A quantum encryption transmission method, system and computer readable storage medium
By implementing unified network management of QKD module, encryption module and multiplexing/demultiplexing module in quantum encrypted transmission system, the problem of the inability to manage equipment in a unified manner in the existing technology is solved, and maintenance efficiency and security are improved.
Patent Information
- Application Number
- CN202410777029.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-17
- Publication Date
- 2026-03-17
- Estimated Expiration
- 2044-06-17
AI Technical Summary
In existing technologies, the classical transmission equipment, QKD module, and encryption module corresponding to quantum encrypted transmission cannot be uniformly managed, leading to difficulties in network management and maintenance.
By connecting the QKD module to the encryption module, then to the network management module, and finally to the multiplexing/demultiplexing module, unified network management is achieved among the QKD module, encryption module, and multiplexing/demultiplexing module. The network management module sends configuration management information to the encryption module, enabling the QKD module to generate quantum state optical signals, which are then transmitted to the other system via the multiplexing/demultiplexing module for quantum key negotiation and encrypted transmission.
It improves the management and maintenance efficiency of quantum encrypted transmission, solves the problem of difficult network management and maintenance in existing technologies, and realizes unified maintenance and security of equipment terminals.
Smart Images

Figure CN118784214B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum communication technology, and in particular to a quantum encrypted transmission method, system, and computer-readable storage medium. Background Technology
[0002] Quantum communication, based on the principles of quantum mechanics, guarantees unconditional security during communication and fundamentally resists the security threats posed by the supercomputing power of quantum computing. Quantum Key Distribution (QKD) technology, as the most advanced technology in the field of quantum communication with the highest level of practical application, has received widespread attention from the industry. However, due to the high deployment cost of QKD networks, laying separate optical fibers for quantum signal transmission would undoubtedly further increase costs. Therefore, multiplexing quantum signals within existing classical optical fiber networks to achieve co-transmission of quantum and classical signals over optical fibers is an inevitable trend in the future development of quantum communication networks. Furthermore, the quantum keys generated by QKD are primarily used to encrypt classical information data. Against this backdrop, the development of quantum-classical fusion equipment is imperative. This not only saves data center space but also enables unified maintenance of equipment terminals, reducing the security risks associated with external encryption devices.
[0003] However, in current quantum-classical fusion encrypted transmission devices, QKD and encryption modules, as additional functional devices of the classical transmission equipment, require control via a network management system. However, existing solutions do not unify this network management system with the classical transmission equipment's network management system, thus presenting difficulties in management and maintenance.
[0004] In summary, the classical transmission equipment, QKD module, and encryption module corresponding to quantum encrypted transmission in the existing technology cannot be uniformly managed, resulting in difficulties in network management and maintenance. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a quantum encrypted transmission method, system and computer-readable storage medium, so as to solve the problem that the classical transmission equipment, QKD module and encryption module corresponding to quantum encrypted transmission in the prior art cannot be uniformly managed, resulting in network management and maintenance difficulties.
[0006] In a first aspect, the present invention provides a quantum encrypted transmission method applied to a first quantum encrypted transmission system. The first quantum encrypted transmission system includes a first quantum key distribution (QKD) module, a first encryption module, a first network management module, and a first wave combining / splitting module. The first QKD module is connected to the first encryption module, the first encryption module is connected to the first network management module, and the first QKD module, the first encryption module, and the first network management module are respectively connected to the first wave combining / splitting module. The method includes:
[0007] The first network management module sends configuration management information to the first encryption module;
[0008] The first encryption module forwards the configuration management information to the first QKD module;
[0009] The first QKD module generates quantum state optical signals based on the configuration management information;
[0010] The first multiplexing / splitting module transmits the quantum state optical signal to the second multiplexing / splitting module of the second quantum encryption transmission system, so that the second QKD module connected to the second multiplexing / splitting module in the second quantum encryption transmission system measures the quantum state optical signal and generates a quantum key negotiation signal based on the quantum state measurement result. The second encryption module connected to the second QKD module in the second quantum encryption transmission system encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0011] Quantum encrypted transmission is achieved based on the processed quantum key negotiation signal.
[0012] Furthermore, the quantum encrypted transmission based on the processed quantum key negotiation signal specifically includes:
[0013] The first multiplexing / splitting module receives the processed quantum key negotiation signal transmitted by the second multiplexing / splitting module;
[0014] The first encryption module decrypts and / or verifies the signature of the processed quantum key negotiation signal;
[0015] The first QKD module responds to the second QKD module based on the quantum state preparation information and returns a quantum key negotiation signal to negotiate and obtain the quantum key;
[0016] Quantum encrypted transmission is achieved based on the quantum key.
[0017] Furthermore, the quantum encrypted transmission based on the quantum key specifically includes:
[0018] When a service signal in plaintext enters the first quantum encryption transmission system, the first multiplexing / demultiplexing module selects whether to encrypt the service signal in plaintext based on the configuration management information of the first network management module.
[0019] In response to a yes selection result, the first multiplexing / demultiplexing module converts the service signal in plaintext state from an optical signal into an electrical signal;
[0020] The first encryption module encrypts and signs the service signal in its plaintext state after conversion into an electrical signal according to the quantum key, thereby obtaining the service signal in its ciphertext state after conversion into an electrical signal.
[0021] The first multiplexing / demultiplexing module converts the encrypted service signal from an electrical signal to an optical signal, and transmits the encrypted service signal to the second multiplexing / demultiplexing module. The second multiplexing / demultiplexing module then converts the encrypted service signal back into an electrical signal, and the second encryption module decrypts and verifies the encrypted service signal using the quantum key to obtain the plaintext service signal.
[0022] Furthermore, the method also includes:
[0023] In response to a negative selection result, the first multiplexer / demultiplexer module transmits the service signal in plaintext state to the second multiplexer / demultiplexer module.
[0024] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0025] Secondly, the present invention provides a quantum encrypted transmission method applied to a second quantum encrypted transmission system. The second quantum encrypted transmission system includes a second quantum key distribution (QKD) module, a second encryption module, a second network management module, and a second multiplexing / demultiplexing module. The second QKD module is connected to the second encryption module, the second encryption module is connected to the second network management module, and the second QKD module, the second encryption module, and the second network management module are respectively connected to the second multiplexing / demultiplexing module. The method includes:
[0026] The second multiplexing / splitting module receives the quantum state optical signal transmitted by the first multiplexing / splitting module in the first quantum encryption transmission system. The quantum state optical signal is generated and sent by the first network management module of the first quantum encryption transmission system to the first encryption module of the first quantum encryption transmission system after the first encryption module sends configuration management information to the first encryption module of the first quantum encryption transmission system. The first encryption module forwards the configuration management information to the first QKD module of the first quantum encryption transmission system.
[0027] The second QKD module measures the quantum state optical signal and generates a quantum key negotiation signal based on the quantum state measurement result obtained after the measurement.
[0028] The second encryption module encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal, wherein the processed quantum key negotiation signal is used to trigger the first quantum encryption transmission system to realize quantum encryption transmission based on the processed quantum key negotiation signal.
[0029] Furthermore, the method also includes:
[0030] The second combining and splitting wave module transmits the processed quantum key negotiation signal to the first combining and splitting wave module, so that the first encryption module can decrypt and / or verify the processed quantum key negotiation signal, and the first QKD module can respond to the second QKD module and return the quantum key negotiation signal according to the quantum state preparation information to negotiate and obtain the quantum key.
[0031] Furthermore, the method also includes:
[0032] The second multiplexing / demultiplexing module receives the encrypted service signal transmitted by the first multiplexing / demultiplexing module after it has been converted into an optical signal.
[0033] The second multiplexing / demultiplexing module converts the encrypted service signal from an optical signal into an electrical signal;
[0034] The second encryption module decrypts and verifies the ciphertext state of the service signal after it has been converted into an electrical signal, based on the quantum key, to obtain the service signal in plaintext state after it has been converted into an electrical signal.
[0035] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0036] Thirdly, the present invention provides a first quantum encryption transmission system, comprising a first quantum key distribution (QKD) module, a first encryption module, a first network management module, and a first multiplexing / splitting module;
[0037] The first QKD module is connected to the first encryption module, the first encryption module is connected to the first network management module, and the first QKD module, the first encryption module, and the first network management module are respectively connected to the first multiplexing / splitting module;
[0038] The first network management module is used to send configuration management information to the first encryption module;
[0039] The first encryption module is used to forward the configuration management information to the first QKD module;
[0040] The first QKD module is used to generate quantum state optical signals according to the configuration management information;
[0041] The first multiplexing / splitting module is used to transmit the quantum state optical signal to the second multiplexing / splitting module of the second quantum encryption transmission system, so that the second QKD module connected to the second multiplexing / splitting module in the second quantum encryption transmission system measures the quantum state optical signal, generates a quantum key negotiation signal based on the quantum state measurement result, and enables the second encryption module connected to the second QKD module in the second quantum encryption transmission system to encrypt and / or sign the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0042] The first quantum encryption transmission system is used to achieve quantum encryption transmission based on the processed quantum key negotiation signal.
[0043] Furthermore, the first multiplexing / splitting module is also used to receive the processed quantum key negotiation signal transmitted by the second multiplexing / splitting module;
[0044] The first encryption module is also used to decrypt and / or verify the processed quantum key negotiation signal;
[0045] The first QKD module is also used to respond to the second QKD module and return a quantum key negotiation signal based on the quantum state preparation information, so as to negotiate and obtain a quantum key;
[0046] The first quantum encryption transmission system is also used to achieve quantum encryption transmission based on the quantum key.
[0047] Furthermore, the first multiplexing / demultiplexing module is also used to select whether to encrypt the plaintext service signal when the service signal in plaintext state enters the first quantum encryption transmission system, based on the configuration management information of the first network management module.
[0048] The first multiplexing / demultiplexing module is also used to convert the service signal in plaintext state from an optical signal to an electrical signal in response to a selection result of yes;
[0049] The first encryption module is further configured to encrypt and sign the service signal in plaintext state after being converted into an electrical signal according to the quantum key, so as to obtain the service signal in ciphertext state after being converted into an electrical signal;
[0050] The first multiplexing / demultiplexing module is further configured to convert the ciphertext service signal from an electrical signal to an optical signal, and transmit the ciphertext service signal after conversion to an optical signal to the second multiplexing / demultiplexing module, so that the second multiplexing / demultiplexing module converts the ciphertext service signal from an optical signal to an electrical signal, and the second encryption module decrypts and verifies the ciphertext service signal after conversion to an electrical signal according to the quantum key, to obtain the plaintext service signal after conversion to an electrical signal.
[0051] Furthermore, the first multiplexing / demultiplexing module is also used to transmit the service signal in plaintext state to the second multiplexing / demultiplexing module in response to a negative selection result.
[0052] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0053] Fourthly, the present invention provides a second quantum encryption transmission system, including a second quantum key distribution (QKD) module, a second encryption module, a second network management module, and a second multiplexing / splitting module;
[0054] The second QKD module is connected to the second encryption module, the second encryption module is connected to the second network management module, and the second QKD module, the second encryption module, and the second network management module are respectively connected to the second multiplexing / splitting module;
[0055] The second multiplexing / splitting module is used to receive the quantum state optical signal transmitted by the first multiplexing / splitting module in the first quantum encryption transmission system. The quantum state optical signal is generated and sent by the first network management module of the first quantum encryption transmission system to the first encryption module of the first quantum encryption transmission system after the first encryption module sends configuration management information to the first encryption module of the first quantum encryption transmission system. The first encryption module forwards the configuration management information to the first QKD module of the first quantum encryption transmission system.
[0056] The second QKD module is used to measure the quantum state optical signal and generate a quantum key negotiation signal based on the quantum state measurement result obtained after the measurement.
[0057] The second encryption module is used to encrypt and / or sign the quantum key negotiation signal to obtain the processed quantum key negotiation signal, wherein the processed quantum key negotiation signal is used to trigger the first quantum encryption transmission system to realize quantum encryption transmission based on the processed quantum key negotiation signal.
[0058] Furthermore, the second combining / splitting module is also used to transmit the processed quantum key negotiation signal to the first combining / splitting module, so that the first encryption module can decrypt and / or verify the processed quantum key negotiation signal, and the first QKD module can respond to the second QKD module and return the quantum key negotiation signal according to the quantum state preparation information, so as to negotiate and obtain the quantum key.
[0059] Furthermore, the second multiplexing / demultiplexing module is also used to receive the service signal in ciphertext state after being converted into an optical signal transmitted by the first multiplexing / demultiplexing module;
[0060] The second multiplexing / demultiplexing module is also used to convert the encrypted service signal from an optical signal into an electrical signal;
[0061] The second encryption module is further configured to decrypt and verify the ciphertext state of the service signal after it has been converted into an electrical signal, based on the quantum key, to obtain the service signal in plaintext state after it has been converted into an electrical signal.
[0062] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0063] Fifthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the quantum encrypted transmission method described in the first or second aspect above.
[0064] The quantum encrypted transmission method, system, and computer-readable storage medium provided by this invention are based on an integrated quantum encrypted transmission system. By connecting the QKD module to the encryption module, connecting the encryption module to the network management module, and then connecting the QKD module, encryption module, and network management module to a multiplexing / demultiplexing module respectively, unified network management can be achieved among the QKD module, encryption module, and multiplexing / demultiplexing module. During quantum encrypted transmission, the network management module of one quantum encrypted transmission system sends configuration management information to the QKD module through the encryption module, enabling the QKD module to generate quantum-state optical signals according to the configuration management information. The multiplexing / demultiplexing module then transmits the quantum-state optical signals to the other quantum encrypted transmission system to achieve quantum key negotiation and quantum encrypted transmission. This significantly improves the management and maintenance efficiency of quantum encrypted transmission and solves the problem in existing technologies where classical transmission equipment, QKD modules, and encryption modules for quantum encrypted transmission cannot be uniformly managed, leading to difficulties in network management and maintenance. Attached Figure Description
[0065] Figure 1 This is a flowchart of a quantum encryption transmission method according to Embodiment 1 of the present invention;
[0066] Figure 2 This is a schematic diagram of the integrated quantum encryption transmission system according to an embodiment of the present invention;
[0067] Figure 3 This is a flowchart illustrating the network management method of the QKD module in the quantum encryption transmission system that integrates communication and encryption according to an embodiment of the present invention.
[0068] Figure 4 This is a schematic diagram of the logical connection of each functional unit in the quantum encryption transmission system A and B, which integrates communication and encryption, according to an embodiment of the present invention.
[0069] Figure 5 This is a flowchart of a quantum encryption transmission method according to Embodiment 2 of the present invention;
[0070] Figure 6 This is a schematic diagram of the structure of a first quantum encryption transmission system according to Embodiment 3 of the present invention;
[0071] Figure 7 This is a schematic diagram of the structure of a second quantum encryption transmission system according to Embodiment 4 of the present invention. Detailed Implementation
[0072] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0073] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0074] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0075] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0076] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0077] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0078] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0079] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0080] Example 1:
[0081] This embodiment provides a quantum encrypted transmission method applied to a first quantum encrypted transmission system. The first quantum encrypted transmission system includes a first quantum key distribution (QKD) module, a first encryption module, a first network management module, and a first multiplexing / demultiplexing module. The first QKD module is connected to the first encryption module, the first encryption module is connected to the first network management module, and the first QKD module, the first encryption module, and the first network management module are respectively connected to the first multiplexing / demultiplexing module. Figure 1 As shown, the method includes:
[0082] Step S101: The first network management module sends configuration management information to the first encryption module.
[0083] It should be noted that the configuration management information sent by the first network management module includes at least the wavelength configuration information of the quantum state optical signal. The first encryption module may include a first configuration management unit and a first data encryption unit. The first configuration management unit is connected to the first network management module, and the first data encryption unit is connected to both the first configuration management unit and the first multiplexing / splitting module.
[0084] Specifically, the first network management module sends configuration management information to the first configuration management unit of the first encryption module.
[0085] Step S102: The first encryption module forwards the configuration management information to the first QKD module.
