IP Library Granted Patent US 11,362,818
Granted Patent B2
US 11,362,818 · App. 16/464,579 · Granted Jun 14, 2022

Method for issuing quantum key chip, application method, issuing platform and system

Inventors: Qing Chen (Guangdong, CN); Xiang Xiao (Guangdong, CN); Jiayi Lin (Guangdong, CN); Songyan Ding (Guangdong, CN); Jierong Chen (Guangdong, CN)
Assignee: QUANTUMCTEK (GUANGDONG) CO., LTD.
H04L9/0852H04L9/0869H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,362,818
App. No.
16/464,579
Granted
Jun 14, 2022
Kind
B2
Abstract

A method for issuing a quantum key chip, a method for applying a quantum key chip, an issuing platform and a system. The method comprises: feeding, by a a quantum key issuing platform, a quantum key into a quantum key chip and binding an ID of the quantum key chip in a one-to-one correspondence to an ID of a user using the quantum key chip, where the ID of the quantum key chip and/or the ID of the user serve as identification information of the quantum key in the quantum key chip, and the quantum key is obtained by pre-negotiation between the quantum key issuing platform and a key distribution center (KDC); and sending, by the quantum key issuing platform, the identification information of the quantum key to the KDC, so that the KDC binds the identification information to the quantum key corresponding to the identification information.

Claims (49)

1. A method for applying a quantum key chip, applied to a communication system of a secure socket layer virtual private network SSL VPN, wherein:

the system comprises a client SSL VPN, a server SSL VPN, a key distribution center (KDC), and a quantum key chip; and

in a case that negotiation on a quantum key performed by the client SSL VPN and the server SSL VPN is normal, the method comprises:

acquiring, by the client SSL VPN, a first random number from the quantum key chip;

sending, by the client SSL VPN, the first random number to the server SSL VPN;

receiving, by the client SSL VPN, a second random number sent by the server SSL VPN;

determining, by the client SSL VPN and the server SSL VPN in the negotiation, that the quantum key in the quantum key chip serves as a pre-master key;

sending, by the client SSL VPN, an index of the quantum key serving as the pre-master key in the quantum key chip and identification information of the quantum key to the server SSL VPN, so that the server SSL VPN acquires the quantum key from the KDC as the pre-master key by using the index of the quantum key and the identification information of the quantum key, wherein an ID of the quantum key chip and/or an ID of a user serve as the identification information of the quantum key in the quantum key chip, and the identification information is bound with the quantum key corresponding to the identification information by the KDC in advance; and

acquiring, by the client SSL VPN and the server SSL VPN, a session key based on the first random number, the second random number and the quantum key serving as the pre-master key through a predetermined algorithm.

2. The method for applying the quantum key chip according to claim 1 , wherein acquiring, by the client SSL VPN, the session key based on the first random number, the second random number and the quantum key serving as the pre-master key through the predetermined algorithm comprises:

acquiring, by the client SSL VPN, the quantum key serving as the pre-master key from the quantum key chip, and acquiring, by the client SSL VPN, the session key based on the first random number, the second random number, and the quantum key serving as the pre-master key through the predetermined algorithm; or

informing, by the client SSL VPN, the quantum key chip of the second random number and the predetermined algorithm, and receiving, by the client SSL VPN, the session key returned by the quantum key chip, wherein the session key is calculated by the quantum key chip based on the quantum key serving as the pre-master key, the first random number, and the second random number through the predetermined algorithm.

3. The method for applying the quantum key chip according to claim 1 , wherein in a case that negotiation on a quantum key performed by the client SSL VPN and the server SSL VPN is abnormal, the method comprises:

sending, by the client SSL VPN, a generated first random number to the server SSL VPN, and receiving, by the client SSL VPN, a second random number sent by the server SSL VPN;

performing, by the client SSL VPN and the server SSL VPN, negotiation on a pre-master key; and

acquiring, by the client SSL VPN and the server SSL VPN, a session key based on the first random number, the second random number, and the pre-master key through a predetermined algorithm.

4. The method for applying the quantum key chip according to claim 1 , wherein the method further comprises:

encrypting and/or decrypting, by the client SSL VPN or the quantum key chip, application data via the session key.

