WO2022143727A1 - 基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台 - Google Patents

基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台 Download PDF

Info

Publication number
WO2022143727A1
WO2022143727A1 PCT/CN2021/142320 CN2021142320W WO2022143727A1 WO 2022143727 A1 WO2022143727 A1 WO 2022143727A1 CN 2021142320 W CN2021142320 W CN 2021142320W WO 2022143727 A1 WO2022143727 A1 WO 2022143727A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
quantum
encrypted
encryption
sim card
Prior art date
Application number
PCT/CN2021/142320
Other languages
English (en)
French (fr)
Inventor
余小洁
刘春华
王学富
杨国梁
姜胜广
温娜
Original Assignee
科大国盾量子技术股份有限公司
山东量子科学技术研究院有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 科大国盾量子技术股份有限公司, 山东量子科学技术研究院有限公司 filed Critical 科大国盾量子技术股份有限公司
Publication of WO2022143727A1 publication Critical patent/WO2022143727A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/085Secret sharing or secret splitting, e.g. threshold schemes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40Security arrangements using identity modules

Definitions

  • the invention relates to the field of quantum security communication, in particular to a communication system and method based on a quantum security SIM card, as well as a quantum security SIM card and a key service platform.
  • the main function of the existing SIM card is to use a preset key to identify the identity of the SIM card holder and to charge the traffic generated during the communication process.
  • the SIM card is a computer chip that stores digital mobile phone customer information, which is used by the GSM network to identify and verify the user's identity.
  • the key preset and stored in the SIM card is mainly used for the authentication and protection of the cardholder's identity information, and the negotiation of the session key to ensure the security of the communication content.
  • the prior art solution does not use the key to process the communication content, so the security of the voice and short message communication process cannot be guaranteed; it cannot provide key services for other upper-layer applications, and the upper-layer applications of the mobile phone are not protected by corresponding security policies.
  • the present invention proposes a communication system and method based on a quantum security SIM card, as well as a quantum security SIM card and a key service platform, in which a file storage space is opened up on the basis of the physical structure and logical architecture of the existing SIM card And increase the definition data interaction interface, so that it can directly provide quantum keys for upper-layer applications to protect the security of the communication process, thus providing quantum security functions and allowing large capacity, so as to meet the increasing security information communication and file storage under the gradual popularization of 5G networks need.
  • the key charging mode and the communication mode the freshness and pre-stored security of the session key and its encryption key can be effectively guaranteed, and the data security of the quantum-safe SIM card can be ensured.
  • the first aspect of the present invention relates to a communication system based on a quantum security SIM card, which includes a quantum key service platform, a mobile device SDK and a quantum security SIM card;
  • the quantum key service platform is configured to: form and transmit first encrypted data in key filling mode, the first encrypted data comprising the shared quantum key K1 encrypted with the first encryption key Ka and the a public key encrypted first encryption key Ka; and, in the communication mode, form and transmit second encrypted data, the second encrypted data including the session key Kb encrypted by the shared quantum key K1;
  • the mobile device SDK is configured to allow data interaction between the quantum key service platform and the quantum security SIM card;
  • the quantum-safe SIM card is configured to: in the key charging mode, store the first encrypted data; and, in the communication mode, based on the first encrypted data and the second encrypted data Encrypt data, and obtain the session key Kb by means of decryption operation for secure communication.
  • the quantum key service platform may be configured to: in the key filling mode, generate the first encryption key Ka, and use the first encryption key Ka to perform the encryption on the shared quantum key. encrypting the first encryption key Ka using the public key; and/or, in the communication mode, generating the session key Kb and using the shared quantum key K1 The session key Kb is encrypted.
  • the quantum security SIM card can be set to: in the communication mode, use a private key to decrypt the first encryption key Ka encrypted by the public key to obtain the first encryption key Ka; Decrypt the shared quantum key K1 encrypted by the first encryption key Ka using the first encryption key Ka to obtain the shared quantum key K1; and use the shared quantum key K1 to decrypt the shared quantum key K1.
  • the session key Kb encrypted by the shared quantum key K1 is decrypted to obtain the session key Kb.
  • the first encryption key Ka is a first symmetric key Ka
  • the session key Kb is a second symmetric key Kb
  • the public key is an ECC public key
  • symmetric encryption and decryption operations can be implemented by means of XOR operations.
  • the mobile device SDK is configured to encapsulate an interaction interface for data interaction with the quantum key service platform, and a call interface for data interaction with the quantum security SIM card; the quantum security The SIM card defines a data interface for allowing the mobile device SDK to be called for data interaction.