[0086] Specifically, the first configuration management unit of the first encryption module forwards configuration management information to the first QKD module.
[0087] Specifically, the specific methods corresponding to steps S101 and S102 may include the following steps:
[0088] (1) The first network management module sends a request to the first configuration management unit of the first encryption module, wherein the request contains configuration management information;
[0089] (2) When the first configuration management unit identifies the destination ID as the first QKD module, it extracts the configuration management information and forwards it to the first QKD module;
[0090] (3) After receiving the configuration management information, the first QKD module sends the response information to the first configuration management unit;
[0091] (4) The first configuration management unit forwards the response information to the first network management module.
[0092] Step S103: The first QKD module generates a quantum state optical signal according to the configuration management information.
[0093] It should be noted that the first QKD module may include a first key distribution unit and a first key negotiation unit. The first key distribution unit is connected to the first multiplexing / splitting module, and the first key negotiation unit is connected to both the first key distribution unit and the first configuration management unit.
[0094] Specifically, after receiving the configuration management information, the first key distribution unit of the first QKD module generates a quantum state light signal of the corresponding wavelength according to the configuration management information.
[0095] Step S104: The first multiplexing / splitting module transmits the quantum state optical signal to the second multiplexing / splitting module of the second quantum encryption transmission system, so that the second QKD module connected to the second multiplexing / splitting module in the second quantum encryption transmission system measures the quantum state optical signal and generates a quantum key negotiation signal based on the quantum state measurement result obtained after the measurement. The second encryption module connected to the second QKD module in the second quantum encryption transmission system encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0096] It should be noted that the second QKD module may include a second key distribution unit and a second key negotiation unit. The second key distribution unit is connected to the second multiplexing / splitting module, and the second key negotiation unit is connected to the second key distribution unit. The second encryption module may include a second configuration management unit and a second data encryption unit. The second configuration management unit is connected to the second key negotiation unit and the second network management module, respectively, and the second data encryption unit is connected to the second configuration management unit and the second multiplexing / splitting module, respectively.
[0097] Specifically, the first multiplexing / splitting module transmits the quantum-state optical signal to the second multiplexing / splitting module of the second quantum encryption transmission system. The second multiplexing / splitting module receives the quantum-state optical signal transmitted by the first multiplexing / splitting module in the first quantum encryption transmission system. The quantum-state optical signal then enters the second key distribution unit of the second QKD module connected to the second multiplexing / splitting module. The second key distribution unit measures the quantum-state optical signal and sends the measurement result to the second key negotiation unit. The second key negotiation unit generates a quantum key negotiation signal based on the quantum-state measurement result. The quantum key negotiation signal is transmitted to the second data encryption unit through the second configuration management unit of the second encryption module connected to the second QKD module. The second data encryption unit encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0098] Step S105: Implement quantum encrypted transmission based on the processed quantum key negotiation signal.
[0099] In one optional embodiment, the quantum encrypted transmission based on the processed quantum key negotiation signal specifically includes:
[0100] The first multiplexing / splitting module receives the processed quantum key negotiation signal transmitted by the second multiplexing / splitting module;
[0101] The first encryption module decrypts and / or verifies the signature of the processed quantum key negotiation signal;
[0102] The first QKD module responds to the second QKD module based on the quantum state preparation information and returns a quantum key negotiation signal to negotiate and obtain the quantum key;
[0103] Quantum encrypted transmission is achieved based on the quantum key.
[0104] Specifically, the first multiplexing / splitting module receives the processed quantum key negotiation signal transmitted by the second multiplexing / splitting module. The processed quantum key negotiation signal then enters the first data encryption unit of the first encryption module. The first data encryption unit decrypts and / or verifies the signature of the processed quantum key negotiation signal and transmits it to the first configuration management unit of the first encryption module. The first configuration management unit forwards the quantum key negotiation signal to the first key negotiation unit of the first QKD module. After receiving the quantum key negotiation signal from the second key negotiation unit, the first key negotiation unit responds to the second key negotiation unit and returns the quantum key negotiation signal according to the quantum state preparation information of the first key distribution unit. The returned quantum key negotiation signal reaches the second key negotiation unit through the same path. After multiple round trips between the first key negotiation unit and the second key negotiation unit, the quantum key is finally obtained. The first quantum encryption transmission system realizes quantum encryption transmission based on the quantum key.
[0105] In one optional embodiment, the quantum encrypted transmission based on the quantum key specifically includes:
[0106] When a service signal in plaintext enters the first quantum encryption transmission system, the first multiplexing / demultiplexing module selects whether to encrypt the service signal in plaintext based on the configuration management information of the first network management module.
[0107] In response to a yes selection result, the first multiplexing / demultiplexing module converts the service signal in plaintext state from an optical signal into an electrical signal;
[0108] The first encryption module encrypts and signs the service signal in its plaintext state after conversion into an electrical signal according to the quantum key, thereby obtaining the service signal in its ciphertext state after conversion into an electrical signal.
[0109] The first multiplexing / demultiplexing module converts the encrypted service signal from an electrical signal to an optical signal, and transmits the encrypted service signal to the second multiplexing / demultiplexing module. The second multiplexing / demultiplexing module then converts the encrypted service signal back into an electrical signal, and the second encryption module decrypts and verifies the encrypted service signal using the quantum key to obtain the plaintext service signal.
[0110] Specifically, when an unencrypted service signal enters the first quantum encryption transmission system, it is in plaintext. The first multiplexing / demultiplexing module selects whether to encrypt the plaintext service signal based on the configuration management information of the first network management module. If encryption is selected, the first multiplexing / demultiplexing module converts the service signal from an optical signal to an electrical signal. The electrical signal enters the first data encryption unit of the first encryption module. The first configuration management unit sends a quantum key to the first data encryption unit based on the configuration management information of the first network management module. The first data encryption unit uses the quantum key to encrypt and sign the electrical signal, changing it from plaintext to ciphertext. The first data encryption unit then sends the electrical signal to the first multiplexing / demultiplexing module, which converts the electrical signal back to an optical signal, thus converting the service signal from plaintext to ciphertext. Subsequently, the ciphertext service signal, converted to an optical signal, is transmitted by the first... The first multiplexing / demultiplexing module transmits the signal to the second multiplexing / demultiplexing module. The second multiplexing / demultiplexing module receives the encrypted service signal transmitted by the first multiplexing / demultiplexing module after it has been converted into an optical signal. The second multiplexing / demultiplexing module determines whether the service signal is encrypted based on the configuration management information of the second network management module. If encryption is selected, the second multiplexing / demultiplexing module converts the service signal from an optical signal to an electrical signal. The electrical signal enters the second data encryption unit of the second encryption module. The second configuration management unit sends a quantum key to the second data encryption unit based on the configuration management information of the second network management module. The second data encryption unit uses the quantum key to decrypt and verify the electrical signal, changing the electrical signal from an encrypted state to a plaintext state. The second data encryption unit sends the electrical signal to the second multiplexing / demultiplexing module, which converts the electrical signal back into an optical signal, thus realizing the conversion of the service signal from an encrypted state to a plaintext state.
[0111] In an optional embodiment, the method further includes:
[0112] In response to a negative selection result, the first multiplexer / demultiplexer module transmits the service signal in plaintext state to the second multiplexer / demultiplexer module.
[0113] Specifically, when an unencrypted service signal enters the first quantum encryption transmission system, it is in plaintext. The first multiplexing / demultiplexing module selects whether to encrypt the plaintext service signal based on the configuration management information of the first network management module. If no encryption is selected, the first multiplexing / demultiplexing module transmits the service signal in plaintext. Subsequently, the plaintext service signal is transmitted from the first multiplexing / demultiplexing module to the second multiplexing / demultiplexing module. The second multiplexing / demultiplexing module receives the plaintext service signal transmitted by the first multiplexing / demultiplexing module. The second multiplexing / demultiplexing module determines whether the service signal should be encrypted based on the configuration management information of the second network management module. If no encryption is selected, the second multiplexing / demultiplexing module receives the service signal in plaintext.
