ABSTRACT
Abstract
A cloud-based encryption machine key injection system includes at least one key injection sub-system including a key generation device and a quantum key distribution device connected with the key generation device, and a cloud-based encryption machine hosting sub-system including an encryption machine carrying a virtual encryption device and a quantum key distribution device connected with the encryption machine. The key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices. The key generation device may generate a root key component of the virtual encryption device and transmit the root key component to the encryption machine. The encryption machine may receive root key components from one or more key generation devices and synthesize a root key of the virtual encryption device in accordance with the received root key components.
Description
CROSS REFERENCE TO RELATED APPLICATION
The present application claims the benefits of priority to Chinese Application No. 201510195062.7, filed Apr. 22, 2015, the entire contents of which are incorporated herein by reference.
TECHNICAL FIELD
The present application relates to methods, apparatus, and systems for cloud-based encryption machine key injection.
BACKGROUND
Encryption machines are often used for protecting data privacy, especially in the banking industry. One of their main functions is key storage. A standard key system of the banking industry is a three-layer key system: ansi x9.17, which strictly limits the use of keys in different levels. The first layer is an encryption machine master key (also referred to as root key), the second layer is a bank master key (also referred to as user master key), and the third layer is a work key, which is also referred to as user work key or user data key.
The root key including three components is stored in a hardware encryption machine, and can be used to protect various keys stored outside the encryption machine and encryption keys of critical data. The role of the user master key is to encrypt a work key to be transmitted on a communication line. The user master key is typically under the encryption protection of a root key or is directly stored in the hardware encryption machine. The role of the user work key is to encrypt a variety of different data, so as to implement functions such as data privacy, information authentication and digital signature, and the user work key is under the encryption protection of the user master key or is directly stored in the hardware encryption machine.
Prior to use, it is necessary to inject a root key into the encryption machine. The encryption machine usually carries a set of IC cards (including an A card, a B card and a C card), and before startup, the management staff inserts the A card into a corresponding slot of the encryption machine and injects three components of the root key through an encryption machine panel menu or a management program provided by a manufacturer, each component being 32 hexadecimal numbers. Afterwards, the root key is stored in the A card and the B card, a user master key is then injected, and after related operations are completed, the user master key is stored in the C card. For a different encryption machine, the key injection process described above may vary but can be completed only by executing an operation of manually inserting a card.
In addition, with rapid development of cloud computing, data storage, data calculation and data applications are increasingly cloud-enabled, and how to guarantee security of sensitive data and critical applications of the cloud users is a major problem for the public cloud. The encryption machine introduced previously is one method of protecting data privacy. A cloud-enabled encryption machine is often desired. For example, users can host the encryption machine at a cloud provider, so as to protect the users' private business data on corresponding clouds.
The traditional manner of injecting a key by manually inserting a card is feasible in a situation where encryption machine devices are relatively few and the encryption machine is placed with a client. However, in the public cloud, the encryption machine is usually placed in a place away from a customer building for hosting, the number of the encryption machine devices increases greatly, and thus the traditional manner has many inconveniences: on the one hand, a cloud user needs to travel a long distance to the cloud provider to insert a card for injecting a key, and operation steps are cumbersome and waste time and energy; on the other hand, as various kinds of cloud users come into and go out of the cloud provider, management efficiency of the cloud provider is low and there are potential safety hazards, thus reducing the cloud users' trust in hosting the encryption machine at the cloud provider.
SUMMARY
One aspect of the present disclosure is directed to a cloud-based encryption machine key injection system. The key injection system includes at least one key injection sub-system including a key generation device and a quantum key distribution device connected with the key generation device, and a cloud-based encryption machine hosting sub-system including an encryption machine carrying a virtual encryption device and a quantum key distribution device connected with the encryption machine. The key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices. The key generation device may generate a root key component and send the root key component via the quantum key distribution devices to the encryption machine. The encryption machine may receive root key components from one or more key generation devices and synthesize a root key of the virtual encryption device in accordance with the received root key components.
According to some embodiments, the quantum key distribution devices may negotiate a shared key pair between the key generation device and the encryption machine, and the quantum key distribution device of the at least one key injection sub-system may use a negotiated shared key to perform encryption transmission of the root key component to the encryption machine.
According to some embodiments, the at least one key injection sub-system includes one key injection sub-system, and the key generation device of the key injection sub-system may generate a number of root key components for the virtual encryption device and send the root key components via the quantum key distribution devices to the encryption machine. In some other embodiments, the encryption machine may generate one root key component for the virtual encryption device and synthesize the root key of the virtual encryption device in accordance with the received root key components from the at least one key injection sub-system and from the encryption machine.
According to some other embodiments, the at least one key injection sub-system includes a cloud-based management sub-system and a user sub-system located at a client terminal, the management sub-system includes a quantum key distribution device and a management device including the key generation device, and the user sub-system includes a quantum key distribution device and a terminal device including the key generation device.
According to some other embodiments, the encryption machine may synthesize a root key of the virtual encryption device in accordance with the received root key components by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
Another aspect of the present disclosure is directed to a key injection method for an encryption machine, implemented by a cloud based encryption machine key injection system. The method includes receiving, by the encryption machine, root key components, from at least one key injection sub-system, and synthesizing, by the encryption machine, a root key in accordance with the received root key components from the at least one key injection sub-system. The encryption machine may include a virtual encryption device, and the root key is for the virtual encryption device. Each of the root key components may be generated by a key generation device of the at least one key injection sub-system. The encryption machine may be connected to a quantum key distribution device, and each of the at least one key injection sub-system includes a quantum key distribution device. The root key components may be transmitted from the at least one key injection sub-system to the encryption machine via the quantum key distribution devices. The encryption machine may synthesize the root key in accordance with the received root key components by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
According to some embodiments, the key injection method may further include generating a root key component by the encryption machine. The encryption machine synthesizes the root key in accordance with the received root key components from the at least one key injection sub-systems and the root key component generated by the encryption machine.
According to some other embodiments, the key injection method may further include negotiating, by the encryption machine with each of the at least one key injection sub-system a shared key pair. The root key components from the at least one key injection sub-systems are encrypted with a key in the shared key pair.
The at least one key injection sub-system may include a cloud-based management sub-system and a user sub-system located at a client terminal, the cloud-based management sub-system including a key generation device, and the user sub-system including a key generation device.
Another aspect of the present disclosure is directed to a key injection apparatus for an encryption machine, the apparatus being deployed in a cloud-based encryption machine key injection system. The apparatus includes a shared key pair negotiation unit that negotiates a shared key pair with at least one key injection sub-system, a root key component generation unit that generates a root key component for a virtual encryption device on the encryption machine, and a root key synthesis unit that synthesizes a root key in accordance with the root key component generated by the root key component generation unit and root key components received from the at least one key injection sub-system. According to some embodiments, the at least one key injection sub-system and the encryption machine may include or be connected to quantum key distribution devices, and the root key components may be transmitted via the quantum key distribution devices respectively to the encryption machine.
Another aspect of the present disclosure is directed to a method for hosting a cloud-based encryption machine. The method includes sending, by a cloud user, an encryption machine hosting request to a management device located at the cloud through a terminal device, assigning, by the management device, a virtual encryption device hosted at the cloud to the cloud user in accordance with the received request, the virtual encryption device being carried by an encryption machine, and injecting a root key of the virtual encryption device into the encryption machine. The injecting the root key of the virtual encryption device into the encryption machine may include generating root key components of the virtual encryption device by the management device and the cloud user, and sending the root key components to the encryption machine, and synthesizing, by the encryption machine, a root key of the virtual encryption device in accordance with the received root key components.
Additional features and advantages of the present disclosure will be set forth in part in the following detailed description, and in part will be obvious from the description, or may be learned by practice of the present disclosure. The features and advantages of the present disclosure will be realized and attained by means of the elements and combinations particularly pointed out in the appended claims.