  • a second aspect of the present invention relates to a communication method based on a quantum security SIM card, comprising a key charging step and a session key acquisition step;
  • the key filling step is used to generate first encrypted data and store it in the quantum security SIM card, the first encrypted data includes the shared quantum key K1 encrypted by the first encryption key Ka and the encrypted shared quantum key K1 encrypted by the public key.
  • the step of obtaining the session key is used for: generating second encrypted data and storing it in the quantum security SIM card, the second encrypted data including the session key Kb encrypted by the shared quantum key K1;
  • the session key Kb is obtained from the first encrypted data and the second encrypted data by means of a decryption operation.
  • the first encryption key Ka is generated by the quantum key service platform, and the shared quantum key K1 is performed using the first encryption key Ka. Encrypt, using the public key to encrypt the first encryption key Ka;
  • the session key Kb is generated by the quantum key service platform, and the session key Kb is encrypted by the shared quantum key K1;
  • the quantum security SIM card decrypts the first encryption key Ka encrypted by the public key with the private key to obtain the first encryption key Ka, and uses the first encryption key Ka to decrypt the first encryption key Ka.
  • the shared quantum key K1 encrypted by the key Ka is decrypted to obtain the shared quantum key K1, and the session key Kb encrypted by the shared quantum key K1 is decrypted using the shared quantum key K1 to obtain all the the session key Kb.
  • the quantum key service platform generates the session key Kb in response to a session key request.
  • the communication method may further include the step of configuring a mobile device SDK to realize data interaction between the quantum key service platform and the quantum security SIM card.
  • the first encryption key Ka is a first symmetric key Ka
  • the session key Kb is a second symmetric key Kb
  • the public key is an ECC public key
  • a third aspect of the present invention relates to a quantum security SIM card, which includes a data interface, a key data storage unit, a session key storage unit, and an encryption/decryption unit;
  • the key data storage unit is configured to store key data, wherein the key data includes first encrypted data and second encrypted data, the first encrypted data including the encrypted data encrypted by the first encryption key Ka. a shared quantum key K1 and a first encryption key Ka encrypted by the public key, and the second encrypted data includes a session key Kb encrypted by the shared quantum key K1;
  • the data interface is defined to allow being called for interaction of the key data
  • the encryption and decryption unit is arranged to obtain the session key Kb from the key data by means of a decryption operation
  • the session key storage unit is arranged to store the session key Kb.
  • the encryption/decryption unit may be configured to: decrypt the first encryption key Ka encrypted by the public key with a private key to obtain the first encryption key Ka; use the first encryption key Ka; decrypting the shared quantum key K1 encrypted by the first encryption key Ka to obtain the shared quantum key K1; and using the shared quantum key K1 to decrypt the shared quantum key K1
  • the encrypted session key Kb is decrypted to obtain the session key Kb.
  • the encryption/decryption unit may be configured to implement a symmetric encryption/decryption operation by means of an exclusive OR operation.
  • a fourth aspect of the present invention relates to a quantum key service platform, which includes a symmetric key generation unit, an encryption/decryption unit, and a data interface;
  • the symmetric key generation unit is configured to: generate a first encryption key Ka in a key-filling mode, and generate a session key Kb in a communication mode;
  • the encryption and decryption unit is configured to: in the key filling mode, encrypt the shared quantum key K1 with the first encryption key Ka, and encrypt the first encryption key Ka with the public key, thereby forming first encrypted data; and in the communication mode, encrypting the session key Kb with the shared quantum key K1, thereby forming second encrypted data;
  • the data interface is provided for data interaction.
  • the public key is an ECC public key; and/or the encryption/decryption unit is configured to implement a symmetric encryption/decryption operation by means of an exclusive OR operation.
  • the symmetric key generation unit is further configured to generate the session key Kb in response to a session key request.
  • FIG. 2 shows a schematic flow chart for implementing encrypted communication in a communication system based on a quantum security SIM card according to the present invention.
  • a communication system based on a quantum security SIM card may include a quantum key service platform, a mobile device SDK and a quantum security SIM card.
  • the quantum key service platform can work in key charging mode and communication mode.
  • the quantum key service platform In the key charging mode, the quantum key service platform generates the first symmetric key Ka, encrypts the shared quantum key K1 with the first symmetric key Ka, and encrypts the first symmetric key Ka with the public key Encrypted, thereby forming the first encrypted data, and sending it out through the network.
  • the first encrypted data may include the shared quantum key K1 encrypted with the first symmetric key Ka, and the first symmetric key Ka encrypted with the public key.
  • the quantum key service platform may include a symmetric key generation unit, an encryption/decryption unit, and a data interface.
