ABSTRACT
Abstract
A mobile secret communications method based on a quantum key distribution network, comprises the following steps: a mobile terminal registering to access the network and establishing a binding relationship with a certain centralized control station in the quantum key distribution network; after a communication service is initiated, the mobile terminals participating in the current communication applying for service keys from the quantum key distribution network; the quantum key distribution network obtaining addresses of the centralized control stations participating in service key distribution during the current communication, designating a service key generation centralized control station according to a current state indicator of each centralized control station; the service key generation centralized control station generating service keys required in the current communication and distributing the keys to the mobile terminals participating in the current communication.
Description
The present application is a continuation-in-part of U.S. patent application Ser. No. 14/896,237, filed on Dec. 4, 2015, which is a national phase of International Application No. PCT/CN2014/079380 titled âMOBILE SECRET COMMUNICATIONS METHOD BASED ON QUANTUM KEY DISTRIBUTION NETWORKâ, filed on Jun. 6, 2014, which claims the priority to Chinese Patent Application No. 201310228383.3, titled âMOBILE SECRET COMMUNICATIONS METHOD BASED ON QUANTUM KEY DISTRIBUTION NETWORKâ, filed on Jun. 8, 2013 with the State Intellectual Property Office of People's Republic of China, which are incorporated herein by reference in their entirety.
TECHNICAL FIELD
The disclosure relates to the field of mobile communication encryption, and in particular to a mobile secure communication method based on a quantum key distribution network.
BACKGROUND
A modern cryptography system is mainly based on unidirectivity of computation, of which security is achieved only through experience; a future quantum computer makes fast prime factorization algorithm possible, thus foundations of the conventional cryptosystem are no longer required. The quantum key distribution technology is a new means of communication encryption emerging in recent years, which uses the single-photon quantum states encoding information to distribute a same string of random numbers of arbitrary length between a quantum signal transmitter and a quantum signal receiver located at different places, i.e., both sharing a large number of random keys. The random keys can be used to encrypt information to be transmitted between the two places. Due to the indivisibility of a single photon and quantum no-cloning theorem, the quantum key distribution can't be eavesdropped according to physical principles, having the highest level of security at present. If classical information is encrypted and decrypted by OTP (One-Time Pad), unconditional security for information transmission will be guaranteed.
In current technology, taking into account decay of the single photon in an optical-fiber channel and detection efficiency of a detector, it is hard to generate a shared quantum key available for practical secure communication if distance between the two places is beyond a certain scope. Thus, it is required to introduce trusted relay equipment between the two places, which are far away from each other, for quantum secure communication.
According to conventional mobile encryption systems and communication methods based on the quantum key distribution network, a mobile terminal is registered for accessing the network and then is connected to a quantum terminal, and applies to the quantum terminal for shared keys with a certain amount. After downloading the keys, the mobile terminal has a binding relationship with a specific quantum centralized control station, registers with the quantum centralized control station, and uses the quantum centralized control station as a calling centralized control station. When the mobile terminal communicates, the mobile terminal transfers ciphertext to the calling centralized control station. The calling centralized control station re-encrypts the ciphertext and transfers the ciphertext to a called centralized control station. The called centralized control station re-encrypts the ciphertext and transfers the ciphertext to a called user. The called user decrypts the ciphertext for plaintext, and the communication ends.
The technical solution may work well in mobile communication, but there are certain limitations for it is difficult to meet all mobile communication requirements. Ciphertext relay mobile secure communication is adopted in the foregoing technical solution. That is, the ciphertext, i.e., encrypted effective communication information load (plaintext information, such as short message and voice), is transferred among quantum centralized control stations in a quantum secure communication network. The transfer of the ciphertext data stream follows the path âcalling terminalâcalling centralized control stationârelay centralized control station(s) (number: 0-n)âcalled centralized control stationâcalled terminalâ. This path is different from that of the data stream in some conventional mobile communication services, such as SIP call. During the call, the voice data stream is directly transferred between two mobile terminal devices in the form of point-to-point without flowing through the secure quantum communication network. Another example is SMS short message. The short message sent from the mobile phone is transferred through a proprietary network of telecom operators (China Mobile, China Telecom, China Unicom, etc.), without flowing through the secure quantum communication network either. Thus, for the above mentioned communication services with a proprietary data stream path, the ciphertext relay is a little troublesome. If necessary, the ciphertext relay can be adopted in these services usually by two ways. According to the first way, large-scale modifications are made to a conventional service link and logic, and a quantum security function is introduced. For example, if the SMS short message needs to be encrypted through the ciphertext relay, the network of telecom operators has to be changed to include quantum devices matching the nodes in the networks of China Mobile or China Unicom when the short message follows through the nodes, which complicates the whole system drastically and increases development and configuration costs. According to the second way, the conventional service link is abandoned, and a proprietary service link is established in the quantum secure network. The foregoing SMS is still taken as an example. The short message sent by the mobile phone is transferred to the quantum secure network wirelessly, without passing through the networks of telecom operators, and then is sent to a receiver through ciphertext relay. In this way, mobile terminals need to be customized, and communication services need to be realized in the quantum secure network (for example, in order to receive and send short messages in the ciphertext relay mobile secure communication scheme, it is required to provide a short message server in the quantum secure network first, and then modify the mobile terminal. Thus the short message is directly sent to the proprietary short message server without passing through networks of telecom operators). The cost is high, realization is complicated, and products are not compatible with conventional networks of telecom operators, which is disadvantageous for promotion.
In addition, characteristics of the ciphertext relay mobile secure communication determine the following content: only when a specific service between two communicating parties is truly established, and the plaintext required to be transferred is generated, encryption and transfer may be started. If there are too many relay nodes in the transferring path and the transfer takes long time, service delay is bound to be increased. For communication services with a high real-time requirement (such as SIP voice call, video call, etc.), user experience may be poor.
Hence, key relay mobile secure communication is adopted in the disclosure to solve the above problems. That is, the data relayed between centralized control stations is the service keys required by the communication instead of the ciphertext. Due to the characteristics of the quantum key, the generation of a shared quantum key is limited by the distance between two places. Thus new trusted relay devices need to be provided between the two places to relay the practical communication service keys if a quantum key distribution network with specific physical coverage is to be built. In some communication services with high real-time requirement, even if the key relay mobile secure communication is adopted, there could be a problem of delayed arrival of the keys caused by a large number of concurrent calls and relay nodes and long time consumed in the generation and relay of the service keys, which lowers the quality of service.
SUMMARY
In view of this, a mobile secure communication method based on a quantum key distribution network is provided. An improved solution for key relay mobile secure communication is adopted, which can meet some of mobile communication service requirements for which the technology of ciphertext relay mobile secure communication is not convenient in practice. Improvement is also made to current solutions in terms of service key generation and key relay, and quality issues caused by delayed arrival of the keys when there are lots of concurrent communication services and relay nodes are improved.
To achieve the above objective, the following technical solution is adopted.
A mobile secure communication method based on a quantum key distribution network is provided, including:
(1) registering mobile terminals to access the network and obtain unique quantum identity numbers;
(2) establishing a binding relationship and sharing keys between each mobile terminal and a centralized control station in the quantum key distribution network;
(3) after a communication service is initiated, sending respectively, by a calling mobile terminal and a called mobile terminal, a service information packet and a called-party response information packet to a quantum network management server in the quantum key distribution network, to apply for service keys for the communication;
(4) obtaining, by the quantum key distribution network, addresses of a calling centralized control station, a called centralized control station, and centralized control stations participating in relaying the service keys in the communication;
(5) collecting, by the quantum key distribution network, current state indicators of centralized control stations participating in distributing the service keys in the communication to designate a centralized control station for service key generation in the communication, send the service information packet to the centralized control station for service key generation, and command the centralized control station for service key generation to generate the service keys required by the communication;
(6) generating and encrypting, by the centralized control station for service key generation, the service keys required by the communication, and distributing, by the centralized control station for service key generation, the encrypted service keys to the mobile terminals participating in the communication;
(7) obtaining and decrypting, by the mobile terminals, the encrypted service keys distributed by a centralized control station(s) bound to the mobile terminals, wherein the mobile terminals decrypt the encrypted service keys through the keys shared with the centralized control station(s) bound to the mobile terminals, to obtain the service keys for the communication;
(8) performing, by the mobile terminals participating in the communication, secure communication with the service keys through an original data link of the communication service.
The âbinding relationshipâ in the step (2) is characterized by:
(2-1) a mobile terminal which has already been registered to access the network has a unique quantum identity number in the quantum key distribution network;
(2-2) one mobile terminal cannot be bound to a plurality of centralized control stations during the same period;
(2-3) it is allowed to bind zero, one or more mobile terminals to one centralized control station during the same period;
(2-4) the binding relationship between mobile terminals and centralized control stations is stored in the quantum network management server in the quantum key distribution network;
(2-5) a mobile terminal and a centralized control station bound to the mobile terminal share keys.
In the step (4), the quantum key distribution network obtaining addresses of centralized control stations participating in distributing the service keys in the communication includes:
the quantum network management server obtaining the addresses of the calling centralized control station and the called centralized control station in the communication, based on information related to the calling mobile terminal and the called mobile terminal in the received information packets and the binding relationship between the centralized control station and the mobile terminal; and querying a stored relay routing table for the service keys, and obtaining the addresses of relay centralized control stations between the calling centralized control station and the called centralized control station in the communication.
In the step (5), the quantum key distribution network designating the centralized control station for service key generation in the communication, and commanding the centralized control station for service key generation to generate the service keys required by the communication includes:
(5-1) the quantum network management server sending an instruction to the calling centralized control station, the called centralized control station, and the relay centralized control stations between the calling centralized control station and the called centralized control station, which are related to the communication, to command the centralized control stations to upload respective current state indicators to the quantum network management server;
(5-2) the quantum network management server collecting the current state indicators of the centralized control stations, and designating the centralized control station for service key generation in the communication based on the current state indicators;
(5-3) the quantum network management server adding the addresses of the calling centralized control station and the called centralized control station in the communication into the service information packet sent from the calling mobile terminal, making a copy of the service information packet, designating, in the two service information packets, the calling centralized control station and the called centralized control station as the target centralized control station respectively, and sending the two service information packets to the centralized control station for service key generation in the communication, to command the centralized control station for service key generation to generate the service keys required by the communication.