[0114] It should be noted that the quantum state optical signal, quantum key negotiation signal and service signal are transmitted through wavelength division multiplexing. For example, the quantum state optical signal is combined with the quantum key negotiation signal and service signal through the first wavelength division multiplexing module and multiplexed into a single optical fiber. The combined signal is then transmitted to the second quantum encryption transmission system, where the second wavelength division multiplexing module demultiplexes the quantum state optical signal from the combined signal.
[0115] It is worth mentioning that this invention proposes a quantum encrypted transmission method, which is applied to the quantum encrypted transmission system provided by this invention. The special feature of this invention is that while realizing selective quantum encryption, it unifies the network management of the encryption process with the network management of the classical communication system, avoiding the maintenance difficulties caused by multiple network management systems controlling simultaneously, and improving network configuration efficiency. This invention can realize unified network management of classical transmission equipment, QKD system, and encryption device, greatly improving the management and maintenance efficiency of quantum-classical integrated encrypted transmission, and providing network management support for quantum-classical integrated networking.
[0116] In one specific embodiment, the present invention proposes a quantum encryption transmission system and method that integrates communication and encryption, enabling unified network management of classical transmission equipment, QKD system, and encryption device, greatly improving the management and maintenance efficiency of quantum-classical fusion encryption transmission, and providing network management support for quantum-classical fusion networking.
[0117] like Figure 2 As shown, this quantum encryption transmission system, which integrates communication and encryption, includes a QKD module, an encryption module, a network management module, and a multiplexing / splitting module.
[0118] The QKD module is connected to the encryption module, the encryption module is connected to the network management module, and both the QKD module and the encryption module are connected to the multiplexing / demultiplexing module.
[0119] The QKD module is used to execute the quantum key distribution (QKD) protocol and generate quantum keys; the QKD module includes a key distribution unit and a key negotiation unit;
[0120] The key distribution unit is used to generate and prepare quantum state optical signals, and / or to receive and measure quantum state optical signals;
[0121] The key negotiation unit is connected to the key distribution unit and is used to obtain the quantum state measurement results and negotiate the quantum key based on the quantum state measurement results; the negotiation process includes basis vector comparison and data post-processing.
[0122] The key negotiation unit is also used to generate and receive quantum key negotiation signals;
[0123] The encryption module includes a configuration management unit and a data encryption unit;
[0124] The configuration management unit is connected to the key negotiation unit and is used to acquire and store the quantum key generated by the QKD module;
[0125] The data encryption unit is connected to the configuration management unit and the multiplexing / demultiplexing module respectively, and is used to obtain the quantum key sent by the configuration management unit, as well as transmit plaintext and ciphertext;
[0126] The data encryption unit is specifically used to encrypt and sign plaintext data using quantum keys, and to decrypt and verify ciphertext.
[0127] The network management module is used for device management and control;
[0128] Specifically, the network management module is connected to the configuration management unit and is used to transmit configuration management information of the encryption module, as well as forward configuration management information of the QKD module, such as... Figure 3 As shown, the specific steps for forwarding the configuration management information of the QKD module are as follows:
[0129] Step 1: The network management module sends a request to the encryption module configuration management unit;
[0130] Step 2: When the configuration management unit identifies the destination ID as the QKD module, it extracts the data payload portion and forwards it to the QKD module;
[0131] Step 3: After receiving the request message, the QKD module fills in the response message and sends it to the configuration management unit;
[0132] Step 4: The configuration management unit forwards the response message to the network management module.
[0133] The network management module is connected to the multiplexing / demultiplexing module and is used to manage and configure the wavelength of the optical signal;
[0134] The multiplexing / demultiplexing module is used to multiplex quantum state optical signals, quantum key negotiation signals, and service signals into a single optical fiber, or to demultiplex quantum state optical signals, quantum key negotiation signals, and service signals in a single optical fiber, and to convert white light signals into electrical signals and electrical signals into colored light signals set by the network management module according to network management information.
[0135] The specific transmission and reception process of the quantum state optical signal is as follows: In the integrated quantum encryption transmission system A (i.e., the first quantum encryption transmission system), the network management module A (i.e., the first network management module) forwards the wavelength configuration information of the quantum state optical signal to the QKD module A (i.e., the first configuration management unit) through the configuration management unit A (i.e., the first encryption module). After receiving the wavelength configuration information of the quantum state optical signal, the QKD module A generates a quantum state optical signal of the corresponding wavelength according to the information by the key distribution unit A (i.e., the first key distribution unit). The quantum state optical signal is then transmitted through the multiplexing / splitting module A. The first multiplexing / demultiplexing module (i.e., the first multiplexing / demultiplexing module) multiplexes the quantum key negotiation signal and the service signal into a single optical fiber. The multiplexed signal is then transmitted to the integrated quantum encryption transmission system B (i.e., the second quantum encryption transmission system). The multiplexing / demultiplexing module B (i.e., the second multiplexing / demultiplexing module) demultiplexes the quantum state optical signal from the multiplexed signal. The quantum state optical signal then enters the key distribution unit B (i.e., the second key distribution unit) of the QKD module B (i.e., the second QKD module). The key distribution unit B measures the quantum state optical signal and sends the measurement result to the key negotiation unit B (i.e., the second key negotiation unit).
[0136] The specific transmission and reception process of the quantum key negotiation signal is as follows: Key negotiation unit B obtains the quantum state measurement result of key distribution unit B, generates a quantum key negotiation signal based on the quantum state measurement result, and transmits the quantum key negotiation signal to data encryption unit B (i.e., the second data encryption unit) through the configuration management unit B (i.e., the second configuration management unit) of encryption module B (i.e., the second encryption module). Data encryption unit B encrypts and / or signs the quantum key negotiation signal. Subsequently, the quantum key negotiation signal is transmitted to the multiplexing / splitting module A through the multiplexing / splitting module B. The quantum key negotiation signal then enters the data encryption unit A (i.e., the first data encryption unit) of encryption module A. According to the encryption unit), the data encryption unit A decrypts the quantum key negotiation signal and / or verifies the signature, and transmits it to the configuration management unit A of the encryption module A. The configuration management unit A forwards the quantum key negotiation signal to the key negotiation unit A (i.e., the first key negotiation unit). After receiving the quantum key negotiation signal from the key negotiation unit B, the key negotiation unit A responds to the key negotiation unit B and returns the quantum key negotiation signal according to the quantum state preparation information of the key distribution unit A. The returned quantum key negotiation signal reaches the key negotiation unit B through the same path. After multiple round trips between the key negotiation unit A and the key negotiation unit B, the quantum key is finally obtained.
[0137] The specific transmission and reception process of the service signal is as follows: When the unencrypted service signal enters the quantum encryption transmission system A, it is in plaintext state; the multiplexing / demultiplexing module A selects whether to encrypt according to the configuration management information of the network management module A. If encryption is selected, the multiplexing / demultiplexing module A converts the service signal from an optical signal to an electrical signal. The electrical signal enters the encryption module A. The configuration management unit A sends a quantum key to the data encryption unit A according to the configuration management information of the network management module A. The data encryption unit A uses the quantum key to encrypt and sign the electrical signal, changing the electrical signal from plaintext to ciphertext. The data encryption unit A sends the electrical signal to the multiplexing / demultiplexing module A, which converts the electrical signal back to an optical signal, thus changing the service signal from plaintext to ciphertext. If no encryption is selected, the multiplexing / demultiplexing module A transmits the service signal in plaintext state. Subsequently, the ciphertext service signal, and / or Alternatively, the plaintext service signal is transmitted from the multiplexing / demultiplexing module A to the multiplexing / demultiplexing module B, entering the integrated quantum encryption transmission system B. The multiplexing / demultiplexing module B determines whether the service signal is encrypted based on the configuration management information from the network management module B (i.e., the second network management module). If encryption is selected, the multiplexing / demultiplexing module B converts the service signal from an optical signal to an electrical signal, which then enters the encryption module B. The configuration management unit B sends a quantum key to the data encryption unit B based on the configuration management information from the network management module B. The data encryption unit B uses the quantum key to decrypt and verify the electrical signal, changing it from ciphertext to plaintext. The data encryption unit B then sends the electrical signal to the multiplexing / demultiplexing module B, which converts it back to an optical signal, thus converting the service signal from ciphertext to plaintext. If no encryption is selected, the multiplexing / demultiplexing module B receives the service signal in plaintext.
[0138] The quantum encryption transmission system, which integrates communication and encryption, may also include auxiliary modules connected to the QKD module, encryption module, network management module, and multiplexing / splitting module, respectively. These modules include conventional chassis module auxiliary equipment such as fan groups, temperature sensors, power supply modules, voltage detection, and power detection, which are used to maintain the normal operation of the equipment.
[0139] It is worth mentioning that this invention achieves unified network management for the QKD module, encryption module, and multiplexing / demultiplexing module. The QKD module and encryption module can be regarded as boards for the multiplexing / demultiplexing module. In this case, the network management module only needs to add corresponding interfaces to retrieve or configure the information of the QKD module and encryption module in addition to having the network management functions of the multiplexing / demultiplexing module, which requires minimal modification to the current classic communication network.
[0140] In another specific embodiment, such as Figure 4 As shown, the business data between node A and node B is transmitted using encrypted technology. Node A corresponds to a quantum encryption transmission system A that integrates communication and encryption, and node B corresponds to a quantum encryption transmission system B that integrates communication and encryption. The specific steps are as follows:
[0141] 1-1: Network management module A sends a request to the configuration management unit A of encryption module A;
[0142] 1-2: When configuration management unit A identifies the destination ID as QKD module A, it extracts the data payload portion and forwards it to QKD module A;
[0143] 1-3: After receiving the request message, QKD module A fills in the response message and sends it to configuration management unit A;
[0144] 1-4: Configuration management unit A forwards the response message to network management module A;
[0145] 1-5: Based on the configuration management information of network management module A, the key distribution unit A of QKD module A generates quantum state optical signals of the corresponding wavelength;
[0146] 1-6: The multiplexing / demultiplexing module A combines the quantum state optical signal with the quantum key negotiation signal and the service signal, multiplexes them into a single optical fiber, and transmits them to the multiplexing / demultiplexing module B; then the multiplexing / demultiplexing module B demultiplexes and demultiplexes the quantum state optical signal from the combined signal.
[0147] 1-7: Key distribution unit B measures the quantum state optical signal and sends the measurement result to key negotiation unit B;
[0148] 1-8: Key negotiation unit B generates a quantum key negotiation signal based on the quantum state measurement results;
[0149] 1-9: The quantum key negotiation signal is transmitted to the data encryption unit B through the configuration management unit B;
[0150] 1-10: Data encryption unit B encrypts and / or signs the quantum key negotiation signal;
[0151] 1-11: The quantum key negotiation signal is transmitted from the multiplexing / splitting module B to the multiplexing / splitting module A;
[0152] 1-12: Data encryption unit A decrypts the quantum key negotiation signal and / or verifies the signature;
[0153] 1-13: Configuration management unit A forwards the quantum key negotiation signal to key negotiation unit A;
[0154] 1-14: After receiving the quantum key negotiation signal from the key negotiation unit B, the key negotiation unit A responds to the key negotiation unit B and returns the quantum key negotiation signal according to the quantum state preparation information of the key distribution unit A;
[0155] 1-15: The quantum key negotiation signal travels back and forth between key negotiation unit A and key negotiation unit B multiple times before finally obtaining the quantum key;
[0156] 1-16: When a service signal enters the quantum encryption transmission system A, which integrates communication and encryption, the multiplexing and demultiplexing module A selects whether to encrypt the signal based on the configuration management information of the network management module A, and the selection result is yes;
[0157] 1-17: The multiplexing / demultiplexing module A converts the service signal from an optical signal to an electrical signal;
[0158] 1-18: Configuration management unit A sends the quantum key to data encryption unit A based on the configuration management information of network management module A;
[0159] 1-19: Data encryption unit A uses a quantum key to encrypt and sign the electrical signal, changing the electrical signal from plaintext to ciphertext, and then sends the ciphertext electrical signal to the multiplexing / demultiplexing module A;
[0160] 1-20: The multiplexing / demultiplexing module A converts electrical signals into optical signals, enabling the service signal to be converted from plaintext to ciphertext.
[0161] 1-21: The multiplexing and splitting module A transmits the encrypted service signal to the multiplexing and splitting module B, which then enters the quantum encryption transmission system B, which integrates communication and encryption.
[0162] 1-22: The multiplexing / demultiplexing module B determines whether the service signal should be encrypted based on the configuration management information of the network management module B, and the result is yes;
[0163] 1-23: The multiplexing / demultiplexing module B converts the service signal from an optical signal to an electrical signal;
[0164] 1-24: Configuration management unit B sends the quantum key to data encryption unit B based on the configuration management information of network management module B;
[0165] 1-25: Data encryption unit B uses quantum key to decrypt and verify the electrical signal, changing the electrical signal from ciphertext to plaintext, and then sends the plaintext electrical signal to the multiplexing / demultiplexing module B;
[0166] 1-26: The multiplexing / demultiplexing module B converts electrical signals into optical signals, enabling the service signal to be converted from ciphertext to plaintext.
[0167] In another specific embodiment, such as Figure 4 As shown, the business data between node A and node B is transmitted without encryption. Node A corresponds to a quantum encryption transmission system A that integrates communication and encryption, and node B corresponds to a quantum encryption transmission system B that integrates communication and encryption. The specific steps are as follows:
[0168] 2-1: Network management module A sends a request to the configuration management unit A of encryption module A;
[0169] 2-2: When configuration management unit A identifies the destination ID as QKD module A, it extracts the data payload portion and forwards it to QKD module A;
[0170] 2-3: After receiving the request message, QKD module A fills in the response message and sends it to configuration management unit A;
[0171] 2-4: Configuration management unit A forwards the response message to network management module A;
[0172] 2-5: Based on the configuration management information of network management module A, the key distribution unit A of QKD module A generates quantum state optical signals of the corresponding wavelength;
[0173] 2-6: The multiplexing / demultiplexing module A combines the quantum state optical signal with the quantum key negotiation signal and the service signal, multiplexes them into a single optical fiber, and transmits them to the multiplexing / demultiplexing module B; then the multiplexing / demultiplexing module B demultiplexes and demultiplexes the quantum state optical signal from the combined signal.
[0174] 2-7: Key distribution unit B measures the quantum state optical signal and sends the measurement result to key negotiation unit B;
[0175] 2-8: Key negotiation unit B generates a quantum key negotiation signal based on the quantum state measurement results;
[0176] 2-9: The quantum key negotiation signal is transmitted to the data encryption unit B through the configuration management unit B;
[0177] 2-10: Data encryption unit B encrypts and / or signs the quantum key negotiation signal;
[0178] 2-11: The quantum key negotiation signal is transmitted from the multiplexing / splitting module B to the multiplexing / splitting module A;
[0179] 2-12: Data encryption unit A decrypts the quantum key negotiation signal and / or verifies the signature;
[0180] 2-13: Configuration management unit A forwards the quantum key negotiation signal to key negotiation unit A;
[0181] 2-14: After receiving the quantum key negotiation signal from the key negotiation unit B, the key negotiation unit A responds to the key negotiation unit B and returns the quantum key negotiation signal according to the quantum state preparation information of the key distribution unit A;
[0182] 2-15: The quantum key negotiation signal travels back and forth between key negotiation unit A and key negotiation unit B multiple times before finally obtaining the quantum key;
[0183] 2-16: When a service signal enters the quantum encryption transmission system A, which integrates communication and encryption, the multiplexing and demultiplexing module A selects whether to encrypt the signal based on the configuration management information of the network management module A, and the selection result is no.
[0184] 2-17: The multiplexing / demultiplexing module A transmits the plaintext service signal to the multiplexing / demultiplexing module B, which then enters the quantum encryption transmission system B, which integrates communication and encryption.
[0185] 2-18: The multiplexing / demultiplexing module B determines whether the service signal should be encrypted based on the configuration management information of the network management module B, and the result is no;
[0186] 2-19: The multiplexing / demultiplexing module B receives the service signal in plaintext.