  • the data interface can be used to realize data interaction with the outside (eg, mobile device SDK), such as outputting the first and second encrypted data, and receiving a session key request.
  • outside e.g, mobile device SDK
  • the mobile device SDK can be encapsulated with an interaction interface for data interaction with the quantum key service platform, and a call interface for data interaction with the quantum security SIM card, thereby providing between the quantum key service platform and the quantum security SIM card. Data channel to allow data interaction between the quantum key service platform and the quantum secure SIM card. Therefore, the mobile device SDK itself does not store any key related data.
  • a data interface can be defined on the quantum security SIM card to allow the mobile device SDK to call for data interaction.
  • the quantum-safe SIM card also works in key charging mode and communication mode.
  • the quantum security SIM card can receive and store the first encrypted data via the mobile device SDK.
  • the quantum security SIM card can receive and store the second encrypted data via the mobile device SDK, and: use the corresponding pre-stored private key (eg, ECC private key) to perform a public key-encrypted first symmetric encryption in the first encrypted data.
  • Decrypt the key Ka to obtain the first symmetric key Ka
  • use the first symmetric key Ka to decrypt the shared quantum key K1 encrypted by the first symmetric key Ka in the first encrypted data to obtain the shared quantum key K1
  • using the shared quantum key K1 to decrypt the second encrypted data to obtain the second symmetric key Kb, and use it as the session key.
  • the key-related data stored in the quantum security SIM card is in encrypted form (stored in the form of the first encrypted data), and the first encrypted data as the session key is generated only in the communication mode.
  • the plaintext of the two-symmetric key Kb is used for secure communication, which can effectively ensure the security of the key data in the quantum security SIM card, thereby ensuring the confidentiality of communication.
  • the quantum security SIM card may include a data interface, a key data storage unit, a session key storage unit, and an encryption/decryption unit.
  • the key data storage unit may be used to store key data, which includes, for example, first encrypted data and second encrypted data.
  • FIG. 1 shows a schematic flow chart for realizing quantum key charging in a communication system based on a quantum secure SIM card according to the present invention.
  • the key charging step will be performed.
  • the first symmetric key Ka is generated by the quantum key service platform, and the shared quantum key K1 is encrypted by the first symmetric key Ka, and the shared quantum key K1 encrypted by the first symmetric key Ka is obtained.
  • the first encrypted data is formed on the quantum key service platform, which includes the shared quantum key K1 encrypted with the first symmetric key Ka, and the first symmetric key Ka encrypted with the ECC public key.
  • the quantum key service platform sends the first encrypted data to the mobile device SDK.
  • the mobile device SDK allows the first encrypted data to be stored in the quantum-safe SIM card by means of the interactive interface and the interface for calling the quantum-safe SIM card. Thereby, the key charging of the quantum-safe SIM card is realized.
  • FIG. 2 shows a schematic flow chart for implementing encrypted communication in a communication system based on a quantum security SIM card according to the present invention.
  • the step of obtaining the session key is performed.
  • a session key request is sent to the subkey service platform via the mobile device SDK to apply for the session key of this communication.
  • the quantum key service platform In response to the session key request, the quantum key service platform generates a second symmetric key Kb (for example, 128 bits) as the session key for this communication; and uses the shared quantum key K1 to encrypt the second symmetric key Kb , obtain the second encrypted data, that is, the second symmetric key Kb encrypted by the shared quantum key K1, and send it out.
  • a second symmetric key Kb for example, 128 bits
  • the mobile device SDK receives the second encrypted data through the interactive interface, and calls the interface of the quantum security SIM card to transmit the second encrypted data to the quantum security SIM card for storage.
  • the quantum security SIM card decrypts the first symmetric key Ka encrypted by the ECC public key in the first encrypted data by using the pre-stored corresponding ECC private key to obtain the first symmetric key Ka; the first symmetric key Ka is used to decrypt the first symmetric key Ka.
  • the shared quantum key K1 encrypted by the first symmetric key Ka in the encrypted data is decrypted to obtain the shared quantum key K1; finally, the shared quantum key K1 is used to decrypt the second encrypted data encrypted by the shared quantum key K1.
  • the second symmetric key Kb is decrypted to obtain the second symmetric key Kb and stored.
  • the SIM card can be allowed to be directly used for upper-layer applications (such as mobile phones).
  • Application provides quantum keys to realize the security protection of the communication process, and also has the functions of traditional SIM card identification and communication billing.
  • the key charging mode and the communication mode the freshness and pre-stored security of the session key and its encryption key can be effectively guaranteed, and the data security of the quantum security SIM card and the security protection of the communication process can be ensured.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Theoretical Computer Science (AREA)
  • Telephone Function (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

