Entity identity authentication method for quantum access control system
By using quantum keys to generate encrypted identity credentials for entity identification through a quantum access control system, the security deficiencies of traditional access control systems are solved, achieving highly secure and scalable entity identity authentication.
Patent Information
- Application Number
- PCT/CN2024/120829
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-21
- Filing Date
- 2024-09-24
- Publication Date
- 2025-12-26
AI Technical Summary
Traditional access control systems lack sufficient security and cannot effectively prevent identity forgery and unauthorized access.
The quantum access control system generates random numbers and auxiliary information through a quantum cryptography service platform, generates encrypted identity credentials using quantum keys, and authenticates the entity's identity through a cryptographic CPU card and card reader. Combined with quantum-secure U-shields for encrypted data transmission, it achieves highly secure entity identity authentication.
It increases the difficulty and security of entity identity authentication, possesses high security, scalability and practicality, complies with cryptographic standards, and prevents unauthorized access.
Smart Images

Figure CN2024120829_26122025_PF_FP_ABST
Abstract
Description
A method for entity identification in a quantum access control system
[0001] This application claims priority to Chinese Patent No. 202410812379.X, filed on June 21, 2024, entitled "A Method for Entity Identity Authentication in a Quantum Access Control System", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of security application product technology, and in particular to a quantum access control system entity identification method, a quantum access control system, an electronic device, and a computer-readable storage medium. Background Technology
[0003] With the continuous advancement of science and technology, access control systems have become an important component of security management. Currently, traditional access control systems identify users using cards and card readers; once authentication is successful, the system can control the opening of the door. However, while traditional access control systems improve security to some extent, they still fall short of full security requirements.
[0004] Summary of the Invention
[0005] The purpose of this application is to provide a quantum access control system entity identification method to address the problem that traditional access control systems still lack sufficient security. The specific technical solution is as follows:
[0006] In a first aspect, this application provides a method for entity identification in a quantum access control system. The quantum access control system includes a cryptographic CPU card, a cryptographic card reader, an access control system, an access controller, and a quantum cryptography service system. The cryptographic CPU card, the cryptographic card reader, and the access control system are each pre-loaded with a corresponding quantum key through the quantum cryptography service system. Each of the cryptographic CPU card, the cryptographic card reader, and the access control system has a corresponding electronic tag. The access control system binds the electronic tag of the cryptographic CPU card to the electronic tag of the cryptographic card reader to obtain auxiliary information, and stores the auxiliary information in the access control system's backend. The method includes:
[0007] The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system;
[0008] The access control system distributes the encrypted identity credentials to the corresponding password reader according to the binding relationship;
[0009] The password reader decrypts the encrypted identity credential to obtain a decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the password CPU card and the random number is generated by the quantum cryptography service system;
[0010] When the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the corresponding random number to the password CPU card to be authenticated based on the authentication electronic tag.
[0011] The password CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader;
[0012] The password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0013] Optionally, the quantum access control system also includes a quantum-secure U-shield, which is inserted into the backend of the access control system and is used to protect the information exchanged between the access control system and the quantum cryptography service platform.
[0014] Optionally, the cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system are pre-loaded with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service system; the cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag, respectively; the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0015] The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform;
[0016] The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information;
[0017] The quantum cryptography service platform determines the first quantum key corresponding to the cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
[0018] Optionally, the password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door, including:
[0019] The password reader compares the authentication credential with the identity credential.
[0020] If the authentication credentials match, the card reader sends a successful comparison result to the access control controller, so that the access control controller can issue an unlocking command to control the door to open based on the successful comparison result;
[0021] If the authentication credentials do not match, the PIN reader will issue an error message.
[0022] Optionally, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0023] When the password reader, the access control system, and the quantum cryptography service system are online, if the access control system obtains new auxiliary information by binding the electronic tag of the password CPU card to the electronic tag of the password reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system.
[0024] The access control system uses the encrypted identity credentials to overwrite the encrypted identity credentials previously issued by the quantum cryptography service platform.
[0025] Optionally, the method further includes:
[0026] When the password reader, the access control system, and the quantum cryptography service system are offline, when the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the random number corresponding to the previous time to the password CPU card to be authenticated based on the authentication electronic tag.
[0027] The password CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader;
[0028] The password reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0029] Optionally, before the quantum cryptography service platform generates a random number, generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, the method further includes:
[0030] The access control system determines the user permissions of the password CPU card to be bound;
[0031] When the user privileges of the password CPU card are ordinary unlocking users, the access control system binds the password CPU card with the agreed auxiliary information of the password card reader;
[0032] When the user of the password CPU card has super administrator privileges, the access control system binds the password CPU card with the auxiliary information of all the password card readers.
[0033] Secondly, this application proposes a quantum access control system, including the aforementioned method for entity identification in a quantum access control system.
[0034] Thirdly, this application proposes an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0035] Memory, used to store computer programs;
[0036] A processor, when executing a program stored in memory, implements the steps of the method described in any one of claims 1-7.