In the step (5), the current state indicators of the centralized control stations include:
<1> an indicator reflecting a heavy state for service key generation tasks which the centralized control station is currently burdened with, wherein the indicator is a quantitative indicator and includes:
<1-1> a rated service key generation rate of the centralized control station;
<1-2> the number of groups of the secure communication services for which the centralized control station is currently generating service keys;
<1-3> an amount of service keys to be generated currently by the centralized control station;
<1-4> an actual generation rate and a consumption rate of each of the groups of service keys which are designated to be generated by the centralized control station;
<1-5> an amount of service keys which are generated and an amount of service keys which are consumed, for each of the groups of the service keys which are designated to be generated by the centralized control station;
<2> an indicator reflecting a current location state of the centralized control station in the quantum key distribution network, wherein the indicator is a quantitative indicator and comprises:
<2-1> the number of other centralized control stations with which the centralized c
The present application is a continuation-in-part of U.S. patent application Ser. No. 14/896,237, filed on Dec. 4, 2015, which is a national phase of International Application No. PCT/CN2014/079380 titled âMOBILE SECRET COMMUNICATIONS METHOD BASED ON QUANTUM KEY DISTRIBUTION NETWORKâ, filed on Jun. 6, 2014, which claims the priority to Chinese Patent Application No. 201310228383.3, titled âMOBILE SECRET COMMUNICATIONS METHOD BASED ON QUANTUM KEY DISTRIBUTION NETWORKâ, filed on Jun. 8, 2013 with the State Intellectual Property Office of People's Republic of China, which are incorporated herein by reference in their entirety.
TECHNICAL FIELD
The disclosure relates to the field of mobile communication encryption, and in particular to a mobile secure communication method based on a quantum key distribution network.
BACKGROUND
A modern cryptography system is mainly based on unidirectivity of computation, of which security is achieved only through experience; a future quantum computer makes fast prime factorization algorithm possible, thus foundations of the conventional cryptosystem are no longer required. The quantum key distribution technology is a new means of communication encryption emerging in recent years, which uses the single-photon quantum states encoding information to distribute a same string of random numbers of arbitrary length between a quantum signal transmitter and a quantum signal receiver located at different places, i.e., both sharing a large number of random keys. The random keys can be used to encrypt information to be transmitted between the two places. Due to the indivisibility of a single photon and quantum no-cloning theorem, the quantum key distribution can't be eavesdropped according to physical principles, having the highest level of security at present. If classical information is encrypted and decrypted by OTP (One-Time Pad), unconditional security for information transmission will be guaranteed.
In current technology, taking into account decay of the single photon in an optical-fiber channel and detection efficiency of a detector, it is hard to generate a shared quantum key available for practical secure communication if distance between the two places is beyond a certain scope. Thus, it is required to introduce trusted relay equipment between the two places, which are far away from each other, for quantum secure communication.
According to conventional mobile encryption systems and communication methods based on the quantum key distribution network, a mobile terminal is registered for accessing the network and then is connected to a quantum terminal, and applies to the quantum terminal for shared keys with a certain amount. After downloading the keys, the mobile terminal has a binding relationship with a specific quantum centralized control station, registers with the quantum centralized control station, and uses the quantum centralized control station as a calling centralized control station. When the mobile terminal communicates, the mobile terminal transfers ciphertext to the calling centralized control station. The calling centralized control station re-encrypts the ciphertext and transfers the ciphertext to a called centralized control station. The called centralized control station re-encrypts the ciphertext and transfers the ciphertext to a called user. The called user decrypts the ciphertext for plaintext, and the communication ends.
The technical solution may work well in mobile communication, but there are certain limitations for it is difficult to meet all mobile communication requirements. Ciphertext relay mobile secure communication is adopted in the foregoing technical solution. That is, the ciphertext, i.e., encrypted effective communication information load (plaintext information, such as short message and voice), is transferred among quantum centralized control stations in a quantum secure communication network. The transfer of the ciphertext data stream follows the path âcalling terminalâcalling centralized control stationârelay centralized control station(s) (number: 0-n)âcalled centralized control stationâcalled terminalâ. This path is different from that of the data stream in some conventional mobile communication services, such as SIP call. During the call, the voice data stream is directly transferred between two mobile terminal devices in the form of point-to-point without flowing through the secure quantum communication network. Another example is SMS short message. The short message sent from the mobile phone is transferred through a proprietary network of telecom operators (China Mobile, China Telecom, China Unicom, etc.), without flowing through the secure quantum communication network either. Thus, for the above mentioned communication services with a proprietary data stream path, the ciphertext relay is a little troublesome. If necessary, the ciphertext relay can be adopted in these services usually by two ways. According to the first way, large-scale modifications are made to a conventional service link and logic, and a quantum security function is introduced. For example, if the SMS short message needs to be encrypted through the ciphertext relay, the network of telecom operators has to be changed to include quantum devices matching the nodes in the networks of China Mobile or China Unicom when the short message follows through the nodes, which complicates the whole system drastically and increases development and configuration costs. According to the second way, the conventional service link is abandoned, and a proprietary service link is established in the quantum secure network. The foregoing SMS is still taken as an example. The short message sent by the mobile phone is transferred to the quantum secure network wirelessly, without passing through the networks of telecom operators, and then is sent to a receiver through ciphertext relay. In this way, mobile terminals need to be customized, and communication services need to be realized in the quantum secure network (for example, in order to receive and send short messages in the ciphertext relay mobile secure communication scheme, it is required to provide a short message server in the quantum secure network first, and then modify the mobile terminal. Thus the short message is directly sent to the proprietary short message server without passing through networks of telecom operators). The cost is high, realization is complicated, and products are not compatible with conventional networks of telecom operators, which is disadvantageous for promotion.
In addition, characteristics of the ciphertext relay mobile secure communication determine the following content: only when a specific service between two communicating parties is truly established, and the plaintext required to be transferred is generated, encryption and transfer may be started. If there are too many relay nodes in the transferring path and the transfer takes long time, service delay is bound to be increased. For communication services with a high real-time requirement (such as SIP voice call, video call, etc.), user experience may be poor.
Hence, key relay mobile secure communication is adopted in the disclosure to solve the above problems. That is, the data relayed between centralized control stations is the service keys required by the communication instead of the ciphertext. Due to the characteristics of the quantum key, the generation of a shared quantum key is limited by the distance between two places. Thus new trusted relay devices need to be provided between the two places to relay the practical communication service keys if a quantum key distribution network with specific physical coverage is to be built. In some communication services with high real-time requirement, even if the key relay mobile secure communication is adopted, there could be a problem of delayed arrival of the keys caused by a large number of concurrent calls and relay nodes and long time consumed in the generation and relay of the service keys, which lowers the quality of service.
SUMMARY
In view of this, a mobile secure communication method based on a quantum key distribution network is provided. An improved solution for key relay mobile secure communication is adopted, which can meet some of mobile communication service requirements for which the technology of ciphertext relay mobile secure communication is not convenient in practice. Improvement is also made to current solutions in terms of service key generation and key relay, and quality issues caused by delayed arrival of the keys when there are lots of concurrent communication services and relay nodes are improved.
To achieve the above objective, the following technical solution is adopted.
A mobile secure communication method based on a quantum key distribution network is provided, including:
(1) registering mobile terminals to access the network and obtain unique quantum identity numbers;
(2) establishing a binding relationship and sharing keys between each mobile terminal and a centralized control station in the quantum key distribution network;
(3) after a communication service is initiated, sending respectively, by a calling mobile terminal and a called mobile terminal, a service information packet and a called-party response information packet to a quantum network management server in the quantum key distribution network, to apply for service keys for the communication;
(4) obtaining, by the quantum key distribution network, addresses of a calling centralized control station, a called centralized control station, and centralized control stations participating in relaying the service keys in the communication;
(5) collecting, by the quantum key distribution network, current state indicators of centralized control stations participating in distributing the service keys in the communication to designate a centralized control station for service key generation in the communication, send the service information packet to the centralized control station for service key generation, and command the centralized control station for service key generation to generate the service keys required by the communication;
(6) generating and encrypting, by the centralized control station for service key generation, the service keys required by the communication, and distributing, by the centralized control station for service key generation, the encrypted service keys to the mobile terminals participating in the communication;
(7) obtaining and decrypting, by the mobile terminals, the encrypted service keys distributed by a centralized control station(s) bound to the mobile terminals, wherein the mobile terminals decrypt the encrypted service keys through the keys shared with the centralized control station(s) bound to the mobile terminals, to obtain the service keys for the communication;
(8) performing, by the mobile terminals participating in the communication, secure communication with the service keys through an original data link of the communication service.
The âbinding relationshipâ in the step (2) is characterized by:
(2-1) a mobile terminal which has already been registered to access the network has a unique quantum identity number in the quantum key distribution network;
(2-2) one mobile terminal cannot be bound to a plurality of centralized control stations during the same period;
(2-3) it is allowed to bind zero, one or more mobile terminals to one centralized control station during the same period;
(2-4) the binding relationship between mobile terminals and centralized control stations is stored in the quantum network management server in the quantum key distribution network;
(2-5) a mobile terminal and a centralized control station bound to the mobile terminal share keys.
In the step (4), the quantum key distribution network obtaining addresses of centralized control stations participating in distributing the service keys in the communication includes:
the quantum network management server obtaining the addresses of the calling centralized control station and the called centralized control station in the communication, based on information related to the calling mobile terminal and the called mobile terminal in the received information packets and the binding relationship between the centralized control station and the mobile terminal; and querying a stored relay routing table for the service keys, and obtaining the addresses of relay centralized control stations between the calling centralized control station and the called centralized control station in the communication.