本发明提出了一种基于量子安全SIM卡的通信系统及方法,以及量子安全SIM卡及量子密钥服务平台,其中在现有SIM卡物理结构和逻辑架构基础上开辟文件存储空间和增加定义数据交互接口,使其能够直接为上层应用提供量子密钥以保护通信过程安全,由此提供量子安全功能且允许大容量,从而满足5G网络逐渐普及下与日俱增的安全信息通信及文件存储需求。借助密钥充注模式和通信模式配合设计,可以有效保证会话密钥及其加密密钥的新鲜度和预存安全性,确保量子安全SIM卡的数据安全。

Description

基于量子安全SIM卡的通信系统及方法、量子安全SIM卡、密钥服务平台
本申请要求于2020年12月30日提交中国专利局、申请号为202011616484.4、发明名称为“基于量子安全SIM卡的通信系统及方法、量子安全SIM卡、密钥服务平台”的国内申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及量子保密通信领域,尤其涉及一种基于量子安全SIM卡的通信系统及方法,以及量子安全SIM卡和密钥服务平台。
背景技术
现有SIM卡的主要功能是利用预置密钥对SIM卡持有者身份进行识别、对通信过程中产生的流量进行计费。SIM卡是存储了数字移动电话客户信息的电脑芯片,供GSM网络对用户身份进行识别与验证。SIM卡中预置及存储的密钥主要是用于持卡者身份信息的认证和保护、协商会话密钥保障通信内容安全。现有技术方案没有对通信内容使用密钥进行处理,语音、短信通信过程的安全性难以得到保障;也无法对上层其他应用提供密钥服务,手机上层应用没有相应安全策略进行保护。
发明内容
针对这一问题,本发明提出了一种基于量子安全SIM卡的通信系统及方法,以及量子安全SIM卡和密钥服务平台,其中在现有SIM卡物理结构和逻辑架构基础上开辟文件存储空间和增加定义数据交互接口,使其能够直接为上层应用提供量子密钥以保护通信过程安全,由此提供量子安全功能且允许大容量,从而满足5G网络逐渐普及下与日俱增的安全信息通信及文件存储需求。其中,借助密钥充注模式和通信模式配合设计,可以有效保证会话密钥及其加密密钥的新鲜度和预存安全性,确保量子安全SIM卡的数据安全。
具体而言,本发明的第一方面涉及一种基于量子安全SIM卡的通信系统,其包括量子密钥服务平台、移动设备SDK和量子安全SIM卡;
所述量子密钥服务平台被设置用于:在密钥充注模式下形成并发送第 一加密数据,所述第一加密数据包括经第一加密密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka;以及,在通信模式下形成并发送第二加密数据,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;
所述移动设备SDK被设置用于允许所述量子密钥服务平台与所述量子安全SIM卡之间进行数据交互;
所述量子安全SIM卡被设置用于:在所述密钥充注模式下,存储所述第一加密数据;以及,在所述通信模式下,基于所述第一加密数据和所述第二加密数据,借助解密运算获得所述会话密钥Kb以用于保密通信。
进一步地,所述量子密钥服务平台可以设置成:在所述密钥充注模式下,生成所述第一加密密钥Ka,并利用所述第一加密密钥Ka对所述共享量子密钥K1进行加密,利用所述公钥对所述第一加密密钥Ka进行加密;以及/或者,在所述通信模式下,生成所述会话密钥Kb,并利用所述共享量子密钥K1对所述会话密钥Kb进行加密。
进一步地,所述量子安全SIM卡可以设置成:在所述通信模式下,利用私钥对所述经公钥加密的第一加密密钥Ka进行解密,获得所述第一加密密钥Ka;利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密,获得所述共享量子密钥K1;以及,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密,获得所述会话密钥Kb。
其中,所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第二对称密钥Kb;以及/或者,所述公钥为ECC公钥。
可选地,可以借助异或运算实现对称加解密操作。
优选地,所述移动设备SDK被设置成封装有用于与所述量子密钥服务平台进行数据交互的交互接口,以及用于与所述量子安全SIM卡进行数据交互的调用接口;所述量子安全SIM卡定义有数据接口,用于允许由所述移动设备SDK调用以进行数据交互。
本发明的第二方面涉及一种基于量子安全SIM卡的通信方法,其包括 密钥充注步骤和会话密钥获取步骤;
所述密钥充注步骤用于生成第一加密数据并存入所述量子安全SIM卡,所述第一加密数据包括经第一加密密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka;
所述会话密钥获取步骤用于:生成第二加密数据并存入所述量子安全SIM卡,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;以及,在所述量子安全SIM卡中借助解密运算从所述第一加密数据和所述第二加密数据中获得所述会话密钥Kb。
进一步地,在所述密钥充注步骤中,由所述量子密钥服务平台生成所述第一加密密钥Ka,并利用所述第一加密密钥Ka对所述共享量子密钥K1进行加密,利用所述公钥对所述第一加密密钥Ka进行加密;
