Encrypted call method based on quantum key distribution, and sip service server and medium

By using quantum key distribution technology to negotiate the generation and destruction of quantum keys between the SIP service server and the terminal device, the problem of insufficient security in key negotiation in existing technologies is solved, and highly secure encrypted calls are achieved.

WO2026012446A1PCT designated stage Publication Date: 2026-01-15XINTONG DIGITAL INTELLIGENCE QUANTUM TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/107981
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-11
Filing Date
2025-07-10
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In existing technologies, the security of key negotiation or transmission processes in communication devices is affected by the threat of quantum computing. The insufficient randomness of keys leads to poor communication security and poses significant security risks.

Method used

An encrypted call method based on quantum key distribution is adopted. The SIP service server negotiates with the quantum encryption key distribution system to generate quantum keys and key identifiers. The terminal device obtains the quantum key through the key identifier to conduct encrypted calls, and destroys the key at the end of the call. Frequent key replacement is used to improve security.

Benefits of technology

It improves the security of quantum keys and communication, reduces the impact of passive attacks, enhances the information theory security and long-term protection of communication, and prevents security challenges brought about by future quantum computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025107981_15012026_PF_FP_ABST
    Figure CN2025107981_15012026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the field of quantum key distribution and application. Disclosed are an encrypted call method based on quantum key distribution, and an SIP service server and a medium. The method comprises: an SIP service server sending a quantum key application request to a first quantum encryption key distribution system, and the first quantum encryption key distribution system performing quantum key negotiation with a second quantum encryption key distribution system, so as to determine a quantum key and a quantum key identifier; receiving the quantum key and the quantum key identifier which are returned by the first quantum encryption key distribution system; sending the quantum key identifier to a target terminal device, and the target terminal device acquiring the quantum key from the second quantum encryption key distribution system by means of the quantum key identifier; and the SIP service server making an encrypted call to or performing encrypted transmission of uplink and downlink instruction data with the target terminal device on the basis of the quantum key. A calling terminal device makes an encrypted call to a target terminal device by means of the SIP service server, thereby improving the key security and the communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Quantum key distribution-based encrypted call method, SIP service server and medium Cross-reference to related applications

[0001] This application is based on and claims priority to Chinese Patent Application No. 202410931320.2, filed on July 11, 2024, the entire contents of which are hereby incorporated herein by reference. Technical Field

[0002] This application relates to the field of quantum key distribution and applications, and in particular to an encrypted call method based on quantum key distribution, a SIP service server, and a medium. Background Technology

[0003] Quantum keys are keys used for encrypting and decrypting communication data, protecting data integrity, and so on. The generation of quantum keys is based on the principles of quantum mechanics, and the properties of qubits are used to ensure the security of key distribution.

[0004] In existing technologies, a pre-set key is injected into the memory of the communication device. Before communication, one communication device securely transmits its encryption key or key negotiation information to the other, achieving key negotiation synchronization between the two devices. The two devices then communicate based on this negotiated key. However, the security of the key negotiation or transmission process is affected by the threat of quantum computing, resulting in low security. Furthermore, the key's variability is small, and the randomness of manually configured keys is insufficient, leading to significant security vulnerabilities in communication between devices. Summary of the Invention

[0005] The purpose of this application is to provide a quantum key distribution-based encrypted call method, SIP service server, and medium to improve the security of keys and the security of communication based on quantum keys.

[0006] To address the aforementioned technical problems, embodiments of this application provide a quantum key distribution-based encrypted call method, applied to a SIP service server and a terminal device. The SIP service server is communicatively connected to a target terminal device and a first quantum encryption key distribution system. The target terminal device is communicatively connected to a second quantum encryption key distribution system. Both the first and second quantum encryption key distribution systems are connected to a quantum network. The method includes: sending a quantum key request to the first quantum encryption key distribution system to enable the first and second quantum encryption key distribution systems to negotiate a quantum key and determine a quantum key and a quantum key identifier; the quantum key is different from a previously used quantum key, and the quantum key identifier is different from a previously used quantum key identifier; receiving the quantum key and the quantum key identifier returned by the first quantum encryption key distribution system in response to the quantum key request; sending the quantum key identifier to the target terminal device to enable the target terminal device to obtain the quantum key from the second quantum encryption key distribution system using the quantum key identifier; and conducting encrypted calls or encrypted transmission of uplink and downlink command data with the target terminal device based on the quantum key.

[0007] An embodiment of this application also provides a method for encrypted calls based on quantum key distribution, wherein sending a quantum key request to the first quantum encryption key distribution system includes: if the SIP service server establishes a new call with the target terminal device, sending a quantum key request to the first quantum encryption key distribution system.

[0008] An embodiment of this application also provides a method for encrypted calls based on quantum key distribution, the method further comprising: destroying the quantum key and the quantum key identifier when the encrypted call with the target terminal device based on the quantum key ends.

[0009] The embodiments of this application also provide a method for encrypted calls based on quantum key distribution. The method further includes: determining the call traffic and call duration between the SIP service server and the target terminal device; if the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time length trigger condition for quantum key distribution, sending a quantum key request to the first quantum encryption key distribution system.

[0010] Embodiments of this application also provide a method for encrypted calls based on quantum key distribution. The SIP service server is communicatively connected to a calling terminal device, and the calling terminal device is communicatively connected to a third quantum encryption key distribution system. The second and third quantum encryption key distribution systems are connected to a quantum network. The method includes: receiving a quantum key identifier sent by the calling terminal device; determining the quantum key identifier through quantum key negotiation between the third and second quantum encryption key distribution systems; sending the quantum key identifier to a target terminal device, so that the target terminal device obtains the quantum key corresponding to the quantum key identifier from the second quantum encryption key distribution system; and the calling terminal device and the target terminal device conduct encrypted calls or encrypted transmission of uplink and downlink command data based on the quantum key through the SIP service server.