It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not restrictive of the invention, as claimed.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which constitute a part of this specification, illustrate several embodiments and, together with the description, serve to explain the disclosed principles.
FIG. 1A is a graphical representation illustrating a cloud-based encryption machine key injection system, according to an exemplary embodiment.
FIG. 1B is a block diagram illustrating a cloud-based encryption machine key injection system, according to an exemplary embodiment.
FIG. 2 is a flow diagram illustrating a key injection method, according to an exemplary embodiment.
FIG. 3 is a block diagram illustrating a key injection apparatus, according to another exemplary embodiment.
FIG. 4 is a flow diagram illustrating a method for hosting a cloud-based encryption machine, according to an exemplary embodiment.
FIG. 5 is a block diagram illustrating an apparatus for hosting a cloud-based encryption machine, according to another exemplary embodiment.
DETAILED DESCRIPTION
Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. The following description refers to the accompanying drawings in which the same numbers in different drawings represent the same or similar elements unless otherwise represented. The implementations set forth in the following description of exemplary embodiments consistent with the present invention do not represent all implementations consistent with the invention. Instead, they are merely examples of systems and methods consistent with aspects related to the invention as recited in the appended claims.
In the present application, a cloud-based encryption machine key injection system, a key injection method for an encryption machine and a corresponding apparatus, and a method for hosting an encryption machine at a cloud and a corresponding apparatus are provided, which are described below.
The cloud-based encryption machine key injection system provided in this example includes at least one key injection sub-system and an encryption machine hosting sub-system located at the cloud. The key injection sub-system includes: a key generation device, and a quantum key distribution device connected with the key generation device; the encryption machine hosting sub-system includes: an encryption machine as a virtual encryption device hosted by a cloud user, and a quantum key distribution device connected with the encryption machine. The key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices.
In some embodiments, the encryption machine hosted at the cloud by the cloud user may be a physical encryption machine, and may also be a virtual encryption device carried by the encryption machine. A plurality of cloud users may share one encryption machine, and each cloud user that shares the same encryption machine owns a separate virtual encryption device. It may also be understood as follows: when one encryption machine is only assigned to one cloud user, the virtual encryption device hosted at the cloud by the cloud user is the encryption machine. As the difference between the above two hosting manners does not affect implementation of the technical solution of the present application, in order to facilitate description, the above two situations are not distinguished in the examples herein, and a description of using a virtual encryption device at the cloud by a cloud user is used in the following examples.
In some embodiments, on the basis of the foregoing system architecture, if the system only includes one key injection sub-system, the quantum key distribution devices in the key injection sub-system and the encryption machine hosting sub-system may negotiate, between the key generation device connected therewith and the encryption machine as the virtual encryption device, a shared key pair by using a quantum key distribution protocol (for example, BB84 protocol). The key generation device may generate root key components of the virtual encryption device in accordance with a number of preset root key components (also referred to as root key constituents), and use a negotiated shared key to perform encryption transmission of the root key components to the encryption machine as the virtual encryption device; and the encryption machine may decrypt the received root key
CROSS REFERENCE TO RELATED APPLICATION
The present application claims the benefits of priority to Chinese Application No. 201510195062.7, filed Apr. 22, 2015, the entire contents of which are incorporated herein by reference.
TECHNICAL FIELD
The present application relates to methods, apparatus, and systems for cloud-based encryption machine key injection.
BACKGROUND
Encryption machines are often used for protecting data privacy, especially in the banking industry. One of their main functions is key storage. A standard key system of the banking industry is a three-layer key system: ansi x9.17, which strictly limits the use of keys in different levels. The first layer is an encryption machine master key (also referred to as root key), the second layer is a bank master key (also referred to as user master key), and the third layer is a work key, which is also referred to as user work key or user data key.
The root key including three components is stored in a hardware encryption machine, and can be used to protect various keys stored outside the encryption machine and encryption keys of critical data. The role of the user master key is to encrypt a work key to be transmitted on a communication line. The user master key is typically under the encryption protection of a root key or is directly stored in the hardware encryption machine. The role of the user work key is to encrypt a variety of different data, so as to implement functions such as data privacy, information authentication and digital signature, and the user work key is under the encryption protection of the user master key or is directly stored in the hardware encryption machine.
Prior to use, it is necessary to inject a root key into the encryption machine. The encryption machine usually carries a set of IC cards (including an A card, a B card and a C card), and before startup, the management staff inserts the A card into a corresponding slot of the encryption machine and injects three components of the root key through an encryption machine panel menu or a management program provided by a manufacturer, each component being 32 hexadecimal numbers. Afterwards, the root key is stored in the A card and the B card, a user master key is then injected, and after related operations are completed, the user master key is stored in the C card. For a different encryption machine, the key injection process described above may vary but can be completed only by executing an operation of manually inserting a card.
In addition, with rapid development of cloud computing, data storage, data calculation and data applications are increasingly cloud-enabled, and how to guarantee security of sensitive data and critical applications of the cloud users is a major problem for the public cloud. The encryption machine introduced previously is one method of protecting data privacy. A cloud-enabled encryption machine is often desired. For example, users can host the encryption machine at a cloud provider, so as to protect the users' private business data on corresponding clouds.
The traditional manner of injecting a key by manually inserting a card is feasible in a situation where encryption machine devices are relatively few and the encryption machine is placed with a client. However, in the public cloud, the encryption machine is usually placed in a place away from a customer building for hosting, the number of the encryption machine devices increases greatly, and thus the traditional manner has many inconveniences: on the one hand, a cloud user needs to travel a long distance to the cloud provider to insert a card for injecting a key, and operation steps are cumbersome and waste time and energy; on the other hand, as various kinds of cloud users come into and go out of the cloud provider, management efficiency of the cloud provider is low and there are potential safety hazards, thus reducing the cloud users' trust in hosting the encryption machine at the cloud provider.
SUMMARY
One aspect of the present disclosure is directed to a cloud-based encryption machine key injection system. The key injection system includes at least one key injection sub-system including a key generation device and a quantum key distribution device connected with the key generation device, and a cloud-based encryption machine hosting sub-system including an encryption machine carrying a virtual encryption device and a quantum key distribution device connected with the encryption machine. The key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices. The key generation device may generate a root key component and send the root key component via the quantum key distribution devices to the encryption machine. The encryption machine may receive root key components from one or more key generation devices and synthesize a root key of the virtual encryption device in accordance with the received root key components.
According to some embodiments, the quantum key distribution devices may negotiate a shared key pair between the key generation device and the encryption machine, and the quantum key distribution device of the at least one key injection sub-system may use a negotiated shared key to perform encryption transmission of the root key component to the encryption machine.
According to some embodiments, the at least one key injection sub-system includes one key injection sub-system, and the key generation device of the key injection sub-system may generate a number of root key components for the virtual encryption device and send the root key components via the quantum key distribution devices to the encryption machine. In some other embodiments, the encryption machine may generate one root key component for the virtual encryption device and synthesize the root key of the virtual encryption device in accordance with the received root key components from the at least one key injection sub-system and from the encryption machine.
According to some other embodiments, the at least one key injection sub-system includes a cloud-based management sub-system and a user sub-system located at a client terminal, the management sub-system includes a quantum key distribution device and a management device including the key generation device, and the user sub-system includes a quantum key distribution device and a terminal device including the key generation device.
