Optical network mutual backup video data encryption method and system based on distributed system
Through the distributed system-based optical network mutual backup video data encryption method, node trust evaluation and dynamic encryption path optimization, combined with quantum channel monitoring, the problems of low encryption efficiency and poor storage reliability in the optical network mutual backup environment are solved, and efficient data transmission and redundant storage are achieved under dynamic networks.
Patent Information
- Application Number
- CN202510700753.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-28
AI Technical Summary
In an environment with dynamic load and unstable network topology, the existing optical network mutual video data encryption method has problems such as low encryption efficiency and poor data redundant storage reliability, mainly due to rigid node trust evaluation and lag in encryption path adjustment.
By obtaining the topology data of optical network and dynamic load parameters of edge nodes, node trust evaluation values are generated, encrypted collaborative nodes are screened using distributed consensus protocols, and encryption paths are dynamically adjusted based on chaotic mapping sequences, and key synchronization is performed in combination with the real-time monitoring of link error rate of quantum channels to achieve dynamic optimization of key distribution and redundant storage.
In a dynamic network environment, the encryption efficiency and the reliability of data redundant storage are improved, and the problem of degradation of key allocation efficiency and insufficient redundant storage reliability caused by network fluctuations in traditional methods is solved, which enhances the system's real-time anti-interference ability and data storage reliability.
Smart Images

Figure CN120389902A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data encryption, and particularly relates to an optical network mutual backup video data encryption method and system based on a distributed system. Background Art
[0002] With the wide application of optical network mutual backup technology in fields such as security monitoring and industrial Internet of Things, the efficient encryption and reliable redundant storage of video data have become the core requirements for ensuring business continuity. The optical network mutual backup system can effectively cope with network single-point failures through multi-path transmission and heterogeneous node collaboration, but its dynamic load and complex topology characteristics pose new requirements for encryption methods, such as real-time performance, anti-quantum cracking, and cross-domain collaboration.
[0003] In the prior art, traditional optical network mutual backup video data encryption methods mainly rely on a fixed key distribution mechanism and a centralized node management mode. Video data is encrypted in blocks using a pre-set key, key updates are completed through a centralized key management node, and the encryption domain is statically divided in combination with the optical network topology, and the encrypted data blocks are stored in redundant nodes.
[0004] However, the optical network mutual backup video data encryption method in the prior art is prone to a decrease in key distribution efficiency and insufficient reliability of redundant storage due to problems such as rigid node trust evaluation and lagging encryption path adjustment in an optical network mutual backup environment with dynamic load and unstable network topology. Therefore, the optical network mutual backup video data encryption method in the prior art has technical problems of low encryption efficiency and poor reliability of data redundant storage in an optical network mutual backup environment with dynamic load and unstable network topology. Summary of the Invention
[0005] This application actually provides an optical network mutual backup video data encryption method, system, device, and computer storage medium based on a distributed system, which can improve encryption efficiency and the reliability of data redundant storage.
[0006] In a first aspect, this application provides an optical network mutual backup video data encryption method based on a distributed system, and the method includes:
[0007] Obtain optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of edge nodes based on the optical network topology data and the dynamic load parameters, where the optical network topology data includes link state parameters;
[0008] Determine edge nodes that meet the mutual backup conditions as encryption collaborative nodes through a distributed consensus protocol, where the mutual backup conditions include that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet a preset threshold range;
[0009] Generate a master key splitting factor based on the node trust evaluation value of the encrypted collaborative nodes, split the master key into multiple sub-key fragments according to the master key splitting factor, and block the optical network backup video data and then bind and encrypt it with multiple sub-key fragments respectively to form backup encrypted data blocks, where the backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations;
[0010] Generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path adapted to the backup storage requirements, and distribute the backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.
[0011] In an implementable embodiment, the method further includes: during the transmission of the target encryption path, obtain the link bit error rate parameter in real time through a quantum channel;
[0012] Determine whether the link bit error rate parameter is greater than a predetermined code rate threshold. When the link bit error rate parameter is greater than the predetermined code rate threshold, trigger the joint decryption verification based on the encrypted collaborative nodes to obtain the updated dynamic load parameter;
[0013] Regenerate the master key splitting factor according to the updated dynamic load parameter and the optical network topology data, and complete the key synchronization of the backup encrypted data blocks through the distributed consensus protocol.