[0037] Fourthly, this application proposes a computer program including computer-readable code, which, when executed on an electronic device, causes the electronic device to perform the entity authentication method for a quantum access control system proposed in the first aspect above.
[0038] Fifthly, this application proposes a computer-readable medium storing the computer program as described in the fourth aspect above.
[0039] Compared with related technologies, the embodiments of this application have at least the following advantages:
[0040] This application provides a method for entity authentication in a quantum access control system. The quantum access control system can include a cryptographic CPU card, a cryptographic card reader, an access control system, an access controller, and a quantum cryptography service system. The cryptographic CPU card, cryptographic card reader, and access control system are each pre-loaded with corresponding quantum keys through the quantum cryptography service system. Furthermore, each of the cryptographic CPU card, cryptographic card reader, and access control system has a corresponding electronic tag. The access control system binds the electronic tag of the cryptographic CPU card to the electronic tag of the cryptographic card reader to obtain auxiliary information, which is then stored in the access control system's backend. Specifically, firstly, the quantum cryptography service platform generates an encrypted identity credential based on the auxiliary information, electronic tags, and quantum keys, and sends the encrypted identity credential to the access control system. The access control system then distributes the encrypted identity credential to the corresponding cryptographic card reader according to the binding relationship. The encrypted identity credential can then be decrypted to obtain a decrypted identity credential and a random number. The identity credential is generated based on the electronic tag corresponding to the cryptographic CPU card and the random number. Subsequently, when the cryptographic CPU card to be authenticated is placed against the PIN reader, the PIN reader reads the authentication electronic tag of the cryptographic CPU card to be authenticated and sends the corresponding random number to the cryptographic CPU card to be authenticated based on the authentication electronic tag. The cryptographic CPU card to be authenticated can then use the random number and its local authentication electronic tag to generate an authentication identity credential and send it to the PIN reader. By comparing the authentication identity credential with the original identity credential, the PIN reader can determine whether the cryptographic CPU card has the authority to open the door controlled by the access control system, and thus determine whether to instruct the access control controller under the access control system to issue an unlocking command to open the door. This achieves identity authentication between entities such as the cryptographic CPU card and the PIN reader. This embodiment of the application enhances the difficulty of identity authentication between entities by utilizing quantum key distribution, possessing high security, scalability, and practicality, and conforming to cryptographic standards. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0042] Figure 1 is a flowchart of the steps of a quantum access control system entity identification method provided in an embodiment of this application;
[0043] Figure 2 is a functional schematic diagram of a quantum access control system module provided in an embodiment of this application;
[0044] Figure 3 is a timing diagram of an entity identification method for a quantum access control system provided in an embodiment of this application;
[0045] Figure 4 is a flowchart of key filling for a cryptographic security module in a quantum access control system provided in an embodiment of this application;
[0046] Figure 5 is a flowchart of the card-reader binding relationship of a quantum access control system provided in an embodiment of this application;
[0047] Figure 6 is a flowchart of a quantum access control system for issuing encrypted identity credentials according to an embodiment of this application;
[0048] Figure 7 is a flowchart of the authentication process of a password CPU card and password reader provided in an embodiment of this application.
[0049] Figure 8 is a schematic diagram of the structure of an electronic device according to an embodiment of this application;
[0050] Figure 9 is a schematic diagram of the structure of a storage unit for program code proposed in an embodiment of this application. Detailed Implementation
[0051] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0052] Referring to Figure 1, which is a flowchart of a quantum access control system entity identification method provided in an embodiment of this application, the method may specifically include the following steps:
[0053] Step 101: The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system.
[0054] In this embodiment, the quantum access control system may include modules such as a cryptographic CPU (Central Processing Unit) card, a cryptographic card reader, an access control system, an access controller, and a quantum cryptography service platform (quantum cryptography service system, which can be simply referred to as a cryptographic system). It should be noted that the cryptographic CPU card and cryptographic card reader modules in this embodiment refer to smart cards and card readers that conform to national cryptographic standards, i.e., smart cards and card readers that comply with cryptographic standards. For example, the cryptographic standard may include using cryptographic technology for physical access authentication to ensure the authenticity of the identity of personnel entering important areas, etc.
[0055] Referring to Figure 2, which is a functional diagram of different modules of a quantum access control system provided in an embodiment of this application, the working content of each module of the quantum access control system (quantum secure access control system) is as follows: access control system, used to store, manage, and authorize user information; password CPU card, the entity being authenticated; password card reader, the terminal device for authenticating other entities; quantum cryptography service platform, including quantum cryptography service system, quantum random number generator, quantum key exchange, and quantum key filling machine, used to provide key services.
[0056] Specifically, the cryptographic CPU card stores a quantum security key (quantum key). This quantum key is a symmetric key, generated by a quantum random number generator in the quantum cryptography service platform and stored within the quantum exchange. A quantum key filling machine fills the cryptographic security module of the cryptographic CPU card with the symmetric key. The quantum key filled into each cryptographic CPU card and the quantum key built into the quantum exchange cryptographic machine form a symmetric key pair. Each cryptographic CPU card has its own unique identifier (also known as an electronic tag), and each quantum key has its own serial number. By providing the electronic tag of the cryptographic CPU card and the serial number of the quantum key, the corresponding symmetric key can be found within the quantum exchange cryptographic machine.