[0187] The quantum encrypted transmission method provided in this invention is based on an integrated quantum encrypted transmission system. By connecting the QKD module to the encryption module, connecting the encryption module to the network management module, and then connecting the QKD module, encryption module, and network management module to a multiplexing / demultiplexing module, unified network management is achieved among the QKD module, encryption module, and multiplexing / demultiplexing module. During quantum encrypted transmission, the network management module of one quantum encrypted transmission system sends configuration management information to the QKD module through the encryption module. This enables the QKD module to generate quantum-state optical signals based on the configuration management information. The multiplexing / demultiplexing module then transmits the quantum-state optical signals to the other quantum encrypted transmission system to achieve quantum key negotiation and quantum encrypted transmission. This significantly improves the management and maintenance efficiency of quantum encrypted transmission and solves the problem in existing technologies where classical transmission equipment, QKD modules, and encryption modules for quantum encrypted transmission cannot be uniformly managed, leading to difficulties in network management and maintenance.
[0188] Example 2:
[0189] This embodiment provides a quantum encrypted transmission method applied to a second quantum encrypted transmission system. The second quantum encrypted transmission system includes a second quantum key distribution (QKD) module, a second encryption module, a second network management module, and a second multiplexing / demultiplexing module. The second QKD module is connected to the second encryption module, and the second encryption module is connected to the second network management module. The second QKD module, the second encryption module, and the second network management module are respectively connected to the second multiplexing / demultiplexing module. Figure 5 As shown, the method includes:
[0190] Step S201: The second multiplexing / splitting module receives the quantum state optical signal transmitted by the first multiplexing / splitting module in the first quantum encryption transmission system. The quantum state optical signal is generated and sent by the first QKD module based on the configuration management information after the first network management module of the first quantum encryption transmission system sends configuration management information to the first encryption module of the first quantum encryption transmission system.
[0191] Specifically, the second combining and splitting wave module receives the quantum state optical signal transmitted by the first combining and splitting wave module in the first quantum encryption transmission system.
[0192] Step S202: The second QKD module measures the quantum state optical signal and generates a quantum key negotiation signal based on the quantum state measurement result obtained after the measurement.
[0193] It should be noted that the second QKD module may include a second key distribution unit and a second key negotiation unit. The second key distribution unit is connected to the second multiplexing / splitting module, and the second key negotiation unit is connected to the second key distribution unit.
[0194] Specifically, the quantum state optical signal then enters the second key distribution unit of the second QKD module connected to the second multiplexing / splitting module. The second key distribution unit measures the quantum state optical signal and sends the measurement result to the second key negotiation unit. The second key negotiation unit generates a quantum key negotiation signal based on the quantum state measurement result.
[0195] Step S203: The second encryption module encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal, wherein the processed quantum key negotiation signal is used to trigger the first quantum encryption transmission system to realize quantum encryption transmission based on the processed quantum key negotiation signal.
[0196] It should be noted that the second encryption module may include a second configuration management unit and a second data encryption unit. The second configuration management unit is connected to the second key negotiation unit and the second network management module, respectively, and the second data encryption unit is connected to the second configuration management unit and the second multiplexing / splitting module, respectively.
[0197] Specifically, the quantum key negotiation signal is transmitted to the second data encryption unit through the second configuration management unit of the second encryption module connected to the second QKD module. The second data encryption unit encrypts and / or signs the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0198] In an optional embodiment, the method further includes:
[0199] The second combining and splitting wave module transmits the processed quantum key negotiation signal to the first combining and splitting wave module, so that the first encryption module can decrypt and / or verify the processed quantum key negotiation signal, and the first QKD module can respond to the second QKD module and return the quantum key negotiation signal according to the quantum state preparation information to negotiate and obtain the quantum key.
[0200] Specifically, the second combining and splitting wave module transmits the processed quantum key negotiation signal to the first combining and splitting wave module.
[0201] In an optional embodiment, the method further includes:
[0202] The second multiplexing / demultiplexing module receives the encrypted service signal transmitted by the first multiplexing / demultiplexing module after it has been converted into an optical signal.
[0203] The second multiplexing / demultiplexing module converts the encrypted service signal from an optical signal into an electrical signal;
[0204] The second encryption module decrypts and verifies the ciphertext state of the service signal after it has been converted into an electrical signal, based on the quantum key, to obtain the service signal in plaintext state after it has been converted into an electrical signal.
[0205] Specifically, the second multiplexing / demultiplexing module receives the encrypted service signal, converted to an optical signal, transmitted by the first multiplexing / demultiplexing module. This service signal is obtained by the first multiplexing / demultiplexing module converting the plaintext service signal from an optical signal to an electrical signal, followed by encryption and signing of the plaintext service signal using the quantum key by the first encryption module, resulting in the encrypted service signal. The first multiplexing / demultiplexing module then converts the encrypted service signal back to an optical signal and transmits it. The second multiplexing / demultiplexing module receives the encrypted service signal from the second network management module based on its configuration management information. The system learns whether the service signal is encrypted. If encryption is selected, the second multiplexing / demultiplexing module converts the service signal from an optical signal to an electrical signal. The electrical signal enters the second data encryption unit of the second encryption module. The second configuration management unit sends a quantum key to the second data encryption unit according to the configuration management information of the second network management module. The second data encryption unit uses the quantum key to decrypt and verify the electrical signal, changing the electrical signal from ciphertext to plaintext. The second data encryption unit then sends the electrical signal to the second multiplexing / demultiplexing module, which converts the electrical signal back to an optical signal, thus changing the service signal from ciphertext to plaintext.
[0206] It should be noted that the quantum state optical signal, quantum key negotiation signal and service signal are transmitted through wavelength division multiplexing. For example, the quantum state optical signal is combined with the quantum key negotiation signal and service signal through the first wavelength division multiplexing module and multiplexed into a single optical fiber. The combined signal is then transmitted to the second quantum encryption transmission system, where the second wavelength division multiplexing module demultiplexes the quantum state optical signal from the combined signal.
[0207] Example 3:
[0208] like Figure 6 As shown, this embodiment provides a first quantum encryption transmission system 10, including a first quantum key distribution (QKD) module 11, a first encryption module 12, a first network management module 13, and a first multiplexing / splitting module 14;
[0209] The first QKD module 11 is connected to the first encryption module 12, the first encryption module 12 is connected to the first network management module 13, and the first QKD module 11, the first encryption module 12 and the first network management module 13 are respectively connected to the first multiplexing / splitting module 14.
[0210] The first network management module 13 is used to send configuration management information to the first encryption module 12;
[0211] The first encryption module 12 is used to forward the configuration management information to the first QKD module 11;
[0212] The first QKD module 11 is used to generate quantum state optical signals according to the configuration management information;
[0213] The first multiplexing / splitting module 14 is used to transmit the quantum state optical signal to the second multiplexing / splitting module of the second quantum encryption transmission system, so that the second QKD module connected to the second multiplexing / splitting module in the second quantum encryption transmission system measures the quantum state optical signal, generates a quantum key negotiation signal based on the quantum state measurement result, and enables the second encryption module connected to the second QKD module in the second quantum encryption transmission system to encrypt and / or sign the quantum key negotiation signal to obtain the processed quantum key negotiation signal.
[0214] The first quantum encryption transmission system 10 is used to achieve quantum encryption transmission based on the processed quantum key negotiation signal.
[0215] Furthermore, the first multiplexing / splitting module 14 is also used to receive the processed quantum key negotiation signal transmitted by the second multiplexing / splitting module;
[0216] The first encryption module 12 is also used to decrypt and / or verify the processed quantum key negotiation signal;
[0217] The first QKD module 11 is also used to respond to the second QKD module and return a quantum key negotiation signal according to the quantum state preparation information, so as to negotiate and obtain a quantum key;
[0218] The first quantum encryption transmission system 10 is also used to realize quantum encryption transmission based on the quantum key.
[0219] Furthermore, the first multiplexing / demultiplexing module 14 is also used to select whether to encrypt the plaintext service signal when the service signal in plaintext state enters the first quantum encryption transmission system 10, according to the configuration management information of the first network management module 13.