[0014] In an implementable embodiment, regenerating the master key splitting factor according to the updated dynamic load parameter and the optical network topology data, and completing the key synchronization of the backup encrypted data blocks through the distributed consensus protocol includes:
[0015] Based on the change amount of the computing resource occupancy rate in the updated dynamic load parameter and the optical network topology data, recalculate the target node trust evaluation value of each encrypted collaborative node;
[0016] Superpose and correct the target node trust evaluation value with the historical master key splitting factor to generate a target master key splitting factor, where the historical master key splitting factor is the key splitting factor generated last time before triggering the joint decryption verification;
[0017] In the distributed consensus protocol, broadcast the target master key splitting factor to all encrypted collaborative nodes, and perform a majority confirmation of the target master key splitting factor and the historical master key splitting factor by the encrypted collaborative nodes. When more than a preset proportion of encrypted collaborative nodes confirm that the target master key splitting factor and the historical master key splitting factor satisfy the association constraint, complete the key synchronization of the backup encrypted data blocks.
[0018] In an implementable embodiment, generating the node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameter includes:
[0019] Calculate the node connection weight of each edge node based on the distance between nodes and the link bandwidth in the optical network topology data, where the distance between nodes is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate;
[0020] Calculate the load balancing factor of each edge node based on the computing resource occupancy rate and the task queue depth in the dynamic load parameters, where the task queue depth is the cumulative number of unprocessed tasks;
[0021] Superimpose the node connection weight and the load balancing factor according to a preset ratio to generate a node trust evaluation value, and the preset ratio is determined by the global node distribution density of the optical network topology data.
[0022] In an implementable embodiment, determine edge nodes that meet the mutual backup conditions as encrypted collaboration nodes through a distributed consensus protocol. The mutual backup conditions include that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet the preset threshold ranges, including:
[0023] For each edge node, respectively determine whether the fluctuation range of the dynamic load parameters is within the first preset threshold interval and whether the node trust evaluation value is within the second preset threshold interval, where the fluctuation range is the difference between the maximum value and the minimum value of the dynamic load parameters within a preset time window;
[0024] Take the edge nodes that meet the condition that the fluctuation range of the dynamic load parameters is within the first preset threshold interval and the node trust evaluation value is within the second preset threshold interval as the candidate node set;
[0025] In the distributed consensus protocol, confirm the real-time state consistency of each candidate node in the candidate node set through interactive voting among the edge nodes in the candidate node set, and screen out the edge nodes with a voting passing rate exceeding the preset ratio as encrypted collaboration nodes.
[0026] In an implementable embodiment, generate a master key splitting factor based on the node trust evaluation value of the encrypted collaboration nodes, split the master key into multiple sub-key fragments according to the master key splitting factor, and bind and encrypt the optical network mutual backup video data in blocks with multiple sub-key fragments respectively to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including:
[0027] Sort the node trust evaluation values of the encrypted collaboration nodes according to the numerical size, and assign corresponding splitting factor weights to each encrypted collaboration node, where the splitting factor weight is inversely proportional to the sorting position of the node trust evaluation value;
[0028] Calculate the target length of each sub - key segment according to the splitting factor weight, and split the master key into multiple sub - key segments according to the target length;
[0029] Divide the optical network mutual - backup video data into data blocks with the same number as the sub - key segments, and perform bit - by - bit logical operations on each data block and the corresponding sub - key segment to generate mutual - backup encrypted data blocks;
[0030] Allocate redundant storage locations for each mutual - backup encrypted data block according to the splitting factor weight, where the redundant storage location is the physical storage node in the heterogeneous nodes that matches the splitting factor weight.
[0031] In an implementable embodiment, generate an initial encryption path according to the link - state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence to generate a target encryption path adapted to the mutual - backup storage requirements, and distribute the mutual - backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path, including:
[0032] Extract the transmission delay and available bandwidth in the link - state parameters, and mark the links with a transmission delay less than the preset delay threshold and an available bandwidth greater than the preset bandwidth threshold as candidate transmission links;
[0033] Generate an initial encryption path according to the physical locations of the two - end nodes of the candidate transmission links, and the initial encryption path is composed of at least two non - overlapping candidate transmission links connected in series;
[0034] Generate a dynamic perturbation factor based on the chaotic mapping sequence, and periodically rearrange the transmission priorities of each candidate transmission link in the initial encryption path according to the dynamic perturbation factor to generate a target encryption path;
[0035] Distribute the mutual - backup encrypted data blocks to the corresponding heterogeneous nodes in order according to the real - time transmission load rate of the target encryption path, where the real - time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encryption path.
[0036] In a second aspect, the present application provides an optical network mutual - backup video data encryption system based on a distributed system, and the system includes:
[0037] An acquisition module, configured to acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge nodes based on the optical network topology data and the dynamic load parameters, where the optical network topology data includes link - state parameters;
[0038] A determination module, configured to determine edge nodes that meet the mutual - backup conditions as encryption collaborative nodes through a distributed consensus protocol, and the mutual - backup conditions include that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet the preset threshold range;
[0039] A generation module, configured to generate a master key splitting factor based on the node trust evaluation value of an encrypted collaboration node, split the master key into multiple sub-key segments according to the master key splitting factor, and perform block binding encryption on the optical network mutual backup video data after block division respectively with the multiple sub-key segments to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations;
[0040] A distribution module, configured to generate an initial encryption path according to the link state parameter, perform dynamic perturbation on the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path adapted to the mutual backup storage requirement, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.
[0041] In a third aspect, the present application provides an electronic device, including: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the optical network mutual backup video data encryption method based on a distributed system in any one of the implementation manners of the first aspect.
[0042] In a fourth aspect, the present application provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the optical network mutual backup video data encryption method based on a distributed system in any one of the implementation manners of the first aspect is implemented.
[0043] In the embodiment of the present application, a dynamic trust evaluation value is first generated based on the real-time network topology and load parameters, which overcomes the rigidity problem of the traditional fixed evaluation mechanism and ensures that node selection adapts to network fluctuations; secondly, an encrypted collaboration node that meets the mutual backup condition is screened through a distributed consensus mechanism, combined with master key splitting and data block binding encryption, to achieve dynamic optimization of key distribution while ensuring the anti-quantum cracking ability; further, a target encryption path adapted to the storage requirement is generated through dynamic perturbation of the chaotic mapping, which solves the problem of lag in traditional static path adjustment, and combined with the redundant storage mechanism, significantly improves the reliability of data transmission. Finally, the collaborative improvement of encryption efficiency and storage reliability is realized in a dynamic network environment, effectively solving the technical problems of the decline in key distribution efficiency and insufficient reliability of redundant storage existing in the prior art.
[0044] Furthermore, by real-time monitoring of the link bit error rate through the quantum channel and triggering the joint decryption verification and key synchronization of the encryption cooperation nodes when the bit error rate exceeds the threshold, the problems of key leakage risk and data redundancy backup failure caused by sudden changes in channel quality in a dynamic network environment are solved. By dynamically updating the load parameters and the main key splitting factor, ensuring that the key distribution is adapted to the node state in real time, and combining with the distributed consensus synchronization mechanism, the timeliness of key update and the fault tolerance of redundant storage are effectively improved, ensuring the encryption efficiency and the reliability of data redundant storage in an optical network mutual backup environment with dynamic load and unstable network topology. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0046] Figure 1 is a schematic flowchart of an optical network mutual backup video data encryption method based on a distributed system provided by an embodiment of the present application;
[0047] Figure 2 is a schematic flowchart of a key synchronization method for mutual backup encrypted data blocks provided by an embodiment of the present application;
[0048] Figure 3 is a schematic flowchart of a method for generating a target encryption path provided by an embodiment of the present application;
[0049] Figure 4 is a schematic structural diagram of an optical network mutual backup video data encryption system based on a distributed system provided by an embodiment of the present application;
[0050] Figure 5 is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.
[0052] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0053] In the prior art optical network mutual backup video data encryption method, in an optical network mutual backup environment with dynamic load and unstable network topology, due to problems such as rigid node trust evaluation and lagging encryption path adjustment, it is easy to cause a decrease in key distribution efficiency and insufficient reliability of redundant storage. Therefore, in an optical network mutual backup environment with dynamic load and unstable network topology, the prior art optical network mutual backup video data encryption method has technical problems of low encryption efficiency and poor reliability of data redundant storage.
[0054] To solve the problems of the prior art, the embodiments of the present application provide an optical network mutual backup video data encryption method, system, device and computer storage medium based on a distributed system. First, the optical network mutual backup video data encryption method based on a distributed system provided by the embodiments of the present application will be introduced below.
[0055] Figure 1 The flowchart of the optical network mutual backup video data encryption method based on a distributed system provided by an embodiment of the present application is shown. As Figure 1 shown, it includes steps S110 to S140.
[0056] S110: Obtain optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of edge nodes based on the optical network topology data and dynamic load parameters, where the optical network topology data includes link state parameters.