[0057] The PIN card reader, as a module used for entity identity authentication in this application embodiment, primarily includes the following functions: firstly, it internally stores encrypted identity credentials (ciphertext identity credentials) pre-generated and issued daily by the access control system; secondly, when a user's card (PIN CPU card) is placed on the PIN card reader, the PIN card reader interacts with the user's PIN CPU card, wherein the encrypted identity credential comparison is performed on the PIN card reader. The access control system, as a back-end management system for business operations, can insert a quantum security U-shield. Through the quantum security U-shield, the unlocking relationship between a new PIN CPU card and different PIN card readers can be bound, and the quantum cryptography system can be informed which PIN card readers use quantum keys to encrypt which specific information.
[0058] In this embodiment, the cryptographic CPU card, the cryptographic card reader, and the access control system are each pre-loaded with corresponding quantum keys through the quantum cryptography service system. Furthermore, each of these components has a corresponding electronic tag. The access control system binds the electronic tag of the cryptographic CPU card to the electronic tag of the cryptographic card reader to obtain auxiliary information, which is then stored in the access control system's backend. Specifically, assuming the electronic tag of the cryptographic CPU card is A and the electronic tag of the cryptographic card reader is B, the auxiliary information could be the unlocking relationship binding A and B. Further, the auxiliary information is also used to inform the quantum cryptography service platform which cryptographic card readers' quantum keys encrypt which cryptographic CPU card's corresponding card identity credentials. For example, assuming the auxiliary information is the unlocking relationship binding A and B, the quantum cryptography service platform can determine, based on the auxiliary information, that A's identity credentials are encrypted using the quantum key corresponding to B.
[0059] In practical applications, upon initial use, the access control system needs to establish a binding relationship between the PIN CPU card and the PIN reader. This binding relationship is used to locate the PIN CPU card bound to the PIN reader, specifically the unique identifier (electronic tag) of the PIN CPU card and the unique identifier (electronic tag) of the PIN reader paired with it. This information is stored in the access control system's backend. When the access control system needs to request encrypted identity credentials from the quantum cryptography service platform, this binding relationship can be communicated to the platform. The quantum key recharged into the PIN reader encrypts the identity credentials of the paired PIN CPU card; this information is referred to as auxiliary information. The auxiliary information and the PIN CPU card's electronic tag can be encrypted using a quantum-secure USB key and uploaded to the quantum cryptography service platform, thus ensuring data security.
[0060] The PIN card reader can send auxiliary information to the quantum cryptography service platform. The platform can then generate encrypted identity credentials based on the auxiliary information, the PIN CPU card, the PIN card reader, and the corresponding electronic tags and quantum keys of the access control system. These encrypted identity credentials are then distributed to the access control system for entity authentication. Specifically, the quantum cryptography service platform generates identity credentials based on the card information (electronic tag), random number, and quantum key corresponding to the PIN CPU card submitted by the access control system. It then determines the PIN card reader bound to the PIN CPU card based on the auxiliary information and encrypts the identity credentials using the quantum key corresponding to the PIN card reader.
[0061] Step 102: The access control system distributes the encrypted identity credentials to the corresponding password reader according to the binding relationship.
[0062] After the access control system receives the encrypted identity credentials issued by the quantum cryptography service platform, it can distribute the encrypted identity credentials to each corresponding card reader based on the auxiliary information.
[0063] Step 103: The password reader decrypts the encrypted identity credential to obtain the decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the password CPU card and the random number is generated by the quantum cryptography service system.
[0064] In this embodiment of the application, the password reader can use a locally pre-charged quantum key to decrypt the encrypted identity credential to obtain the identity credential, wherein the identity credential includes an electronic tag corresponding to the password CPU card, a random number, and a quantum key corresponding to the password CPU card.
[0065] Step 104: When the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the corresponding random number to the password CPU card to be authenticated based on the authentication electronic tag.
[0066] Step 105: The password CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader.
[0067] Step 106: The password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0068] When entity authentication is required, the PIN CPU card to be authenticated is placed against the PIN reader, and the card sends its unique identifier, i.e., an electronic tag, to the reader. After recognizing the electronic tag, the reader sends a corresponding salt (random number) to the PIN CPU card. The PIN CPU card uses its pre-charged quantum key to encrypt the electronic tag and the salt to obtain the authentication credential, which is then sent to the reader. The reader locally compares the authentication credential with the identity credential to complete entity authentication, and the electronic tag authentication is successful. If the successful comparison result of the authentication credential and the identity credential is communicated to the access control controller, the access control controller issues an unlocking command to open the door. This embodiment of the application enhances the difficulty of entity authentication by utilizing quantum keys and random numbers, possessing high security, scalability, and practicality, and conforming to cryptographic standards.