According to some other embodiments, the encryption machine may synthesize a root key of the virtual encryption device in accordance with the received root key components by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
Another aspect of the present disclosure is directed to a key injection method for an encryption machine, implemented by a cloud based encryption machine key injection system. The method includes receiving, by the encryption machine, root key components, from at least one key injection sub-system, and synthesizing, by the encryption machine, a root key in accordance with the received root key components from the at least one key injection sub-system. The encryption machine may include a virtual encryption device, and the root key is for the virtual encryption device. Each of the root key components may be generated by a key generation device of the at least one key injection sub-system. The encryption machine may be connected to a quantum key distribution device, and each of the at least one key injection sub-system includes a quantum key distribution device. The root key components may be transmitted from the at least one key injection sub-system to the encryption machine via the quantum key distribution devices. The encryption machine may synthesize the root key in accordance with the received root key components by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
According to some embodiments, the key injection method may further include generating a root key component by the encryption machine. The encryption machine synthesizes the root key in accordance with the received root key components from the at least one key injection sub-systems and the root key component generated by the encryption machine.
According to some other embodiments, the key injection method may further include negotiating, by the encryption machine with each of the at least one key injection sub-system a shared key pair. The root key components from the at least one key injection sub-systems are encrypted with a key in the shared key pair.
The at least one key injection sub-system may include a cloud-based management sub-system and a user sub-system located at a client terminal, the cloud-based management sub-system including a key generation device, and the user sub-system including a key generation device.
Another aspect of the present disclosure is directed to a key injection apparatus for an encryption machine, the apparatus being deployed in a cloud-based encryption machine key injection system. The apparatus includes a shared key pair negotiation unit that negotiates a shared key pair with at least one key injection sub-system, a root key component generation unit that generates a root key component for a virtual encryption device on the encryption machine, and a root key synthesis unit that synthesizes a root key in accordance with the root key component generated by the root key component generation unit and root key components received from the at least one key injection sub-system. According to some embodiments, the at least one key injection sub-system and the encryption machine may include or be connected to quantum key distribution devices, and the root key components may be transmitted via the quantum key distribution devices respectively to the encryption machine.
Another aspect of the present disclosure is directed to a method for hosting a cloud-based encryption machine. The method includes sending, by a cloud user, an encryption machine hosting request to a management device located at the cloud through a terminal device, assigning, by the management device, a virtual encryption device hosted at the cloud to the cloud user in accordance with the received request, the virtual encryption device being carried by an encryption machine, and injecting a root key of the virtual encryption device into the encryption machine. The injecting the root key of the virtual encryption device into the encryption machine may include generating root key components of the virtual encryption device by the management device and the cloud user, and sending the root key components to the encryption machine, and synthesizing, by the encryption machine, a root key of the virtual encryption device in accordance with the received root key components.
Additional features and advantages of the present disclosure will be set forth in part in the following detailed description, and in part will be obvious from the description, or may be learned by practice of the present disclosure. The features and advantages of the present disclosure will be realized and attained by means of the elements and combinations particularly pointed out in the appended claims.
It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not restrictive of the invention, as claimed.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which constitute a part of this specification, illustrate several embodiments and, together with the description, serve to explain the disclosed principles.
FIG. 1A is a graphical representation illustrating a cloud-based encryption machine key injection system, according to an exemplary embodiment.
FIG. 1B is a block diagram illustrating a cloud-based encryption machine key injection system, according to an exemplary embodiment.
FIG. 2 is a flow diagram illustrating a key injection method, according to an exemplary embodiment.
FIG. 3 is a block diagram illustrating a key injection apparatus, according to another exemplary embodiment.
FIG. 4 is a flow diagram illustrating a method for hosting a cloud-based encryption machine, according to an exemplary embodiment.
FIG. 5 is a block diagram illustrating an apparatus for hosting a cloud-based encryption machine, according to another exemplary embodiment.
DETAILED DESCRIPTION
Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. The following description refers to the accompanying drawings in which the same numbers in different drawings represent the same or similar elements unless otherwise represented. The implementations set forth in the following description of exemplary embodiments consistent with the present invention do not represent all implementations consistent with the invention. Instead, they are merely examples of systems and methods consistent with aspects related to the invention as recited in the appended claims.
In the present application, a cloud-based encryption machine key injection system, a key injection method for an encryption machine and a corresponding apparatus, and a method for hosting an encryption machine at a cloud and a corresponding apparatus are provided, which are described below.
The cloud-based encryption machine key injection system provided in this example includes at least one key injection sub-system and an encryption machine hosting sub-system located at the cloud. The key injection sub-system includes: a key generation device, and a quantum key distribution device connected with the key generation device; the encryption machine hosting sub-system includes: an encryption machine as a virtual encryption device hosted by a cloud user, and a quantum key distribution device connected with the encryption machine. The key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices.
In some embodiments, the encryption machine hosted at the cloud by the cloud user may be a physical encryption machine, and may also be a virtual encryption device carried by the encryption machine. A plurality of cloud users may share one encryption machine, and each cloud user that shares the same encryption machine owns a separate virtual encryption device. It may also be understood as follows: when one encryption machine is only assigned to one cloud user, the virtual encryption device hosted at the cloud by the cloud user is the encryption machine. As the difference between the above two hosting manners does not affect implementation of the technical solution of the present application, in order to facilitate description, the above two situations are not distinguished in the examples herein, and a description of using a virtual encryption device at the cloud by a cloud user is used in the following examples.
In some embodiments, on the basis of the foregoing system architecture, if the system only includes one key injection sub-system, the quantum key distribution devices in the key injection sub-system and the encryption machine hosting sub-system may negotiate, between the key generation device connected therewith and the encryption machine as the virtual encryption device, a shared key pair by using a quantum key distribution protocol (for example, BB84 protocol). The key generation device may generate root key components of the virtual encryption device in accordance with a number of preset root key components (also referred to as root key constituents), and use a negotiated shared key to perform encryption transmission of the root key components to the encryption machine as the virtual encryption device; and the encryption machine may decrypt the received root key components with the negotiated shared key, synthesize a root key of the virtual encryption device with the decrypted root key components, and store the root key. In some embodiments, the key injection sub-system may be a cloud-based management sub-system and may also be a user sub-system located at a client terminal.
The cloud user no longer needs to run to the encryption machine hosting region to execute the operation of manually inserting a card, and remote injection of the root key of the virtual encryption device is implemented. Since a quantum key serves as a cross product of quantum mechanics and cryptography, its security is ensured based on the principle of quantum mechanics and has nothing to do with computing power and storage capacity of an attacker, and thus security of the remote key injection process is sufficiently ensured.
In some embodiments, in order to further ensure the security of the root key of the virtual encryption device and also take the cloud user's trust in the cloud provider into account, the number of the key injection sub-system may be less than the greatest integer of the number of preset root key components. The key generation device in each key injection sub-system may generate one root key component of the virtual encryption device. The encryption machine is responsible for generating one root key component of the virtual encryption device, and synthesizing a root key of the virtual encryption device in accordance with the root key component received from each key injection sub-system and the root key component generated by the encryption machine.
The foregoing implementation manner of the system is described below in detail in combination with a traditional encryption machine key system with a relatively popular application, for example, a financial encryption machine key system. The traditional encryption machine key system is made up of three layers: a root key, a user master key and a user work key, in which the root key is composed of three components. The system includes two key injection sub-systems: a cloud-based management sub-system and a user sub-system (also called a cloud user) located at a client terminal. The management sub-system includes: a quantum key distribution device and a management device that undertakes a function of the key generation device. The user sub-system includes: a quantum key distribution device and a terminal device that undertakes a function of the key generation device.
FIGS. 1A and 1B show a block diagram of a cloud-based encryption machine key injection system 100 in different views. The system includes a number of components and sub-components, some of which are optional.