In the step (5), the quantum key distribution network designating the centralized control station for service key generation in the communication, and commanding the centralized control station for service key generation to generate the service keys required by the communication includes:
(5-1) the quantum network management server sending an instruction to the calling centralized control station, the called centralized control station, and the relay centralized control stations between the calling centralized control station and the called centralized control station, which are related to the communication, to command the centralized control stations to upload respective current state indicators to the quantum network management server;
(5-2) the quantum network management server collecting the current state indicators of the centralized control stations, and designating the centralized control station for service key generation in the communication based on the current state indicators;
(5-3) the quantum network management server adding the addresses of the calling centralized control station and the called centralized control station in the communication into the service information packet sent from the calling mobile terminal, making a copy of the service information packet, designating, in the two service information packets, the calling centralized control station and the called centralized control station as the target centralized control station respectively, and sending the two service information packets to the centralized control station for service key generation in the communication, to command the centralized control station for service key generation to generate the service keys required by the communication.
In the step (5), the current state indicators of the centralized control stations include:
<1> an indicator reflecting a heavy state for service key generation tasks which the centralized control station is currently burdened with, wherein the indicator is a quantitative indicator and includes:
<1-1> a rated service key generation rate of the centralized control station;
<1-2> the number of groups of the secure communication services for which the centralized control station is currently generating service keys;
<1-3> an amount of service keys to be generated currently by the centralized control station;
<1-4> an actual generation rate and a consumption rate of each of the groups of service keys which are designated to be generated by the centralized control station;
<1-5> an amount of service keys which are generated and an amount of service keys which are consumed, for each of the groups of the service keys which are designated to be generated by the centralized control station;
<2> an indicator reflecting a current location state of the centralized control station in the quantum key distribution network, wherein the indicator is a quantitative indicator and comprises:
<2-1> the number of other centralized control stations with which the centralized control station shares quantum channels, thus shared keys may be generated;
<2-2> the number of hops between the centralized control station and other centralized control stations;
<3> any combination of one or more items among the above seven state indicators.
Further, in the step (6), the centralized control station for service key generation distributing the encrypted service keys to the mobile terminals participating in the communication includes:
(6-1) the centralized control station for service key generation respectively analyzing content of the two service information packets sent by the quantum network management server, if the target centralized control station designated in the service information packet is the centralized control station itself, encrypting the service keys with the keys shared between the centralized control station and the calling mobile terminal or the called mobile terminal participating in the communication, and then sending the encrypted service keys to the calling mobile terminal or the called mobile terminal; if the target centralized control station designated in the service information packet is not the centralized control station itself, searching in a relay routing table for the service keys for a next hop centralized control station leading to the target centralized control station, encrypting the service keys for the communication with the keys shared with the next hop centralized control station, and then sending the encrypted service keys along with the service information packet to the next hop centralized control station;
(6-2) after receiving the encrypted service keys and the service information packet relayed from a last hop centralized control station, a centralized control station decrypting the received service keys with the keys shared with the last hop centralized control station at first, and then performing processes according to (6-1).
In the step (6-1) and (6-2), the centralized control station receiving the service keys relayed from the last hop centralized control station, and then sending the service keys to the next hop centralized control station or a mobile terminal, is characterized by: the centralized control station starts encrypting and forwarding the service keys at the beginning of receiving and decrypting a first frame data of the service keys, rather than after completely receiving the service keys for the communication from the last hop centralized control station; or a threshold is set, and once an amount of decrypted service keys is greater than the threshold, the centralized control station starts encrypting and forwarding the service keys; a dynamic upper limit of the amount of encrypted and forwarded service keys is the amount of service keys received and decrypted currently; and during the same period, the service keys for the communication are in a state of concurrent relaying among a plurality of centralized control stations.
The relay routing table for the service keys consists of records, and each record comprises: [address of local station] [address of target] [address of next hop]; a respective relay routing table for the service keys is stored in each of the centralized control stations in the quantum key distribution network; current relay routing tables for the service keys for centralized control stations are stored in the quantum network management server; the relay routing table for the service keys is updated with changes of a topology of the quantum key distribution network.
Main functions of the quantum network management server include: storing, maintaining and querying the âbinding relationshipâ between centralized control stations and mobile terminals, and the ârelay routing table for the service keysâ; distributing a unique quantum identity number in the network to a mobile terminal which is newly registered to access the network; maintaining classic network connections to centralized control stations; determining legality of a mobile terminal based on received information associated with the mobile terminal; collecting current state indicators of centralized control stations participating in service key distribution, determining and designating the centralized control station for service key generation, and generating and sending new service information packets to the centralized control station; querying addresses of centralized control stations located in a region where the mobile terminal is located, according to a geographic location of the mobile terminal; communicating with centralized control stations, and sending instructions to the centralized control stations.
Preferably, when the quantum key distribution network distributes service keys for a non-real-time non-bidirectional interactive communication service:
<1> after receiving an application for the service keys from the calling mobile terminal, the quantum key distribution network directly designates the centralized control station for service key generation for the communication instead of collecting the current state indicators of the centralized control stations, commands the centralized control station for service key generation to generate the service keys required by the communication, distributes the service keys to the calling mobile terminal, and relays the service keys to the called centralized control station; the calling mobile terminal encrypts plaintext with the service keys to obtain ciphertext and sends the ciphertext to the called mobile terminal, and the called mobile terminal applies to the quantum key distribution network for the service keys and downloads the service keys from the called centralized control station after receiving the ciphertext;
<2> the quantum key distribution network retains the service information packet sent from the calling mobile terminal for a period of time, matches the service information packet with a called-party response information packet sent from the called mobile terminal, in order to distribute to the called mobile terminal the service keys which are the same as the ones distributed to the calling mobile terminal; a threshold time is set for the period, and if the called-party response information packet is not received when the threshold time is reached, the quantum key distribution network destroys the service keys generated for the communication.
Preferably, when geographic location of a mobile terminal changes, the binding relationship is established between the mobile terminal and a centralized control station currently located in a region where the mobile terminal is located; and the keys shared between the mobile terminal and an original centralized control station bound to the mobile terminal are transferred to a new centralized control station bound to the mobile terminal after being encrypted, the new centralized control station bound to the mobile terminal shares the keys with the mobile terminal after decrypting the keys.
Beneficial effects of the disclosure:
(1) Through the calling mobile terminal-centralized control stations in the quantum key distribution networkâthe called mobile terminal, what are transferred are not the ciphertext of encrypted service information, but are the encrypted service keys. The ciphertext are still transferred through an original data link of a specific service, and arrive at the mobile terminal through a path different from that for the keys, and the encryption and decryption for the service information are only performed once at the mobile terminal. This is referred to as key relay mobile secure communication, with better compatibility with existing communication services. It is only required to connect the data flow transmission path for the original mobile communication service to a new quantum key distribution network, without changing the data flow transmission path, and application scope of the quantum secure network is extended. Implementation is relatively easier, modification cost is low, and construction period is short.
(2) For communication services with high real-time requirement, such as voice call service, improved quality of calling and reduced delay can be achieved. An SIP call is taken as example:
After the calling end dials, the called end receives the call and begins to ring. From the beginning of ringing because of reception of the call to the moment the called end presses the answer key, there is an interval of several seconds, and this interval can be used to transfer and download the service keys required by the communication. When the call is completely established, parts of the service keys have been already downloaded, and may even have been downloaded completely. This cannot be achieved in the ciphertext relay mobile secure communication, where voice plaintext may be encrypted only after the voice call between two parties begins and the voice plaintext are generated, and then the relay transmission begins stage by stage; in this way, time consumed for each frame of real-time voice data to transfer between the calling mobile terminal and the called mobile terminal in the communication is an accumulation of delay for the relay transmission (including encryption and decryption in each centralized control station) among centralized control stations. In the key relay mobile secure communication, both parties of the communication already have the service keys (at least parts of the service keys), thus voice data plaintext can arrive at the destination through the original service path with only one round of transmission, encryption and decryption. The delay is greatly shortened, and the greater the number of relay centralized control stations is, the more obvious the comparative advantages are. Further, the ciphertext relay mobile secure communication faces the issue of delay caused by encrypting and decrypting stage by stage during the whole communication rather than only at the beginning of the communication. While in the key relay mobile secure communication, the service keys can be downloaded to the mobile terminal (either downloaded for the first time or downloaded for continuation during the communication) before being used, thus effective communication information is always transferred between the calling mobile terminal and the called mobile terminal in the communication directly, and is only encrypted and decrypted once.
(3) In one communication, choosing which centralized control station in the link as the centralized control station for service key generation for the communication directly relates to the quality of service, especially when there is a large amount of concurrent communications and great pressure on the service key generation in the entire network. Taking full account of real-time states of current service key generation and location states for centralized control stations in the communication link, the most suitable one is chosen as the centralized control station for service key generation for the communication, which is advantageous for reducing the delay caused by the service key generation and transmission, improving key relay efficiency of the quantum key distribution network, and enhancing the quality of service.
(4) When the geographic location of the mobile terminal changes, the quantum key distribution network can dynamically allocate the centralized control station bound to the mobile terminal, which allows the mobile terminal to obtain service keys from a nearby centralized control station, and adapts to characteristics of the mobile communication.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1( a ) and FIG. 1( b ) are diagrams for comparing ciphertext relay mobile secure communication with key relay mobile secure communication;
FIG. 2 is a diagram showing various communication channels in a quantum key distribution network;
FIG. 3 is a flow chart of a mobile secure communication;
FIG. 4 is a diagram illustrating that a mobile terminal applies to a quantum key distribution network for registration for accessing the network;
FIG. 5 is a diagram illustrating switching a bound centralized control station when geographic location of the mobile terminal changes;
FIG. 6 is a diagram illustrating that the quantum key distribution network determines addresses of centralized control stations participating in distributing service keys during a communication;
FIG. 7 is a diagram illustrating that a quantum network management server determines a centralized control station for service key generation during a communication;
FIG. 8( a ) , FIG. 8( b ) , FIG. 8( c ) and FIG. 8( d ) are diagrams illustrating various possible distributions with key relay in the quantum key distribution network;
FIG. 9( a ) and FIG. 9( b ) are diagrams illustrating comparing two relay methods for transferring the service keys through multiple centralized control stations.