[0069] In one embodiment of this application, the cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system are pre-charged with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service system; the cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag, respectively; step 101, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0070] The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform;
[0071] The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information;
[0072] The quantum cryptography service platform determines the first quantum key corresponding to the cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
[0073] In this embodiment, the quantum cryptography service platform decrypts the encrypted auxiliary information and the electronic tag of the cryptographic CPU card. It obtains the identity credential using a random number generated by an encrypted quantum random number generator and the electronic tag of the cryptographic CPU card. Based on the access control system's information in the auxiliary information, the quantum key of the cipher reader is used to encrypt the corresponding identity credential of the cryptographic CPU card. The cipher reader, powered by its own quantum key, encrypts the identity credential and a salt, obtaining an encrypted identity credential, which is then sent to the access control system. Subsequently, the access control system issues the encrypted identity credential to the corresponding cipher reader based on the auxiliary information. The cipher reader then decrypts the encrypted identity credential using its own corresponding quantum key to obtain the identity credential.
[0074] Referring to Figure 3, it is a flowchart of a quantum access control system entity identity authentication method provided in the embodiment of this application. The authentication process of the access control system personnel identity is roughly divided into three main processes: key filling, authorization, and card-reader (password CPU card-password reader) identity authentication.
[0075] Referring to Figure 4, which is a flowchart illustrating the key filling process of a cryptographic security module in a quantum access control system according to an embodiment of this application, the cryptographic CPU card, cryptographic card reader, and quantum security U-shield need to complete key filling at the quantum key filling machine. Each of the cryptographic CPU card, cryptographic card reader, and quantum security U-shield only needs to be filled with a fixed quantum key, for example, the filled quantum keys are the first quantum key, the second quantum key, and the third quantum key, which can be represented by Ka, Kb, and Kd, respectively. Furthermore, in this embodiment, to illustrate the unlocking relationship between the cryptographic CPU card and the cryptographic card reader, the electronic tags corresponding to the cryptographic CPU card, cryptographic card reader, and quantum security U-shield, namely the first electronic tag, the second electronic tag, and the third electronic tag, are represented by UID, MID, and UCID, respectively.
[0076] The authorization process can be divided into two steps: card-reader relationship binding and issuance of encrypted identity credentials. The first step, card-reader relationship binding, establishes an unlocking relationship between the password CPU card and the password reader. The access control system is equipped with a quantum-secure U-shield and compatible quantum middleware (middleware SDK). The U-shield uses its quantum key Kd to encrypt the UID and auxiliary information θc, and then sends the encrypted UID and other information to the cryptographic system.
[0077] The second step involves issuing identity credentials. The cryptographic system locates the quantum key Kd of the quantum-secure U-shield based on its electronic tag, and uses Kd to decrypt the UID and auxiliary information ciphertext of all cryptographic CPU cards. It then finds the corresponding cryptographic CPU card's quantum key Ka and uses the salt for encryption, thereby generating identity credentials for all cryptographic CPU cards. Based on the auxiliary information θc sent by the access control system, it informs the quantum cryptographic service system of the quantum key Kb of the corresponding password reader to encrypt the corresponding identity credentials. The system then finds the corresponding password reader, encrypts the salt and identity credentials together to generate ciphertext identity credentials, and sends them to the access control system. The access control system then issues them to the corresponding password reader based on the bound unlocking relationship.
[0078] Referring to Figure 5, a flowchart illustrating the card-reader binding relationship of a quantum access control system provided in this embodiment is shown. After the password CPU card completes key charging, the access control system needs to manually enter the unlocking relationship between the password CPU card and the password reader (for example, the unlocking relationship between password CPU card A and password reader B can be UIDA-MIDB). If the user is a super administrator, the user can set the user permissions for the password CPU card in the access control system. The super administrator user has the permission to open all doors, while ordinary unlocking users only have the permission to open one or a few doors.
[0079] Referring to Figure 6, it is a flowchart of a quantum access control system for issuing encrypted identity credentials provided in an embodiment of this application. The password CPU card completes the card-reader unlocking relationship binding. The access control system stores the unlocking relationship between the password CPU card and the password reader. The access control system uses the quantum key Kd of the quantum security U-shield to encrypt the auxiliary information θc at a fixed time every day to apply for the encrypted identity credentials corresponding to the password CPU card.
[0080] The cryptographic system uses the symmetric key Kd to decrypt and obtain auxiliary information θc and the electronic tag UID. The auxiliary information θc informs the quantum cryptography service system which cryptographic CPU cards' credentials need to be encrypted using the quantum key of the cipher reader. The credentials are calculated using a daily updated salt to represent the credentials of all cryptographic CPU cards. The cipher credentials and salt are then encrypted using the corresponding cipher reader's quantum key and sent to the access control system. After obtaining the encrypted credentials for all cryptographic CPU cards, the access control system issues encrypted credentials to the corresponding cipher reader based on the unlocking relationship. Each cipher reader obtains the credentials for authentication.
