应用科学学报 ›› 2023, Vol. 41 ›› Issue (1): 170-182.doi: 10.3969/j.issn.0255-8297.2023.01.013

• 计算机应用专辑 • 上一篇    

基于区块链的量子密钥全生命周期管理

林雨生1,2, 昌燕1,2, 陈天肃1,2, 喻世鹏1,2, 张仕斌1,2   

  1. 1. 成都信息工程大学 网络空间安全学院, 四川 成都 610225;
    2. 先进密码技术与系统安全四川省重点实验室, 四川 成都 610225
  • 收稿日期:2021-11-12 出版日期:2023-01-31 发布日期:2023-02-03
  • 通信作者: 昌燕,教授,研究方向为量子密码、信息安全。E-mail:250098842@qq.com E-mail:250098842@qq.com
  • 基金资助:
    成都市重点研发支撑计划基金(No.2019-YF05-02028-GX);国家自然科学基金(No.62076042);四川省重点研发计划项目基金(No.2021YFSY0012)资助

Quantum Key Lifecycle Management Based on Blockchain

LIN Yusheng1,2, CHANG Yan1,2, CHEN Tiansu1,2, YU Shipeng1,2, ZHANG Shibin1,2   

  1. 1. College of Cyberspace Security, Chengdu University of Information Technology, Chengdu 610225, Sichuan, China;
    2. Sichuan Provincial Key Laboratory of Advanced Cryptography and System Security, Chengdu 610225, Sichuan, China
  • Received:2021-11-12 Online:2023-01-31 Published:2023-02-03

摘要: 为确保量子密钥从生成、分发、存储、使用、更新到销毁的安全性更高,提出一种基于区块链的量子密钥全生命周期管理方案。首先有保密通信需求的两方机构通过量子密钥分发设备产生真随机对称量子协商密钥,并将其分别存储在两方机构的量子设备管理员处;然后两方量子设备管理员协商量子密钥编号规则生成量子密钥文件;最后两方机构用户分别向各自量子设备管理员申请量子密钥用于通信。在通信过程中,与量子密钥生成、分发、使用、更新、销毁的相关日志信息上传到区块链,由量子设备管理员、通信用户协同区块链管理员完成量子密钥全生命周期的管理与追溯。理论分析表明:该方案能解决量子密钥在通信系统中无法有效追溯和管理的问题,可以实现对量子密钥全生命周期管理和追溯过程的透明可信。

关键词: 区块链, 保密通信, 量子密钥, 量子密钥管理

Abstract: In order to ensure a higher security of quantum key from generation, distribution, storage, use, update and destruction, this paper proposes a quantum key lifecycle management scheme based on blockchain. The two-party which has the requirement of confidential communication generates a truly random symmetric quantum negotiation key pool through quantum key distribution devices, and stores it in the quantum device administrator of each party. Then the quantum device administrators of two parties generate quantum key files according to negotiated numbering rules of quantum keys. Users of the two parties respectively apply for quantum keys from their quantum device administrators for communication. In the process of communication, the log information related to the generation, distribution, use, update and destruction of quantum keys is uploaded to a blockchain, and the quantum device administrators and communication users cooperate with the blockchain administrator to complete the management and traceability of the full lifecycle of quantum keys. Theoretical analysis shows that this scheme can solve the problem that quantum key cannot be effectively traced and managed in communication system, and realize the transparency and reliability of management and traceability of quantum key in whole lifecycle.

Key words: blockchain, secure communication, quantum key, quantum key management

中图分类号: