixed key pool;

[0025] A working key is issued to the current service terminal, so that the current service terminal uses the working key to encrypt interactive service information and communicate with the service terminal at the opposite end.

[0026] Furthermore, the bidirectional fixed key pool includes a first fixed key pool and a second fixed key pool, wherein the first fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the calling party to a quantum key distribution node corresponding to the called party, and the second fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the called party to a quantum key distribution node corresponding to the calling party;

[0027] Accordingly, the process of obtaining the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal includes:

[0028] When the current service terminal is the calling party, obtaining a key stream corresponding to the current service communication direction from the first fixed key pool as a working key;

[0029] When the current service terminal serves as the called party, a key stream corresponding to the current service communication direction is obtained from the second fixed key pool as a working key.

[0030] Furthermore, the received working key request information also includes a preset key sequence. After obtaining the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes:

[0031] Obtaining a symmetric preset key from a preset key pool based on the preset key sequence;

[0032] The working key is encrypted using a symmetric preset key to obtain a working key ciphertext and send it to the current service terminal.

[0033] Furthermore, before acquiring the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes:

[0034] Establishing a link with a corresponding quantum key distribution node, obtaining a key stream distributed by the corresponding quantum key distribution node to a receiving end when the corresponding quantum key distribution node acts as a transmitter, and receiving a key stream distributed by the corresponding quantum key distribution node when the corresponding quantum key distribution node acts as a receiving end;

[0035] The received directional key streams are respectively stored in fixed key pools corresponding to the communication directions.

[0036] Furthermore, before issuing the working key to the current service terminal, the method further includes:

[0037] The key data stream is injected into the quantum security chip corresponding to the current business terminal as a preset key.

[0038] In a third aspect, the present application proposes a service terminal, which serves as a calling party or a called party and includes:

[0039] The information interaction module is used to exchange service information with the service terminal of the other end and determine the calling and called party relationships;

[0040] An address query module is used to request the service management platform to obtain the addresses of the quantum key management platforms corresponding to the calling and called parties;

[0041] A working key request module is used to request a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from the bidirectional fixed key pool based on the caller-caller relationship;

[0042] The encryption communication module is used to receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt the interactive business information to communicate with the business terminal on the other end.

[0043] In a fourth aspect, this application proposes a quantum key management platform, which includes

[0044] A key request receiving module is used to receive working key request information sent by the current service terminal, wherein the working key request information includes the calling and called relationship of the current service terminal and the address of the quantum key management platform to which the current service terminal belongs;

[0045] A working key acquisition module is used to obtain a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal;

[0046] The working key issuing module is used to issue a working key to the current service terminal, so that the current service terminal uses the working key to encrypt interactive service information and communicate with the opposite service terminal.

[0047] In a fifth aspect, the present application proposes a quantum cryptography system implemented by a bidirectional key pool, the system comprising: a service terminal A and a service terminal B, the service terminal A and the service terminal B being connected via a service management platform, the service terminal A being connected to the quantum key management platform A to obtain a working key corresponding to the communication direction of the service terminal A from the quantum key management platform A, and the service terminal B being connected to the quantum key management platform B to obtain a working key corresponding to the communication direction of the service terminal B from the quantum key management platform B; a quantum key distribution node A being connected to the quantum key management platform A to pre-inject a directional key stream into the quantum key management platform A as a working key, and a quantum key distribution node B being connected to the quantum key management platform B to pre-inject a directional key stream into the quantum key management platform B as a working key; wherein the service terminal A and the service terminal B are used to execute a method for quantum key distribution implemented by a bidirectional key pool as proposed in the first aspect above, and the quantum key management platform A and the quantum key management platform B are used to execute a method for quantum key distribution implemented by a bidirectional key pool as proposed in the second aspect above.

[0048] In the sixth aspect, the present application proposes a computing and processing device, which includes: a memory in which computer-readable code is stored; and one or more processors. When the computer-readable code is executed by one or more processors, the computing and processing device executes the two-way key pool to implement the quantum key distribution method proposed in the first and second aspects above.

[0049] In the seventh aspect, the present application proposes a computer program, including a computer-readable code. When the computer-readable code runs on a computing processing device, it causes the computing processing device to execute the two-way key pool to implement the quantum key distribution method proposed in the first and second aspects above.

[0050] In an eighth aspect, the present application proposes a computer-readable medium in which the computer program proposed in the seventh aspect is stored.