[0011] Embodiments of this application also provide a method for encrypted calls based on quantum key distribution. The method further includes: determining the call traffic and call duration of the calling terminal device and the target terminal device; if the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time duration trigger condition for quantum key distribution, sending a quantum key modification request to the calling terminal device and the target terminal device, so that the calling terminal device sends a quantum key application request to the third quantum encryption key distribution system, and the third quantum encryption key distribution system and the second quantum encryption key distribution system perform quantum key negotiation to determine a new quantum key and a new quantum key identifier.

[0012] Embodiments of this application also provide a method for encrypted calls based on quantum key distribution. The method for determining the quantum key identifier includes: if the calling terminal device establishes a new call with the target terminal device, the calling terminal device sends a quantum key request to the third quantum encryption key distribution system; the third quantum encryption key distribution system and the second quantum encryption key distribution system perform quantum key negotiation to determine the quantum key and quantum key identifier of the calling terminal device and the target terminal device; the method further includes: if the call ends, the calling terminal device and the target terminal device destroy the quantum key and the quantum key identifier.

[0013] Embodiments of this application also provide an encrypted call method based on quantum key distribution, wherein the quantum key includes: a quantum key negotiation encryption key, and / or, a quantum session key, and / or, a quantum random number, and / or, a storage encryption key, and / or, an authentication key; the keys in the quantum key are all different.

[0014] Embodiments of this application also provide a SIP service server, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to execute the above-described quantum key distribution-based encrypted call method.

[0015] Embodiments of this application also provide a computer-readable storage medium storing a computer program that can access cryptographic services provided by a cryptographic product. When the computer program is executed by a processor, it implements the above-described encrypted call method based on quantum key distribution.

[0016] In this application, the SIP service server and the target terminal device do not transmit quantum keys, but transmit quantum key identifiers to improve the security of quantum keys and thus improve communication security. Furthermore, the quantum keys are not pre-set in the SIP service server and the target terminal device, but are determined through negotiation between the first quantum encryption key distribution system corresponding to the SIP service server and the second quantum encryption key distribution system corresponding to the target terminal device. The SIP service server can send a quantum key request to the first quantum encryption key distribution system at any time to generate new quantum keys, so that the keys can be updated at any time, further improving the security of keys and communication security. Attached Figure Description

[0017] One or more embodiments are illustrated by way of example with reference to the accompanying drawings, and these illustrative descriptions do not constitute a limitation on the embodiments.

[0018] Figure 1 is a schematic diagram of the structure of the first communication system provided in the embodiment of this application;

[0019] Figure 2 is a flowchart of the first quantum key distribution-based encrypted call method provided in the embodiments of this application;

[0020] Figure 3 is a flowchart of the second quantum key distribution-based encrypted call method provided in the embodiments of this application;

[0021] Figure 4 is a schematic diagram of the structure of the second communication system provided in the embodiment of this application;

[0022] Figure 5 is a flowchart of the third quantum key distribution-based encrypted call method provided in the embodiments of this application;

[0023] Figure 6 is a flowchart of the fourth quantum key distribution-based encrypted call method provided in the embodiments of this application;

[0024] Figure 7 is a flowchart of a key negotiation and allocation method provided in an embodiment of this application;

[0025] Figure 8 is a schematic diagram of the structure of the SIP service server provided in the embodiment of this application. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been provided in the various embodiments of this application to help readers better understand this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various changes and modifications based on the following embodiments. The division of the various embodiments below is for the convenience of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.

[0027] To address the technical problems in existing technologies where communication between devices using fixed keys or public-key algorithms for key negotiation results in poor key security, poor communication security based on these keys, or significant risks, embodiments of this application provide a communication system. Figure 1 is a schematic diagram of the structure of the first communication system provided in this application embodiment. As shown in Figure 1, the communication system includes: a Session Initiation Protocol (SIP) service server 100, a target terminal device 200, a first quantum encryption key distribution system 300, and a second quantum encryption key distribution system 400.

[0028] The SIP service server 100 communicates with the first quantum encryption key distribution system 300 to perform online distribution and key filling of quantum keys (QKD-key). Specifically, the SIP service server also includes a quantum key distribution machine, which communicates with the first quantum encryption key distribution system 300 to perform online distribution and key filling of quantum keys.

[0029] In this embodiment, quantum key distribution (QKD) is the process of ensuring the secure synchronization of quantum keys between communicating parties. It is a method for generating symmetric keys by transmitting quantum states, possessing information-theoretic security at the theoretical protocol level. Key injection, on the other hand, ensures the secure acceptance and use of the key by the encryption terminal. Specifically, quantum key distribution refers to the secure distribution of quantum keys between two communicating terminals, ensuring that the quantum keys are not eavesdropped on or tampered with during transmission, so that they can be used for subsequent encryption and decryption of communication content. Quantum key distribution utilizes the properties of quantum mechanics to achieve extremely high security.

[0030] Key impregnation refers to the process of securely injecting a key into an encrypted terminal. The purpose of this process is to ensure that the encrypted terminal can use the correct key to encrypt and decrypt data, and that this key is not leaked during the injection process. Key impregnation can also enable the secure writing of personalized parameter information, such as user identifiers and authorization information. Impregnated keys include module device keys, authentication keys, and transmission protection keys.

[0031] The quantum key machine communicates with the SIP service via an encrypted interface used for encrypting and decrypting transmitted data.

[0032] The SIP service server 100 communicates with the target terminal device 200 to transmit SIP uplink and downlink data. Specifically, the SIP service server includes SIP services, which are used to transmit SIP uplink and downlink data with the target terminal device 200. Secure multimedia communication between the SIP application and the SIP service server can be achieved through various access networks based on Internet Protocol (IP) links.

[0033] The target terminal device 200 includes: Session Initiation Protocol Application (SIP APP, SIP software), encryption / decryption service software, and quantum key cryptography module.