5. A system for applying a quantum key, comprising a quantum key chip, a client SSL VPN, a server SSL VPN, and a key distribution center (KDC), wherein:

the client SSL VPN is configured to, in case of determining that negotiation on the quantum key performed with the server SSL VPN is normal:

acquire a first random number from the quantum key chip,

send the first random number to the server SSL VPN,

receive a second random number sent by the server SSL VPN,

determine, in the negotiation with the server SSL VPN, that the quantum key in the quantum key chip serves as a pre-master key, and

send an index of the quantum key serving as the pre-master key in the quantum key chip and identification information of the quantum key to the server SSL VPN;

the quantum key chip is configured to generate the first random number;

the server SSL VPN is configured to acquire the quantum key from the KDC as the pre-master key by using the index of the quantum key and the identification information of the quantum key;

the KDC is configured to bind the identification information with the quantum key corresponding to the identification information in advance, wherein an ID of the quantum key chip and/or an ID of a user serve as the identification information of the quantum key in the quantum key chip; and

the client SSL VPN and the server SSL VPN are further configured to acquire a session key based on the first random number, the second random number and the quantum key serving as the pre-master key through a predetermined algorithm.

6. The system for applying the quantum key according to claim 5 , wherein the client SSL VPN is configured to acquire the session key based on the first random number, the second random number and the quantum key serving as the pre-master key through the predetermined algorithm; and

wherein:

the client SSL VPN is configured to acquire the quantum key from the quantum key chip as the pre-master key, and acquire the session key based on the first random number, the second random number and the quantum key serving as the pre-master key through the predetermined algorithm; or

the client SSL VPN is configured to inform the quantum key chip of the second random number and the predetermined algorithm; the quantum key chip is configured to calculate the session key by using the quantum key serving as the pre-master key, the first random number, the second random number, and the predetermined algorithm; and send the session key to the client SSL VPN.

7. The system for applying the quantum key according to claim 5 , wherein:

the client SSL VPN is further configured to send a generated first random number to the server SSL VPN, in case of determining that the negotiation on the quantum key performed by the client SSL VPN and the server SSL VPN is abnormal;

the server SSL VPN is configured to send the generated second random number to the client SSL VPN;

the client SSL VPN and the server SSL VPN are further configured to perform negotiation on a pre-master key; and

the client SSL VPN and the server SSL VPN are further configured to acquire a session key based on the first random number, the second random number, and the pre-master key through a predetermined algorithm.

8. The system for applying the quantum key according to claim 5 , wherein:

the client SSL VPN is further configured to encrypt and/or decrypt application data via the session key, or the quantum key chip is further configured to encrypt and/or decrypt application data via the session key.

9. The method for applying the quantum key chip according to claim 2 , wherein in a case that negotiation on a quantum key performed by the client SSL VPN and the server SSL VPN is abnormal, the method comprises:

sending, by the client SSL VPN, a generated first random number to the server SSL VPN, and receiving, by the client SSL VPN, a second random number sent by the server SSL VPN;

performing, by the client SSL VPN and the server SSL VPN, negotiation on a pre-master key; and

acquiring, by the client SSL VPN and the server SSL VPN, a session key based on the first random number, the second random number, and the pre-master key through a predetermined algorithm.

10. The system for applying the quantum key according to claim 6 , wherein:

the client SSL VPN is further configured to send a generated first random number to the server SSL VPN, in case of determining that the negotiation on the quantum key performed by the client SSL VPN and the server SSL VPN is abnormal;

the server SSL VPN is configured to send the generated second random number to the client SSL VPN;

the client SSL VPN and the server SSL VPN are further configured to perform negotiation on a pre-master key; and

the client SSL VPN and the server SSL VPN are further configured to acquire a session key based on the first random number, the second random number, and the pre-master key through a predetermined algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2019
From: CHEN, QING; XIAO, XIANG; LIN, JIAYI; DING, SONGYAN; CHEN, JIERONG
To: QUANTUMCTEK (GUANGDONG) CO., LTD.
Reel/Frame 049302/0554 →
Priority Claims (1)
CN 201611070527.7 · Nov 28, 2016 · national
Continuity (1)
Related Publication 20210067331A1 · Mar 4, 2021
Cited By (1)
US 12,341,880