[0051] The advantages of this application are:

[0052] (1) This application sets up a bidirectional fixed key pool in the quantum key management platform to store key data from different directions between two quantum key distribution nodes. When the user is in an application scenario where the key needs to be obtained immediately, the key data of the specific direction of the symmetric key required by both parties of the business can be quickly obtained from the fixed key pool according to the caller-caller relationship of the business terminal. By changing the actual use of the existing quantum key in the business, the directionality problem is solved at the key level through the bidirectional key pool. After the business using the quantum key determines the caller-caller, the required symmetric quantum key can be directly determined, which solves the problem of how to select the quantum key as the working key when the two parties of the business communication are in different places.

[0053] (2) This application allows users to use keys distributed in advance in a fixed key pool to conduct conversations, which can average and rationalize the originally irregular or dense key requirements, greatly alleviating the key distribution pressure of the quantum key link and solving the congestion problem of the quantum key distribution link.

[0054] (3) This application accelerates the speed of business obtaining working keys by setting up a fixed key pool with direction, realizes the instant issuance of key requests during user communication, and enhances the user experience.

[0055] (4) This application improves and optimizes the original quantum key distribution technology solution. Most devices can use the original devices to achieve resource reuse.

[0056] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0058] FIG1 is a flow chart of a method for implementing quantum key distribution using a bidirectional key pool according to an embodiment of the present application;

[0059] FIG2 is a flow chart of a method for implementing quantum key distribution using a bidirectional key pool, as proposed in another embodiment of the present application;

[0060] FIG3 is a schematic structural diagram of a service terminal proposed in another embodiment of the present application;

[0061] FIG4 is a schematic structural diagram of a quantum key management platform proposed in another embodiment of the present application;

[0062] FIG5 is a schematic diagram of the structure of a quantum cryptography system implemented by a bidirectional key pool proposed in another embodiment of the present application;

[0063] FIG6 is a diagram showing the controlled relationship between various components in a quantum cryptography system implemented by a two-way key pool according to another embodiment of the present application;

[0064] FIG7 is a diagram showing the data flow relationship between components in a quantum cryptography system implemented by a bidirectional key pool according to another embodiment of the present application;

[0065] FIG8 is a specific example diagram of a quantum cryptography system implemented by a bidirectional key pool proposed in another embodiment of the present application;

[0066] FIG9 is a service timing diagram of a quantum cryptography system implemented by a two-way key pool according to another embodiment of the present application;

[0067] FIG10 is a schematic structural diagram of a computing and processing device for implementing a quantum key distribution method using a bidirectional key pool, as proposed in another embodiment of the present application;

[0068] FIG11 is a schematic diagram of the structure of a computer program for implementing a quantum key distribution method using a bidirectional key pool according to another embodiment of the present application. Specific embodiments

[0069] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0070] As shown in FIG1 , an embodiment of the present application discloses a method for implementing quantum key distribution using a bidirectional key pool. The method is applied to a service terminal, where the service terminal acts as a calling party or a called party, and includes the following steps:

[0071] S101, exchanging service information with the service terminal of the other end to determine the calling and called party relationship;

[0072] Specifically, the service terminal A initiates a service request to the service terminal B, interacts with the service terminal B to obtain the other party's information, and determines the calling and called party roles of the service terminal A and the service terminal B.

[0073] S102: Requesting the service management platform to obtain the addresses of the quantum key management platforms corresponding to the calling and called parties;

[0074] It should be noted that business terminal A and business terminal B respectively request the business management platform to query the address of the quantum key management platform to which the other party belongs, that is, business terminal A requests the business management platform to query the address QMS-B of the quantum key management platform to which business terminal B belongs, and business terminal B requests the business management platform to query the address QMS-A of the quantum key management platform to which business terminal A belongs.

[0075] S103: Requesting a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from a bidirectional fixed key pool based on the caller-caller relationship;

[0076] It should be noted that service terminal A requests a working key from quantum key management platform A, and service terminal B requests a working key from quantum key management platform B. After receiving the working key request sent by the corresponding service terminal, the corresponding quantum key management platform obtains the working key for the corresponding communication direction from the fixed key pool based on the caller-caller relationship of the corresponding service terminal.

[0077] S104: Receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt interactive business information to communicate with the business terminal of the other end.