DETAILED DESCRIPTION OF THE EMBODIMENTS
The disclosure is to be described in conjunction with drawings and embodiments hereinafter.
Main hardware devices related to a mobile secure communication method based on a quantum key distribution network include: {circle around (0)} a mobile terminal, which may be a smart phone, tablet computer, set-top box, notebook computer, PDA or other mobile devices, and is an initiator or a recipient of communication service. The mobile terminal includes: a permanent storage device, such as flash memory chip, to store the downloaded keys shared with a centralized control station; a temporary storage device, such as memory, to store the downloaded service keys; a hardware module with a capability of supporting network access, which is capable to send or receive data through conventional uplink or downlink network channel (including various wireless networks); and a processor with enough computing power, capable of encrypting and decrypting service information. The mobile terminal should have a capability of exchanging information with the quantum key distribution network. {circle around (2)} a quantum centralized control station (also referred to as centralized control station), which is a major part of the quantum key distribution network, and consists of optical matrix switch, quantum key transceiver, true random number generator, quantum communication server, etc. The quantum centralized control station can generate shared keys with other centralized control stations and quantum terminals. The quantum device or the true random number generator can generate the service keys required by the communication. The generated keys are stored in the quantum communication server. The major role of the quantum centralized control station is to manage the generation, storage and relay of the keys, make statistics of various state indicators of the quantum centralized control station, and interact with a quantum network management server. {circle around (3)} a quantum terminal. The centralized control stations have a large volume, and the number of them is limited within a certain region. Thus a certain number of quantum terminals are required as an extension of the centralized control station in most cases. The quantum terminal includes a key temporal unit, a quantum key transmitter and/or a quantum key receiver, etc. A plurality of quantum terminals can be connected to one centralized control station. Each quantum terminal can generate the shared quantum keys with the connected centralized control station. The mobile terminal can choose a nearby quantum terminal for connection to accomplish operations such as registration for accessing the network, and downloading the keys shared with the centralized control station. {circle around (4)} a quantum network management server, which is a computer server installed with a quantum key distribution network management program, and is in a âhousekeeperâ role in the quantum key distribution network. The quantum network management server has classic network connections with each centralized control station, and can collect in real time various state information of respective centralized control stations for computation and give corresponding instructions to the respective centralized control stations.
The keys according to the disclosure mainly include: {circle around (1)} the keys shared between the centralized control stations, which are generated by the quantum key distribution devices among the centralized control stations and are stored in the centralized control stations. {circle around (2)} the shared keys between the centralized control station and the mobile terminal, which are generated by the quantum key distribution devices among the centralized control stations and quantum terminals, and can be downloaded by the mobile terminal to a local permanent storage device in a wired way. The shared keys are also stored in the centralized control station. {circle around (3)} the service keys required by each communication, which are generated by a centralized control station for service key generation for each communication. Based on secrecy levels and application scenarios, the service keys may be generated by the quantum devices, or may be generated by the true random number generator. The service keys are downloaded to the temporary storage device (such as the memory) of the mobile terminal for each communication, and are discarded if they are used or discarded when the communication is completed regardless whether the service keys are used.
Different from the ciphertext relay mobile secure communication, the key relay mobile secure communication is adopted in the disclosure. The case that a calling mobile terminal sends a message to a called mobile terminal is taken as an example, and the differences between the two methods are shown in FIG. 1 . To put it simply, in the former solution (as shown in FIG. 1( a ) ), after plaintext being encrypted by the calling mobile terminal A, ciphertext is sent to a calling centralized control station S, then is sent to the called mobile terminal B stage by stage where it is decrypted; in the latter solution, after being encrypted by a centralized control station (in the example shown in FIG. 1( b ) , the calling centralized control station S serves as the centralized control station for service key generation) in the link, the service key is sent to two mobile terminals A and B stage by stage, the mobile terminal A encrypts the plaintext with the service key and sends the ciphertext to the mobile terminal B which will decrypt the ciphertext.
In the solution of the disclosure, there is a plurality of connection channels between hardware devices, as shown in FIG. 2 . The channel between the quantum network management server and the centralized control station is the classic network channel (can be wireless network or wired network connection), of which the major role is to transfer real-time data and control information between the quantum network management server and the centralized control station. Both classic network channels and quantum channels exist between centralized control stations within the quantum key distribution network, as well as between the centralized control station and the quantum terminal. The classic network can be wired or wireless network, and the quantum channel can be a fiber channel, a quantum channel in free space, etc. The quantum channel is configured to generate the quantum keys, with the aid of the classic channel to transfer some negotiation information. At the same time, the classic channel is also responsible for tasks such as key relay between centralized control stations. Information is transferred between a mobile terminal in a free-moving state and a binding centralized control station within the quantum key distribution network through the classic network, especially through the classic wireless network technology, such as Wi-Fi technology or 3G technology. Service communication between two mobile terminals still adopts the conventional data link, e.g. SMS short message, the data stream of which flows through the conventional short message link of telecom operators; however the content of the short message is encrypted.
The foregoing classic network channel can be a direct point-to-point physical connection between two devices, or can be a logic connection established by connecting the two devices to a classic network.
The process from initial registration of the mobile terminal for accessing the network to accomplishment of a secure communication between two mobile terminals implementing the method is taken as example, to illustrate the specific implementation of the disclosure. The overall flow is shown in FIG. 3 .
In Step1, mobile terminals are registered to access a network and obtain unique quantum identity numbers.
A mobile terminal holder (can be an individual, or a manufacturer of the mobile device) first should go through formalities related to accessing a secure communication network (referred to as accessing the network hereinafter) in a quantum secure authentication center, and the quantum secure authentication center is responsible for manually reviewing a user application for accessing the network. If it is approved, a quantum identity number, which is unique in the network, is assigned by a quantum network management server to the mobile terminal applying for accessing the network. The quantum identity number is stored in a permanent storage medium (such as a SD card or a flash memory of the terminal) in the mobile terminal applying for accessing the network. A password is set for authentication when connecting to a quantum terminal. While assigning the quantum identity number, the quantum network management server also adds a new record to a native table of binding relationship between centralized control stations and mobile terminals, and writes the quantum identity number and password to the new record. In general, a mobile terminal only needs to apply for accessing the network once, and can use the network after approval of the application for accessing the network.
In Step2, the binding relationship is established between each mobile terminal and a centralized control station in the quantum key distribution network, and the mobile terminal shares keys with the centralized control station.
As shown in FIG. 4 , mobile terminal A chooses an arbitrary quantum terminal T 11 in the quantum key distribution network, and is connected to the quantum terminal T 11 in a reliable wired mode (such as USB data cable connection). The authentication password is to be input when prompted. The quantum identity number QID-A (this item is null if the mobile terminal has not accessed the network yet) and authentication password of the mobile terminal A, as well as accounts of the communication services requiring encryption-protection of the mobile terminal A are sent to the quantum terminal T 11 , and the quantum terminal T 11 sends these information to the centralized control station S 1 to which the quantum terminal belongs. Then the centralized control station S 1 forwards the information along with an address of the centralized control station S 1 to the quantum network management server QM. The quantum network management server QM performs searching in the natively stored table of binding relationship between centralized control stations and mobile terminals, and the searching result may include the following four cases.
<1> If it fails to find the quantum identity number QID-A uploaded by the mobile terminal A in the table, or the uploaded quantum identity number is null, or the quantum identity number does not correspond to the authentication password, it concludes that the connection is illegal and fails to pass the system authentication. Possible reasons include: the quantum identity number QID-A of the mobile terminal A is forged or deregistered; the mobile terminal A has not yet gone through formalities in the authentication center for obtaining the quantum identity number; the current holder of the mobile terminal A is not a legal holder of the mobile terminal, etc. In these cases, the quantum terminal T 11 sends information prompt for illegal connection to the mobile terminal A, and breaks the logic connection with the mobile terminal A.
<2> If the system authentication for connection is passed, but the record, corresponding to the quantum identity number QID-A, in the table of binding relationship between centralized control stations and mobile terminals in the quantum network management server QM has only two items: the quantum identity number and the authentication password, it concludes that the mobile terminal just went through formalities in the authentication center and has not yet been bound to any centralized control station. The quantum network management server QM writes the received address S 1 of the centralized control station (for convenience, the address S 1 of the centralized control station and the centralized control station S 1 are both referred to as S 1 , and description of other centralized control stations is similar) and the accounts of the communication services uploaded by the mobile terminal A to the record corresponding to the quantum identity number QID-A in the table of binding relationship between centralized control stations and mobile terminals. After obtaining the address S 1 of the centralized control station, the mobile terminal A stores the address S 1 in the permanent storage medium of the mobile terminal A, and takes the centralized control station S 1 as its binding centralized control station, thus binding between the mobile terminal A and the centralized control station S 1 is achieved.
The same shared keys key(S 1 -A) are generated through a quantum key distribution mechanism between the centralized control station S 1 and the quantum terminal T 11 . The mobile terminal A downloads the shared keys through a reliable wired connection to the quantum terminal T 11 , and stores the shared keys in the permanent storage medium of the mobile terminal A, thus the mobile terminal A and its binding centralized control station S 1 have the same shared keys. After the downloading, the mobile terminal A breaks the wired connection to the quantum terminal T 11 , and recovers to a state of free movement.