在所述会话密钥获取步骤中,由所述量子密钥服务平台生成所述会话密钥Kb,并利用所述共享量子密钥K1对所述会话密钥Kb进行加密;以及,由所述量子安全SIM卡利用私钥对所述经公钥加密的第一加密密钥Ka进行解密以获得所述第一加密密钥Ka,利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密以获得所述共享量子密钥K1,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密以获得所述会话密钥Kb。
更进一步地,在所述会话密钥获取步骤中,所述量子密钥服务平台响应于会话密钥请求生成所述会话密钥Kb。
进一步地,该通信方法还可以包括配置移动设备SDK以实现所述量子密钥服务平台与所述量子安全SIM卡之间的数据交互的步骤。
其中,所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第二对称密钥Kb;以及/或者,所述公钥为ECC公钥。
本发明的第三方面涉及一种量子安全SIM卡,其包括数据接口、密钥数据存储单元、会话密钥存储单元和加解密单元;
所述密钥数据存储单元被设置用于存储密钥数据,其中,所述密钥数据包括第一加密数据和第二加密数据,所述第一加密数据包括经第一加密 密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;
所述数据接口定义成允许被调用以进行所述密钥数据的交互;
所述加解密单元被设置用于借助解密运算从所述密钥数据中获得所述会话密钥Kb;
所述会话密钥存储单元被设置用于存储所述会话密钥Kb。
进一步地,所述加解密单元可以被设置成:利用私钥对所述经公钥加密的第一加密密钥Ka进行解密,获得所述第一加密密钥Ka;利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密,获得所述共享量子密钥K1;以及,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密,获得所述会话密钥Kb。
更进一步地,所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第二对称密钥Kb;以及/或者,所述公钥为ECC公钥。
其中,所述加解密单元可以被设置成借助异或运算实现对称加解密操作。
本发明的第四方面涉及一种量子密钥服务平台,其包括对称密钥生成单元、加解密单元以及数据接口;
所述对称密钥生成单元被设置用于:在密钥充注模式下生成第一加密密钥Ka,以及在通信模式下生成会话密钥Kb;
所述加解密单元被设置用于:在所述密钥充注模式下,利用所述第一加密密钥Ka加密共享量子密钥K1,并且利用公钥加密所述第一加密密钥Ka,从而形成第一加密数据;以及在所述通信模式下,利用所述共享量子密钥K1加密所述会话密钥Kb,从而形成第二加密数据;
所述数据接口被设置用于进行数据交互。
进一步地,所述公钥为ECC公钥;以及/或者,所述加解密单元被设置成借助异或运算实现对称加解密操作。
进一步地,所述对称密钥生成单元被进一步设置成响应于会话密钥请求生成所述会话密钥Kb。
附图说明
下面结合附图对本发明的具体实施方式作进一步详细的说明。
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需使用的附图作简单地介绍,显而易见,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图来获得其他的附图。
图1示出了根据本发明的基于量子安全SIM卡的通信系统用于实现量子密钥充注的流程示意图;
图2示出了根据本发明的基于量子安全SIM卡的通信系统用于实现加密通信的流程示意图。
具体实施方式
在下文中,本发明的示例性实施例将参照附图来详细描述。下面的实施例以举例的方式提供,以便充分传达本发明的精神给本发明所属领域的技术人员。因此,本发明不限于本文公开的实施例。
根据本发明,基于量子安全SIM卡的通信系统可以包括量子密钥服务平台、移动设备SDK和量子安全SIM卡。
量子密钥服务平台可以工作在密钥充注模式和通信模式下。
在密钥充注模式下,量子密钥服务平台生成第一对称密钥Ka,并利用第一对称密钥Ka对共享量子密钥K1进行加密,以及利用公钥对第一对称密钥Ka进行加密,从而形成第一加密数据,并通过网络向外发送。相应地,第一加密数据可以包括经第一对称密钥Ka加密的共享量子密钥K1,以及经公钥加密的第一对称密钥Ka。
在通信模式下,量子密钥服务平台生成第二对称密钥Kb,并利用共享量子密钥K1对第二对称密钥Kb进行加密,从而形成第二加密数据,并通过网络向外发送。相应地,第二加密数据可以包括经共享量子密钥K1加 密的第二对称密钥Kb。
作为示例,公钥可以为ECC公钥。作为示例,可以利用异或运算进行对称加密运算。
在一种实施方式中,量子密钥服务平台可以包括对称密钥生成单元、加解密单元以及数据接口。
对称密钥生成单元可以在密钥充注模式下生成第一加密密钥Ka,并在通信模式下生成会话密钥Kb。