[0078] This embodiment sets up a bidirectional fixed key pool in the quantum key management platform to store key data from different directions between two quantum key distribution nodes. When a user needs to obtain a key immediately, the key data of the specific direction of the symmetric key required by both parties of the service can be quickly obtained from the fixed key pool based on the caller-caller relationship of the service terminal. By changing the actual use of the existing quantum key in the service, the directionality problem is solved at the key level through the bidirectional key pool. After the service using the quantum key determines the caller-caller, the required symmetric quantum key can be directly determined. This solves the problem of how to select the quantum key as the working key when the two parties of the service communication are in different locations. In addition, only the key pool between the AC terminals needs to be considered, and there is no need to add a B series connection.

[0079] Furthermore, this embodiment enhances the existing single key pool by adding directionality to the key pool. This allows keys from the key pool to be assigned to specific directions based on the service, ensuring that key data for the specific direction of the symmetric key required by both parties can be determined. In particular, in call applications where there is a clear distinction between caller and callee, if key directionality is not distinguished, both the service system and the key distribution system will require an additional key negotiation step. For example, in the default scenario, QKD is the transmitter for user A and the receiver for user B. If user A calls user B, A-QKD can directly negotiate a key with B-QKD. However, if user B calls user A, since B-QKD is the receiver and cannot send, the service application system and the password management system must notify A-QKD to negotiate a key with B-QKD before communication can proceed. This complicates the application's service logic and is not compatible with existing applications. Furthermore, it increases communication preparation time, impacting the user experience. This embodiment uses a bidirectional key pool. A call from user A to user B is the same as a call from user B to user A, regardless of who is the receiver in the underlying quantum key distribution network.

[0080] Since real-time generation of QKD takes time, this embodiment generates keys in advance during idle time through a key pool, so that users can use them at any time, and it will not cause congestion even when the number of users is extremely large.

[0081] In one embodiment, the step S103 of requesting a working key from the quantum key management platform corresponding to the service terminal of the local end includes the following steps:

[0082] S131. Obtaining a preset key stored in the service terminal of the local end, and sending the preset key sequence and the address of the quantum key management platform corresponding to the service terminal of the opposite end to the quantum key management platform corresponding to the local end, so that the quantum key management platform corresponding to the local end obtains the working key corresponding to the communication direction of the local end from the corresponding fixed key pool according to the caller-caller relationship, and obtains the corresponding symmetric preset key from the preset key pool according to the preset key sequence;

[0083] It should be noted that the preset key is a key stream pre-filled by the quantum key management platform corresponding to the local business terminal, which is symmetrical with the preset key in the preset key pool. The quantum key management platform corresponding to the business terminal obtains the corresponding symmetric preset key from the preset key pool according to the preset key sequence, and encrypts the working key with the symmetric preset key and sends it to the business terminal to provide security protection for the working key distribution process.

[0084] S132. Receive a working key ciphertext issued by a corresponding quantum key management platform, where the working key ciphertext is encrypted using a symmetric preset key;

[0085] S133. Decrypt the working key ciphertext using the preset key of the local end to obtain the working key.

[0086] In one embodiment, the service terminal includes a quantum security chip, and the quantum security chip stores a preset key pre-filled by the quantum key management platform to which it belongs.

[0087] Specifically, the quantum key management platform encrypts the working key using a pre-set key and sends it to the service terminal. The service terminal then decrypts the working key using the pre-set key of the corresponding quantum chip. The working key is provided by the quantum key management platform and is used to implement specific services. The quantum key management platform directly injects the quantum key into the quantum security chip. The quantum key management platform node where the pre-set key originated is the quantum key management platform to which the quantum security chip belongs. In this embodiment, the quantum security chip is combined with the service terminal to provide service applications. The quantum security chip obtains the key from the quantum key management platform for the corresponding service terminal to obtain.

[0088] Furthermore, the quantum key management platform obtains the directional working key from the fixed key pool and sends it to the quantum security chip for acquisition by the corresponding business terminal.

[0089] In one embodiment, the bidirectional fixed key pool stores a key stream corresponding to the user communication direction that is pre-generated by the quantum key distribution node.

[0090] Specifically, the key stream corresponding to the user communication direction includes the key stream distributed by the quantum key distribution node corresponding to the caller to the quantum key distribution node corresponding to the called party and the key stream distributed by the quantum key distribution node corresponding to the called party to the quantum key distribution node corresponding to the caller.

[0091] This embodiment allows users to use pre-distributed keys from a fixed key pool for conversations. This can even out and rationalize the previously irregular or dense key demand, significantly alleviating the key distribution pressure on the quantum key link and resolving congestion issues. Furthermore, by establishing a directional fixed key pool, the speed at which services acquire working keys is accelerated, enabling the immediate issuance of key requests during user communications and enhancing the user experience.

[0092] In one embodiment, the business management platform is pre-set with the correspondence between the business terminal, the quantum security chip, and the quantum key management platform address, and the business management platform provides business and management platform address query services to the business terminal.

[0093] As shown in FIG2 , another embodiment of the present application discloses a method for implementing quantum key distribution using a bidirectional key pool. The method is applied to a quantum key management platform and includes the following steps:

[0094] S201. Receive working key request information sent by the current service terminal, where the working key request information includes the calling and called relationship of the current service terminal and the address of the quantum key management platform to which the current service terminal belongs;

[0095] S202, based on the calling and called relationship of the current service terminal, obtaining a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool;

[0096] S203: issuing a working key to the current service terminal, so that the current service terminal uses the working key to encrypt interactive service information and communicate with the opposite service terminal.

[0097] This embodiment sets up a bidirectional fixed key pool in the quantum key management platform to store key data from different directions between two quantum key distribution nodes. When a user is in an application scenario where they need to obtain a key immediately, they can quickly obtain key data in the specific direction of the symmetric key required by both parties of the service from the fixed key pool based on the caller and caller relationship of the service terminal. The bidirectional key pool solves the directionality problem at the key level. After the service using quantum keys determines the caller and caller, it can directly determine the required symmetric quantum key, solving the problem of how to select a quantum key as a working key when the two parties of the service communication are in different locations.

[0098] In one embodiment, the bidirectional fixed key pool includes a first fixed key pool and a second fixed key pool, wherein the first fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to a calling party to a quantum key distribution node corresponding to a called party, and the second fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the called party to a quantum key distribution node corresponding to the calling party;

[0099] Accordingly, the step S202: obtaining a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal, includes the following steps:

[0100] When the current service terminal is the calling party, obtaining a key stream corresponding to the current service communication direction from the first fixed key pool as a working key;

[0101] When the current service terminal serves as the called party, a key stream corresponding to the current service communication direction is obtained from the second fixed key pool as a working key.

[0102] In one embodiment, the received working key request information further includes a preset key sequence. After step S202: obtaining a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes the following steps:

[0103] Obtaining a symmetric preset key from a preset key pool based on the preset key sequence;

[0104] The working key is encrypted using a symmetric preset key to obtain a working key ciphertext and send it to the current service terminal.

[0105] In this embodiment, the working key is encrypted by a symmetric preset key and then sent to the service terminal, thereby providing security protection for the working key distribution process.

[0106] In one embodiment, before step S202: obtaining a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes the following steps:

[0107] Establishing a link with a corresponding quantum key distribution node, obtaining a key stream distributed by the corresponding quantum key distribution node to a receiving end when the corresponding quantum key distribution node acts as a transmitter, and receiving a key stream distributed by the corresponding quantum key distribution node when the corresponding quantum key distribution node acts as a receiving end;

[0108] The received directional key streams are respectively stored in fixed key pools corresponding to the communication directions.

[0109] This embodiment allows users to use keys distributed in advance in a fixed key pool to conduct conversations, which can average and rationalize the originally irregular or dense key demands, greatly alleviating the key distribution pressure of the quantum key link and solving the congestion problem of the quantum key distribution link.

[0110] In one embodiment, in step S203, before issuing the working key to the current service terminal, the method further includes:

[0111] The key data stream is injected into the quantum security chip corresponding to the current business terminal as a preset key.

[0112] In this embodiment, a preset key is pre-filled into the quantum security chip to decrypt the received working key ciphertext and obtain the working key.

[0113] As shown in FIG3 , another embodiment of the present application discloses a service terminal, which serves as a calling party or a called party and includes:

[0114] An information interaction module 11 is used to exchange service information with the service terminal of the other end and determine the calling and called party relationship;

[0115] An address query module 12 is used to request the service management platform to obtain the address of the quantum key management platform corresponding to the calling party and the called party;

[0116] A working key request module 13 is configured to request a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from the bidirectional fixed key pool based on the caller-caller relationship;

[0117] The encryption communication module 14 is used to receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt the interactive business information to communicate with the business terminal of the other end.