<3> The system authentication for connection is passed, and the address of binding centralized control station corresponding to the quantum identity number is the same as the received address of the centralized control station. This often happens when the remaining shared keys between the mobile terminal and the centralized control station bound to the mobile terminal are few, and the mobile terminal re-establishes wired connection to a quantum terminal belonging to the centralized control station bound to the mobile terminal, attempting to add keys shared with the centralized control station bound to the mobile terminal. For example, the mobile terminal B as shown in FIG. 4 has downloaded the keys shared with S 2 through quantum terminal T 21 previously, and now it may download the keys shared with S 2 through quantum terminal T 2 n . On this occasion, the shared keys key(S 2 -B) between the centralized control station S 2 and the quantum terminal T 2 n are generated through the quantum key distribution mechanism, and the mobile terminal B downloads the shared keys via the reliable wired connection with the quantum terminal T 2 n and stores the shared keys in the permanent storage medium of the mobile terminal B. After the downloading, the mobile terminal B breaks the wired connection to the quantum terminal T 2 n , and recovers to a state of free movement. When using the keys, the previous remaining shared keys are consumed first, and then the shared keys downloaded lately are consumed.
<4> If the mobile terminal C as shown in FIG. 4 , passes the system authentication for connection, but the address S 4 of the binding centralized control station corresponding to the quantum identity number is different from the received address S 3 of centralized control station, it concludes that the mobile terminal C is connected to a quantum terminal belonging to the centralized control station S 3 not bound to the mobile terminal. The quantum network management server QM sends a prompt through the link of centralized control station S 3 âquantum terminal T 31 âmobile terminal C, to inquire whether to change the binding centralized control station for the mobile terminal C. If the holder of the mobile terminal C agrees with the change, the quantum network management server QM changes the record related to the quantum identity number QID-C in the table of binding relationship between centralized control stations and mobile terminals, i.e., changes the address of the binding centralized control station in the record from S 4 to the received address S 3 of centralized control station, thus the binding between the mobile terminal C and the address S 3 of the new centralized control station is achieved, and a message is sent to the address S 4 of the original binding centralized control station, instructing S 4 to discard the keys shared with the mobile terminal C. The quantum network management server QM sends the address S 3 of the new binding centralized control station to the mobile terminal C, and the mobile terminal C uses the address S 3 of the new binding centralized control station to overwrite previously locally stored address S 4 of the original binding centralized control station after reception of the address S 3 , and adopts the centralized control station S 3 as the binding centralized control station. The shared keys key(S 3 -C) between the new binding centralized control station S 3 and the quantum terminal T 31 are generated through the quantum key distribution mechanism, and the mobile terminal C downloads the shared keys via the reliable wired connection with the quantum terminal T 31 and stores the shared keys in the permanent storage medium of the mobile terminal C. Thus, the mobile terminal C and the new binding centralized control station S 3 have the same shared keys key(S 3 -C). If there are some remaining keys shared with the original binding centralized control station S 4 stored within the mobile terminal C, the remaining shared keys are discarded. After the downloading, the mobile terminal C breaks the wired connection with the quantum terminal T 31 , and recovers to the state of free movement.
In the case <4> of Step2, a solution of switching binding centralized control stations through the wired connection when geographic location of a mobile terminal changes is described. Besides, the centralized control station bound to the mobile terminal may be switched through wireless connection. As shown in FIG. 5 , the geographic location of the mobile terminal M changes from a location where centralized control station S 1 is located to a location where centralized control station S 2 is located. The quantum key distribution network inquires the holder of mobile terminal M whether to change the binding centralized control station for the mobile terminal M when knowing the change of the geographic location. On this occasion, the holder of mobile terminal M may choose not to change, and the service keys required for each communication of the mobile terminal M must be applied for from the cross-regional binding centralized control station S 1 , which may cause issues such as delay, expense, and inconveniency. If the holder of mobile terminal M agrees with the change, the quantum network management server QM in the quantum key distribution network searches for, based on the new geographic location of mobile terminal M, the corresponding centralized control station S 2 located in a region of the geographic location, and the quantum key distribution network notifies mobile terminal M, so that M uses S 2 as the new binding centralized control station. Then, the quantum network management server QM changes the record related to the quantum identity number QID-M in the table of binding relationship between centralized control stations and mobile terminals, i.e., changes the address of the binding centralized control station in the record from the original S 1 to S 2 . Next, the quantum network management server QM instructs the original binding centralized control station S 1 of mobile terminal M to encrypt the stored keys key(S 1 -M) shared between centralized control station S 1 and mobile terminal M with the keys key(S 1 -S 2 ) shared between centralized control station S 1 and centralized control station S 2 , and the encrypted keys key(S 1 -M) (S 1 -S 2 ) are relayed to the new binding centralized control station S 2 ; after reception and decryption, the new binding centralized control station S 2 has keys key(S 2 -M) shared with mobile terminal M, which are the same as the keys key(S 1 -M), and the keys key(S 1 -M) stored in the original binding centralized control station S 1 are no longer used.
There may be a further solution for the relay process of key(S 1 -M) from S 1 to S 2 , e.g., only parts of the keys (such as in case of short-term business trip) may be chosen to be relayed to the new binding centralized control station, in this case, for the key(S 1 -M) stored in the original binding centralized control station S 1 , the parts relayed to S 2 can be destroyed, and other parts can be temporarily reserved. In addition, if there are other centralized control stations between S 1 and S 2 , multiple relays are required to relay key(S 1 -M) from S 1 to S 2 , and a concept of relay with multiple centralized control stations is described in details hereinafter.
In the case <4> of Step2, a similar following method can also be used. The keys shared between mobile terminal C and its original binding centralized control station S 4 are relayed to the new binding centralized control station S 3 , and serve as the keys shared between mobile terminal C and its new binding centralized control station S 3 (the shared keys are not generated through the quantum key distribution mechanism between the new binding centralized control station S 3 and the quantum terminal T 31 ). The method is as follows: the original centralized control station S 4 bound to mobile terminal C encrypts the shared keys key(S 4 -C) and relays the encrypted keys to the new binding centralized control station S 3 , thus the new binding centralized control station S 3 has keys key(S 3 -C) shared with mobile terminal C after decryption, which are the same as the previous key(S 4 -C). In this method, mobile terminal C needs not to update its original local shared keys.
In conclusion, other modifications easy to think of based on the method fall within the protection scope of the disclosure.
In the cases <3> and <4> of Step2, if accounts of communication services in the table of binding relationship between centralized control stations and mobile terminals are inconsistent with the accounts uploaded by the mobile terminal, the holder of the mobile terminal is prompted to determine whether to update account information of communication services to be protected. If it is yes, the accounts of communication services corresponding to the quantum identity number in the table of binding relationship between centralized control stations and mobile terminals in the quantum network management server are updated. In the Step1 and Step2, the âtable of binding relationship between centralized control stations and mobile terminalsâ is composed of records. Each record represents registration information of a mobile terminal which is already registered for accessing the network, with the format: [quantum identity number of the mobile terminal] [authentication password] [address of the binding centralized control station] [identifiers of service accounts]. The âidentifiers of service accountsâ is a collection of accounts of services supported by the mobile terminal and the quantum key distribution network, and may include accounts of one or more different services (e.g., telephone number, SIP account).
An example of the format of the table of binding relationship between centralized control stations and mobile terminals (symbols such as S 1 and S 2 are used to represent the real ne
CLAIMS
Claims ( 20 )
What is claimed is:
1. A mobile secure communication method based on a quantum key distribution network, comprising:
(1) registering a plurality of mobile terminals to access the quantum key distribution network and obtain a unique quantum identity number for each of the plurality of mobile terminals;
(2) establishing a table of binding relationship between each of the plurality of mobile terminals and a respective one of a plurality of centralized control stations in the quantum key distribution network and assigning sharing keys between each of the plurality of mobile terminals and its binding one of the plurality of centralized control stations in the quantum key distribution network;
(3) after a communication is initiated, providing, by one of the plurality of mobile terminals, information related to the communication based on the table of binding relationship for the quantum key distribution network, to apply for service keys for the communication from the quantum key distribution network;
(4) obtaining, by a quantum network management server of the quantum key distribution network, addresses of a calling centralized control station of the plurality of centralized control stations, a called centralized control station of the plurality of centralized control stations, and relay centralized control stations of the plurality of centralized control stations, by performing searching according to the information, wherein the relay centralized control stations participate in relaying the service keys for the communication, the calling centralized control station is bound with a calling mobile terminal, and the called centralized control station is bound with a called mobile terminal;
(5) collecting, by the quantum network management server, current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining an optimal service key generation centralized control station for the communication based on the collected current state indicators, sending a service information packet to the optimal service key generation centralized control station, and commanding the optimal service key generation centralized control station to generate the service keys for the communication;
(6) generating and encrypting, by the service key generation centralized control station, the service keys for the communication, and distributing, by the service key generation centralized control station, the encrypted service keys to the calling mobile terminal and the called mobile terminal;
(7) obtaining and decrypting, by the calling mobile terminal and the called mobile terminal, the encrypted service keys distributed by the service key generation centralized control station, wherein the calling mobile terminal and the called mobile terminal decrypt the encrypted service keys with the sharing keys, to obtain the service keys for the communication; and
(8) performing, by the calling mobile terminal and the called mobile terminal, the communication with the service keys through an original data link of the communication.
2. The mobile secure communication method based on the quantum key distribution network according to claim 1 , wherein the âtable of binding relationshipâ in the step (2) is characterized in that:
(2-1) the table of binding relationship comprises [quantum identity numbers of the plurality of mobile terminals] [authentication password] [addresses of the binding centralized control stations] [service account identifiers];
(2-2) the plurality of mobile terminals which have already been registered to access the quantum key distribution network have the unique quantum identity numbers in the quantum key distribution network;
(2-3) the authentication password is configured to determine an identity when the one of the plurality of mobile terminals is connected to the quantum key distribution network;
(2-4) the âservice account identifiersâ are a collection of accounts of one or more different services supported by the one of the plurality of mobile terminals and the quantum key distribution network;
(2-5) the one of the plurality of mobile terminals can only be bound to a single one of the plurality of centralized control stations during a same period;
(2-6) said single one of the plurality of centralized control stations is allowed to be bound to a further one of the plurality of mobile terminals during the same period;
(2-7) the table of binding relationship is stored in the quantum network management server in the quantum key distribution network; and
(2-8) said one of the plurality of mobile terminals and said single one of the plurality of centralized control stations bound to said one of the plurality of mobile terminals have one of the sharing keys.
3. The mobile secure communication method based on the quantum key distribution network according to claim 2 , wherein providing, by the one of the plurality of mobile terminals, information related to the communication based on the table of binding relationship for the quantum key distribution network in step (3) comprises: sending respectively, by the calling mobile terminal of the plurality of mobile terminals and the called mobile terminal of the plurality of mobile terminals, the service information packet and a called-party response information packet to the quantum network management server of the quantum key distribution network;
the service information packet is generated by the calling mobile terminal and comprises the quantum identity number and authentication information of the calling mobile terminal, a communication service account of the called mobile terminal, service type of the communication, and parameter information related to the communication; and
the called-party response information packet is generated by the called mobile terminal and comprises a communication service account of the calling mobile terminal, the communication service account of the called mobile terminal, authentication information of the called mobile terminal, the service type of the communication, and the parameter information related to the communication.
4. The mobile secure communication method based on the quantum key distribution network according to claim 1 , wherein obtaining, by the quantum network management server of the quantum key distribution network, addresses of the calling centralized control station, the called centralized control station and the relay centralized control stations comprises:
the quantum network management server obtaining the addresses of the calling centralized control station and the called centralized control station in the communication, based on received information related to the calling mobile terminal and the called mobile terminal and the table of binding relationship; and querying stored relay routing tables for the service keys, and obtaining the addresses of the relay centralized control stations between the calling centralized control station and the called centralized control station in the communication.
5. The mobile secure communication method based on the quantum key distribution network according to claim 3 , wherein determining the optimal service key generation centralized control station for the communication, and commanding the optimal service key generation centralized control station to generate the service keys for the communication in the step (5) comprises:
(5-1) the quantum network management server sending an instruction to the calling centralized control station, the called centralized control station, and the relay centralized control stations between the calling centralized control station and the called centralized control station, to command the calling centralized control station, the called centralized control station, and the relay centralized control stations to upload the current state indicators to the quantum network management server;
(5-2) the quantum network management server collecting the current state indicators, and determining the optimal service key generation centralized control station in the communication based on the current state indicators; and
(5-3) the quantum network management server adding the addresses of the calling centralized control station and the called centralized control station in the communication into the service information packet sent from the calling mobile terminal, making a copy of the service information packet to form two service information packets, designating, in the two service information packets, the calling centralized control station and the called centralized control station as target centralized control stations respectively, and sending the two service information packets to the optimal service key generation centralized control station, to command the optimal service key generation centralized control station to generate the service keys for the communication.
6. The mobile secure communication method based on the quantum key distribution network according to claim 5 , wherein
distributing, by the service key generation centralized control station, the encrypted service keys to the calling mobile terminal and the called mobile terminal in the step (6) comprises:
(6-1) the service key generation centralized control station respectively analyzing content of the two service information packets sent by the quantum network management server, if one of the target centralized control stations designated in one of the two service information packets is not the service key generation centralized control station, searching in a relay routing table for the service keys for a next hop centralized control station leading to the one of the target centralized control stations, encrypting the service keys for the communication with first keys shared between the service key generation centralized control station and the next hop centralized control station, and then sending the encrypted service keys along with the one of the two service information packets to the next hop centralized control station; and
(6-2) after receiving the encrypted service keys and the one of the two service information packets relayed from a last hop centralized control station, the next hop centralized control station decrypting the received service keys with the first keys shared between the last hop centralized control station and the next hop centralized control station, analyzing content of the one of the two service information packets, if the one of the target centralized control stations designated in the one of the two service information packets is the next hop centralized control station, encrypting the service keys with the sharing keys shared between the next hop centralized control station and the calling mobile terminal or the called mobile terminal, and then sending the encrypted service keys to the calling mobile terminal or the called mobile terminal; if the one of the target centralized control stations designated in the one of the two service information packets is not the next hop centralized control station, searching for a further next hop centralized control station leading to the one of the target centralized control stations, encrypting the service keys for the communication with second keys shared between the next hop centralized control station and the further next hop centralized control station, and then sending the encrypted service keys along with the one of the two service information packets to the further next hop centralized control station.
7. The mobile secure communication method based on the quantum key distribution network according to claim 6 , wherein the next hop centralized control station starts encrypting and forwarding the service keys at the beginning of receiving and decrypting a first frame data of the service keys, rather than after completely receiving the service keys for the communication from the last hop centralized control station; or
a threshold is set, and once an amount of the decrypted service keys is greater than the threshold, the next hop centralized control station starts encrypting and forwarding the service keys; a dynamic upper limit of the amount of the encrypted and forwarded service keys is the amount of the service keys received and decrypted currently; and during a same period, the service keys for the communication are in a state of concurrent relaying among the relay centralized control stations.
8. The mobile secure communication method based on the quantum key distribution network according to claim 4 , wherein the ârelay routing tables for the service keysâ are characterized by:
(8-1) each of the relay routing tables for the service keys consists of records, and each record comprises: a local station address, a target address, and a next hop address;
(8-2) each of the plurality of centralized control stations in the quantum key distribution network stores a respective one of the relay routing tables;
(8-3) the quantum network management server stores the relay routing tables; and
(8-4) the relay routing tables for the service keys are updated with changes of a topology of the quantum key distribution network.
9. The mobile secure communication method based on the quantum key distribution network according to claim 1 , wherein:
(9-1) the current state indicators reflect a heavy state for service key generation tasks which each of the calling centralized control station, the called centralized control station, and the relay centralized control stations is currently burdened with, wherein each of the current state indicators is a quantitative indicator and comprises:
(9-1-1) a rated service key generation rate of each of the calling centralized control station, the called centralized control station, and the relay centralized control stations;
(9-1-2) a number of groups of secure communication services for which each of the calling centralized control station, the called centralized control station, and the relay centralized control stations is currently generating the service keys;
(9-1-3) an amount of the service keys to be generated currently by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations;
(9-1-4) an actual generation rate and a consumption rate of the service keys which are designated to be generated by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations; or
(9-1-5) a generation amount and a consumption amount of the service keys which are designated to be generated by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations; or
(9-2) the current state indicators reflect a current location state of each of the calling centralized control station, the called centralized control station, and the relay centralized control stations in the quantum key distribution network, wherein each of the current state indicators is a quantitative indicator and comprises:
(9-2-1) a number of quantum channels between the calling centralized control station, the called centralized control station, the relay centralized control stations and others of the plurality of centralized control stations; or
(9-2-2) a number of hops between the calling centralized control station, the called centralized control station, the relay centralized control stations and others of the plurality of centralized control stations.
10. The mobile secure communication method based on the quantum key distribution network according to claim 1 , wherein main functions of the quantum network management server comprise:
(10-1) storing, maintaining and querying the âtable of binding relationshipâ and ârelay routing tables for the service keysâ;
(10-2) distributing the unique quantum identity numbers in the quantum key distribution network to the plurality of mobile terminals;
(10-3) maintaining classic network connections to the plurality of centralized control stations;
(10-4) determining legality of each of the plurality of mobile terminals based on received information associated with the plurality of mobile terminals;
(10-5) collecting the current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining and designating the service key generation centralized control station, and generating and sending a new service information packet to the service key generation centralized control station;
(10-6) querying addresses of ones of the plurality of centralized control stations located in a region where one of the plurality of mobile terminals is located, according to a geographic location of said one of the plurality of mobile terminals; and
(10-7) communicating with the plurality of centralized control stations, and sending instructions to the plurality of centralized control stations.
11. The mobile secure communication method based on the quantum key distribution network according to claim 3 , wherein the quantum key distribution network distributes the service keys for a non-real-time non-bidirectional interactive communication service, and wherein:
(11-1) after receiving an application for the service keys from the calling mobile terminal, the quantum key distribution network directly designates the service key generation centralized control station for the communication instead of collecting the current state indicators, commands the service key generation centralized control station to generate the service keys for the communication, distributes the service keys to the calling mobile terminal, and relays the service keys to the called centralized control station; and the calling mobile terminal encrypts plaintext with the service keys to obtain ciphertext and sends the ciphertext to the called mobile terminal, and the called mobile terminal applies to the quantum key distribution network for the service keys and downloads the service keys from the called centralized control station after receiving the ciphertext; and
(11-2) the quantum key distribution network retains the service information packet sent from the calling mobile terminal for a period of time, matches the service information packet with the called-party response information packet sent from the called mobile terminal, in order to distribute to the called mobile terminal the service keys which are the same as the ones distributed to the calling mobile terminal; and a threshold time is set for the period, and if the called-party response information packet is not received when the threshold time is reached, the quantum key distribution network destroys the service keys generated for the communication.
12. The mobile secure communication method based on the quantum key distribution network according to claim 1 , wherein when a geographic location of one of the plurality of mobile terminals changes:
(12-1) the one of the plurality of mobile terminals is bound with a new one of the plurality of centralized control stations currently located in a region where the one of the plurality of mobile terminals is located; and
(12-2) the sharing keys shared between the one of the plurality of mobile terminals and an original centralized control station bound to the one of the plurality of mobile terminals are transferred to the new one of the plurality of centralized control stations after being encrypted, and the new one of the plurality of centralized control stations shares the sharing keys with the one of the plurality of mobile terminals after decrypting the keys.