加解密单元可以用于执行加密操作以生成第一加密数据和第二加密数据。其中,在密钥充注模式下,可以利用第一加密密钥Ka加密共享量子密钥K1,并且利用公钥加密第一加密密钥Ka,形成第一加密数据;在通信模式下,利用共享量子密钥K1加密会话密钥Kb,从而形成第二加密数据。
数据接口可以用于实现与外部(例如移动设备SDK)之间的数据交互,例如输出第一和第二加密数据,以及接收会话密钥请求等。
移动设备SDK可以封装有用于与量子密钥服务平台进行数据交互的交互接口,以及用于与量子安全SIM卡进行数据交互的调用接口,从而在量子密钥服务平台和量子安全SIM卡之间提供数据通道,以允许量子密钥服务平台与量子安全SIM卡之间的数据交互。因此,移动设备SDK本身并不存储任何密钥相关数据。
相应地,量子安全SIM卡上可以定义数据接口,用于允许移动设备SDK调用以进行数据交互。
此外,量子安全SIM卡也工作在密钥充注模式和通信模式下。
在密钥充注模式下,量子安全SIM卡可以经移动设备SDK接收并存储第一加密数据。
在通信模式下,量子安全SIM卡可以经移动设备SDK接收并存储第二加密数据,并且:利用预存的相应私钥(例如ECC私钥)对第一加密数据中经公钥加密的第一对称密钥Ka进行解密,获得第一对称密钥Ka;利 用第一对称密钥Ka对第一加密数据中经第一对称密钥Ka加密的共享量子密钥K1进行解密,获得共享量子密钥K1;以及,利用共享量子密钥K1对第二加密数据进行解密,获得第二对称密钥Kb,并将其作为会话密钥。
由此可见,在非通信模式下,量子安全SIM卡中存储的密钥相关数据均为加密形式(以第一加密数据的形式存储),且只有在通信模式下才生成作为会话密钥的第二对称密钥Kb的明文以用于保密通信,由此可以有效保证量子安全SIM卡中密钥数据的安全性,从而确保通信的保密性。
作为一种实施方式,量子安全SIM卡可以包括数据接口、密钥数据存储单元、会话密钥存储单元和加解密单元。
其中,密钥数据存储单元可以用于存储密钥数据,其例如包括第一加密数据和第二加密数据。
数据接口可以被定义成允许被调用(例如移动设备SDK)以进行例如密钥数据等数据的交互。
加解密单元可以执行加解密操作,以从密钥数据中获得会话密钥Kb。
会话密钥存储单元则可以存储会话密钥Kb,以便用于保密通信过程。
下面将继续描述根据本发明的基于量子安全SIM卡的通信方法的工作流程,以便更好地理解本发明的通信系统的工作原理。
图1示出了根据本发明的基于量子安全SIM卡的通信系统用于实现量子密钥充注的流程示意图。
如图1所示,在密钥充注模式下,将执行密钥充注步骤。
在密钥充注步骤中,由量子密钥服务平台生成第一对称密钥Ka,并利用第一对称密钥Ka对共享量子密钥K1进行加密,得到经第一对称密钥Ka加密的共享量子密钥K1;以及利用ECC公钥对第一对称密钥Ka进行加密,得到经ECC公钥加密的第一对称密钥Ka。由此,在量子密钥服务平台上形成第一加密数据,其包括经第一对称密钥Ka加密的共享量子密钥K1,以及经ECC公钥加密的第一对称密钥Ka。
随后,量子密钥服务平台将第一加密数据发送给移动设备SDK。
移动设备SDK借助交互接口以及调用量子安全SIM卡的接口,从而允许将第一加密数据存入量子安全SIM卡中进行存储。由此,实现对量子安全SIM卡的密钥充注。
图2示出了根据本发明的基于量子安全SIM卡的通信系统用于实现加密通信的流程示意图。
当上层应用有通信需求时,即处于通信模式下,执行会话密钥获取步骤。
如图2所示,在会话密钥获取步骤中,经由移动设备SDK向量子密钥服务平台发送会话密钥请求,申请本次通信的会话密钥。
量子密钥服务平台响应会话密钥请求,生成第二对称密钥Kb(其例如为128bit),作为本次通信的会话密钥;并利用共享量子密钥K1对第二对称密钥Kb进行加密,得到第二加密数据,即经共享量子密钥K1加密的第二对称密钥Kb,并将其向外发送。
移动设备SDK经交互接口接收第二加密数据,并调用量子安全SIM卡的接口将第二加密数据传送至量子安全SIM卡以进行存储。
量子安全SIM卡利用预存的相应ECC私钥对第一加密数据中经ECC公钥加密的第一对称密钥Ka进行解密,得到第一对称密钥Ka;利用第一对称密钥Ka对第一加密数据中经第一对称密钥Ka加密的共享量子密钥K1进行解密,得到共享量子密钥K1;最后,利用共享量子密钥K1对第二加密数据中经共享量子密钥K1加密的第二对称密钥Kb进行解密,获得第二对称密钥Kb,并进行存储。
此时,由于量子安全SIM卡中已存储有作为会话密钥的第二对称密钥Kb的明文,因此通信业务双方可以使用量子安全SIM卡中存储的第二对称密钥Kb作为会话密钥,进行保密通信。
综上可知,借助本发明所提出的基于量子安全SIM卡的通信系统及方法,可以在不改变传统SIM卡结构,仅通过增加定义数据交互接口,即可允许SIM卡直接为上层应用(例如手机应用)提供量子密钥以实现通信过 程的安全保护,同时还具有传统SIM卡身份识别和通信计费功能。其中,借助密钥充注模式和通信模式配合设计,可以有效保证会话密钥及其加密密钥的新鲜度和预存安全性,确保量子安全SIM卡的数据安全及通信过程的安全保护。
尽管前面结合附图通过具体实施例对本发明进行了说明,但是,本领域技术人员容易认识到,上述实施例仅仅是示例性的,用于说明本发明的原理,其并不会对本发明的范围造成限制,本领域技术人员可以对上述实施例进行各种组合、修改和等同替换,而不脱离本发明的精神和范围。