[0118] In one embodiment, the working key request module 13 specifically includes:

[0119] a preset key acquisition unit, configured to acquire a preset key stored in a service terminal on the local end, and send a preset key sequence and the address of a quantum key management platform corresponding to the service terminal on the opposite end to the quantum key management platform corresponding to the local end, so that the quantum key management platform corresponding to the local end acquires a working key corresponding to the communication direction of the local end from a corresponding fixed key pool based on a caller-caller relationship, and acquires a corresponding symmetric preset key from a preset key pool based on the preset key sequence;

[0120] A working key ciphertext receiving unit is used to receive the working key ciphertext issued by the corresponding quantum key management platform, wherein the working key ciphertext is obtained by encrypting the symmetric preset key;

[0121] The key decryption unit is used to decrypt the working key ciphertext using the preset key of the local end to obtain the working key.

[0122] In one embodiment, the service terminal includes a quantum security chip, and the quantum security chip stores a preset key pre-filled by the quantum key management platform to which it belongs.

[0123] In one embodiment, the bidirectional fixed key pool stores a key stream corresponding to the user communication direction that is pre-generated by the quantum key distribution node.

[0124] In one embodiment, the business management platform is pre-set with a correspondence between the business terminal, the quantum security chip, and the quantum key management platform address.

[0125] It should be noted that other embodiments or implementation methods of the service terminal described in this application can refer to the above-mentioned method embodiments, which will not be repeated here.

[0126] As shown in FIG4 , another embodiment of the present application further discloses a quantum key management platform, which includes:

[0127] The key request receiving module 21 is used to receive the working key request information sent by the current service terminal, wherein the working key request information includes the calling and called relationship of the current service terminal and the address of the quantum key management platform to which the current service terminal belongs;

[0128] The working key acquisition module 22 is used to obtain the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal;

[0129] The working key issuing module 23 is configured to issue a working key to the current service terminal, so that the current service terminal uses the working key to encrypt interactive service information and communicate with the opposite service terminal.

[0130] In one embodiment, the bidirectional fixed key pool includes a first fixed key pool and a second fixed key pool, wherein the first fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to a calling party to a quantum key distribution node corresponding to a called party, and the second fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the called party to a quantum key distribution node corresponding to the calling party;

[0131] Accordingly, the working key acquisition module 22 includes:

[0132] A first key acquisition unit is configured to acquire, when the current service terminal is a calling party, a key stream corresponding to the current service communication direction from the first fixed key pool as a working key;

[0133] The second key obtaining unit is configured to obtain, when the current service terminal serves as the called party, a key stream corresponding to the current service communication direction from the second fixed key pool as a working key.

[0134] In one embodiment, the received working key request information further includes a preset key sequence, and the management platform further includes:

[0135] A preset key acquisition module, configured to acquire a symmetric preset key from a preset key pool based on the preset key sequence;

[0136] The key encryption module is used to encrypt the working key using a symmetric preset key, obtain the working key ciphertext and send it to the current service terminal.

[0137] In one embodiment, the management platform further includes:

[0138] The working key storage module is used to establish a link with the corresponding quantum key distribution node, obtain the key stream distributed by the corresponding quantum key distribution node to the receiving end when it acts as a transmitter, and receive the key stream distributed by the corresponding quantum key distribution node when it acts as a receiving end; and store the received directional key streams in the fixed key pool corresponding to the communication direction.

[0139] In one embodiment, the management platform further includes:

[0140] The charging module is used to charge the key data stream as the preset key into the quantum security chip corresponding to the current business terminal.

[0141] It should be noted that other embodiments or implementation methods of the quantum key management platform described in this application can refer to the above-mentioned method embodiments, which will not be repeated here.

[0142] As shown in Figure 5, another embodiment of the present application further discloses a quantum cryptography system implemented by a bidirectional key pool, wherein the system includes: a service terminal A and a service terminal B, wherein the service terminal A and the service terminal B are connected via a service management platform, the service terminal A is connected to the quantum key management platform A to obtain a working key corresponding to the communication direction of the service terminal A from the quantum key management platform A, and the service terminal B is connected to the quantum key management platform B to obtain a working key corresponding to the communication direction of the service terminal B from the quantum key management platform B; the quantum key distribution node A is connected to the quantum key management platform A to pre-inject a directional key stream into the quantum key management platform A as a working key, and the quantum key distribution node B is connected to the quantum key management platform B to pre-inject a directional key stream into the quantum key management platform B as a working key; wherein the service terminal A and the service terminal B are used to execute the quantum key distribution method implemented by the bidirectional key pool as described in the first embodiment above, and the quantum key management platform A and the quantum key management platform B are used to execute the quantum key distribution method implemented by the bidirectional key pool as described in the second embodiment above.