[0081] After completing the charging and authorization, the execution process of this application embodiment will be described in detail below with reference to Figure 7. Specifically, referring to Figure 7, there is a flowchart of a quantum access control system unlocking process provided in this application embodiment: Password CPU card A is attached to the password card reader, the password card reader reads the card, password CPU card A sends the electronic tag UIDA to the card reader, the password card reader sends the salt (random number Rd) to password CPU card A, password CPU card A uses the quantum key Ka and the salt to encrypt and obtain the authentication credential, and sends the authentication credential back to the password card reader, the password card reader obtains the authentication credential, checks whether there is a corresponding credential locally, if there is, it can control the access control controller to issue an unlocking command to open the door.
[0082] This application embodiment utilizes the electronic tags corresponding to the cryptographic CPU card, cryptographic card reader, and quantum security U-shield, as well as the quantum cryptography corresponding to the cryptographic CPU card, cryptographic card reader, and quantum security U-shield, to generate identity credentials through multiple encryptions for transmission and authentication. This provides extremely high security, effectively protecting user rights and ensuring the safety of users' lives and property.
[0083] In one embodiment of this application, the method may further include:
[0084] When the password reader, the access control system, and the quantum cryptography service system are offline, when the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the random number corresponding to the previous time to the password CPU card to be authenticated based on the authentication electronic tag.
[0085] The password CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader;
[0086] The password reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0087] In this embodiment, when the PIN card reader, access control system, and quantum cryptography service system are offline, and the quantum cryptography service system cannot issue new identity credentials, when the PIN CPU card to be authenticated is placed on the PIN card reader, the PIN card reader reads the authentication electronic tag of the PIN CPU card to be authenticated, and sends the corresponding random number from the previous time to the PIN CPU card to be authenticated based on the authentication electronic tag. In this way, the PIN CPU card can use the random number generated by the quantum cryptography service system last time and the local authentication electronic tag to generate an authentication identity credential, and send it to the PIN card reader. The PIN card reader can then use the corresponding identity credential from the previous time to verify the authentication identity credential. Thus, door opening can be completed even in offline state, ensuring user experience.
[0088] In one embodiment of this application, step 106, where the password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door, includes:
[0089] The PIN card reader compares the authentication credential with the identity credential. If the authentication credential and the identity credential match, the PIN card reader sends a successful comparison result to the access control controller, so that the access control controller issues an unlocking command to control the door to open based on the successful comparison result. If the authentication credential and the identity credential do not match, the PIN card reader issues an error message.
[0090] In this embodiment, after the PIN card reader obtains the authentication credentials of the PIN CPU card to be authenticated, it compares them with the local credentials. If the authentication credentials match, the authentication is successful, and the PIN card reader can send the successful comparison result to the access control controller so that the access control controller can issue an unlocking command to control the door to open. Conversely, if the authentication credentials do not match, the authentication fails, and the PIN card reader issues an error message. The error message can be displayed by playing a voice message such as "Authentication failed".
[0091] In one embodiment of this application, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0092] When the PIN reader, the access control system, and the quantum cryptography service system are online, if the access control system obtains new auxiliary information by binding the electronic tag of the PIN CPU card to the electronic tag of the PIN reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the PIN reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system; the access control system uses the encrypted identity credential to overwrite the encrypted identity credential previously issued by the quantum cryptography service platform.
[0093] In this embodiment, when online, the cryptographic system generates a random number upon reaching a preset time (e.g., media access), and generates an encrypted identity credential based on the random number, auxiliary information, electronic tag, and quantum key. This encrypted identity credential is then sent to the access control system, which in turn sends it to the corresponding PIN reader based on the bound unlocking relationship. Thus, the PIN reader can use the identity credential issued daily by the cryptographic system to verify the authentication credentials. Changing the identity credential daily quickly reduces the risk of unauthorized access. If the cryptographic system issues a new identity credential, the previous one is overwritten. Furthermore, when the electronic tag of the PIN CPU card bound to the access control system and the electronic tag of the PIN reader receive new auxiliary information, the cryptographic system can also be triggered to send an encrypted identity credential to the access control system.
[0094] Specifically, the authorization mode of the quantum access control system in this application embodiment is online authorization, supporting offline unlocking. There are two scenarios for online authorization. The first is when a new password CPU card needs to be bound to the access control system for unlocking. In this scenario, the access control system manually binds the password CPU card to the unlocking relationship, determines the unique identifier (electronic tag) and auxiliary information of the password CPU card based on the bound unlocking relationship, encrypts the auxiliary information and electronic tag using a quantum key Kd, and uploads it to the quantum cryptography service system. The quantum cryptography service system calculates the encrypted identity credential of the password CPU card and securely sends it to the access control system. The access control system then sends it to the corresponding password reader based on the bound unlocking relationship. The second scenario is fixed at midnight every day when there is network access. The quantum key service system iterates through all password CPU cards, uses a new salt (a new random number) to obtain a new identity credential, and encrypts the updated identity credential and salt using the password reader's quantum key Kb, sending it to the access control system. The access control system distributes the updated encrypted identity credential and salt to the password reader, and unlocking can be completed in both online and offline states.
[0095] In one embodiment of this application, before the quantum cryptography service platform generates a random number, generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, the method further includes:
[0096] The access control system determines the user permissions of the password CPU card to be bound; when the user permissions of the password CPU card are ordinary unlocking users, the access control system binds the password CPU card with the agreed auxiliary information of the password card reader; when the user permissions of the password CPU card are super administrator users, the access control system binds the password CPU card with the auxiliary information of all the password card readers.