The system 100 may include a management sub-system 101 , an encryption machine hosting sub-system 102 , a first cloud user 103 , and a second cloud user 104 , all connected through a network 105 . In some embodiments, the management sub-system 101 may also be referred to as an encryption machine hosting platform management center of a cloud provider. The management sub-system 101 may include a first management device 111 and a second management device 121 . The management devices
111 and 121 can be responsible for security monitoring, identification, authorized hosting, audit and the like of the encryption machine. The management devices
111 and 121 can include key generation devices for generating root key components and remotely inject the root key components into the encryption machine to make the root key for the virtual encryption device. The management sub-system 101 further includes a first quantum key distribution device 131 and a second quantum key distribution device 141 connected with the aforementioned management devices
111 and 121 respectively. The encryption machine hosting sub-system 102 may also be referred to as an encryption machine hosting region, including a first encryption machine 112 and a second encryption machine 122 that each carry a virtual encryption device. The encryption machine hosting sub-system 102 may include a third quantum key distribution device 132 and a fourth quantum key distribution device 142 connected to the first and second encryption machines
112 and 122 respectively. The third quantum key distribution device 132 and the fourth quantum key distribution device 142 are also connected to the first and second quantum key distribution devices
131 and 141 , as shown in FIG. 1A . The encryption machine hosting sub-system 102 may further include a fifth quantum key distribution device 152 and a sixth quantum key distribution device 162 connected to the cloud users' quantum key distribution devices via network 105 .
The first cloud user 103 includes a first terminal device 113 and a seventh quantum key distribution device 123 . The second cloud user 104 includes a second terminal device 114 and an eighth quantum key distribution device 124 . The first and second terminal devices
113 and 114 may include key generation devices for generating root key components. As shown in FIG. 1A , the seventh quantum key distribution device 123 and eighth quantum key distribution device 124 may be respectively connected to the fifth quantum key distribution device 152 and sixth quantum key distribution device 162 via network 105 . The first and second cloud users may each be a group of devices used by an individual based on a cloud service, and may also be used by enterprise based on the cloud service.
In one example, the first encryption machine 112 carries a virtual encryption device, where a root key is to be injected, hosted by the first cloud user at the cloud. The first management device 111 in the management sub-system 101 is responsible for injecting one root key component into the virtual encryption device. The first and third quantum key distribution devices
131 and 132 may negotiate, between the first management device 111 in the management sub-system 101 and the first encryption machine 112 in the encryption machine hosting sub-system 102 , a shared key pair. The first management device 111 may generate a first root key component of the virtual encryption device through an operation of an administrator of the cloud provider or through an installed key generation and management program, and use a negotiated shared key to perform encryption transmission of the first root key component to the first encryption machine 112 . The first encryption machine 112 uses the same negotiated shared key for decryption, so as to acquire the first root key component injected by the management sub-system 101 .
The fifth and seventh quantum key distribution devices
152 and 123 may negotiate, between the first terminal device 113 of the first could user 103 and the first encryption machine 112 , a shared key pair. The terminal device 113 of the first could user 103 may generate a second root key component of the virtual encryption device through an operation of the first could user 103 or through an installed key generation and management program, and use a negotiated shared key to perform encryption transmission of the second root key component to the first encryption machine 112 . The first encryption machine 112 uses the same negotiated shared key for decryption, so as to acquire the second root key component injected by the user sub-system 101 .
The first encryption machine 112 may randomly generate a third root key component of the virtual encryption device through a key generation module or a tool carried by the first encryption machine 112 . The first encryption machine 112 may receive root key components from one or more key generation devices and synthesize a root key of the virtual encryption device in accordance with the first root key component and the second root key component injected by the management sub-system 101 and the first could user 103 , and the third root key component generated by the first encryption machine 112 . The first encryption machine 112 may synthesize the root key by using different algorithms. For example, the root key may be synthesized by using the three root key components in a manner of addition modulo 2 or a manner of bitwise exclusive-OR, or in a more complicated manner, for example, the root key being synthesized by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
As described above, the cloud provider management sub-system, the cloud user, and the encryption machine each contribute a component for generating the root key. This mechanism decentralizes the rights to generate the root key components. Even if any of the three sides leaks a root key component, security of root key, and thus the services and data of the cloud user at the cloud, will not be endangered, so that the cloud user's trust in the cloud provider is enhanced.
The traditional encryption machine key system usually may include a user master key. It is feasible to store the user master key into the encryption machine. The terminal device (e.g., terminal device 113 ) of the user sub-system may generate a user master key through an operation of the cloud user or through an installed key generation and management program, and use a negotiated shared key to perform encryption transmission of the user master key to the encryption machine. Correspondingly, the encryption machine may store the received user master key as a user master key of the virtual encryption device.
The traditional encryption machine key system may further include a user work key. It is also feasible to store the user work key into the encryption machine. The terminal device (e.g., terminal device 113 ) of the user sub-system may generate a user work key through an operation of the cloud user or through an installed key generation and management program, and use a negotiated shared key to perform encryption transmission of the user work key to the encryption machine as the virtual encryption device. Correspondingly, the encryption machine may store the received user work key as a user work key of the virtual encryption device.
In some embodiments, the key generations or the key component generations as described above can be implemented by key generation devices included in the management devices (e.g., the first management device 111 ) and a user's terminal device (e.g., terminal device 113 ). The key generation devices may also perform encryption transmission of the key components or the keys to the encryption machine. For example, in some embodiments, if the quantum key distribution device does not have a data encryption and decryption function, the key generation device encrypts the root key components or other keys in accordance with a negotiated quantum key provided to it by the quantum key distribution device, and then transmits the root key components or other keys to the encryption machine via a classical channel between the key generation device and the encryption machine. The encryption machine executes a decryption operation to obtain the root key components or the other keys. If the quantum key distribution device has the data encryption and decryption function, that is, the quantum key distribution device is a quantum encryption machine, the key generation device can send the root key components or other keys to a quantum key distribution device connected therewith, and the quantum key distribution device uses a negotiated quantum key for encryption and transmits the encrypted root key components or other keys to the quantum key distribution device at the side of the encryption machine via a classical channel. The quantum key distribution device executes a decryption operation and sends the decrypted root key components or the other keys to the encryption machine.
The user sub-system may own its own quantum key distribution device or rent a quantum key distribution device at the cloud. The physical position of the quantum key distribution device of the user sub-system may not be at the client terminal side but at the cloud. In this case, the terminal device may log into the quantum key distribution device via, for example, VPN, to implement the above-described operations including, for example, acquiring a negotiated shared key or sending a root key component to be injected or a user master key or the like to the quantum key distribution device associated with the encryption machine.
FIGS. 1A and 1B merely illustrate a schematic system architectural diagram of an encryption machine key injection system based on the embodiments of the present application. A person having ordinary skill in the art should appreciate that many changes can be made based on a user's desires. For example, the number of the management device in the management sub-system and the number of the encryption machine in the encryption machine hosting sub-system can be configured in accordance with specific demands; the management sub-system and the encryption machine hosting sub-system may be located at the same network domain at the cloud and may also be located at different network domains, and their quantum key distribution devices can be connected with each other through a routing device having a quantum key relaying function. For another example, the quantum key distribution devices may be omitted, and in this example, the management devices and the terminal devices may negotiate the shared key pairs with the encryption machine. For a further example, as a complete system, a maintenance sub-system may also be included, and the maintenance sub-system can perform initial authorization to the virtual encryption device on the encryption machine carries by an encryption machine device manufacturer. The maintenance sub-system can also perform fault monitoring and maintenance on the encryption machines.
The cloud-based encryption machine key injection system provided in this example organically combines a quantum key technology with a cloud-enabled encryption machine technology. Such an injection system changes the traditional manner of manually inserting a card to inject a root key, achieves remote injection of an encryption machine root key, and ensures security of the remote injection process by quantum cryptography. The injection system thus exempts the necessity that the cloud user goes to a hosting region to manually insert a card, simplifies the operation process of key injection, facilitates a cloud provider to manage the hosting region, and enhances the security of the keys generated by the encryption machine at the cloud. In particular, for example, if more than one key injection sub-system and encryption machine jointly participate in a generation process of root key components, the security of a root key can be substantially improved, and the cloud user's trust in the cloud provider can be further enhanced.
The present application further provides a key injection method for an encryption machine, in which the method is implemented in the aforementioned cloud-based encryption machine key injection system.