[0143] Specifically, the quantum key distribution network is composed of quantum key distribution nodes, each of which contains a quantum key distribution device, wherein:

[0144] Quantum Key Distribution Network (QKDN): A network formed by two or more quantum key distribution nodes connected by a quantum key distribution device link.

[0145] Quantum key distribution node: A node consisting of one or more quantum key distribution devices.

[0146] Quantum Key Distribution Device (QKD): A device that implements quantum key distribution. The communicating parties can use this device to transmit quantum signals and thus distribute quantum keys. The device exists in pairs between nodes and is divided into receivers and senders.

[0147] Key Manager (KM): A unit in a quantum key distribution node that implements the key management function of the key management layer.

[0148] Quantum Key Management Platform (QMS): manages the quantum keys in each quantum key distribution node and is responsible for distributing the quantum keys distributed by the quantum key distribution device to users.

[0149] Fixed direction key pool: belongs to the quantum key management platform, used to store the quantum keys distributed by the current quantum key distribution node and other nodes, and is directional.

[0150] Business terminal: a terminal product that can use quantum key services, with no limitation on terminal form.

[0151] Business management platform: manages business status and the address of the quantum key management platform to which the quantum security chip belongs.

[0152] In this embodiment, the quantum key distribution network consists of different quantum key distribution nodes, each located in a different location. Quantum key distribution is performed between nodes via quantum key links established by quantum key distribution devices. The quantum key distribution devices are managed by a key manager within the quantum key distribution nodes.

[0153] The quantum key management platform is linked to the quantum key distribution node to obtain the quantum key.

[0154] In one embodiment, both the service terminal A and the service terminal B include a quantum security chip, which contains a preset key and a working key, and can provide quantum keys to the service terminals. Among them: Preset key (UK): The quantum key directly injected into the quantum security chip by the quantum key management platform. The quantum key management platform node from which the preset key comes is the quantum key management platform to which the quantum security chip belongs. Working key (WK): The quantum key used for business communication encrypted and issued between the quantum key management platform and the quantum security chip using the preset key

[0155] In this embodiment, the quantum security chip is combined with the business terminal to provide business applications, and the quantum security chip obtains keys from the quantum key management platform.

[0156] In one embodiment, the solid arrows in FIG6 show the controlled relationship of each component in the quantum cryptography system: KM controls QKD; QMS controls KM; QMS controls the key pool; the service terminal controls the security chip;

[0157] The dotted arrows in FIG6 show that the service relationship provided by the components is: the QMS provides charging services to the quantum security chip; the service management platform provides services to the service terminal and the management platform address query service.

[0158] In one embodiment, the arrows in Figure 7 show that the data flow relationship of each component is: QKD transmits key data flow; the quantum key distribution node transmits key data flow to QMS; QMS transmits key data flow to the fixed key pool; QMS transmits key data flow to the quantum security chip; QMS transmits key data flow to the service terminal; the service management platform and the service terminal transmit service data flow to each other.

[0159] In one embodiment, as shown in FIG8 and FIG9 , taking a certain instant messaging service as an example, the implementation process of the method in the actual service is described as follows:

[0160] (1) The basic conditions obtained through the preparation stage are:

[0161] The quantum security chip already stores the key injected from the QMS platform to which it belongs: Quantum Security Chip-A belongs to QMS-A, and its preset key is Ukey-A; Quantum Security Chip-B belongs to QMS-B, and its preset key is Ukey-B;

[0162] Quantum key distribution nodes A and B have already performed quantum key distribution. The key stream from A to B is called KEYA-B, and the key stream from B to A is called KEYB-A.

[0163] QMS has placed KEYA-B and KEYB-A in the corresponding fixed key pools AB and BA;

[0164] The business management platform stores the corresponding information of the quantum security chip and the QMS platform to which it belongs, as well as the address of the corresponding QMS platform.