[0220] The first multiplexing / demultiplexing module 14 is also configured to convert the service signal in plaintext state from an optical signal to an electrical signal in response to a selection result of yes;
[0221] The first encryption module 12 is further configured to encrypt and sign the service signal in plaintext state after being converted into an electrical signal according to the quantum key, so as to obtain the service signal in ciphertext state after being converted into an electrical signal;
[0222] The first multiplexing / demultiplexing module 14 is further configured to convert the ciphertext service signal from an electrical signal to an optical signal, and transmit the ciphertext service signal after conversion to an optical signal to the second multiplexing / demultiplexing module, so that the second multiplexing / demultiplexing module converts the ciphertext service signal from an optical signal to an electrical signal, and the second encryption module decrypts and verifies the ciphertext service signal after conversion to an electrical signal according to the quantum key, to obtain the plaintext service signal after conversion to an electrical signal.
[0223] Furthermore, the first multiplexing / demultiplexing module 14 is also used to transmit the service signal in plaintext state to the second multiplexing / demultiplexing module in response to a negative selection result.
[0224] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0225] Example 4:
[0226] like Figure 7 As shown, this embodiment provides a second quantum encryption transmission system 20, including a second quantum key distribution (QKD) module 21, a second encryption module 22, a second network management module 23, and a second multiplexing / splitting module 24;
[0227] The second QKD module 21 is connected to the second encryption module 22, the second encryption module 22 is connected to the second network management module 23, and the second QKD module 21, the second encryption module 22, and the second network management module 23 are respectively connected to the second multiplexing / splitting module 24.
[0228] The second multiplexing / splitting module 24 is used to receive the quantum state optical signal transmitted by the first multiplexing / splitting module in the first quantum encryption transmission system. The quantum state optical signal is generated and sent by the first network management module of the first quantum encryption transmission system to the first encryption module of the first quantum encryption transmission system after the first encryption module sends configuration management information to the first encryption module of the first quantum encryption transmission system. The first encryption module forwards the configuration management information to the first QKD module of the first quantum encryption transmission system.
[0229] The second QKD module 21 is used to measure the quantum state optical signal and generate a quantum key negotiation signal based on the quantum state measurement result obtained after the measurement.
[0230] The second encryption module 22 is used to encrypt and / or sign the quantum key negotiation signal to obtain the processed quantum key negotiation signal, wherein the processed quantum key negotiation signal is used to trigger the first quantum encryption transmission system to realize quantum encryption transmission based on the processed quantum key negotiation signal.
[0231] Furthermore, the second combiner / splitter module 24 is also used to transmit the processed quantum key negotiation signal to the first combiner / splitter module, so that the first encryption module can decrypt and / or verify the processed quantum key negotiation signal, and cause the first QKD module to respond to the second QKD module 21 and return the quantum key negotiation signal according to the quantum state preparation information, so as to negotiate and obtain the quantum key.
[0232] Furthermore, the second multiplexing / demultiplexing module 24 is also used to receive the service signal in ciphertext state after being converted into an optical signal transmitted by the first multiplexing / demultiplexing module;
[0233] The second multiplexing / demultiplexing module 24 is also used to convert the encrypted service signal from an optical signal into an electrical signal;
[0234] The second encryption module 22 is further configured to decrypt and verify the ciphertext state of the service signal after it has been converted into an electrical signal, based on the quantum key, to obtain the service signal in the plaintext state after it has been converted into an electrical signal.
[0235] Furthermore, the quantum state optical signal, quantum key negotiation signal, and service signal are transmitted via wavelength division multiplexing.
[0236] Example 5:
[0237] This embodiment provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the quantum encryption transmission method described in Embodiment 1 or Embodiment 2 above.
[0238] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0239] In summary, the quantum encrypted transmission method, system, and computer-readable storage medium provided by the embodiments of the present invention are based on an integrated quantum encrypted transmission system. By connecting the QKD module to the encryption module, connecting the encryption module to the network management module, and then connecting the QKD module, encryption module, and network management module to the multiplexing / demultiplexing module respectively, unified network management can be achieved among the QKD module, encryption module, and multiplexing / demultiplexing module. During quantum encrypted transmission, the network management module of one quantum encrypted transmission system sends configuration management information to the QKD module through the encryption module, so that the QKD module generates quantum state optical signals according to the configuration management information. The multiplexing / demultiplexing module then transmits the quantum state optical signals to the other quantum encrypted transmission system to realize quantum key negotiation and quantum encrypted transmission. This greatly improves the management and maintenance efficiency of quantum encrypted transmission and solves the problem in the prior art that the classical transmission equipment, QKD module, and encryption module corresponding to quantum encrypted transmission cannot be uniformly managed, resulting in difficult network management and maintenance.
[0240] It is understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A method of quantum encryption transmission, characterized by, The method is applied to a first quantum encryption transmission system, and the first quantum encryption transmission system comprises a first quantum key distribution (QKD) module, a first encryption module, a first network management module and a first multiplexer / demultiplexer module. The first QKD module is connected with the first encryption module, the first encryption module is connected with the first network management module, and the first QKD module, the first encryption module and the first network management module are connected with the first multiplexer / demultiplexer module respectively. The method comprises the following steps: The first network management module sends configuration management information to the first encryption module; The first encryption module forwards the configuration management information to the first QKD module; The first QKD module generates a quantum state optical signal according to the configuration management information; The first multiplexer / demultiplexer module transmits the quantum state optical signal to a second multiplexer / demultiplexer module of a second quantum encryption transmission system, so that a second QKD module connected with the second multiplexer / demultiplexer module in the second quantum encryption transmission system measures the quantum state optical signal, generates a quantum key agreement signal according to a quantum state measurement result obtained after the measurement, and makes a second encryption module connected with the second QKD module in the second quantum encryption transmission system encrypt and / or sign the quantum key agreement signal to obtain a processed quantum key agreement signal; Quantum encryption transmission is realized based on the processed quantum key agreement signal; The realization of the quantum encryption transmission based on the processed quantum key agreement signal specifically comprises the following steps: The first multiplexer / demultiplexer module receives the processed quantum key agreement signal transmitted by the second multiplexer / demultiplexer module; The first encryption module decrypts and / or verifies the signature of the processed quantum key agreement signal; The first QKD module responds to the second QKD module according to quantum state preparation information and returns a quantum key agreement signal, and the quantum key agreement signal is finally obtained after multiple rounds of back-and-forth between the first QKD module and the second QKD module; When a plaintext state service signal enters the first quantum encryption transmission system, the first multiplexer / demultiplexer module selects whether to encrypt the plaintext state service signal according to the configuration management information of the first network management module; In response to a selection result of yes, the first multiplexer / demultiplexer module converts the plaintext state service signal from an optical signal to an electrical signal; The first encryption module encrypts and signs the plaintext state service signal converted into an electrical signal according to the quantum key to obtain a ciphertext state service signal converted into an electrical signal; The first multiplexer / demultiplexer module converts the ciphertext state service signal from an electrical signal to an optical signal, and transmits the ciphertext state service signal converted into an optical signal to the second multiplexer / demultiplexer module, so that the second multiplexer / demultiplexer module converts the ciphertext state service signal from an optical signal to an electrical signal, and the second encryption module decrypts and verifies the signature of the ciphertext state service signal converted into an electrical signal according to the quantum key to obtain a plaintext state service signal converted into an electrical signal.
2. The method of claim 1, wherein, The method further comprises the following steps: In response to the selection result being no, the first add-drop module transmits the service signal in the plaintext state to the second add-drop module.
3. The method of claim 1, wherein, The quantum state optical signal, the quantum key agreement signal and the service signal are transmitted by wavelength division multiplexing.