13. The mobile secure communication method based on the quantum key distribution network according to claim 6 , wherein the ârelay routing tables for the service keysâ are characterized by:
(13-1) each of the relay routing tables for the service keys consists of records, and each record comprises: a local station address, a target address, and a next hop address;
(13-2) each of the plurality of centralized control stations in the quantum key distribution network stores a respective one of the relay routing tables;
(13-3) the quantum network management server stores the relay routing tables; and
(13-4) the relay routing tables for the service keys are updated with changes of a topology of the quantum key distribution network.
14. The mobile secure communication method based on the quantum key distribution network according to claim 5 , wherein:
(14-1) the current state indicators reflect a heavy state for service key generation tasks which each of the calling centralized control station, the called centralized control station, and the relay centralized control stations is currently burdened with, wherein each of the current state indicators is a quantitative indicator and comprises:
(14-1-1) a rated service key generation rate of each of the calling centralized control station, the called centralized control station, and the relay centralized control stations;
(14-1-2) a number of groups of secure communication services for which each of the calling centralized control station, the called centralized control station, and the relay centralized control stations is currently generating the service keys;
(14-1-3) an amount of the service keys to be generated currently by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations;
(14-1-4) an actual generation rate and a consumption rate of the service keys which are designated to be generated by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations; or
(14-1-5) a generation amount and a consumption amount of the service keys which are designated to be generated by each of the calling centralized control station, the called centralized control station, and the relay centralized control stations; or
(14-2) the current state indicators reflect a current location state of each of the calling centralized control station, the called centralized control station, and the relay centralized control stations in the quantum key distribution network, wherein each of the current state indicators is a quantitative indicator and comprises:
(14-2-1) a number of quantum channels between the calling centralized control station, the called centralized control station, the relay centralized control stations and others of the plurality of centralized control stations; or
(14-2-2) a number of hops between the calling centralized control station, the called centralized control station, the relay centralized control stations and others of the plurality of centralized control stations.
15. The mobile secure communication method based on the quantum key distribution network according to claim 2 , wherein when a geographic location of one of the plurality of mobile terminals changes:
(15-1) the one of the plurality of mobile terminals is bound with a new one of the plurality of centralized control stations currently located in a region where the one of the plurality of mobile terminals is located; and
(15-2) the sharing keys shared between the one of the plurality of mobile terminals and an original centralized control station bound to the one of the plurality of mobile terminals are transferred to the new one of the plurality of centralized control stations after being encrypted, and the new one of the plurality of centralized control stations shares the sharing keys with the one of the plurality of mobile terminals after decrypting the keys.
16. The mobile secure communication method based on the quantum key distribution network according to claim 2 , wherein main functions of the quantum network management server comprise:
(16-1) storing, maintaining and querying the âtable of binding relationshipâ, and ârelay routing tables for the service keysâ;
(16-2) distributing the unique quantum identity numbers in the quantum key distribution network to the plurality of mobile terminals;
(16-3) maintaining classic network connections to the plurality of centralized control stations;
(16-4) determining legality of each of the plurality of mobile terminals based on received information associated with the plurality of mobile terminals;
(16-5) collecting the current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining and designating the service key generation centralized control station, and generating and sending a new service information packet to the service key generation centralized control station;
(16-6) querying addresses of ones of the plurality of centralized control stations located in a region where one of the plurality of mobile terminals is located, according to a geographic location of said one of the plurality of mobile terminals; and
(16-7) communicating with the plurality of centralized control stations, and sending instructions to the plurality of centralized control stations.
17. The mobile secure communication method based on the quantum key distribution network according to claim 3 , wherein main functions of the quantum network management server comprise:
(17-1) storing, maintaining and querying the âtable of binding relationshipâ, and ârelay routing tables for the service keysâ;
(17-2) distributing the unique quantum identity numbers in the quantum key distribution network to the plurality of mobile terminals;
(17-3) maintaining classic network connections to the plurality of centralized control stations;
(17-4) determining legality of each of the plurality of mobile terminals based on received information associated with the plurality of mobile terminals;
(17-5) collecting the current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining and designating the service key generation centralized control station, and generating and sending a new service information packet to the service key generation centralized control station;
(17-6) querying addresses of ones of the plurality of centralized control stations located in a region where one of the plurality of mobile terminals is located, according to a geographic location of said one of the plurality of mobile terminals; and
(17-7) communicating with the plurality of centralized control stations, and sending instructions to the plurality of centralized control stations.
18. The mobile secure communication method based on the quantum key distribution network according to claim 4 , wherein main functions of the quantum network management server comprise:
(18-1) storing, maintaining and querying the âtable of binding relationshipâ, and ârelay routing tables for the service keysâ;
(18-2) distributing the unique quantum identity numbers in the quantum key distribution network to the plurality of mobile terminals;
(18-3) maintaining classic network connections to the plurality of centralized control stations;
(18-4) determining legality of each of the plurality of mobile terminals based on received information associated with the plurality of mobile terminals;
(18-5) collecting the current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining and designating the service key generation centralized control station, and generating and sending a new service information packet to the service key generation centralized control station;
(18-6) querying addresses of ones of the plurality of centralized control stations located in a region where one of the plurality of mobile terminals is located, according to a geographic location of said one of the plurality of mobile terminals; and
(18-7) communicating with the plurality of centralized control stations, and sending instructions to the plurality of centralized control stations.
19. The mobile secure communication method based on the quantum key distribution network according to claim 5 , wherein main functions of the quantum network management server comprise:
(19-1) storing, maintaining and querying the âtable of binding relationshipâ, and ârelay routing tables for the service keysâ;
(19-2) distributing the unique quantum identity numbers in the quantum key distribution network to the plurality of mobile terminals;
(19-3) maintaining classic network connections to the plurality of centralized control stations;
(19-4) determining legality of each of the plurality of mobile terminals based on received information associated with the plurality of mobile terminals;
(19-5) collecting the current state indicators of the calling centralized control station, the called centralized control station, and the relay centralized control stations, determining and designating the service key generation centralized control station, and generating and sending a new service information packet to the service key generation centralized control station;
(19-6) querying addresses of ones of the plurality of centralized control stations located in a region where one of the plurality of mobile terminals is located, according to a geographic location of said one of the plurality of mobile terminals; and
(19-7) communicating with the plurality of centralized control stations, and sending instructions to the plurality of centralized control stations.
20. The mobile secure communication method based on the quantum key distribution network according to claim 5 , wherein
distributing, by the service key generation centralized control station, the encrypted service keys to the calling mobile terminal and the called mobile terminal in the step (6) comprises:
the service key generation centralized control station respectively analyzing content of the two service information packets sent by the quantum network management server, if one of the target centralized control stations designated in one of the two service information packets is the service key generation centralized control station, encrypting the service keys with the sharing keys shared between the service key generation centralized control station and the calling mobile terminal or the called mobile terminal, and then sending the encrypted service keys to the calling mobile terminal or the called mobile terminal.
US15/481,927
2013-06-08
2017-04-07
Mobile secret communications method based on quantum key distribution network
Active
2035-04-10
US10560265B2
( en )
Priority Applications (1)
Application Number
Priority Date
Filing Date
Title
US15/481,927
US10560265B2
( en )
2013-06-08
2017-04-07
Mobile secret communications method based on quantum key distribution network
Applications Claiming Priority (6)
Application Number
Priority Date
Filing Date
Title
CN201310228383.3A
CN104243143B
( en )
2013-06-08
2013-06-08
A mobile secure communication method based on quantum key distribution network
CN201310228383
2013-06-08
CN201310228383.3
2013-06-08
PCT/CN2014/079380
WO2014194858A1
( en )
2013-06-08
2014-06-06
Mobile secret communications method based on quantum key distribution network
US201514896237A
2015-12-04
2015-12-04
US15/481,927
US10560265B2
( en )
2013-06-08
2017-04-07
Mobile secret communications method based on quantum key distribution network
Related Parent Applications (2)
Application Number
Title
Priority Date
Filing Date
US14/896,237
Continuation-In-Part
US9654287B2
( en )
2013-06-08
2014-06-06
Mobile secret communications method based on quantum key distribution network
PCT/CN2014/079380
Continuation-In-Part
WO2014194858A1
( en )
2013-06-08
2014-06-06
Mobile secret communications method based on quantum key distribution network
Publications (2)
Publication Number
Publication Date
US20170214525A1
US20170214525A1 ( en )
2017-07-27
US10560265B2
true
US10560265B2 ( en )
2020-02-11
Family
ID=59360913
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US15/481,927
Active
2035-04-10
US10560265B2
( en )
2013-06-08
2017-04-07
Mobile secret communications method based on quantum key distribution network
Country Status (1)
Country
Link
US
( 1 )
US10560265B2
( en )
Cited By (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20240097892A1
( en )
*
2020-12-10
2024-03-21
Abn Amro Bank N.V.
Orchestrated quantum key distribution
US12556381B2
( en )
*
2024-07-11
2026-02-17
Interwise Ltd.
Out-of-band quantum key distribution using cellular SMS
Families Citing this family (112)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
CN107347058B
( en )
2016-05-06
2021-07-23
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data encryption method, data decryption method, device and system
CN112217637B
( en )
*
2016-11-04
2024-03-15
åä¸ºææ¯æéå ¬å¸
A quantum key relay method and device based on centralized management and control network
CN108123795B
( en )
*
2016-11-28
2020-01-10
广ä¸å½ç¾éåç§ææéå ¬å¸
Quantum key chip issuing method, application method, issuing platform and system
CN108667608B
( en )
2017-03-28
2021-07-27
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data key protection method, device and system
WO2019039380A1
( en )
*
2017-08-22
2019-02-28
æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾
Share generation device, share conversion device, secret calculation system, share generation method, share conversion method, program, and recording medium
CN109510701B
( en )
*
2017-09-15
2021-10-01
åä¸ºææ¯æéå ¬å¸
Continuous variable quantum key distribution device and method
CN109787751A
( en )
*
2017-11-14
2019-05-21
é¿éå·´å·´é墿§è¡æéå ¬å¸
The dissemination system and its distribution method and data processing method of quantum key
US11457042B1
( en )
2018-02-27
2022-09-27
Wells Fargo Bank, N.A.