[0057] Optical network topology data refers to a set of structured parameters that describe the physical connection relationships and link states of each node in an optical network, including link state parameters such as the physical link length between nodes, available transmission rate of the link, transmission delay, and bit error rate. Dynamic load parameters refer to the load change indicators generated during the real-time operation of edge nodes, including dynamic parameters such as computing resource occupancy rate, task queue depth, and network throughput that reflect the current processing capabilities of nodes. The node trust evaluation value is a quantitative index calculated based on the comprehensive calculation of node connection stability and load balance, and is used to characterize the credibility and reliability of nodes during the encryption collaboration process.
[0058] First, the physical connection information and link state parameters of each edge node are periodically collected through the optical network management protocol to construct a global optical network topology map. At the same time, a resource monitoring agent deployed on the edge node is used to collect dynamic load parameters in real time, including indicators such as CPU utilization rate, memory occupancy rate, and the number of tasks to be processed. Subsequently, according to the distance between nodes and link bandwidth in the optical network topology data, the connection weight of each node is calculated. The shorter the distance between nodes and the higher the link bandwidth, the greater the connection weight. At the same time, based on the computing resource occupancy rate and task queue depth in the dynamic load parameters, the load balance factor is calculated. The lower the resource occupancy rate and the smaller the task queue depth, the higher the load balance factor. Finally, the connection weight and the load balance factor are superimposed according to a preset ratio dynamically adjusted by the global node distribution density to generate the node trust evaluation value. For example, in a dense node area, the weight of the load balance factor is preferentially increased, while in a sparse area, the contribution of the connection weight is emphasized, so as to ensure the scenario adaptability of the evaluation value.
[0059] Exemplarily, the topology data of 10 edge nodes is obtained through the optical network controller, including the physical link length, bandwidth, and transmission delay between each node. At the same time, the monitoring agent reports that the CPU occupancy rate of each node ranges from 30% to 80%, and the task queue depth ranges from 5 to 20. For node A, the average link length with adjacent nodes is 100 meters, the available bandwidth is 10 Gbps, and the calculated connection weight is 0.8. The CPU occupancy rate of node A is 40%, the task queue depth is 8, and the load balance factor is 0.7. If the global node distribution density is low, and the preset ratio is 60% for the connection weight and 40% for the load balance factor, then the node trust evaluation value is 0.8×0.6 + 0.7×0.4 = 0.76.
[0060] S120: Determine edge nodes that meet the mutual backup conditions as encryption collaboration nodes through a distributed consensus protocol. The mutual backup conditions include that the fluctuation range of dynamic load parameters and the node trust evaluation value simultaneously meet the preset threshold range.
[0061] A distributed consensus protocol refers to a collaborative decision-making mechanism that achieves state consistency through interactive communication and rule verification among multiple nodes in a network environment without a central control node. The mutual backup condition refers to the dual constraint conditions of dynamic load stability and trust required for edge nodes to participate in encrypted collaborative tasks, including the fluctuation range limit of dynamic load parameters within a preset time window and the lower limit of the credibility of the node trust evaluation value.
[0062] First, calculate the fluctuation range of the dynamic load parameters of each edge node. Specifically, by statistically calculating the difference between the maximum and minimum values of the load parameters within a preset time window, and determining whether this difference is within the first preset threshold range. For example, if the load parameter is the CPU occupancy rate, the fluctuation range is the difference between the highest occupancy rate and the lowest occupancy rate in the past 5 minutes. At the same time, verify whether the node trust evaluation value meets the minimum credibility requirement of the second preset threshold range. Filter out the edge nodes that meet both conditions to form a candidate node set. Subsequently, implement the distributed consensus protocol within the candidate node set. Each candidate node broadcasts its own real-time status information to other nodes, and the receiving nodes perform cross-checking on the broadcast information according to the preset verification rules. After passing the verification, each node votes on the availability of the candidate nodes, and counts the voting passing rate of each candidate node. If the passing rate of a certain node exceeds the preset ratio, it is included in the encrypted collaborative node set.
[0063] S130: Generate a master key splitting factor based on the node trust evaluation value of the encrypted collaborative node. Split the master key into multiple sub-key segments according to the master key splitting factor, and after dividing the optical network mutual backup video data into blocks, respectively bind and encrypt them with multiple sub-key segments to form mutual backup encrypted data blocks. Among them, the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations.