Claims (18)

  1. 一种基于量子安全SIM卡的通信系统,其包括量子密钥服务平台、移动设备SDK和量子安全SIM卡;
    所述量子密钥服务平台被设置用于:在密钥充注模式下形成并发送第一加密数据,所述第一加密数据包括经第一加密密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka;以及,在通信模式下形成并发送第二加密数据,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;
    所述移动设备SDK被设置用于允许所述量子密钥服务平台与所述量子安全SIM卡之间进行数据交互;
    所述量子安全SIM卡被设置用于:在所述密钥充注模式下,存储所述第一加密数据;以及,在所述通信模式下,基于所述第一加密数据和所述第二加密数据,借助解密运算获得所述会话密钥Kb以用于保密通信。
  2. 如权利要求1所述的通信系统,其中,所述量子密钥服务平台被进一步设置成:在所述密钥充注模式下,生成所述第一加密密钥Ka,并利用所述第一加密密钥Ka对所述共享量子密钥K1进行加密,利用所述公钥对所述第一加密密钥Ka进行加密;以及/或者,在所述通信模式下,生成所述会话密钥Kb,并利用所述共享量子密钥K1对所述会话密钥Kb进行加密。
  3. 如权利要求1所述的通信系统,其中,所述量子安全SIM卡被进一步设置成:在所述通信模式下,利用私钥对所述经公钥加密的第一加密密钥Ka进行解密,获得所述第一加密密钥Ka;利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密,获得所述共享量子密钥K1;以及,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密,获得所述会话密钥Kb。
  4. 如权利要求1所述的通信系统,其中:
    所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第 二对称密钥Kb;
    以及/或者,所述公钥为ECC公钥。
  5. 如权利要求1所述的通信系统,其中,借助异或运算实现对称加解密操作。
  6. 如权利要求1所述的通信系统,其中,所述移动设备SDK被设置成封装有用于与所述量子密钥服务平台进行数据交互的交互接口,以及用于与所述量子安全SIM卡进行数据交互的调用接口;
    所述量子安全SIM卡定义有数据接口,用于允许由所述移动设备SDK调用以进行数据交互。
  7. 一种基于量子安全SIM卡的通信方法,其包括密钥充注步骤和会话密钥获取步骤;
    所述密钥充注步骤用于生成第一加密数据并存入所述量子安全SIM卡,所述第一加密数据包括经第一加密密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka;
    所述会话密钥获取步骤用于:生成第二加密数据并存入所述量子安全SIM卡,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;以及,在所述量子安全SIM卡中借助解密运算从所述第一加密数据和所述第二加密数据中获得所述会话密钥Kb。
  8. 如权利要求7所述的通信方法,其中:
    在所述密钥充注步骤中,由所述量子密钥服务平台生成所述第一加密密钥Ka,并利用所述第一加密密钥Ka对所述共享量子密钥K1进行加密,利用所述公钥对所述第一加密密钥Ka进行加密;
    在所述会话密钥获取步骤中,由所述量子密钥服务平台生成所述会话密钥Kb,并利用所述共享量子密钥K1对所述会话密钥Kb进行加密;以及,由所述量子安全SIM卡利用私钥对所述经公钥加密的第一加密密钥Ka进行解密以获得所述第一加密密钥Ka,利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密以获得所述共享量 子密钥K1,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密以获得所述会话密钥Kb。
  9. 如权利要求8所述的通信方法,其中,在所述会话密钥获取步骤中,所述量子密钥服务平台响应于会话密钥请求生成所述会话密钥Kb。
  10. 如权利要求7所述的通信方法,其还包括配置移动设备SDK以实现所述量子密钥服务平台与所述量子安全SIM卡之间的数据交互的步骤。
  11. 如权利要求7所述的通信方法,其中:
    所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第二对称密钥Kb;以及/或者,所述公钥为ECC公钥。
  12. 一种量子安全SIM卡,其包括数据接口、密钥数据存储单元、会话密钥存储单元和加解密单元;
    所述密钥数据存储单元被设置用于存储密钥数据,其中,所述密钥数据包括第一加密数据和第二加密数据,所述第一加密数据包括经第一加密密钥Ka加密的共享量子密钥K1和经公钥加密的第一加密密钥Ka,所述第二加密数据包括经所述共享量子密钥K1加密的会话密钥Kb;
    所述数据接口定义成允许被调用以进行所述密钥数据的交互;
    所述加解密单元被设置用于借助解密运算从所述密钥数据中获得所述会话密钥Kb;
    所述会话密钥存储单元被设置用于存储所述会话密钥Kb。
  13. 如权利要求12所述的量子安全SIM卡,其中,所述加解密单元被设置成:利用私钥对所述经公钥加密的第一加密密钥Ka进行解密,获得所述第一加密密钥Ka;利用所述第一加密密钥Ka对所述经第一加密密钥Ka加密的共享量子密钥K1进行解密,获得所述共享量子密钥K1;以及,利用所述共享量子密钥K1对经所述共享量子密钥K1加密的会话密钥Kb进行解密,获得所述会话密钥Kb。
  14. 如权利要求12或13所述的量子安全SIM卡,其中,所述第一加密密钥Ka为第一对称密钥Ka,且所述会话密钥Kb为第二对称密钥Kb; 以及/或者,所述公钥为ECC公钥。
  15. 如权利要求12所述的量子安全SIM卡,其中,所述加解密单元被设置成借助异或运算实现对称加解密操作。
  16. 一种量子密钥服务平台,其包括对称密钥生成单元、加解密单元以及数据接口;
    所述对称密钥生成单元被设置用于:在密钥充注模式下生成第一加密密钥Ka,以及在通信模式下生成会话密钥Kb;
    所述加解密单元被设置用于:在所述密钥充注模式下,利用所述第一加密密钥Ka加密共享量子密钥K1,并且利用公钥加密所述第一加密密钥Ka,从而形成第一加密数据;以及在所述通信模式下,利用所述共享量子密钥K1加密所述会话密钥Kb,从而形成第二加密数据;
    所述数据接口被设置用于进行数据交互。
  17. 如权利要求16所述的量子密钥服务平台,其中,所述公钥为ECC公钥;以及/或者,所述加解密单元被设置成借助异或运算实现对称加解密操作。
  18. 如权利要求16所述的量子密钥服务平台,其中,所述对称密钥生成单元被进一步设置成响应于会话密钥请求生成所述会话密钥Kb。
PCT/CN2021/142320 2020-12-30 2021-12-29 基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台 WO2022143727A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202011616484.4 2020-12-30
CN202011616484.4A CN114697008B (zh) 2020-12-30 2020-12-30 基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台

Publications (1)

Publication Number Publication Date
WO2022143727A1 true WO2022143727A1 (zh) 2022-07-07

Family

ID=82132817

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/142320 WO2022143727A1 (zh) 2020-12-30 2021-12-29 基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台

Country Status (2)