Multi-tiered system for detecting and reducing unauthorized network access
CN108510270B
( en )
*
2018-03-06
2023-03-31
æé½é¶å éåç§ææéå ¬å¸
Mobile transfer method with safe quantum
US11343087B1
( en )
2018-03-09
2022-05-24
Wells Fargo Bank, N.A.
Systems and methods for server-side quantum session authentication
US10728029B1
( en )
2018-03-09
2020-07-28
Wells Fargo Bank, N.A.
Systems and methods for multi-server quantum session authentication
US10812258B1
( en )
*
2018-03-09
2020-10-20
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US10855454B1
( en )
2018-03-09
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US11025416B1
( en )
*
2018-03-09
2021-06-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
JPWO2019198516A1
( en )
*
2018-04-11
2021-04-01
æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾
Key distribution system, terminal device, key distribution method, and program
CN108667607A
( en )
*
2018-05-18
2018-10-16
å½ç½ä¿¡æ¯é信产ä¸é墿éå ¬å¸
A kind of quantum key synchronous method with electric terminal
US12567981B2
( en )
2018-08-01
2026-03-03
Cable Television Laboratories, Inc.
Systems and methods for data authentication using composite keys and signatures
US10855453B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for time-bin quantum session authentication
US10855457B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11240013B1
( en )
2018-08-20
2022-02-01
Wells Fargo Bank, N.A.
Systems and methods for passive quantum session authentication
US10540146B1
( en )
2018-08-20
2020-01-21
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11095439B1
( en )
2018-08-20
2021-08-17
Wells Fargo Bank, N.A.
Systems and methods for centralized quantum session authentication
US11190349B1
( en )
2018-08-20
2021-11-30
Wells Fargo Bank, N.A.
Systems and methods for providing randomness-as-a-service
US10552120B1
( en )
2018-08-20
2020-02-04
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
TWI713902B
( en )
*
2018-09-26
2020-12-21
ç«æ° é³
A telephone communication system and method for dynamic assignment the ip-pbx
CN109450620B
( en )
2018-10-12
2020-11-10
åæ°å è¿ææ¯æéå ¬å¸
Method for sharing security application in mobile terminal and mobile terminal
CN109462547B
( en )
*
2018-11-13
2021-03-12
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Path selection method and device based on quantum metropolitan area communication network
CN109525390B
( en )
*
2018-11-20
2021-08-24
æ±è亨éé®å¤©éåä¿¡æ¯ç ç©¶é¢æéå ¬å¸
Quantum key wireless distribution method and system for terminal equipment secret communication
US11343084B2
( en )
*
2019-03-01
2022-05-24
John A. Nix
Public key exchange with authenticated ECDHE and security against quantum computers
GB2582900A
( en )
2019-03-18
2020-10-14
Pqshield Ltd
Cryptography using a cryptographic state
US11258601B1
( en )
*
2019-06-04
2022-02-22
Trend Micro Incorporated
Systems and methods for distributed digital rights management with decentralized key management
WO2020250269A1
( en )
*
2019-06-10
2020-12-17
æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾
Secret division system, secret calculation device, secret division method, and program
CN110336720B
( en )
*
2019-06-29
2021-08-20
åä¸ºææ¯æéå ¬å¸
Device control method and device
US11218472B2
( en )
*
2019-07-01
2022-01-04
Steve Rosenblatt
Methods and systems to facilitate establishing a connection between an access-seeking device and an access granting device
US11626983B1
( en )
2019-09-10
2023-04-11
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11240014B1
( en )
2019-09-10
2022-02-01
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11343270B1
( en )
2019-09-10
2022-05-24
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11477016B1
( en )
2019-09-10
2022-10-18
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11451383B2
( en )
*
2019-09-12
2022-09-20
General Electric Company
Communication systems and methods
US11228431B2
( en )
*
2019-09-20
2022-01-18
General Electric Company
Communication systems and methods for authenticating data packets within network flow
US20210119787A1
( en )
*
2019-10-17
2021-04-22
Cable Television Laboratories, Inc.
Quantum key distribution and management in passive optical networks
KR102944641B1
( en )
*
2019-12-23
2026-03-27
주ìíì¬ ì¼ì´í°
Method, apparatus and system for controlling quantum key relay in quantum key distribution network
US11429519B2
( en )
2019-12-23
2022-08-30
Alibaba Group Holding Limited
System and method for facilitating reduction of latency and mitigation of write amplification in a multi-tenancy storage drive
US11838410B1
( en )
2020-01-30
2023-12-05
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11533175B1
( en )
2020-01-30
2022-12-20
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography on a smartcard
US11449799B1
( en )
2020-01-30
2022-09-20
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
US11322050B1
( en )
*
2020-01-30
2022-05-03
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography optimization
KR102222080B1
( en )
*
2020-02-24
2021-03-04
íêµì ìíµì ì°êµ¬ì
Apparatus and method for authenticating quantum entity
US12088702B2
( en )
*
2020-04-10
2024-09-10
Cyborn Limited
Systems and methods for adaptive recursive descent data redundancy
US11750379B2
( en )
*
2020-06-11
2023-09-05
Western Digital Technologies, Inc.
Secure optical communication link
US12200122B1
( en )
2020-08-06
2025-01-14
Cable Television Laboratories, Inc.
Systems and methods for advanced quantum-safe PKI credentials for authentications
KR20230054669A
( en )
*
2020-08-24
2023-04-25
ìì§ì ì 주ìíì¬
Method and apparatus for estimating quantum bit error rate based on maximum bit group and two-dimensional parity
US11664983B2
( en )
2020-09-22
2023-05-30
Mellanox Technologies, Ltd.
Hybrid quantum key distribution link for an optical transceiver
CN114362923B
( en )
*
2020-09-28
2024-05-17
å¦è¬éåç§ææéå ¬å¸
Secret key refreshing system and method in quantum secret communication system
US11683165B2
( en )
*
2020-11-30
2023-06-20
At&T Intellectual Property I, L.P.
Quantum key distribution networking as a service
US11329806B1
( en )
*
2020-12-04
2022-05-10
The Florida International University Board Of Trustees
Systems and methods for authentication and key agreement in a smart grid
US11895233B2
( en )
2020-12-28
2024-02-06
Mellanox Technologies, Ltd.
Quantum key distribution enabled intra-datacenter network
DE102021214904A1
( en )
2020-12-28
2022-06-30
Mellanox Technologies Ltd.
QUANTUM KEY DISTRIBUTION-READY INTERNAL DATA CENTER NETWORK
US11711210B2
( en )
*
2020-12-28
2023-07-25
Mellanox Technologies, Ltd.
Quantum key distribution-based key exchange orchestration service
CN112787807B
( en )
*
2020-12-31
2022-03-18
æ¸ å大å¦
Quantum communication method and communication network based on secure relay
GB2603113B
( en )
*
2021-01-13
2023-12-20
Arqit Ltd
System and method for key establishment
US12483396B2
( en )
*
2021-01-29
2025-11-25
Arqit Limited
Key exchange protocol for satellite based quantum network
EP4298757B1
( en )
*
2021-02-23
2024-08-21
Telefonaktiebolaget LM Ericsson (publ)
Method and apparatus for a software defined network
US12627465B2
( en )
*
2021-03-02
2026-05-12
Sri International
Attribute based encryption with bounded collusion resistance
US12192318B2
( en )
*
2021-03-10
2025-01-07
Quantropi Inc.
Quantum-safe cryptographic method and system
CN113098872B
( en )
*
2021-04-02
2021-12-03
å±±ä¸éåç§å¦ææ¯ç ç©¶é¢æéå ¬å¸
Encryption communication system and method based on quantum network and convergence gateway
US12301710B2
( en )
*
2021-05-10
2025-05-13
Electronics And Telecommunications Research Institute
Method and apparatus for key relay control based on software defined networking in quantum key distribution network
KR20240021193A
( en )
*
2021-05-31
2024-02-16
íìì¨ì´ í í¬ëë¡ì§ì¤ ìºëë¤ ì»´í¼ë, 리미í°ë
Method and system for two-qubit multi-user quantum key distribution protocol
US12052350B2
( en )
*
2021-07-08
2024-07-30
Cisco Technology, Inc.
Quantum resistant secure key distribution in various protocols and technologies
US20240333398A1
( en )
*
2021-07-14
2024-10-03
General Electric Company
System and Method for Implementing Quantum-Secure Wireless Networks
GB2608999A
( en )
*
2021-07-15
2023-01-25
Pqshield Ltd
Cryptographic system for post-quantum cryptographic operations
EP4374541A4
( en )
*
2021-07-20
2025-05-28
The Research Foundation for The State University of New York
SYSTEM AND METHOD FOR QUANTUM-SECURE MICRONETWORKS
US11743037B2
( en )
*
2021-07-29
2023-08-29
QuNu Labs Private Ltd
Quantum key distribution system and method for performing differential phase shift in a quantum network
US12267421B2
( en )
*
2021-10-18
2025-04-01
International Business Machines Corporation
Post quantum secure ingress/egress network communication
US12008147B2
( en )
2021-10-29
2024-06-11
Mellanox Technologies, Ltd.
Co-packaged switch with integrated quantum key distribution capabilities
CN113757909B
( en )
*
2021-11-08
2022-02-08
å½ç½æµæ±ççµåæéå ¬å¸ç»å ´ä¾çµå ¬å¸
Air conditioner cluster control method based on quantum encryption technology
JP7612557B2
( en )
*
2021-11-11
2025-01-14
æ ªå¼ä¼ç¤¾æ±è
Quantum cryptography storage system, distributed control device and program