[0064] The master key splitting factor is a weight coefficient generated based on the trust evaluation value of the encrypted collaborative node, and is used to determine the length allocation ratio of each sub-key segment when splitting the master key. The sub-key segment is an encrypted segment obtained by dividing the master key according to the splitting factor weight, and each segment is bound to a specific data block. Binding encryption refers to the process of generating an encrypted data block by performing a logical operation on the sub-key segment and the video data block. The mutual backup encrypted data block is an encrypted unit with redundant storage attributes after binding encryption processing, and needs to be dispersed and stored in heterogeneous nodes at different physical locations, such as storage servers in different computer rooms and geographical regions. Heterogeneous nodes refer to storage nodes with dispersed physical locations and different hardware configurations, which are used to achieve cross-domain redundant storage of data blocks.
[0065] First, arrange the encrypted collaborative nodes in descending order of their node trust evaluation values. The higher the ranking of a node, the greater the weight of the splitting factor assigned to it. For example, the nodes in the top 20% of the node trust evaluation values are assigned a weight of 0.3, the middle 60% are assigned a weight of 0.5, and the bottom 20% are assigned a weight of 0.2. The sum of the weights is normalized to 1. After that, calculate the target lengths of the sub-key segments according to the weights of the splitting factors. Assume the length of the master key is 1024 bits, and the weights are 0.3, 0.5, and 0.2 respectively. Then the lengths of the sub-key segments are 307 bits, 512 bits, and 205 bits in sequence, and they are split according to the length using the key sharding algorithm. Then, divide the video data into blocks according to the number of sub-key segments, and the size of each block matches the corresponding sub-key segment. Bind the data block to the sub-key segment through bitwise exclusive OR operation to generate an encrypted data block. For example, the data block D1 is XORed with the sub-key K1 to generate the encrypted block E1. Finally, allocate storage locations according to the weights of the splitting factors. The data block corresponding to the sub-key with a higher weight is stored in a node with higher reliability, which can be a node with dual power supplies and multiple links. For example, the encrypted block corresponding to the segment with a weight of 0.3 is stored in node A, the one with a weight of 0.5 is stored in node B, and the one with a weight of 0.2 is stored in node C.
[0066] S140: Generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path adapted to the mutual backup storage requirements, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.
[0067] The link state parameters refer to the set of indicators characterizing the real-time performance of communication links in an optical network, including key parameters such as transmission delay, available bandwidth, and packet loss rate. The chaotic mapping sequence is a pseudo-random number sequence generated using a chaotic system, which has the characteristics of initial value sensitivity and ergodicity and is used to impose dynamic perturbation on the transmission priority. Dynamic perturbation means periodically adjusting the priority sorting of each link in the path through an algorithm to cope with network environment fluctuations.
[0068] First, extract the transmission delay and available bandwidth data from the link state parameters, and screen out the candidate transmission links with a delay lower than the preset threshold and a bandwidth higher than the minimum requirement. For example, the preset delay threshold is 50 milliseconds and the bandwidth threshold is 5 Gbps, and the links that meet the conditions are marked as the candidate set. Subsequently, construct an initial encryption path according to the physical locations of the candidate links, ensuring that the path is composed of at least two non-overlapping links in series to avoid the risk of single-point failure. For example, select the path from node A to node B and then to node C, and form a mutual backup with the path from node A to node D and then to node C.
[0069] Next, a dynamic perturbation factor sequence is generated based on the Logistic chaotic map, and each perturbation factor corresponds to a priority adjustment coefficient. The perturbation factors are applied to the priority values of each link in the initial path according to a preset period, and the link priorities are reordered through weighted calculation. For example, if the initial priority of a certain link is 0.8 and the perturbation factor is -0.1, the updated priority is 0.72. This process is continuously iterated to form a dynamically changing target encrypted path. Finally, according to the real-time transmission load rate of the target encrypted path, the mutually backup encrypted data blocks are distributed in order from high to low priority. For example, when the load rate of path 1 is 70% while that of path 2 is 40%, path 2 is preferentially selected to transmit new data blocks to ensure load balancing.
[0070] In this embodiment, by first generating a dynamic trust evaluation value based on the real-time network topology and load parameters, the rigidity problem of the traditional fixed evaluation mechanism is overcome, ensuring that node selection adapts to network fluctuations. Secondly, through the distributed consensus mechanism, the encrypted collaborative nodes that meet the mutually backup conditions are screened, and combined with the main key splitting and data block binding encryption, while ensuring the anti-quantum cracking ability, the dynamic optimization of key distribution is realized. Further, through the chaotic map dynamic perturbation, a target encrypted path adapted to the storage requirements is generated, solving the problem of lag in traditional static path adjustment, and significantly improving the data transmission reliability in combination with the redundant storage mechanism. Finally, the collaborative improvement of encryption efficiency and storage reliability is realized in a dynamic network environment, effectively solving the technical problems of the decrease in key distribution efficiency and insufficient redundant storage reliability existing in the prior art.