In some embodiments, for a virtual encryption device carried by an encryption machine, where a root key is to be injected, in order to achieve remote safe injection of a root key thereof, the method includes the following steps:
1) negotiating, by the key generation device of the key injection sub-system and the encryption machine of the encryption machine hosting sub-system, a shared key pair through their respective quantum key distribution devices, in which the encryption machine carries the virtual encryption device, where a root key is to be injected, hosted by a cloud user at the cloud;
2) generating, by the key generation devices, root key components of the virtual encryption device, and using the negotiated shared key to perform encryption transmission of the root key components to the encryption machine; and
3) synthesizing, by the encryption machine, a root key of the virtual encryption device in accordance with the received root key components, and storing the root key.
In some embodiments, it is feasible that a key injection sub-system (for example, a cloud-based management sub-system or a user sub-system located in a client terminal) generates all the root key components for the virtual encryption device in accordance with a number of preset root key components that may be needed and uses a negotiated shared key to perform encryption transmission of the all root key components to the virtual encryption device on the encryption machine, and the encryption machine decrypts all the root key components and the synthesizes and stores a root key of the virtual encryption device in accordance with the all components received.
In some embodiments, it is also feasible that more than one key injection sub-system and encryption machine jointly participate in the generation of the root key components, and in this case, the encryption machine synthesizes the root key in accordance with the root key components received from different key injection sub-systems and the root key component generated by the encryption machine.
In order to enhance security of the root key and the cloud user's trust in the cloud provider, this example focuses on describing the latter implementation. In this implementation, the number of the key injection sub-system is less than the greatest integer of the number of preset root key components that are needed. In some embodiments, the key generation device, which is responsible for generating a root key component, can be implemented in a key injection sub-system. The key generation device can complete a quantum key agreement with the encryption machine. The key generation device of each key injection sub-system can generate a root key component and performs encryption transmission of the root key component to the encryption machine. The encryption machine can also generate a root key component. The encryption machine then synthesizes a root key of the virtual encryption device in accordance with the aforementioned root key components.
FIG. 2 is a flow diagram of an example of a key injection method 200 for an encryption machine according to the present application. The contents of this example which are the same as those of the example of the cloud-based encryption machine key injection system provided previously are not repeated, and the following focuses on their differences. The key injection method for an encryption machine according to the present application includes:
Step 201 : The management device (e.g., the first management device 111 in FIG. 1B ) and the encryption machine (e.g., the first encryption machine 112 in FIG. 1B ) negotiate a shared key pair through their respective quantum key distribution devices. The encryption machine includes a virtual encryption device, where a root key is to be injected, hosted by a cloud user at a cloud.
In some embodiments, in order to ensure security of a key agreement process and a subsequent root key component injection process, before execution of the quantum key agreement, the management device and the encryption machine may first perform mutual identity authentication. The management device can send an identity authentication request to the encryption machine, the request carrying a private key signature identity certificate of the management device. The encryption machine, after receiving the identity authentication request, decrypts the private key signature identity certificate with a public key corresponding to the management device, and if the decryption is successful, it indicates that the identity of the management device is valid. For the same reason, the encryption machine may also send a private key signature identity certificate of the virtual encryption device that the encryption machine carries to the management device, and the management device uses the same method to verify the identity of the virtual encryption device. In the foregoing mutual identity authentication process, if identity authentication of any side fails, execution of the method is ended.
The above gives an identity authentication manner based on a public/private key pair. While in other implementations, it is also feasible to perform identity authentication in other manners. For example, the encryption machine can send a device identifier (for example, a sequence number preset by a device manufacturer) of the virtual encryption device to the management device, and the management device performs identity authentication on the virtual encryption device by using the device identifier. The public/private key pairs and identity certificates of the management device and the virtual encryption device, the device identifier and other information may be preset in the management device and the virtual encryption device.
In some embodiments, if the management device and the virtual encryption device both pass the identity authentication of the other, the management device and the encryption machine can negotiate a shared key pair in accordance with a quantum key distribution protocol, for example, a BB84 protocol, through their respective quantum key distribution devices.
Step 202 : The management device generates a first root key component of the virtual encryption device, and uses a negotiated shared key to perform encryption transmission of the first root key component to the encryption machine.
In some embodiments, the management device may generate the first root key component of the virtual encryption device through an operation of an administrator of the cloud provider or through an installed key generation and management program, and use a shared key negotiated in step 201 to perform encryption transmission of the first root key component to the encryption machine. The data encryption and decryption functions may be completed by the corresponding management device or encryption machine and may also be completed by a quantum key distribution device. Reference can be made to the related description in the examples of the cloud-based encryption machine key injection system provided above.
Step 203 : The terminal device and the encryption machine negotiate a shared key pair through their respective quantum key distribution devices.
In some embodiments, before execution of a quantum key agreement of the step, the terminal device and the encryption machine may first perform mutual identity authentication between the terminal device and the virtual encryption device, and reference can be made to the description in step 201 for the specific processing flow thereof with respect to the management device and the encryption machine. If the terminal device and the virtual encryption device both pass the identity authentication of the other, the terminal device and the encryption machine can negotiate a shared key pair in accordance with a quantum key distribution protocol, for example, a BB84 protocol, through their respective quantum key distribution devices.
Step 204 : The terminal device generates a second root key component of the virtual encryption device, and uses a negotiated shared key to perform encryption transmission of the second root key component to the encryption machine.
In some embodiments, the terminal device may generate the second root key component of the virtual encryption device through an operation of a cloud user or through an installed key generation and management program, and use a shared key negotiated in step 203 to perform encryption transmission of the second root key component to the encryption machine, in which the data encryption and decryption function may be completed by the corresponding terminal device or encryption machine and may also be completed by a quantum key distribution device. Reference can be made to the related description in the examples of the cloud-based encryption machine key injection system provided above.
Step 205 : The encryption machine generates a third root key component of the virtual encryption device.
<div id="p-0070" num="0069" class="description-paragr
CLAIMS
Claims ( 33 )
What is claimed is:
1. A cloud-based key injection system, comprising:
at least one key injection sub-system including a key generation device and a quantum key distribution device connected with the key generation device; and
a cloud-based encryption machine hosting sub-system including an encryption machine and a quantum key distribution device connected with the encryption machine, wherein:
the encryption machine includes a virtual encryption device,
the key injection sub-system and the encryption machine hosting sub-system are connected with each other through their respective quantum key distribution devices,
the key generation device is configured to generate a root key component and to send the root key component via the quantum key distribution devices to the encryption machine, and
the encryption machine is configured to receive root key components from one or more key generation devices and to generate a root key of the virtual encryption device in accordance with the received root key components.
2. The cloud-based key injection system of claim 1 , wherein:
the quantum key distribution devices are configured to negotiate a shared key pair between the key generation device and the encryption machine, and
the quantum key distribution device of the at least one key injection sub-system is configured to use a negotiated shared key to perform encryption transmission of the root key component to the encryption machine.
3. The cloud-based key injection system of claim 1 , wherein
the at least one key injection sub-system includes one key injection sub-system; and
the key generation device of the key injection sub-system is configured to generate a number of root key components for the virtual encryption device and to send the root key components via the quantum key distribution devices to the encryption machine.
4. The cloud-based key injection system of claim 1 , wherein:
the encryption machine is further configured to generate one root key component for the virtual encryption device and to generate the root key of the virtual encryption device in accordance with the received root key components from the at least one key injection sub-system and from the encryption machine.
5. The cloud-based key injection system of claim 4 , wherein:
the at least one key injection sub-system comprises a cloud-based management sub-system and a user sub-system located at a client terminal;
the management sub-system comprises a quantum key distribution device and a management device including the key generation device; and
the user sub-system comprises a quantum key distribution device and a terminal device including the key generation device.