[0097] In this embodiment of the application, each password CPU card needs to be bound to a password card reader in the access control system. The bound password card reader is distinguished according to the user's permissions. The user permissions may include super administrator users and ordinary unlocking users, but are not limited to these.
[0098] If the password CPU card belongs to a super administrator user, the access control system should register the password CPU card and bind it to all password readers. When issuing encrypted identity credentials, the quantum cryptography service platform should be informed that all password readers should encrypt the password CPU card's identity credentials. If the password CPU card belongs to a regular unlocking user, it should be bound to an agreed-upon password reader. When issuing encrypted identity credentials, the quantum cryptography service platform should be informed that the quantum key of the bound password reader should encrypt the password CPU card's identity credentials. This application embodiment allocates different permissions for binding password readers based on different user permissions. Regular unlocking users can only bind to specific password readers, while super administrator users can bind to all password readers. By limiting the binding scope of regular unlocking users, potential security risks can be reduced.
[0099] To enable those skilled in the art to better understand the embodiments of this application, a specific example is provided below. Specifically, this application discloses a method for entity authentication in a quantum access control system. The quantum access control system is an access control system based on a quantum secure key (quantum key), which includes:
[0100] Access control system for storing, managing, and authorizing user information; cryptographic CPU card for the entity being authenticated; cryptographic card reader for the terminal device authenticating other entities; quantum security U-shield inserted into the access control system backend to protect the information exchanged between the access control system and the quantum cryptography service platform; quantum cryptography service platform, including quantum cryptography service system, quantum random number generator, quantum key exchange, and quantum key filling machine, provides key services.
[0101] When authenticating a PIN CPU card, the card is placed against the PIN reader, which reads the card and retrieves the card information (electronic tag). The PIN reader then sends a random number to the PIN CPU card as a challenge. The PIN CPU card obtains the random number, generates an authentication credential, and sends it to the PIN reader. The PIN reader obtains the authentication credential and performs a verification process locally. If the verification is successful, the access control system issues an unlocking command, and the door opens.
[0102] Specifically, the authentication method for this cryptographic CPU card includes the following steps:
[0103] S1: Filling: The password CPU card, password reader, and quantum security U-shield are filled with quantum keys at the quantum cryptography service platform.
[0104] S2: Authorization: For initial use, the access control system needs to complete the card and password reader unlocking relationship binding. This unlocking relationship is used to locate the password CPU card bound to the password reader, i.e., the electronic tag of the password CPU card and the electronic tag of the password reader paired with the password CPU card. This information is stored in the access control system's backend. When the access control system needs to request identity credentials from the password service platform, this unlocking relationship can be communicated to the quantum cryptography platform. The password reader's quantum key encrypts the identity credentials of the paired password CPU card; this information is referred to as auxiliary information. Using the quantum security U-shield auxiliary information and the password CPU card's electronic tag, this information is uploaded to the quantum cryptography service platform. The quantum cryptography service platform decrypts the encrypted auxiliary information and electronic tag. It obtains the identity credentials using a random number generated by an encrypted quantum random number generator and the electronic tags of all password CPU cards. Based on the quantum key provided by the access control system to the password system in the auxiliary information, it uses the password reader's quantum key to encrypt the corresponding password CPU card's identity credentials. The identity credentials and salt are then encrypted using the quantum key charged to the password reader, resulting in the encrypted identity credentials issued to the access control system. The access control system issues encrypted identity credentials to the corresponding card reader based on the unlocking relationship. The card reader then uses its own corresponding quantum key to decrypt the encrypted identity credentials and obtain the identity credentials.
[0105] S3: Identity Authentication: The PIN CPU card is placed against the PIN reader, sending an electronic tag to it. The reader recognizes the tag and sends a salt to the PIN CPU card. The PIN CPU card uses its pre-charged quantum key to encrypt the electronic tag and the salt, obtaining identity credentials, which are then sent to the reader. The reader performs physical authentication locally, and the electronic tag is successfully authenticated. Subsequently, based on the comparison result, the access control controller is notified, and the controller issues an unlocking command to open the door.
[0106] In a specific example, the S2 method is as follows:
[0107] S201: After being filled with a password CPU card A, its electronic tag UIDA is the electronic tag of the password CPU card A. N password CPU cards A can be represented by a set Ai (i = 1, 2, 3... N), and the set of electronic tags is represented by UIDAi (i = 1, 2, 3... N). The password reader is B, and its electronic tag can be represented by MIDB. M password readers can be represented by a set Bj (j = 1, 2, 3... M). The unlocking relationship between the password CPU card and the password reader is manually completed in the access control system. The multi-card and multi-reader binding relationship is as follows: UIDAi-MIDBj (i = 1, 2, 3... N, j = 1, 2, 3... M). After the unlocking relationship is bound, it can be stored in the access control system.