[0034] The SIP app can initiate and manage calls, not just traditional voice calls, but also supporting various media types such as video calls and real-time text messaging. The SIP app can communicate with the SIP service in the SIP service server to transmit SIP uplink and downlink data.

[0035] The SIP app connects with the encryption service software via an encryption interface to provide functions such as transmitting data to be encrypted, obtaining the encrypted ciphertext, and obtaining data integrity verification codes as needed; transmitting data to be decrypted, obtaining the decrypted plaintext, and obtaining data integrity verification results as needed. Through encryption and / or integrity protection, it enhances the security of the communication system, protects data and privacy, and ensures the confidentiality and integrity of communications. The transmitted encrypted data can be the actual content of the call, such as voice, video, and text messages. The SIP app and the encryption service software communicate via interface calls to provide terminal devices with functions such as user authentication, end-to-end quantum key synchronization, voice encryption, and data encryption and integrity protection.

[0036] The encryption / decryption service software communicates with the quantum key distribution module. The software provides the module with encryption or decryption data, which can be obtained via SIP APP transmission or online distribution through the second quantum encryption key distribution system. The quantum key distribution module performs encryption or decryption based on this data and then transmits the encrypted or decrypted data to the encryption / decryption service software. The software can then transmit the encrypted or decrypted data to the SIP service server as needed via the SIP APP. The encryption / decryption service software interacts with the quantum key distribution module to handle cryptographic algorithms and protocols, and manage and utilize keys.

[0037] The target terminal device 200 communicates with the second quantum encryption key distribution system 400 for online distribution and key filling of quantum keys (QKD-key). Specifically, the encryption / decryption service software in the target terminal device 200 communicates with the second quantum encryption key distribution system 400 to distribute quantum keys online, and the quantum key cryptography module in the target terminal device 200 communicates with the second quantum encryption key distribution system 400 to fill keys. The interface between the target terminal device 200 and the second quantum encryption key distribution system 400 mainly provides the terminal device with functions such as network access authentication and end-to-end or group quantum session key negotiation and synchronization.

[0038] The first quantum encryption key distribution system 300 and the second quantum encryption key distribution system 400 are connected to a quantum network, so that there are classical communication channels and quantum channels between the first quantum encryption key distribution system 300 and the second quantum encryption key distribution system 400. The classical communication channel is used for quantum key negotiation, and the quantum channel is used for quantum key distribution.

[0039] Specifically, each quantum encryption key distribution system includes a quantum key distribution (QKD) device. The QKD device in the first quantum encryption key distribution system 300 and the QKD device in the quantum channel of the second quantum encryption key distribution system 400 distribute quantum keys through the quantum channel.

[0040] Based on the communication system provided in the above embodiments, the embodiments of this application also provide an encrypted call based on quantum key distribution. Figure 2 is a flowchart of the first encrypted call method based on quantum key distribution provided in the embodiments of this application. As shown in Figure 2, the encrypted call method based on quantum key distribution is applied to the SIP service server in the above communication system, and specifically includes the following steps.

[0041] Step 201: Send a quantum key request to the first quantum encryption key distribution system.

[0042] The SIP service server sends a quantum key request to the first quantum encryption key distribution system it is connected to. After receiving the quantum key request, the first quantum encryption key distribution system negotiates the quantum key distribution protocol with the second quantum encryption key distribution system through a classical communication channel. The two QKD devices in the first and second quantum encryption key distribution systems perform quantum key distribution and generate a shared symmetric random bit sequence, which is the quantum key. Then, a unique corresponding quantum key identifier is configured for the quantum key.

[0043] Both the first and second quantum encryption key distribution systems store the generated quantum key and the corresponding quantum key identifier.

[0044] The quantum key is different from the quantum key used in the past, and the quantum key identifier is also different from the quantum key identifier used in the past. For example, if the SIP service server and the target terminal device have at least one quantum key used in the past, then the quantum key determined in this negotiation is different from each of the at least one quantum key used in the past, and correspondingly, the quantum key identifier is also different from each of the at least one quantum key identifier used in the past.

[0045] Step 202: Receive the quantum key and quantum key identifier returned by the first quantum encryption key distribution system in response to the quantum key request.

[0046] The first quantum encryption key distribution system returns the quantum key and quantum key identifier to the SIP service server. Specifically, the first quantum encryption key distribution system sends the quantum key and quantum key identifier to the quantum key cryptography machine in the SIP service server through online distribution.

[0047] Step 203: Send the quantum key identifier to the target terminal device.

[0048] The SIP service retrieves the quantum key identifier from the quantum key machine and sends it to the target terminal device, enabling the target terminal device to obtain the quantum key from the second quantum encryption key distribution system using the quantum key identifier.

[0049] Specifically, the quantum key identifier can be sent to the SIP APP in the target terminal device. The SIP APP then distributes the quantum key identifier online to the second quantum encryption key distribution system through the SIP service server. The second quantum encryption key distribution system determines the corresponding quantum key based on the quantum key identifier and securely distributes the quantum key online to the encryption / decryption service software in the target terminal device.

[0050] In this embodiment, the first quantum encryption key distribution system can also inject the quantum key into the quantum key cryptography machine in the SIP service server through key injection. The second quantum encryption key distribution system can also inject the quantum key into the quantum key cryptography module in the target terminal device through key injection. The difference between online distribution and key injection is that online distribution is completed automatically by the program, while key injection is generally completed manually. Therefore, these two methods generally do not coexist when distributing quantum keys and quantum key identifiers. In engineering practice, during the installation and activation of the SIP service server, before the target terminal device is activated, key injection is performed manually on the cryptography device in the SIP service server. During the installation and activation of the target terminal device, key injection is performed manually on the cryptography device in the target terminal device. This achieves pre-injection of authentication keys, key negotiation encryption keys, etc., which provide encryption or authentication support for subsequent key distribution interaction protocols.