6. The cloud-based key injection system of claim 5 , wherein the terminal device of the user sub-system is further configured to generate a user master key and to transmit the user master key to the encryption machine.
7. The cloud-based key injection system of claim 6 , wherein the terminal device of the user sub-system is further configured to generate a user work key and to transmit the user work key to the encryption machine.
8. The cloud-based key injection system of claim 1 , wherein the quantum key distribution device comprises a quantum encryption machine having a data encryption and decryption function.
9. The cloud-based key injection system of claim 1 , wherein the encryption machine is configured to generate a root key of the virtual encryption device in accordance with the received root key components by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
10. A key injection method for an encryption machine comprising:
receiving, by the encryption machine, root key components from at least one key injection sub-system; and
generating, by the encryption machine, a root key in accordance with the received root key components from the at least one key injection sub-system, wherein:
the encryption machine is connected to a quantum key distribution device;
each of the at least one key injection sub-system includes a quantum key distribution device; and
receiving, by the encryption machine, the root key components from the at least one key injection sub-system comprises receiving, by the encryption machine, via the quantum key distribution devices, the root key components from the at least one key injection sub-system.
11. The key injection method of claim 10 , wherein:
the encryption machine includes a virtual encryption device; and
the root key is for the virtual encryption device.
12. The key injection method of claim 10 , wherein each root key component is generated by a key generation device of the at least one key injection sub-system.
13. The key injection method of claim 10 , further comprising generating a root key component by the encryption machine, wherein generating, by the encryption machine, the root key in accordance with the received root key components from the at least one key injection sub-systems comprises:
generating, by the encryption machine, the root key in accordance with the received root key components from the at least one key injection sub-system and the root key component generated by the encryption machine.
14. The key injection method of claim 10 , further comprising negotiating, by the encryption machine with each of the at least one key injection sub-system a shared key pair, and wherein the root key components from the at least one key injection sub-system are encrypted with a key in the shared key pair.
15. The key injection method of claim 10 , wherein:
the at least one key injection sub-system comprises a cloud-based management sub-system and a user sub-system located at a client terminal, the cloud-based management sub-system including a key generation device, and the user sub-system including a key generation device.
16. The key injection method of claim 15 , further comprising:
receiving a user master key generated by the user sub-system from the user sub-system.
17. The key injection method of claim 15 , further comprising:
receiving a user work key generated by the user sub-system from the user sub-system.
18. The key injection method of claim 10 , further comprising verifying identities of the at least one key injection sub-system.
19. The key injection method of claim 10 , wherein generating, by the encryption machine, the root key in accordance with the received root key components from the at least one key injection sub-system comprises:
generating, by the encryption machine, a root key in accordance with the received root key components from the at least one key injection sub-system by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
20. A key injection apparatus for an encryption machine, comprising:
a memory storing a set of instructions; and
a processor configured to execute the set of instructions to cause the key injection apparatus for the encryption machine to perform:
negotiating a shared key pair with at least one key injection sub-system;
receiving root key components from the at least one key injection sub-system;
generating a root key component for a virtual encryption device on the encryption machine; and
generating a root key in accordance with the root key component for the virtual encryption device and the root key components received from the at least one key injection sub-system, wherein:
the encryption machine is connected to a quantum key distribution device:
each of the at least one key injection sub-system includes a quantum key distribution device; and
receiving the root key components from the at least one key injection sub-system comprises receiving, via the quantum key distribution devices, the root key components from the at least one key injection sub-system.
21. The key injection apparatus of claim 20 , wherein:
the root key components received from the at least one key injection sub-system are encrypted with a key in the shared key pair.
22. The key injection apparatus of claim 20 , wherein:
the at least one key injection sub-system includes a cloud-based management sub-system including a key generation device and a user sub-system including a key generation device located at a client terminal.
23. The key injection apparatus of claim 20 , further comprising generating the root key by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
24. A non-transitory computer readable medium that stores a set of instructions that is executable by at least one processor of an encryption machine to cause the encryption machine to perform a key injection method comprising:
receiving root key components from at least one key injection sub-system; and
generating a root key in accordance with the received root key components from the at least one key injection sub-system, wherein:
the encryption machine is connected to a quantum key distribution device;
each of the at least one key injection sub-system includes a quantum key distribution device; and
receiving root key components, from the at least one key injection sub-system comprises receiving, via the quantum key distribution devices, the root key components from the at least one key injection sub-system.
25. The computer readable medium of claim 24 , wherein:
the encryption machine includes a virtual encryption device; and
the root key is for the virtual encryption device.
26. The computer readable medium of claim 24 , wherein each root key component is generated by a key generation device of the at least one key injection sub-system.
27. The computer readable medium of claim 24 , wherein the key injection method further comprises generating a root key component by the encryption machine, wherein generating the root key in accordance with the received root key components from the at least one key injection sub-systems comprises:
generating the root key in accordance with the received root key components from the at least one key injection sub-system and the root key component generated by the encryption machine.
28. The computer readable medium of claim 24 , wherein the key injection method further comprises:
negotiating with each of the at least one key injection sub-system a shared key pair, and
wherein the root key components from the at least one key injection sub-system are encrypted with a key in the shared key pair.
29. The computer readable medium of claim 24 , wherein:
the at least one key injection sub-system comprises a cloud-based management sub-system and a user sub-system located at a client terminal, the cloud-based management sub-system including a key generation device, and the user sub-system including a key generation device.
30. The computer readable medium of claim 29 , wherein the key injection method further comprises:
receiving a user master key generated by the user sub-system from the user sub-system.
31. The computer readable medium of claim 29 , wherein the key injection method further comprises:
receiving a user work key generated by the user sub-system from the user sub-system.
32. The computer readable medium of claim 24 , wherein the key injection method further comprises:
verifying identities of the at least one key injection sub-system.
33. The computer readable medium of claim 24 , wherein generating the root key in accordance with the received root key components from the at least one key injection sub-system comprises:
generating the root key in accordance with the received root key components from the at least one key injection sub-system by using a secret reconstruction algorithm based on a threshold secret sharing mechanism.
US15/134,105
2015-04-22
2016-04-20
Method, apparatus, and system for cloud-based encryption machine key injection
Active
2036-07-05
US10305688B2
( en )
Applications Claiming Priority (3)
Application Number
Priority Date
Filing Date
Title
CN201510195062
2015-04-22
CN201510195062.7A
CN106161402B
( en )
2015-04-22
2015-04-22
Encryption equipment key injected system, method and device based on cloud environment
CN201510195062.7
2015-04-22
Publications (2)
Publication Number
Publication Date
US20160315768A1
US20160315768A1 ( en )
2016-10-27
US10305688B2
true
US10305688B2 ( en )
2019-05-28
Family
ID=57148139
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US15/134,105
Active
2036-07-05
US10305688B2
( en )
2015-04-22
2016-04-20
Method, apparatus, and system for cloud-based encryption machine key injection
Country Status (7)
Country
Link
US
( 1 )
US10305688B2
( en )
EP
( 1 )
EP3286867B1
( en )
JP
( 1 )
JP6797828B2
( en )
KR
( 1 )
KR20170139570A
( en )
CN
( 1 )
CN106161402B
( en )
TW
( 1 )
TWI715537B
( en )
WO
( 1 )
WO2016190990A2
( en )
Cited By (3)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20230099471A1
( en )
*
2021-09-30
2023-03-30
Juniper Networks, Inc.