[0108] S202: The access control system applies to the quantum cryptography service platform at a fixed time every day to issue identity credentials based on the authorized physical card (password CPU card). The identity credential is determined by the identifier of the password CPU card, the salt (random number), and the quantum key of the password CPU card. It is then encrypted again with the quantum key of the password reader corresponding to the physical card to obtain an encrypted identity credential. The quantum cryptography service platform issues the encrypted identity credential to the access control system. The access control system stores the unlocking relationship between the password CPU card and the password reader in the background and distributes the encrypted identity credential to each password reader according to the physical card-reader binding relationship.
[0109] In a specific example, the specific method of S3 is as follows: S301: The password CPU card calculates the identity credentials and sends them to the password card reader. The password card reader uses the identity credentials issued by the password system every day for verification. The newly issued identity credentials overwrite the previous identity credentials.
[0110] S302: If the access control system is offline and the password system cannot issue identity credentials, the password reader will use the previous random number, Rd-1, and use the corresponding identity credentials for verification.
[0111] In one specific example, the S201 method is as follows: S401: Each card needs to be bound to a password reader in the access control system. The bound password reader is distinguished according to user permissions. User permissions may include super administrator users and ordinary unlocking users.
[0112] S402: If the user of the password CPU card is a super administrator user, then the access control system shall record the user's binding to all password card readers, and when issuing encrypted identity credentials, the quantum cryptography service platform shall be informed that all password card readers should encrypt the user's identity credentials; if the user of the password CPU card is a regular unlocking user, then the user shall be bound to the agreed password card reader, and when issuing encrypted identity credentials, the quantum cryptography service platform shall be informed that the quantum key of the bound password card reader should encrypt the user's identity credentials.
[0113] In a specific example, the specific method of S202 is as follows: S501: The quantum cryptography system does not store the unlocking relationship between the cryptographic CPU card and the cryptographic card reader. The access control system needs to inform the quantum cryptography service system which cryptographic card readers' quantum keys are used to encrypt the identity credentials of the corresponding cryptographic CPU cards. The quantum security U-shield of the access control system encrypts and sends auxiliary information θc to the quantum cryptography service system. The auxiliary information θc informs the quantum cryptography service system which cryptographic CPU cards' identity credentials are used to encrypt by the quantum keys of the cryptographic card readers.
[0114] S502: The quantum key of the quantum-safe U-shield is Kc, and the encrypted information is βm=EnKc[UIDAi,θc],(i=1,2,3...N).
[0115] S503: The quantum cryptography service system decrypts βm, finds the corresponding symmetric key Kai (i = 1, 2, 3... N) based on the electronic tags of all cryptographic CPU cards, and calculates the identity credentials of all cryptographic CPU cards (i = 1, 2, 3... N) based on the salt generated by the quantum random number generator.
[0116] S504: Based on the auxiliary information θc, find the quantum key Kb of the password reader corresponding to the password CPU card, encrypt the identity credential to obtain the ciphertext identity credential (i = 1, 2, 3... N), (j = 1, 2, 3... M). This is used to protect the credential sent to the password reader.
[0117] S505: The quantum random number generator of the quantum cryptography service system updates the random number Rd at a fixed time every day.
[0118] S506: The quantum cryptography service system uses a pre-distribution method to distribute the identity credentials and random number protection of all cryptographic CPU cards to the access control system every morning.
[0119] S507: The access control system traverses all password CPU cards and, based on the bound unlocking relationship UIDAi-MIDBj (i = 1, 2, 3... N, j = 1, 2, 3... M), accurately sends the encrypted identity credentials and random numbers to the fixed password card reader.
[0120] In summary, the advantages of this application embodiment are: this application embodiment uses a quantum cryptography service system to enhance the security of traditional security access control systems.
[0121] 1. A novel and more secure method for physical and environmental security entity identification: (1) Using a quantum random number generator to generate new random numbers and using the entity's symmetric key to encrypt the identifier of the cryptographic CPU card, which has higher security than the traditional electronic tag method. (2) The access control system uses quantum cryptography service to encrypt and protect the key sensitive information of the card identifier and upload it to the quantum cryptography service system for issuing encrypted identity credentials.
[0122] 2. Compared with traditional standard entity identity authentication methods, the embodiments of this application have scalability and convenience: (1) The embodiments of this application support an online authorization mechanism. The newly added password CPU card can be directly authorized in the access control system. When the access control system has a network connection, it will update and issue encrypted identity credentials in real time for identity authentication. (2) The password system updates the salt and encrypted identity credentials at a fixed time every day and issues them to the access control system in real time for identity authentication. Even when the network is disconnected, the password CPU card and password reader can be used to complete identity authentication, which has certain convenience.
[0123] It should be noted that the embodiments of this application may involve the use of user data. In practical applications, user-specific personal data may be used in the scheme described herein within the scope permitted by applicable laws and regulations, provided that it complies with the applicable laws and regulations of the country (e.g., with the user's explicit consent, with the user being properly notified, etc.).
[0124] It should also be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required for the embodiments of this application.
[0125] This application also provides a quantum access control system for implementing the entity identity authentication method of the quantum access control system described in any of the above embodiments.