Country Link
CN (1) CN114697008B (zh)
WO (1) WO2022143727A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115348085A (zh) * 2022-08-12 2022-11-15 长江量子(武汉)科技有限公司 一种基于量子加密的防疫管理方法及防疫终端
CN117220878A (zh) * 2023-10-20 2023-12-12 合肥合燃华润燃气有限公司 一种燃气表远程在线量子密钥管理方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101483808A (zh) * 2008-01-07 2009-07-15 中兴通讯股份有限公司 保障多媒体广播业务安全的方法
CN106465121A (zh) * 2014-05-23 2017-02-22 苹果公司 电子用户身份模块配置
US20180084415A1 (en) * 2015-04-09 2018-03-22 Vodafone Ip Licensing Limited Mitigation of problems arising from sim key leakage
CN111865589A (zh) * 2020-08-14 2020-10-30 国科量子通信网络有限公司 实现移动通信量子加密传输的量子通信加密系统及其方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101720071B (zh) * 2009-12-01 2012-10-03 郑州信大捷安信息技术股份有限公司 基于安全sim卡的短消息两阶段加密传输和安全存储方法
CN106712932B (zh) * 2016-07-20 2019-03-19 腾讯科技(深圳)有限公司 密钥管理方法、装置及系统
CN110650011A (zh) * 2019-10-29 2020-01-03 江苏亨通问天量子信息研究院有限公司 基于量子密钥的加密存储方法和加密存储卡

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101483808A (zh) * 2008-01-07 2009-07-15 中兴通讯股份有限公司 保障多媒体广播业务安全的方法
CN106465121A (zh) * 2014-05-23 2017-02-22 苹果公司 电子用户身份模块配置
US20180084415A1 (en) * 2015-04-09 2018-03-22 Vodafone Ip Licensing Limited Mitigation of problems arising from sim key leakage
CN111865589A (zh) * 2020-08-14 2020-10-30 国科量子通信网络有限公司 实现移动通信量子加密传输的量子通信加密系统及其方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
WANG JIANQUAN, ZHANGCHAO MA, XINZHONG LI, LEI SUN, CHANGWEI HU: "Quantum secure communication network architecture and mobile application solution", DIANXIN KEXUE - TELECOMMUNICATIONS SCIENCE, RENMIN YOUDIAN CHUBANSHE, BEIJING, CN, no. 9, 20 September 2018 (2018-09-20), CN , pages 10 - 19, XP055948877, ISSN: 1000-0801, DOI: 10.11959/j.issn.1000−0801.2018256 *

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115348085A (zh) * 2022-08-12 2022-11-15 长江量子(武汉)科技有限公司 一种基于量子加密的防疫管理方法及防疫终端
CN117220878A (zh) * 2023-10-20 2023-12-12 合肥合燃华润燃气有限公司 一种燃气表远程在线量子密钥管理方法及系统
CN117220878B (zh) * 2023-10-20 2024-05-28 合肥合燃华润燃气有限公司 一种燃气表远程在线量子密钥管理方法

Also Published As

Publication number Publication date
CN114697008A (zh) 2022-07-01
CN114697008B (zh) 2024-03-12

Similar Documents

Publication Publication Date Title
US8417218B2 (en) SIM based authentication
CN103458382B (zh) 一种手机私密短信的硬件加密传输和存储方法及系统
WO2022143727A1 (zh) 基于量子安全sim卡的通信系统及方法、量子安全sim卡、密钥服务平台
CN102572817B (zh) 实现移动通信保密的方法和智能存储卡
US20100135491A1 (en) Authentication method
RU2495532C2 (ru) Способ и устройство для осуществления связи со сквозным шифрованием
CN101340443A (zh) 一种通信网络中会话密钥协商方法、系统和服务器
CN102196425A (zh) 基于量子密钥分配网络的移动加密系统及其通信方法
CN101720071A (zh) 基于安全sim卡的短消息两阶段加密传输和安全存储方法
US9363034B2 (en) Method to encrypt information that is transferred between two communication units
WO2012024906A1 (zh) 一种移动通信系统及其语音通话加密的方法
CN101626567A (zh) 短信发送、接收方法及发送、接收装置以及移动终端
CN102202299A (zh) 一种基于3g/b3g的端到端语音加密系统的实现方法
CN103458400A (zh) 一种语音加密通信系统中的密钥管理方法
CN109600725A (zh) 一种基于sm9算法的短信加密方法
CN104901803A (zh) 一种基于cpk标识认证技术的数据交互安全保护方法
CN104601820A (zh) 一种基于tf密码卡的手机终端信息保护方法
CN109586899B (zh) 信令操作及其指示方法、装置及计算机存储介质
CN105262759A (zh) 一种加密通信的方法和系统
CN106911632B (zh) 一种调用能力封装的方法和系统
KR101329789B1 (ko) 모바일 디바이스의 데이터베이스 암호화 방법
CN115204876A (zh) 一种用于移动支付的量子安全u盾设备及方法
CN102413462B (zh) 基于安全tf卡的增强移动终端系统语音通信安全性的方法及系统
US20230070408A1 (en) Secure communication device equipped with quantum encryption chip based quantum random number and method of providing secure communication service using the same
CN103986640A (zh) 一种可保障用户通讯内容安全的即时通讯方法及其系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21914460

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21914460

Country of ref document: EP

Kind code of ref document: A1