Delayed quantum key-distribution
US12095917B2
( en )
2021-09-10
2024-09-17
International Business Machines Corporation
Securely transporting a root key using a privately/public key pair for user-controlled authentication of nodes in a hardware security module cluster
US12316617B2
( en )
2022-12-02
2025-05-27
Bank Of America Corporation
System for cloud computing security using a quantum encryption algorithm
Families Citing this family (33)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
CN106953732B
( en )
*
2017-03-10
2020-02-07
åæ¹åå¢ä¿¡æ¯å®å ¨ç§ææéå ¬å¸
Key management system and method for chip card
CN108809906B
( en )
*
2017-05-03
2020-07-07
è ¾è®¯ç§æï¼æ·±å³ï¼æéå ¬å¸
Data processing method, system and device
CN109561047B
( en )
2017-09-26
2021-04-13
å®å¾½é®å¤©éåç§æè¡ä»½æéå ¬å¸
Encrypted data storage system and method based on key remote storage
CN107844707B
( en )
*
2017-10-30
2020-12-29
æ·±å³å¸éªçç§ææéå ¬å¸
Card data management method and card data management system
CN108572861A
( en )
*
2018-04-26
2018-09-25
浪潮(å京)çµåä¿¡æ¯äº§ä¸æéå ¬å¸
A kind of guard method, system, equipment and the storage medium of virtual credible root
CN109067527B
( en )
*
2018-08-31
2020-12-22
èå·ç§è¾¾ç§æè¡ä»½æéå ¬å¸
Quantum encryption communication method, communication terminal and computer readable storage medium
CN109299618B
( en )
*
2018-09-20
2020-06-16
å¦è¬éåç§ææéå ¬å¸
Quantum-resistant computing cloud storage method and system based on quantum key card
CN109688141A
( en )
*
2018-12-27
2019-04-26
æå·ç¿¼å ç½ç»ç§ææéå ¬å¸
A kind of physiological parameter data encrypted transmission method
CN109728908B
( en )
*
2019-03-18
2021-10-15
åæ¹çµç½è°å³°è°é¢åçµæéå ¬å¸ä¿¡æ¯éä¿¡åå ¬å¸
Secret key management method based on quantum secure mobile storage medium
CN110011794B
( en )
*
2019-04-11
2021-08-13
å京æºè¯å¾®çµåç§ææéå ¬å¸
Test Methods for Cipher Key Properties
CN110519238B
( en )
*
2019-08-08
2021-11-12
å京å®å¾¡éåç§ææéå ¬å¸
Internet of things security system and communication method based on cryptographic technology
CN112367160B
( en )
*
2019-09-01
2023-09-26
æé½éå®åºåé¾ç§ææéå ¬å¸
A virtual quantum link service method and device
CN110690960B
( en )
*
2019-09-01
2022-02-22
æé½éå®åºåé¾ç§ææéå ¬å¸
Routing service method and device of relay node
CN110837634B
( en )
*
2019-10-24
2023-10-27
æå·å®åç½ç»ç§ææéå ¬å¸
Electronic signature method based on hardware encryption machine
KR102222080B1
( en )
*
2020-02-24
2021-03-04
íêµì ìíµì ì°êµ¬ì
Apparatus and method for authenticating quantum entity
JP7738586B2
( en )
*
2020-06-29
2025-09-12
ã¤ã«ãã ã¤ã³ã³ã¼ãã¬ã¤ããã
Temporary Cloud Provider Credentials via a Secure Discovery Framework
AU2021299262A1
( en )
2020-06-29
2023-01-05
Illumina, Inc.
Policy-based genomic data sharing for software-as-a-service tenants
KR102592873B1
( en )
*
2020-07-03
2023-10-25
íêµì ìíµì ì°êµ¬ì
Quantum Key Distribution Node Apparatus and Method for Quantum Key Distribution thereof
CN111865589B
( en )
*
2020-08-14
2023-09-08
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Quantum communication encryption system and method for realizing mobile communication quantum encryption transmission
CN114117458B
( en )
*
2020-08-29
2025-10-21
åä¸ºææ¯æéå ¬å¸
Key usage methods and related products
CN112769805A
( en )
*
2020-12-31
2021-05-07
æ®åè¯ä¿¡ä¿¡æ¯ææ¯æéå ¬å¸
Cloud password management method, system and storage medium
CN114070640B
( en )
*
2021-11-25
2024-02-06
èªå¤©æ°éç§ææéå ¬å¸
Secure communication method and system
CN114244506B
( en )
*
2021-12-10
2024-04-02
é®å¤©é¼è®¯éåç§æ(æ é¡)æéå ¬å¸
Method and system for quickly synchronizing quantum keys
CN116418485B
( en )
*
2021-12-29
2025-12-23
ç§å¤§å½ç¾éåææ¯è¡ä»½æéå ¬å¸
Quantum key injection method, system and components based on quantum cryptography service platform
CN114499851B
( en )
*
2022-01-30
2023-05-26
éåºé¿å®æ±½è½¦è¡ä»½æéå ¬å¸
Method for realizing safe filling of root keys based on end cloud integration
CN114567438B
( en )
*
2022-03-04
2025-06-06
ä¸å½é¶è¡è¡ä»½æéå ¬å¸
Shared encryption and decryption method and device
US11791994B1
( en )
*
2022-03-31
2023-10-17
Juniper Networks, Inc.
Quantum cryptography in an internet key exchange procedure
CN114531238B
( en )
*
2022-04-24
2022-07-19
ä¸çµä¿¡éåç§ææéå ¬å¸
Secret key safe filling method and system based on quantum secret key distribution
CN115865350B
( en )
*
2023-02-27
2023-05-05
åè¥å·¥ä¸å¤§å¦
A quantum security-based vehicle cloud service system
CN116527259B
( en )
*
2023-07-03
2023-09-19
ä¸çµä¿¡éåç§ææéå ¬å¸
Cross-domain identity authentication method and system based on quantum key distribution network
CN118523909B
( en )
*
2024-06-26
2026-04-24
ç¦å»ºåè ¾èµè®¯æéå ¬å¸
Key filling method and key filling system based on storage medium
CN119544198A
( en )
*
2024-10-24
2025-02-28
ä¸çµä¿¡éåç§ææéå ¬å¸
A key injection and synthesis method and system based on secret sharing algorithm
CN119603272B
( en )
*
2024-11-25
2025-10-10
å京å¯ç äºè¯ç§ææéå ¬å¸
Virtual cipher machine management method, device, equipment, medium and product
Citations (137)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US5515438A
( en )
*
1993-11-24
1996-05-07
International Business Machines Corporation
Quantum key distribution using non-orthogonal macroscopic signals
US20050036624A1
( en )
*
2003-07-25
2005-02-17
Kent Adrian Patrick
Quantum cryptography
US6931128B2
( en )
*
2001-01-16
2005-08-16
Microsoft Corporation
Methods and systems for generating encryption keys using random bit generators
US20050190921A1
( en )
*
2002-10-15
2005-09-01
Bbnt Solutions Llc
Systems and methods for framing quantum cryptographic links
US20060062392A1
( en )
*
2004-07-08
2006-03-23
Magiq Technologies, Inc.
Key manager for QKD networks
US20060088157A1
( en )
*
2004-10-22
2006-04-27
Mikio Fujii
Public key encryption apparatus
US7068790B1
( en )
*
2001-08-31
2006-06-27
Bbn Technologies Corp.
Systems and methods for path set-up in a quantum key distribution network
US20060222180A1
( en )
*
2002-10-15
2006-10-05
Elliott Brig B
Chip-scale transmitter for quantum cryptography
US20070014415A1
( en )
*
2005-06-16
2007-01-18
Harrison Keith A
Quantum key distribution method and apparatus
US20070016534A1
( en )
*
2005-06-16
2007-01-18
Harrison Keith A
Secure transaction method and transaction terminal for use in implementing such method
US20070076884A1
( en )
*
2005-09-30
2007-04-05
Mci, Inc.