[0051] Step 204: Conduct encrypted calls or encrypted transmission of uplink and downlink command data with the target terminal device based on quantum keys.

[0052] The quantum key received by the SIP service server is the same as the quantum key received by the target terminal device. Therefore, the SIP service server and the target terminal device can conduct encrypted calls or encrypted transmission of uplink and downlink command data based on the quantum key.

[0053] For example, the SIP service server encrypts the communication data using a quantum key and then transmits it to the target terminal device. The encryption / decryption service software in the target terminal device transmits the quantum key identifier and the encrypted communication data to the quantum key cryptography module. The quantum key cryptography module performs a decryption operation based on the quantum key to obtain the original communication data.

[0054] For example, the target terminal device encrypts the communication data using a quantum key and then transmits it to the SIP service server. The quantum key cryptography machine in the SIP service server performs a decryption operation based on the quantum key to obtain the original communication data.

[0055] In this embodiment, the SIP service server and the target terminal device do not transmit quantum keys, but transmit quantum key identifiers instead, thereby improving the security of quantum keys and thus communication security. Furthermore, the quantum keys are not pre-set in the SIP service server and the target terminal device, but are determined through negotiation between the first quantum encryption key distribution system corresponding to the SIP service server and the second quantum encryption key distribution system corresponding to the target terminal device. The SIP service server can send a quantum key request to the first quantum encryption key distribution system at any time to generate new quantum keys, so that the quantum keys can be updated at any time, further improving the security of quantum keys and communication security.

[0056] Based on the quantum key distribution-based encrypted call method shown in Figure 2 above, the embodiments of this application also provide another quantum key distribution-based encrypted call method. Step 201 above, sending a quantum key application request to the first quantum encryption key distribution system, specifically includes the following steps.

[0057] If the SIP service server establishes a new call with the target terminal device, it sends a quantum key request to the first quantum encryption key distribution system.

[0058] Each time the SIP service server establishes a new call with the target terminal device, it sends a quantum key request to the first quantum encryption key distribution system to determine the corresponding quantum key and quantum key identifier.

[0059] Each new call has a unique quantum key and quantum key identifier, achieving one key per call, which further improves the security of quantum keys and communication security.

[0060] Using a different quantum key each time ensures the theoretical security of the call information. Even if an attacker intercepts and obtains a quantum key, that key can only be used to decrypt the corresponding call and will not leak information from other calls.

[0061] Even if quantum computers or other attack techniques are developed in the future, previous communications remain secure. Using a new quantum key each time prevents future attackers from using long-term retained information to crack previous communications.

[0062] Using different quantum keys can reduce the impact of passive attacks (such as intercepting and storing encrypted data for future cracking). Even if an attacker manages to intercept the quantum key and data of a single call, they still cannot apply this information to other calls.

[0063] Frequent changes to quantum keys can increase perceived security, making communication participants more trusting and reliant on the encryption technology used.

[0064] Based on the quantum key distribution-based encrypted call method shown in Figure 2 above, embodiments of this application also provide another quantum key distribution-based encrypted call method, which further includes the following steps.

[0065] When the quantum key-based encrypted call with the target terminal device ends, the quantum key and quantum key identifier are destroyed.

[0066] When an encrypted call or encrypted transmission of uplink and downlink command data ends, all terminals in the communication system and all quantum encryption key distribution systems are destroyed, resulting in the absence of quantum keys and quantum key identifiers in the communication system. This ensures that even if the quantum key is intercepted by an attacker during the call, its subsequent security will not be threatened, because after the quantum key is destroyed, the attacker cannot use the quantum key to decrypt the call content.

[0067] Destroying the quantum key reduces the risk of attackers intercepting and storing encrypted data for future cracking. Even if the data is intercepted, attackers cannot effectively decrypt it because they cannot obtain the quantum key used during the call.

[0068] In this embodiment of the application, the security of the key and the communication security are further improved by destroying the quantum key and the quantum key identifier at the end of the call.

[0069] Based on the quantum key distribution-based encrypted call method shown in Figure 2 above, the embodiments of this application also provide another quantum key distribution-based encrypted call method. Figure 3 is a flowchart of the second quantum key distribution-based encrypted call method provided by the embodiments of this application. As shown in Figure 3, the above method also specifically includes the following steps.

[0070] Step 301: Determine the call traffic and call duration of the session initiation protocol service server and the target terminal device.

[0071] For example, all communication packets between the SIP server and the target terminal device can be captured locally using network traffic analysis software (such as network packet capture tools) or software modules. These communication packets contain all call messages. By analyzing the total number of bytes sent and received in each communication packet, the call traffic can be obtained by adding up the sizes of all captured communication packets.

[0072] In packet capture data, each communication data packet typically has a timestamp, indicating the time the data packet was sent and received. By analyzing the timestamp of the first request and the timestamp of the last related SIP message, the call duration can be calculated.

[0073] Step 302: If the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time length trigger condition for quantum key distribution, send a quantum key application request to the first quantum encryption key distribution system.

[0074] Both the call traffic trigger condition and the time length trigger condition for quantum key distribution are preset.

[0075] For example, if the call traffic is too high and / or the call duration is too long, and the same quantum key is always used, the security of the quantum key will decrease as the call traffic and call duration increase. Therefore, it is necessary to set a new quantum key to continue encrypted calls or encrypted transmission of uplink and downlink command data to improve call security.

[0076] Therefore, if the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time length trigger condition for quantum key distribution, a quantum key application request is sent to the first quantum encryption key distribution system. The first and second quantum encryption key distribution systems negotiate quantum keys to determine a new quantum key and a new quantum key identifier. This new quantum key is different from the previously used quantum key, and the new quantum key identifier is different from the previously used quantum key identifier. Upon receiving the new quantum key and new quantum key identifier returned by the first quantum encryption key distribution system in response to the quantum key application request, the new quantum key identifier is sent to the target terminal device. The target terminal device obtains the new quantum key from the second quantum encryption key distribution system using the new quantum key identifier. The SIP service server and the target terminal device continue encrypted communication based on the new quantum key and maintain the normal operation of encrypted communication during the switch between the old and new keys.