4. A method of quantum encryption transmission, characterized by, The second quantum encryption transmission system comprises a second quantum key distribution (QKD) module, a second encryption module, a second network management module and a second add-drop module. The second QKD module is connected with the second encryption module. The second encryption module is connected with the second network management module. The second QKD module, the second encryption module and the second network management module are respectively connected with the second add-drop module. The method comprises the following steps: The second add-drop module receives a quantum state optical signal transmitted by a first add-drop module in a first quantum encryption transmission system. The quantum state optical signal is generated and sent by a first QKD module in the first quantum encryption transmission system according to configuration management information sent by a first network management module in the first quantum encryption transmission system to a first encryption module in the first quantum encryption transmission system, and then the configuration management information is forwarded to the first QKD module by the first encryption module. The second QKD module measures the quantum state optical signal and generates a quantum key agreement signal according to a quantum state measurement result obtained after the measurement. The second encryption module encrypts and / or signs the quantum key agreement signal to obtain a processed quantum key agreement signal. The processed quantum key agreement signal is used to trigger the first quantum encryption transmission system to implement quantum encryption transmission based on the processed quantum key agreement signal. The implementation of quantum encryption transmission based on the processed quantum key agreement signal comprises the following steps: The first add-drop module receives the processed quantum key agreement signal transmitted by the second add-drop module. The first encryption module decrypts and / or verifies the signature of the processed quantum key agreement signal. The first QKD module responds to the second QKD module and returns a quantum key agreement signal according to quantum state preparation information. The quantum key agreement signal is obtained after multiple rounds of back-and-forth between the first QKD module and the second QKD module. When a service signal in the plaintext state enters the first quantum encryption transmission system, the first add-drop module selects whether to encrypt the service signal in the plaintext state according to configuration management information of the first network management module. In response to the selection result being yes, the first add-drop module converts the service signal in the plaintext state from an optical signal to an electrical signal. The first encryption module encrypts and signs the service signal in the plaintext state converted into an electrical signal according to the quantum key to obtain the service signal in the ciphertext state converted into an electrical signal. The first multiplexing / demultiplexing module converts the ciphertext state of the service signal from an electrical signal to an optical signal, and transmits the ciphertext state of the service signal converted into an optical signal to the second multiplexing / demultiplexing module, so that the second multiplexing / demultiplexing module converts the ciphertext state of the service signal from an optical signal to an electrical signal, and the second encryption module decrypts and verifies the ciphertext state of the service signal converted into an electrical signal according to the quantum key, to obtain the plaintext state of the service signal converted into an electrical signal.
5. The method of claim 4, wherein, The quantum state optical signal, the quantum key agreement signal and the service signal are transmitted through wavelength division multiplexing.
6. A first quantum encryption transmission system characterized by, The first quantum key distribution (QKD) module, the first encryption module, the first network management module and the first multiplexing / demultiplexing module are included. The first QKD module is connected with the first encryption module, the first encryption module is connected with the first network management module, and the first QKD module, the first encryption module and the first network management module are respectively connected with the first multiplexing / demultiplexing module. The first network management module is configured to send configuration management information to the first encryption module. The first encryption module is configured to forward the configuration management information to the first QKD module. The first QKD module is configured to generate a quantum state optical signal according to the configuration management information. The first multiplexing / demultiplexing module is configured to transmit the quantum state optical signal to a second multiplexing / demultiplexing module of a second quantum encryption transmission system, so that a second QKD module connected with the second multiplexing / demultiplexing module in the second quantum encryption transmission system measures the quantum state optical signal, generates a quantum key agreement signal according to a quantum state measurement result obtained after the measurement, and a second encryption module connected with the second QKD module in the second quantum encryption transmission system encrypts and / or signs the quantum key agreement signal to obtain a processed quantum key agreement signal. The first quantum encryption transmission system is configured to implement quantum encryption transmission based on the processed quantum key agreement signal. The first multiplexing / demultiplexing module is further configured to receive the processed quantum key agreement signal transmitted by the second multiplexing / demultiplexing module. The first encryption module is further configured to decrypt and / or verify the processed quantum key agreement signal. The first QKD module is further configured to respond to the second QKD module and return a quantum key agreement signal according to quantum state preparation information, and the quantum key agreement signal is finally obtained after multiple rounds of back-and-forth between the first QKD module and the second QKD module. The first multiplexing / demultiplexing module is further configured to select whether to encrypt the plaintext state of the service signal according to the configuration management information of the first network management module when the plaintext state of the service signal enters the first quantum encryption transmission system. The first multiplexing / demultiplexing module is further configured to convert the plaintext state of the service signal from an optical signal to an electrical signal in response to the selection result being yes. The first encryption module is further configured to encrypt and sign the plaintext state of the service signal converted into an electrical signal according to the quantum key, to obtain the ciphertext state of the service signal converted into an electrical signal. The first multiplexing / demultiplexing module is further configured to convert the ciphertext state of the service signal from an electrical signal to an optical signal, and transmit the ciphertext state of the service signal converted to the optical signal to the second multiplexing / demultiplexing module, so that the second multiplexing / demultiplexing module converts the ciphertext state of the service signal from the optical signal to the electrical signal, and so that the second encryption module decrypts and verifies the ciphertext state of the service signal converted to the electrical signal according to the quantum key, to obtain the plaintext state of the service signal converted to the electrical signal.
7. The system of claim 6, wherein, The first multiplexing / demultiplexing module is further configured to, in response to the selection result being no, transmit the plaintext state of the service signal to the second multiplexing / demultiplexing module.
8. The system of claim 6, wherein, The quantum state optical signal, the quantum key agreement signal and the service signal are transmitted by wavelength division multiplexing.
9. A second quantum encryption transmission system characterized by, The second quantum key distribution (QKD) module, the second encryption module, the second network management module and the second multiplexing / demultiplexing module are included. The second QKD module is connected with the second encryption module, the second encryption module is connected with the second network management module, and the second QKD module, the second encryption module and the second network management module are respectively connected with the second multiplexing / demultiplexing module. The second multiplexing / demultiplexing module is configured to receive the quantum state optical signal transmitted by the first multiplexing / demultiplexing module in the first quantum encryption transmission system, and the quantum state optical signal is generated and sent by a first QKD module of the first quantum encryption transmission system according to configuration management information sent by a first network management module of the first quantum encryption transmission system to a first encryption module of the first quantum encryption transmission system after the first encryption module forwards the configuration management information to the first QKD module. The second QKD module is configured to measure the quantum state optical signal, and generate a quantum key agreement signal according to a quantum state measurement result obtained after the measurement. The second encryption module is configured to encrypt and / or sign the quantum key agreement signal to obtain a processed quantum key agreement signal, wherein the processed quantum key agreement signal is used to trigger the first quantum encryption transmission system to implement quantum encryption transmission based on the processed quantum key agreement signal. The quantum encryption transmission based on the processed quantum key agreement signal specifically includes: The first multiplexing / demultiplexing module receives the processed quantum key agreement signal transmitted by the second multiplexing / demultiplexing module. The first encryption module decrypts and / or verifies the processed quantum key agreement signal. The first QKD module responds to and returns a quantum key agreement signal to the second QKD module according to quantum state preparation information, and the quantum key agreement signal is finally obtained after multiple rounds of back-and-forth between the first QKD module and the second QKD module. When the plaintext state of the service signal enters the first quantum encryption transmission system, the first multiplexing / demultiplexing module selects whether to encrypt the plaintext state of the service signal according to configuration management information of the first network management module. In response to the selection result being yes, the first multiplexing / demultiplexing module converts the plaintext state of the service signal from an optical signal to an electrical signal. The first encryption module encrypts and signs the service signal in the plaintext state converted into an electrical signal according to the quantum key, to obtain the service signal in the ciphertext state converted into an electrical signal; The first multiplexing and demultiplexing module converts the service signal in the ciphertext state from an electrical signal into an optical signal, and transmits the service signal in the ciphertext state converted into an optical signal to the second multiplexing and demultiplexing module, so that the second multiplexing and demultiplexing module converts the service signal in the ciphertext state from an optical signal into an electrical signal, and so that the second encryption module decrypts and verifies the service signal in the ciphertext state converted into an electrical signal according to the quantum key, to obtain the service signal in the plaintext state converted into an electrical signal.
10. The system of claim 9, wherein, The quantum state optical signal, the quantum key agreement signal and the service signal are transmitted through wavelength division multiplexing.
11. A computer readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the quantum encryption transmission method in any one of claims 1-3, or implement the quantum encryption transmission method in any one of claims 4-5.
Citation Information
Patent Citations
Wavelength division multiplexing transmission device, receiving device, relay device and transmission system
CN109428665A
Quantum network management system
CN113824592A