Quantum key distribution system
US20070076888A1
( en )
*
2005-09-30
2007-04-05
Nortel Networks Limited
Double phase encoding quantum key distribution
US20070130455A1
( en )
*
2005-12-06
2007-06-07
Elliott Brig B
Series encryption in a quantum cryptographic system
US20070133798A1
( en )
*
2005-12-14
2007-06-14
Elliott Brig B
Quantum cryptography on a multi-drop optical network
US20070140495A1
( en )
*
2003-11-13
2007-06-21
Magiq Technologies, Inc
Qkd with classical bit encryption
US7245722B2
( en )
*
2000-10-06
2007-07-17
Osamu Hirota
System and method for distributing key
US20070234051A1
( en )
*
2006-03-31
2007-10-04
Akutsu Shigeto
Method for synchronization in encrypted communications using shared key
EP1848142A2
( en )
2006-04-19
2007-10-24
Nec Corporation
Secret communications system and channel control method
US20070248362A1
( en )
*
2006-04-20
2007-10-25
Nec Corporation
Optical communication device and quantum key distribution system using the same
US20080037790A1
( en )
*
2006-08-14
2008-02-14
Magiq Technologies, Inc.
Frame synchronization method for QKD systems
US20080144836A1
( en )
2006-12-13
2008-06-19
Barry Sanders
Distributed encryption authentication methods and systems
US20080152147A1
( en )
*
2006-12-21
2008-06-26
Verizon Services Operations, Inc.
Large scale quantum cryptographic key distribution network
US7430295B1
( en )
*
2003-03-21
2008-09-30
Bbn Technologies Corp.
Simple untrusted network for quantum cryptography
US20080263363A1
( en )
*
2007-01-22
2008-10-23
Spyrus, Inc.
Portable Data Encryption Device with Configurable Security Functionality and Method for File Encryption
US20090003591A1
( en )
*
2006-03-06
2009-01-01
National University Corporation NARA Institute of Science and Technology
Quantum Cryptographic Communication Method
US20090044170A1
( en )
*
2007-08-10
2009-02-12
Microsoft Corporation
Automated Application Modeling for Application Virtualization
US20090064086A1
( en )
*
2007-08-31
2009-03-05
Norman Lee Faus
Systems and methods for packaging an application
US20090074192A1
( en )
*
2007-09-19
2009-03-19
Magiq Technologies, Inc.
Systems and methods for enhanced quantum key formation using an actively compensated QKD system
US7519814B2
( en )
*
2003-09-15
2009-04-14
Trigence Corp.
System for containerization of application sets
US20090106553A1
( en )
*
2007-10-23
2009-04-23
Jingyi Wang
Method and system utilizing quantum authentication
US20090169015A1
( en )
*
2005-01-24
2009-07-02
Inter-Univ Res Ins Corp / Res Org Of Info And Syst
Quantum key distribution method, communication system, and communication device
US20090271787A1
( en )
*
2008-04-25
2009-10-29
Vmware, Inc.
Linking virtualized application namespaces at runtime
US7627126B1
( en )
*
2002-10-15
2009-12-01
Bbn Technologies Corp.
Systems and methods for implementing path length control for quantum cryptographic systems
US20090316901A1
( en )
*
2006-07-26
2009-12-24
Japan Science And Technology Agency
Secret communication method and secret communication device thereof
US20100023934A1
( en )
*
2008-07-28
2010-01-28
Microsoft Corporation
Computer Application Packages with Customizations
US20100020964A1
( en )
*
2007-02-20
2010-01-28
Oki Electric Industry Co., Ltd.
Key generation method using quadratic-hyperbolic curve group
US20100034390A1
( en )
*
2005-11-04
2010-02-11
Yoshihisa Yamamoto
Differential Phase Shift Keying Quantum Key Distribution
US7697693B1
( en )
*
2004-03-09
2010-04-13
Bbn Technologies Corp.
Quantum cryptography with multi-party randomness
US7706535B1
( en )
*
2003-03-21
2010-04-27
Bbn Technologies Corp.
Systems and methods for implementing routing protocols and algorithms for quantum cryptographic key transport
US20100138823A1
( en )
*
2007-06-27
2010-06-03
Installsheild Company, Inc.
Method and system for software virtualization directly from an installation package
US20100158252A1
( en )
*
2008-12-22
2010-06-24
Electronics And Telecommunication Research Institute
Polarization coding quantum cryptography system
US20100195831A1
( en )
*
2007-07-13
2010-08-05
Akihiro Tanaka
Quantum key distribution system, optical transmitter, optical modulation control circuit, and optical modulation control method
US20100208893A1
( en )
*
2007-09-05
2010-08-19
National Institute Of Information And Communications Technology
Apparatus and method for quantum cryptography communication
US20100293380A1
( en )
*
2008-01-25
2010-11-18
Qinetiq Limited
Quantum cryptography apparatus
US20100299526A1
( en )
*
2008-01-25
2010-11-25
Qinetiq Limited
Network having quantum key distribution
US20110035747A1
( en )
*
2008-03-07
2011-02-10
Fumio Machida
Virtual machine package generation system, virtual machine package generation method, and virtual machine package generation program
US20110055585A1
( en )
*
2008-07-25
2011-03-03
Kok-Wah Lee
Methods and Systems to Create Big Memorizable Secrets and Their Applications in Information Engineering
US20110064222A1
( en )
*
2008-05-19
2011-03-17
Qinetiq Limited
Quantum key distribution involving moveable key device
US20110075839A1
( en )
*
2008-05-30
2011-03-31
Electronics And Telecommunications Research Institute
System and method for quantum cryptography
US20110126197A1
( en )
*
2009-11-25
2011-05-26
Novell, Inc.
System and method for controlling cloud and virtualized data centers in an intelligent workload management system
US20110213979A1
( en )
*
2008-10-27
2011-09-01
Qinetiq Limited
Quantum key distribution
US20110231665A1
( en )
*
2008-12-05
2011-09-22
Qinetiq Limited
Method of performing authentication between network nodes
US20110228937A1
( en )
*
2008-12-05
2011-09-22
Qinetiq Limited
Method of establishing a quantum key for use between network nodes
US20110243331A1
( en )
*
2008-12-10
2011-10-06
Nec Corporation
Shared random numbers management method and management system in secret communication network
US20110265164A1
( en )
*
2010-04-26
2011-10-27
Vmware, Inc.
Cloud platform architecture
US20110271279A1
( en )
*
2010-04-29
2011-11-03
High Cloud Security, Inc.
Secure Virtual Machine
US20110280405A1
( en )
*
2010-05-17
2011-11-17
Raytheon Bbn Technologies Corp.
Systems and methods for stabilization of interferometers for quantum key distribution
US8082443B2
( en )
*
2006-01-09
2011-12-20
Bbnt Solutions Llc.
Pedigrees for quantum cryptography
US20120087495A1
( en )
*
2009-07-03
2012-04-12
Kelisec Ab
Method for generating an encryption/decryption key
US8213616B2
( en )
*
2006-09-18
2012-07-03
Georgia Tech Research Corporation
Systems and methods for providing opportunistic security for physical communication channels
US8213607B2
( en )
*
2006-10-18
2012-07-03
Qualcomm Incorporated
Method for securely extending key stream to encrypt high-entropy data
US20120177201A1
( en )
*
2009-09-29
2012-07-12
Qinetiq Limited
Methods and apparatus for use in quantum key distribution
US20120246634A1
( en )
*
2011-03-23
2012-09-27
Dell Products L.P.
Portable virtual applications
US20120331463A1
( en )
*
2011-06-27
2012-12-27
France Telecom
Method for providing an on-demand software execution service
US20130051559A1
( en )
*
2011-08-26
2013-02-28
Shinichi Baba
Key sharing device, key sharing method, and computer program product
US20130083926A1
( en )
*
2011-09-30
2013-04-04
Los Alamos National Security, Llc
Quantum key management
US20130101121A1
( en )
*
2010-06-15
2013-04-25
Los Alamos National Security Llc
Secure multi-party communication with quantum key distribution managed by trusted authority
US20130101119A1
( en )
2010-06-15
2013-04-25
Los Alamos National Security Llc
Quantum key distribution using card, base station and trusted authority
US20130132950A1