[0165] (2) Key distribution based on a two-way key pool:

[0166] Business terminal A and business terminal B exchange business information, determine the roles of the calling and called parties, and both request the business management platform to query the address of the other party's QMS;

[0167] Business terminal A and business terminal B receive the address of the other party's QMS returned by the business management platform;

[0168] Service terminal A and service terminal B obtain the preset key from their respective quantum security chips, and send the preset key sequence, the caller-caller relationship, and the address of the other party's QMS to form a key request message to their respective quantum key management platforms;

[0169] Quantum key management platform A and quantum key management platform B respectively obtain the working key of the corresponding communication direction from the fixed key pool according to the caller-caller relationship of the corresponding service terminal, and obtain the corresponding symmetric preset key from the preset key pool according to the preset key sequence, and use the symmetric preset key to encrypt the working key and send it to the corresponding service terminal;

[0170] Business terminal A and business terminal B receive the working key ciphertext issued by the corresponding quantum key management platform, and use the preset key to decrypt the working key ciphertext to obtain the working key;

[0171] Service terminal A and service terminal B use working keys to encrypt service information for communication.

[0172] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0173] The various component embodiments of the present application can be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing equipment according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0174] For example, FIG10 illustrates a computing device that can implement the methods according to the present application. The computing device typically includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020. Memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, a hard disk, or ROM. Memory 1020 has storage space 1030 for program code 1031 for executing any of the method steps described above. For example, the storage space 1030 for program code can include individual program codes 1031 for implementing various steps in the method described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units, as described with reference to FIG11. The storage unit can have storage segments, storage space, and the like arranged similarly to memory 1020 in the computing device of FIG10. The program code can, for example, be compressed in a suitable form. Typically, the storage unit includes computer-readable codes 1031 ′, ie, codes that can be read by a processor such as 1010 , which, when executed by a computing device, cause the computing device to perform the steps of the method described above.

[0175] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present application. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0176] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0177] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.

[0178] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A method for implementing quantum key distribution using a bidirectional key pool, wherein: The method is applied to a service terminal, where the service terminal serves as a calling party or a called party, and includes: Exchange business information with the business terminal of the other end to determine the relationship between the calling party and the called party; Request the service management platform to obtain the address of the quantum key management platform corresponding to the calling party and the called party; Requesting a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from the bidirectional fixed key pool based on the master-caller relationship; Receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt interactive business information to communicate with the business terminal on the other end.

2. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 1, wherein: The requesting a working key from the quantum key management platform corresponding to the service terminal of the local end includes: Obtaining the preset key stored in the service terminal of the local end, sending the preset key sequence and the address of the quantum key management platform corresponding to the service terminal of the opposite end to the quantum key management platform corresponding to the local end, so that the quantum key management platform corresponding to the local end obtains the working key corresponding to the communication direction of the local end from the corresponding fixed key pool according to the caller-caller relationship and obtains the corresponding symmetric preset key from the preset key pool according to the preset key sequence; Receiving a working key ciphertext issued by a corresponding quantum key management platform, wherein the working key ciphertext is obtained by encrypting with a symmetric preset key; The working key ciphertext is decrypted using the preset key of the local end to obtain the working key.

3. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 1, wherein: The service terminal includes a quantum security chip, in which a preset key pre-filled by a quantum key management platform to which it belongs is stored.

4. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 1, wherein: The bidirectional fixed key pool stores a key stream corresponding to the user communication direction pre-generated by the quantum key distribution node.

5. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 1, wherein: The business management platform is pre-set with a correspondence between the business terminal, the quantum security chip, and the quantum key management platform address.

6. A method for implementing quantum key distribution using a bidirectional key pool, wherein: The method is applied to a quantum key management platform, comprising: Receiving work key request information sent by the current service terminal, wherein the work key request information includes a caller-called relationship of the current service terminal and an address of a quantum key management platform to which the current service terminal belongs; Based on the calling and called relationship of the current service terminal, a working key corresponding to the communication direction of the current service terminal is obtained from a bidirectional fixed key pool; A working key is issued to the current service terminal, so that the current service terminal uses the working key to encrypt interactive service information to communicate with the service terminal at the opposite end.

7. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 6, wherein: The bidirectional fixed key pool includes a first fixed key pool and a second fixed key pool, wherein the first fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the calling party to a quantum key distribution node corresponding to the called party, and the second fixed key pool stores a key stream distributed from a quantum key distribution node corresponding to the called party to a quantum key distribution node corresponding to the calling party; Correspondingly, the step of obtaining a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal includes: When the current service terminal is the calling party, obtaining a key stream corresponding to the current service communication direction from the first fixed key pool as a working key; When the current service terminal serves as the called party, a key stream corresponding to the current service communication direction is obtained from the second fixed key pool as a working key.

8. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 6, wherein: The received working key request information also includes a preset key sequence. After obtaining the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes: Obtaining a symmetric preset key from a preset key pool based on the preset key sequence; The working key is encrypted using a symmetric preset key to obtain the working key ciphertext and send it to the current service terminal.

9. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 6, wherein: Before acquiring the working key corresponding to the communication direction of the current service terminal from the bidirectional fixed key pool based on the calling and called relationship of the current service terminal, the method further includes: Establishing a link with a corresponding quantum key distribution node, obtaining a key stream distributed by the corresponding quantum key distribution node to a receiving end when the corresponding quantum key distribution node acts as a sending end, and receiving a key stream distributed by the sending end when the corresponding quantum key distribution node acts as a receiving end; The received directional key stream is stored in the fixed key corresponding to the communication direction. In the pool.

10. The method for implementing quantum key distribution using a bidirectional key pool as claimed in claim 6, wherein: Before sending the working key to the current service terminal, the method further includes: The key data stream is injected into the quantum security chip corresponding to the current business terminal as the preset key.

11. A service terminal, wherein: The service terminal, as a calling party or a called party, includes: An information interaction module is used to exchange service information with the service terminal of the other end and determine the calling and called party relationship; An address query module is used to request the service management platform to obtain the address of the quantum key management platform corresponding to the calling party and the called party; A working key request module is used to request a working key from the quantum key management platform corresponding to the service terminal of the local end, so that the quantum key management platform obtains the working key corresponding to the communication direction of the local end from the bidirectional fixed key pool based on the master-caller relationship; The encryption communication module is used to receive the working key issued by the corresponding quantum key management platform, and use the working key to encrypt the interactive business information to communicate with the business terminal of the other end.

12. A quantum key management platform, wherein: The management platform includes: A key request receiving module, used to receive working key request information sent by the current service terminal, wherein the working key request information includes the calling and calling relationship of the current service terminal and the address of the quantum key management platform to which the current service terminal belongs; A working key acquisition module is used to acquire a working key corresponding to the communication direction of the current service terminal from a bidirectional fixed key pool based on the calling and called relationship of the current service terminal; The working key sending module is used to send the working key to the current service terminal, so that the current service terminal uses the working key to encrypt the interactive service information and communicate with the service terminal of the opposite end.

13. A quantum cryptographic system implemented by a two-way key pool, wherein: The system comprises: a service terminal A and a service terminal B, wherein the service terminal A and the service terminal B are connected via a service management platform, the service terminal A is connected to the quantum key management platform A to obtain a working key corresponding to the communication direction of the service terminal A from the quantum key management platform A, and the service terminal B is connected to the quantum key management platform B to obtain a working key corresponding to the communication direction of the service terminal B from the quantum key management platform B; a quantum key distribution node A is connected to the quantum key management platform A to pre-inject a key stream with directionality into the quantum key management platform A as a working key, and a quantum key distribution node B is connected to the quantum key management platform B to pre-inject a key stream with directionality into the quantum key management platform B as a working key; wherein the service terminal A and the service terminal B are used to execute the method for implementing quantum key distribution by a bidirectional key pool as described in any one of claims 1 to 5, and the quantum key management platform A and the quantum key management platform B are used to execute the method for implementing quantum key distribution by a bidirectional key pool as described in any one of claims 6 to 10.

14. A computing device, wherein: include: a memory having computer readable code stored therein; One or more processors, when the computer readable code is executed by the one or more processors, the computing processing device executes the quantum key distribution method implemented by the bidirectional key pool according to any one of claims 1 to 10.

15. A computer program, comprising a computer readable code, which, when executed on a computing processing device, causes the computing processing device to execute the method for implementing quantum key distribution using a bidirectional key pool according to any one of claims 1 to 10.

16. A computer readable medium having stored therein the computer program according to claim 15.

Citation Information

Patent Citations

  • Quantum trusted relay key synchronization method and system of bidirectional key pool

    CN114024670A

  • VoLTE voice encryption communication method, terminal and system

    CN114553422A

  • Database encryption method, terminal and system suitable for cloud environment

    CN115913621A

  • Method for realizing quantum key distribution by bidirectional key pool and quantum cryptography system

    CN117955641A

  • Key distribution network based on trusted relay

    CN217825001U