[0077] In this embodiment of the application, using the same quantum key for an extended period during a call may give attackers more opportunities to obtain enough information to crack the key or intercept the communication content. Smoothly changing the quantum key during communication can greatly reduce this risk, enhance the security and long-term protection of the communication, reduce potential encryption cracking risks, and address the security challenges brought about by future quantum computing.

[0078] Based on the above embodiments, this application also provides a communication system. Figure 4 is a schematic diagram of the structure of a second communication system provided by this application. As shown in Figure 4, the communication system further includes: a calling terminal device 500 and a third quantum encryption key distribution system 600. In this case, the target terminal device 200 is the called terminal, and the SIP service server 100 can act as a server to realize encrypted calls or encrypted transmission of uplink and downlink command data between the calling terminal device 500 and the target terminal device 200.

[0079] The calling terminal device 500 includes: a SIP app, encryption / decryption service software, and a quantum key cryptography module. The SIP app and encryption service software are connected via an encryption interface to transmit encrypted data, and the encryption / decryption service software is communicatively connected to the quantum key cryptography module.

[0080] The SIP service server 100 communicates with the calling terminal device 500 to transmit SIP uplink and downlink data. Specifically, the SIP application in the SIP service server 100 communicates with the SIP service server.

[0081] The calling terminal device 500 is communicatively connected to the third quantum encryption key distribution system 600 for online distribution and key filling of quantum keys (QKD-key).

[0082] The second quantum key distribution system 400 and the third quantum key distribution system 600 are connected to a quantum network, enabling communication between them to include both classical and quantum channels. The third quantum key distribution system 600 includes a QKD device, and this QKD device distributes quantum keys to the QKD device in the quantum channel of the second quantum key distribution system 400 via the quantum channel.

[0083] Based on the communication system provided in the above embodiments, the embodiments of this application also provide an encrypted call based on quantum key distribution. Figure 5 is a flowchart of the third encrypted call method based on quantum key distribution provided in the embodiments of this application. As shown in Figure 5, the encrypted call method based on quantum key distribution is applied to the SIP service server in the above communication system, and specifically includes the following steps.

[0084] Step 501: Receive the quantum key identifier sent by the calling terminal device.

[0085] The calling terminal device sends a quantum key request to the third quantum encryption key distribution system. After receiving the request, the third quantum encryption key distribution system negotiates quantum key with the second quantum encryption key distribution system through a classical communication channel. Two QKD devices in the third and second quantum encryption key distribution systems generate a quantum key, and then assign a unique corresponding quantum key identifier to this key. In other words, the quantum key identifier is determined through quantum key negotiation between the third and second quantum encryption key distribution systems.

[0086] Both the second and third quantum encryption key distribution systems store the generated quantum keys and their corresponding quantum key identifiers.

[0087] The calling terminal device sends a quantum key identifier to the SIP service server. Specifically, the SIP application in the calling terminal device sends the quantum key identifier to the SIP service server. Encryption of communication between the calling terminal device and the SIP service server is optional. In one scenario, such as in application systems with a security level of level 2 or below and no explicit requirements from the application system, the SIP service server can transparently forward encrypted communication between the calling and target terminal devices. In another scenario, such as when high security requirements are in place or the application system has explicit requirements, communication between the calling terminal device and the SIP service server should involve authentication and encryption measures, and can be based on encrypted communication using a quantum key negotiated between the calling terminal device and the SIP service server.

[0088] Step 502: Send the quantum key identifier to the target terminal device.

[0089] The SIP service server sends the quantum key identifier transmitted by the calling terminal device to the target terminal device. Specifically, the SIP service server sends the quantum key identifier transmitted by the calling terminal device to the SIP APP in the target terminal device. Encryption of communication between the target terminal device and the SIP service server is optional. In one scenario, such as in application systems with a security level of level 2 or below and no explicit requirements from the application system, the SIP service server can transparently forward encrypted communication between the calling and target terminal devices. In another scenario, such as when high security requirements are in place or the application system has explicit requirements, communication between the target terminal device and the SIP service server should involve authentication and encryption measures, and can be based on encrypted communication using a quantum key negotiated between the target terminal device and the SIP service server.

[0090] The target terminal device obtains the quantum key corresponding to the quantum key identifier from the second quantum encryption key distribution system via the quantum key identifier. Specifically, the SIP APP forwards the quantum key identifier to the encryption / decryption service software, which then distributes the quantum key identifier online to the second quantum encryption key distribution system. The second quantum encryption key distribution system determines the corresponding quantum key based on the quantum key identifier and securely distributes the quantum key online to the encryption / decryption service software of the target terminal device. The second quantum encryption key distribution system can also inject the quantum key into the quantum key cryptography module in the target terminal device through key injection. The difference between online distribution and key injection is that online distribution is done automatically, while key injection is generally done manually. Therefore, these two methods are generally not used simultaneously when distributing quantum keys and quantum key identifiers. In engineering practice, during the installation and activation of the target terminal device, key injection is performed manually on the cryptographic devices in the target terminal device to pre-inject authentication keys, key negotiation encryption keys, etc. These keys provide encryption or authentication support for subsequent key distribution interaction protocols.

[0091] After the target terminal device and the calling terminal device determine the same quantum key, the calling terminal device conducts encrypted calls or encrypted transmission of uplink and downlink command data with the target terminal device through the SIP service server based on the quantum key.

[0092] For example, the calling terminal device encrypts the communication data using a quantum key and then transmits it to the target terminal device via a SIP service server. The encryption / decryption service software in the target terminal device transmits the quantum key identifier and the encrypted communication data to the quantum key cryptography module. The quantum key cryptography module performs a decryption operation based on the quantum key to obtain the original communication data.