[0126] The above-described quantum access control system embodiment is basically similar to the method embodiment, so the description is relatively simple. For relevant details, please refer to the description of the method embodiment.
[0127] The various component embodiments of this application can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to the embodiments of this application. This application can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such a program implementing this application can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0128] For example, Figure 8 illustrates an electronic device that can implement the method according to this application. This electronic device conventionally includes a processor 1010 and a computer program product or computer-readable medium in the form of a memory 1020, as well as a communication interface (not shown) and a communication bus (not shown). The processor 1010, the communication interface, and the memory 1020 communicate with each other via the communication bus. The memory 1020 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 1020 has a storage space 1030 for program code 1031 for performing any of the method steps described above. For example, the storage space 1030 for program code can include various program codes 1031 respectively for implementing the various steps in the above method. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, CDs, memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units as described with reference to Figure 9. The storage unit may have storage segments, storage spaces, etc., arranged similarly to the memory 1020 in the electronic device of FIG8. The program code may be compressed, for example, in an appropriate form. Typically, the storage unit includes computer-readable code 1031', i.e., code that can be read by a processor such as 1010, which, when executed by the electronic device, causes the electronic device to perform the various steps in the method described above.
[0129] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The various embodiments in this specification are described in a related manner, and similar or identical parts between the embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system embodiments, since they are substantially similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments.
[0130] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.
Claims
1. A method for entity identification in a quantum access control system, wherein, The quantum access control system includes a cryptographic CPU card, a cryptographic card reader, an access control system, an access control controller, and a quantum cryptography service system. The cryptographic CPU card, the cryptographic card reader, and the access control system are each pre-loaded with a corresponding quantum key through the quantum cryptography service system. Each of the cryptographic CPU card, the cryptographic card reader, and the access control system has a corresponding electronic tag. The access control system binds the electronic tag of the cryptographic CPU card to the electronic tag of the cryptographic card reader to obtain auxiliary information, and stores the auxiliary information in the access control system's backend. The method includes: The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system; The access control system distributes the encrypted identity credentials to the corresponding password reader according to the binding relationship; The password reader decrypts the encrypted identity credential to obtain a decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the password CPU card and the random number is generated by the quantum cryptography service system; When the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the corresponding random number to the password CPU card to be authenticated based on the authentication electronic tag. The password CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader; The password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door.
2. The method according to claim 1, wherein, The quantum access control system also includes a quantum security U-shield, which is inserted into the backend of the access control system and is used to protect the information exchanged between the access control system and the quantum cryptography service platform.
3. The method according to claim 2, wherein, The cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system are pre-charged with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service system; the cryptographic CPU card, the cryptographic card reader, and the quantum-secure U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag, respectively; the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including: The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform; The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information; The quantum cryptography service platform determines the first quantum key corresponding to the cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
4. The method according to claim 1, wherein, The password reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door, including: The password reader compares the authentication credential with the identity credential. If the authentication credentials match, the card reader sends a successful comparison result to the access control controller, so that the access control controller can issue an unlocking command to control the door to open based on the successful comparison result; If the authentication credentials do not match, the PIN reader issues an error message. Incorrect message.
5. The method according to claim 1, wherein, The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including: When the password reader, the access control system, and the quantum cryptography service system are online, if the access control system obtains new auxiliary information by binding the electronic tag of the password CPU card to the electronic tag of the password reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system. The access control system uses the encrypted identity credentials to overwrite the encrypted identity credentials previously issued by the quantum cryptography service platform.
6. The method according to claim 5, wherein, The method further includes: When the password reader, the access control system, and the quantum cryptography service system are offline, when the password CPU card to be authenticated is placed on the password reader, the password reader reads the authentication electronic tag of the password CPU card to be authenticated, and sends the random number corresponding to the previous time to the password CPU card to be authenticated based on the authentication electronic tag. The password CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the password card reader; The password reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
7. The method according to claim 1, wherein, Before the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the password reader determined based on the auxiliary information, and before sending the encrypted identity credential to the access control system, the method further includes: The access control system determines the user permissions of the password CPU card to be bound; When the user privileges of the password CPU card are those of a regular unlocking user, the access control system is bound... The password CPU card and the agreed auxiliary information of the password reader; When the user of the password CPU card has super administrator privileges, the access control system binds the password CPU card with the auxiliary information of all the password card readers.
8. A quantum access control system, wherein, Including a quantum access control system entity identification method as described in any one of claims 1 to 7.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the steps of the method described in any one of claims 1-7.
10. A computer program comprising computer-readable code, which, when executed on an electronic device, causes the electronic device to perform an entity authentication method for a quantum access control system according to any one of claims 1-7.
11. A computer-readable medium storing the computer program as claimed in claim 10.
Citation Information
Patent Citations
CPU security access control method and system
CN109272609A
Electronic access control authentication method based on quantum true random key
CN110738767A
Access control authentication method and system based on quantum key
CN116152979A
Access control method based on Internet of Things, access control system and storage medium
CN117095484A
Quantum authentication method and device, electronic equipment and storage medium
CN117318925A