The invention provides a method and
system for using the
quantum cryptography in safe IP communication. The method is on the basis of a framework defined by an ISAKMP and comprises the following steps that
quantum keys are distributed and a
shared secret is established; IQKE SA negotiation is conducted;
IPSec SA negotiation is conducted; session keys are generated. According to an IQKE protocol defined by the method and
system, the framework defined by the ISAKMP is adopted and is independent of a standard IKE protocol, the problem existing in the compatibility of the standard IKE protocol and a QKD
system can be avoided so that the safety of the
quantum keys generated by the
IPSec through the QKD system can be enhanced; in addition, according to the IQKE protocol, the quantum keys generated by the QKD system are adopted and serve as pre-shared keys, so that the adoption of the typical
key exchange algorithm is not needed and the complexity of key negotiation is reduced. QIKE and QKD can be conducted in parallel; according to the QKD system with the
low speed, the
key storage technology is adopted; according to the QKD system with the high speed, OTP
encryption can be achieved, so that the unconditional safety is achieved. The method and system are significant for improvement of the safety of IP communication.