[0071] Since the prior art cannot respond in real time to link quality fluctuations and node load changes in a dynamic network environment, this application solves the problems of encrypted path failure and key synchronization delay caused by the lag in network state perception by monitoring the link error rate through the quantum channel and triggering the dynamic key update mechanism, thereby improving the real-time anti-interference ability and data storage reliability of the system.
[0072] In an implementable embodiment, the method further includes: during the transmission of the target encrypted path, the link error rate parameter is obtained in real time through the quantum channel.
[0073] The quantum channel is a communication channel based on the principles of quantum mechanics, which uses quantum states to transmit information and has the characteristics of being non-eavesdroppable and anti-interference. The link error rate parameter is an index that measures the proportion of error bits in the data transmission process and reflects the link transmission quality. Obtaining the error rate parameter through the quantum channel can ensure the security of parameter transmission and avoid being tampered with or stolen.
[0074] During the data transmission of the target encryption path, a quantum channel is established through quantum key distribution technology, such as the BB84 protocol. The sender embeds a check code in each transmission cycle, and the receiver compares the check code through quantum measurement to calculate the link bit error rate. Specifically, when implementing, the sender encodes the check code into a quantum state, such as the photon polarization state, and the receiver counts the number of error bits after measurement to calculate the bit error rate. For example, if 1000 quantum bits are sent and the receiver detects 10 error bits, the bit error rate is 1%. The bit error rate parameter collected in real time is transmitted back to the control node through the quantum channel to ensure data integrity.
[0075] Judge whether the link bit error rate parameter is greater than the predetermined code rate threshold. When the link bit error rate parameter is greater than the predetermined code rate threshold, trigger the joint decryption verification based on the encryption cooperation nodes to obtain the updated dynamic load parameters.
[0076] The predetermined code rate threshold is the upper limit of the bit error rate set according to the service reliability requirements. For example, the maximum allowable bit error rate for video transmission is 0.1%. Joint decryption verification refers to the decryption process jointly participated by multiple encryption cooperation nodes, and verifies the integrity of the encrypted data through distributed cooperation. The updated dynamic load parameters are the real-time load indicators re-collected by the encryption cooperation nodes during the verification process.
[0077] The control node compares the real-time bit error rate with the predetermined code rate threshold. If the bit error rate exceeds the threshold, it sends a verification instruction to the encryption cooperation nodes. The encryption cooperation nodes start the joint decryption verification based on the distributed consensus protocol. Each node obtains the corresponding mutually backup encrypted data block from the redundant storage location, decrypts part of the data block using the local sub-key segment, and verifies the correctness of the decryption result through the majority voting mechanism. For example, three nodes decrypt the data block segments respectively. If the decryption results of two nodes are the same, it is determined that the data is complete. During the verification process, each node synchronously reports the current computing resource occupancy rate, task queue depth and other dynamic load parameters to form an updated dynamic load data set.
[0078] Regenerate the main key splitting factor according to the updated dynamic load parameters and the optical network topology data, and complete the key synchronization of the mutually backup encrypted data blocks through the distributed consensus protocol.
[0079] Key synchronization means ensuring that the sub-key segments held by all encryption cooperation nodes are consistent with the updated main key splitting factor through a distributed protocol.
[0080] Based on the updated dynamic load parameters and combined with the optical network topology data, recalculate the node trust evaluation value of each encrypted collaboration node. In the distributed consensus protocol, broadcast the newly generated master key splitting factor to all encrypted collaboration nodes, and each node verifies its association with the historical splitting factor, such as whether it meets the threshold constraint. If more than a preset proportion of nodes confirm that the new splitting factor is legal, then re-split the master key through the secret sharing algorithm and distribute the new sub-key segments to the corresponding nodes to complete the key synchronization. For example, using the Shamir threshold scheme, any 2 out of 3 nodes can collaborate to recover the master key.
[0081] Figure 2 FIG. shows a schematic flowchart of a key synchronization method for mutually backup encrypted data blocks provided by an embodiment of the present application. As Figure 2 shown, it includes steps S210 to S230.