[0093] In this embodiment, the calling terminal device and the target terminal device do not transmit quantum keys, but transmit quantum key identifiers to improve key security and thus communication security. Furthermore, the quantum key is not pre-set in the calling terminal device and the target terminal device, but is determined through negotiation between the third quantum encryption key distribution system corresponding to the calling terminal device and the second quantum encryption key distribution system corresponding to the target terminal device. The calling terminal device can send a quantum key application request to the third quantum encryption key distribution system at any time to generate a new quantum key, so that the quantum key can be updated at any time, further improving the security of the quantum key and communication security.

[0094] Based on the quantum key distribution-based encrypted call method shown in Figure 5 above, the embodiments of this application also provide another quantum key distribution-based encrypted call method. Figure 6 is a flowchart of the fourth quantum key distribution-based encrypted call method provided by the embodiments of this application. As shown in Figure 6, the above method further includes the following steps.

[0095] Step 601: Determine the call traffic and call duration of the calling terminal device and the target terminal device.

[0096] The SIP service server acts as a call relay station between the calling terminal and the target terminal, used for SIP message transmission between them.

[0097] As a call relay station, the SIP service server can record all SIP messages forwarded through it. By recording these messages, the SIP service server can obtain the start time, end time, and timestamp of SIP message transmission, thereby calculating the call duration.

[0098] The SIP service server can capture data packets on its network interface. By capturing all data packets sent and received from the calling and receiving terminals, including audio streams and SIP control messages, the SIP service server can calculate the total amount of data transmitted during the call and obtain the call traffic.

[0099] Step 602: If the call traffic reaches the call traffic trigger condition for quantum key allocation, and / or the call duration reaches the time duration trigger condition for quantum key allocation, send a quantum key modification request to the calling terminal device and the target terminal device.

[0100] Both the call traffic trigger condition and the time duration trigger condition for quantum key distribution are preset. For example, if the call traffic is too high and / or the call duration is too long, and the same quantum key is always used, the security of that quantum key will decrease as the call traffic and call duration increase. Therefore, it is necessary to set a new quantum key to continue encrypted calls or encrypted transmission of uplink and downlink command data to improve call security.

[0101] Therefore, if the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time length trigger condition for quantum key distribution, a quantum key modification request is sent to both the calling terminal and the target terminal. Upon receiving the quantum key modification request, the calling terminal sends a quantum key application request to the third quantum encryption key distribution system. The third and second quantum encryption key distribution systems then negotiate the quantum key to determine a new quantum key and a new quantum key identifier.

[0102] The new quantum key is different from the quantum key used in the past, and the new quantum key identifier is also different from the quantum key identifier used in the past.

[0103] After the new quantum key and the new quantum key identifier are determined, the calling terminal device sends the new quantum key identifier to the SIP service server. The SIP service server receives the new quantum key identifier sent by the calling terminal device and sends it to the target terminal device. The target terminal device obtains the new quantum key from the second quantum encryption key distribution system using the new quantum key identifier. The calling terminal device communicates with the target terminal device using the new quantum key through the SIP service server and maintains the normal operation of encrypted communication during the switch between the old and new keys.

[0104] In this embodiment of the application, using the same quantum key for a long time during a call may give attackers more opportunities to obtain enough information to crack the key or intercept the communication content. Changing the quantum key during the communication can greatly reduce this risk and enhance the security and long-term protection of the communication.

[0105] Based on the quantum key distribution-based encrypted call method shown in Figure 5 above, embodiments of this application also provide another quantum key distribution-based encrypted call method, wherein the method for determining the quantum key identifier includes the following steps.

[0106] If the calling terminal device establishes a new call with the target terminal device, the calling terminal device sends a quantum key request to the third quantum encryption key distribution system. The third quantum encryption key distribution system and the second quantum encryption key distribution system negotiate the quantum key to determine the quantum key and quantum key identifier of the calling terminal device and the target terminal device.

[0107] Each time a new call is established between the calling and target terminals, a quantum key request is sent to the third-party quantum encryption key distribution system to determine the corresponding quantum key and quantum key identifier. Each new call has a unique quantum key and quantum key identifier, achieving one-to-one encryption and further enhancing the security of both the quantum key and the communication.

[0108] If the call ends, both the calling terminal and the target terminal destroy the quantum key and quantum key identifier.

[0109] In one scenario, upon completion of an encrypted call or encrypted transmission of uplink / downlink command data, the quantum keys and quantum key identifiers in the calling terminal device, the target terminal device, the third quantum encryption key distribution system, and the second quantum encryption key distribution system are destroyed, leaving no quantum keys or quantum key identifiers in the communication system. In another scenario, based on management needs, the quantum keys and quantum key identifiers in the calling and target terminal devices may be destroyed and cleared. However, the quantum keys and quantum key identifiers in the third and second quantum encryption key distribution systems may be retained and not destroyed for certain management reasons.

[0110] In this embodiment of the application, the security of the quantum key and the quantum key identifier are further improved by destroying the quantum key and the quantum key identifier at the end of the call.

[0111] Based on the above embodiments, the embodiments of this application also provide another encrypted call method based on quantum key distribution. The quantum key in the above embodiments includes: a quantum key negotiation encryption key, and / or a quantum session key, and / or a quantum random number, and / or a storage encryption key, and / or an authentication key.

[0112] In this embodiment of the application, after the quantum key is distributed to the terminal device by the quantum encryption key distribution system, the terminal device can adjust its length and arrange its format.

[0113] The quantum-key encryption key (QEK) is mainly used for key encryption during quantum key negotiation and synchronization in end-to-end or group communication between terminal devices. The QEK originates from the QKD system or QKD network and is initially installed into the quantum key cryptography module of the terminal device through the quantum encryption service key distribution module. The QEK can be updated online.

[0114] Among them, the quantum-key session key (QSK) is negotiated in real time with the corresponding quantum encryption key distribution system (quantum encryption service key distribution module) and adopts a one-to-one quantum key distribution scheme.

[0115] The calling party initiates an end-to-end or group session key negotiation request. The calling party completes authentication and applies for a session key QSK-i (i represents a new QKD-key, and the value of i is a natural number) with the corresponding quantum encryption service key distribution module. After the authentication and application process is successful, the calling party obtains the session key (one or more sets) for this communication. The called party obtains the encryption parameters for this communication through the communication between the calling and called parties, and obtains the session key QSK-i with the quantum encryption service key distribution module through the information synchronized in the encryption parameters (at least including the unique identifier of the QSK-i for this call).

[0116] During transmission, QSK-i is protected by pre-filled QEK-n (n represents the cryptographic modules of different terminal devices, and each cryptographic module QEK is different from the others; the value of n is a natural number). The encryption protection is not limited to encryption alone, but may also include protection of the integrity of the key.

[0117] After the communication initiator and receiver obtain the QSK-i key for each call, they will temporarily store it in the volatile storage medium of the password module (such as RAM (Random Access Memory)). It will be deleted after the call or data is sent / received. It will also be automatically cleared when the device is powered off.

[0118] When the terminal device fails to negotiate a key with the quantum encryption service key distribution module in real time, it can still use the pre-stored QSK key emergency library (no less than 1000 sets of quantum keys) for communication encryption. In this case, the communication initiator selects a set of QSK-j (j equals a natural number from 1 to the maximum number of sets in the pre-stored key library; a set of QSK-j can be one or more keys), and synchronizes it to the communication receiver using a symmetric algorithm-based encrypted digital envelope method, through encryption parameters. This ensures the availability of encrypted communication. The QSK key emergency library still supports manual replenishment and updates during maintenance via the quantum encryption service key distribution module, or online negotiation updates. Online updates of QSK-j are protected by the QEK-n of the updated terminal device.

[0119] Among them, quantum random numbers (QRNs) can be generated from QKD systems, QKD networks, or quantum random number generators (QRNGs), and provide random numbers and random entropy sources to terminal devices during handshake protocols, authentication, or encrypted communication protocols through a quantum encryption service key distribution module.

[0120] Among them, the storage encryption protection of cryptographic products such as cryptographic modules must comply with the secure storage protection mechanism of the cryptographic modules themselves. The storage encryption key (LMK-n) (n represents the cryptographic modules of different terminal devices, and each cryptographic module has a different LMK) and authentication key (AuK-n) (n represents the cryptographic modules of different terminal devices, and each cryptographic module has a different AuK) related to SIP services are pre-generated by the quantum encryption service key distribution module during the initial installation stage of the device and are initially installed and added to the quantum key cryptographic module of the terminal device.

[0121] In this embodiment, all terminal devices have different personalized keys, such as storage protection keys, authentication keys, and quantum key negotiation encryption keys. The loss or loss of control of one terminal will not pose a threat to other devices.

[0122] Based on the above embodiments, this application also provides an end-to-end key negotiation and allocation process. Figure 7 is a flowchart of a key negotiation and allocation method provided by this application. The end-to-end quantum key negotiation and allocation process is divided into four stages: initialization, key negotiation / preparation, cryptographic service, and exit. The main work and interaction process of each stage are shown in Figure 7.

[0123] In Figure 7, the encryption service software is the encryption / decryption service software in Figure 4; the SIP application initiator in Figure 7 is the SIP APP in the calling terminal device in Figure 4; and the SIP application receiver in Figure 7 is the SIP APP in the target terminal device in Figure 4.

[0124] During the key negotiation / preparation phase, Mode 1 and Mode 2 are selected based on application requirements. Generally, Mode 1 is used for end-to-end secure communication between two terminal devices or between a terminal device and a SIP service server. Mode 2 is used for group secure communication between multiple terminal devices. The SIP application receiver can obtain the QSK according to the key negotiation protocol through the encrypted parameter information transmitted within the SIP communication band.

[0125] In the cryptographic service phase, Mode 1 and Mode 2 are selected according to application requirements. Mode 1 provides QKD-key services; Mode 2 provides cryptographic services such as encryption of the negotiated and distributed QKD-key and calculation of message authentication codes.

[0126] In summary, the embodiments described above include integrating quantum key distribution (QKD) technology with an end-to-end communication system based on the SIP protocol to achieve the distribution of different types of quantum keys. It also includes manually distributed quantum keys QEK (quantum key negotiation encryption key); online distributed quantum keys QSK (quantum session key) protected by QEK; and QSK directly used for encryption of information such as voice or data, adopting a one-key-per-voice strategy.

[0127] This application offers the following enhanced security capabilities: High random quality of the quantum key; detection of quantum states on wide-area or regional quantum channels will be achieved, thereby improving the unpredictability of the communication session key and providing stronger protection for communication encryption; the one-to-one QSK-i distribution to the end-user is initiated by the communication initiator in real-time and protected by QEK-n encryption; QEK-n originates from the pre-prepared and distributed quantum key, and the QEK-n of each terminal device's cryptographic module is unique, ensuring the confidentiality, integrity, and unpredictability of QSK-i distribution to the end-user, thus guaranteeing the security of this communication; real-time negotiation of QSK-i provides unpredictability and security for backward communication session keys; QSK-i is temporarily stored in RAM, deleted after use, and automatically cleared upon power failure, thus providing forward security for communication.

[0128] This application employs quantum key distribution technology; it fully considers the independence of terminal devices, ensuring that the storage protection key (Local Master Key, LMK), authentication key (AuK), and quantum key negotiation encryption key (QEK) are all different from each other, so that the loss or loss of control of one terminal will not pose a threat to other devices; it fully considers the forward and backward security of the encrypted communication system; and through the mechanism of the emergency quantum session key library, it ensures that even if real-time negotiation of QSK-i fails, it still has a certain QSK-j encrypted communication capability.