[0082] In an implementable embodiment, according to the updated dynamic load parameters and optical network topology data, regenerate the master key splitting factor, and complete the key synchronization of the mutually backup encrypted data blocks through the distributed consensus protocol, including:
[0083] S210: Based on the change in the computing resource occupancy rate in the updated dynamic load parameters and the optical network topology data, recalculate the target node trust evaluation value of each encrypted collaboration node.
[0084] Obtain the real-time computing resource occupancy rate of the encrypted collaboration node during the joint decryption verification. For example, if the CPU occupancy rate rises from 40% to 55%, calculate its change relative to the historical value. Combine the node connection weights in the optical network topology data and the updated load balancing factor, and generate a new trust evaluation value by superimposing according to a preset proportion. For example, the load balancing factor of node A decreases due to the increase in CPU occupancy rate, resulting in its trust evaluation value dropping from 0.7 to 0.65.
[0085] S220: Superimpose and correct the target node trust evaluation value with the historical master key splitting factor to generate the target master key splitting factor, where the historical master key splitting factor is the key splitting factor generated last time before triggering the joint decryption verification.
[0086] The historical master key splitting factor is the key splitting weight coefficient generated last time before triggering the joint decryption verification. Using the weighted average method, superimpose the target node trust evaluation value and the historical splitting factor according to a dynamic ratio. For example, the weight of the historical splitting factor of node A is 0.5, and the weight corresponding to the new trust evaluation value is 0.4. If the superimposing ratio is 60% for the new weight and 40% for the historical weight, then the corrected target splitting factor weight is 0.4×0.6 + 0.5×0.4 = 0.44. This process ensures the smooth transition of the key splitting factor and avoids key distribution oscillations caused by sudden load changes.
[0087] S230: In the distributed consensus protocol, broadcast the target master key splitting factor to all encrypted collaboration nodes. Through the encrypted collaboration nodes, perform majority confirmation on the target master key splitting factor and the historical master key splitting factor. When more than a preset proportion of encrypted collaboration nodes confirm that the target master key splitting factor and the historical master key splitting factor satisfy the association constraint, complete the key synchronization of the mutual backup encrypted data blocks.
[0088] The association constraint refers to the logical relationship restriction between the new and old splitting factors. For example, the change range of the weight does not exceed a preset threshold, or the sum of the splitting factors remains normalized. The control node broadcasts the target splitting factor to all encrypted collaboration nodes, and each node verifies the relevance of the new and old splitting factors. For example, node A checks whether the change in the weight of the target splitting factor is within the range of ±20% and whether the sum is normalized to 1. If the verification passes, the node sends a confirmation signal; if more than 2 / 3 of the nodes confirm, trigger the key synchronization. During the synchronization process, use the Shamir threshold algorithm to re-split the master key and distribute the new sub-key fragments to the corresponding storage nodes through redundant paths.
[0089] Exemplarily, assume that the historical splitting factor weights of the encrypted collaboration nodes N1, N2, and N3 in the optical network mutual backup system are 0.5, 0.3, and 0.2 respectively. After the combined decryption verification is triggered due to the link bit error rate exceeding the standard, the CPU occupancy rate of node N1 increases from 40% to 55%, and its trust evaluation value decreases from 0.7 to 0.65. When recalculating the target splitting factor, the new weight of N1 is adjusted to 0.44 according to the superposition correction rule, N2 remains 0.3, and N3 is adjusted to 0.26. In the distributed consensus protocol, node N1 broadcasts the target splitting factor weight of 0.44. After N2 and N3 verify that its change range is within the allowable range and the sum is 1, and the confirmation passes, use the threshold algorithm to split the master key into new sub-key fragments with lengths corresponding to the weights of 0.44, 0.3, and 0.26. The new sub-keys are distributed to the off-site disaster recovery nodes, local clusters, and edge nodes through the target encryption path to complete the key synchronization.
[0090] In this embodiment, the link bit error rate is monitored in real time through a quantum channel, and when the bit error rate exceeds the threshold, the combined decryption verification and key synchronization of the encrypted collaboration nodes are triggered, solving the problems of key leakage risk and data redundancy backup failure caused by sudden changes in channel quality in a dynamic network environment. By dynamically updating the load parameters and the master key splitting factor, ensure that the key distribution is adapted to the node state in real time. Combining with the distributed consensus synchronization mechanism, effectively improve the timeliness of key update and the fault tolerance ability of redundant storage, and ensure the encryption efficiency and the reliability of data redundant storage in the optical network mutual backup environment with dynamic load and unstable network topology.