[0129] This application highlights the rapid industrial application of SIP protocol-based multimedia communication services, such as encrypted telephony and encrypted intercom. It has led to the development of encrypted call and video communication applications and security services tailored to important industries, special scenarios, and enterprise personnel. Through encrypted communication services for voice, information, and video data, it effectively prevents the leakage of important information during calls, ensuring call security, data security, and protecting trade secrets and personal privacy. It possesses significant development potential within the industry. Therefore, the technology presented in this application can be promoted independently in the commercial market and in cryptographic applications of critical infrastructure, demonstrating a certain market foundation, development scale, and potential.

[0130] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this patent.

[0131] This application embodiment relates to an initial node. Figure 8 is a schematic diagram of the structure of the SIP service server provided in this application embodiment. As shown in Figure 8, it includes: at least one processor 801; and a memory 802 communicatively connected to at least one processor 801. The memory 802 stores instructions that can be executed by at least one processor 801. The instructions are executed by at least one processor 801 to enable at least one processor 801 to execute the uplink and downlink data message transmission methods in the above embodiments.

[0132] The memory 802 and the processor 801 are connected by a bus, which can include any number of interconnected buses and bridges, and connect various circuits of one or more processors and the memory together.

[0133] This application relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the method embodiments described above.

[0134] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, hard disks, disk arrays, read-only memory (ROM), and random access memory (RAM).

[0135] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.

Claims

1. A quantum key distribution-based encrypted call method, applied to a SIP service server, wherein the SIP service server is communicatively connected to a target terminal device, the SIP service server is communicatively connected to a first quantum encryption key distribution system, the target terminal device is communicatively connected to a second quantum encryption key distribution system, and the first and second quantum encryption key distribution systems are connected to a quantum network, the method comprising: A quantum key request is sent to the first quantum encryption key distribution system to enable the first and second quantum encryption key distribution systems to negotiate a quantum key and determine a quantum key and a quantum key identifier; the quantum key is different from the previously used quantum key, and the quantum key identifier is different from the previously used quantum key identifier; Receive the quantum key and the quantum key identifier returned by the first quantum encryption key distribution system in response to the quantum key application request; The quantum key identifier is sent to the target terminal device so that the target terminal device can obtain the quantum key from the second quantum encryption key distribution system through the quantum key identifier. Encrypted calls or encrypted transmission of uplink and downlink command data are conducted with the target terminal device based on the quantum key.

2. The encrypted call method according to claim 1, wherein, Sending a quantum key request to the first quantum encryption key distribution system includes: If the SIP service server establishes a new call with the target terminal device, it sends a quantum key request to the first quantum encryption key distribution system.

3. The encrypted call method according to claim 1, wherein, The method further includes: When the encrypted call with the target terminal device based on the quantum key ends, the quantum key and the quantum key identifier are destroyed.

4. The encrypted call method according to claim 1, wherein, The method further includes: Determine the call traffic and call duration between the SIP service server and the target terminal device; If the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time duration trigger condition for quantum key distribution, a quantum key application request is sent to the first quantum encryption key distribution system.

5. The encrypted call method according to claim 1, wherein, The SIP service server is communicatively connected to the calling terminal device, the calling terminal device is communicatively connected to the third quantum encryption key distribution system, and the second quantum encryption key distribution system and the third quantum encryption key distribution system are connected to the quantum network. The method includes: The system receives a quantum key identifier sent by the calling terminal device; the quantum key identifier is determined through quantum key negotiation between the third quantum encryption key distribution system and the second quantum encryption key distribution system. The quantum key identifier is sent to the target terminal device so that the target terminal device can obtain the quantum key corresponding to the quantum key identifier from the second quantum encryption key distribution system. The calling terminal device then conducts encrypted calls or encrypted transmission of uplink and downlink command data with the target terminal device through the SIP service server based on the quantum key.

6. The encrypted call method according to claim 5, wherein, The method further includes: Determine the call traffic and call duration of the calling terminal device and the target terminal device; If the call traffic reaches the call traffic trigger condition for quantum key distribution, and / or the call duration reaches the time duration trigger condition for quantum key distribution, a quantum key modification request is sent to the calling terminal device and the target terminal device, so that the calling terminal device sends a quantum key application request to the third quantum encryption key distribution system. The third quantum encryption key distribution system and the second quantum encryption key distribution system perform quantum key negotiation to determine a new quantum key and a new quantum key identifier.

7. The encrypted call method according to claim 5, wherein, The method for determining the quantum key identifier includes: If the calling terminal device establishes a new call with the target terminal device, the calling terminal device sends a quantum key application request to the third quantum encryption key distribution system. The third quantum encryption key distribution system and the second quantum encryption key distribution system negotiate quantum keys to determine the quantum keys and quantum key identifiers of the calling terminal device and the target terminal device. The method further includes: If the call ends, the calling terminal device and the target terminal device destroy the quantum key and the quantum key identifier.

8. The encrypted call method according to any one of claims 1 to 7, wherein, The quantum key includes: a quantum key negotiation encryption key, and / or a quantum session key, and / or a quantum random number, and / or a storage encryption key, and / or an authentication key; each of the quantum keys is different.

9. A SIP service server, wherein, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the quantum key distribution-based encrypted call method according to any one of claims 1 to 8.

10. A computer-readable storage medium storing a computer program, wherein, When the computer program is executed by the processor, it implements the quantum key distribution-based encrypted call method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Quantum secret key synchronization method for distribution terminal

    CN108667607A

  • Quantum security key synchronization method and device, electronic equipment and storage medium

    CN113595722A

  • Data transmission encryption method and device, electronic equipment and storage medium

    CN114338005A

  • Data transmission method and device and related product

    CN118282637A

  • Encrypted call method based on quantum key distribution, SIP business server and medium

    CN118944866A