[0091] In an implementable embodiment, generating a node trust evaluation value of an edge node based on optical network topology data and dynamic load parameters in step S110 includes:
[0092] Based on the distance between nodes and link bandwidth in the optical network topology data, calculate the node connection weight of each edge node. The distance between nodes is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate.
[0093] First, extract the physical link lengths between the target edge node and all its adjacent nodes from the optical network topology data, and calculate the average distance between nodes. For example, if the link lengths between node A and adjacent nodes B and C are 100 meters and 200 meters respectively, the average distance is 150 meters. At the same time, obtain the available bandwidth data of node A and its adjacent links, such as the bandwidths are 10 Gbps and 8 Gbps respectively. Subsequently, use the inverse proportional function to normalize the distance between nodes. The shorter the distance, the higher the score. For example, the normalization formula is: distance score = 1 / (average distance + 1). At the same time, linearly normalize the link bandwidth. The larger the bandwidth, the higher the score. For example, bandwidth score = bandwidth value / maximum bandwidth threshold. Finally, weighted sum the distance score and the bandwidth score according to a preset weight (such as distance accounting for 40% and bandwidth accounting for 60%) to generate the node connection weight. For example, the distance score of node A is 0.6 and the bandwidth score is 0.9, then the connection weight is 0.6×0.4 + 0.9×0.6 = 0.78. Calculate the load balancing factor of each edge node based on the computing resource occupancy rate and task queue depth in the dynamic load parameters. The task queue depth is the cumulative number of unprocessed tasks.
[0094] First, collect the CPU occupancy rate and memory occupancy rate of the edge node in real time, and calculate their average value as the computing resource occupancy rate. For example, if the CPU occupancy rate is 50% and the memory occupancy rate is 40%, the average occupancy rate is 45%.
[0095] At the same time, monitor the task queue depth of the node and count the number of unprocessed tasks. For example, there are 12 pending tasks in the current queue. Subsequently, perform inverse normalization processing on the computing resource occupancy rate. The lower the occupancy rate, the higher the score. For example, occupancy rate score = 1 - (occupancy rate / 100). Use the exponential decay function to calculate the score for the task queue depth. The smaller the queue depth, the higher the score. For example, depth score = 1 / (1 + queue depth × 0.1). Finally, superimpose the occupancy rate score and the depth score according to a preset ratio (such as occupancy rate accounting for 70% and depth accounting for 30%) to generate the load balancing factor. For example, the occupancy rate score is 0.55 and the depth score is 0.7, then the load balancing factor is 0.55×0.7 + 0.7×0.3 = 0.595.
[0096] Superimpose the node connection weight and the load balancing factor according to a preset ratio to generate a node trust evaluation value, and the preset ratio is determined by the global node distribution density of the optical network topology data.
[0097] First, count the global distribution density of the nodes in the optical network and calculate the average number of nodes per unit area. For example, if there are 50 nodes within 10 square kilometers, the density is 5 nodes per square kilometer. Dynamically adjust the preset ratio according to the density value: if the density is higher than the threshold, the weight of the load balancing factor is increased (such as accounting for 60%); if the density is lower than the threshold, the weight of the connection weight is increased (such as accounting for 60%). Finally, perform a weighted sum of the node connection weight and the load balancing factor according to the adjusted ratio to generate a node trust evaluation value. For example, if the connection weight of node A is 0.78, the load balancing factor is 0.595, and the preset ratio is 40% for the connection weight and 60% for the load balancing factor, then the trust evaluation value is 0.78×0.4 + 0.595×0.6 = 0.669.
[0098] In an implementable embodiment, step S120: Determine edge nodes that meet the mutual backup conditions as encryption collaboration nodes through a distributed consensus protocol. The mutual backup conditions include that the fluctuation range of the dynamic load parameter and the node trust evaluation value simultaneously meet the preset threshold range, including:
[0099] For each edge node, respectively determine whether the fluctuation range of the dynamic load parameter is within the first preset threshold interval and whether the node trust evaluation value is within the second preset threshold interval, where the fluctuation range is the difference between the maximum value and the minimum value of the dynamic load parameter within a preset time window.
[0100] The fluctuation range of the dynamic load parameter refers to the difference between the maximum value and the minimum value of the dynamic load parameter of the edge node within a preset time window, and is used to quantify the stability of the node load. For example, the difference between the highest value and the lowest value of the CPU occupancy rate within 5 minutes. The first preset threshold interval refers to the preset allowable range of load fluctuations. Exceeding this range indicates that the node load fluctuates too much and is not suitable for participating in the encryption collaboration task. The second preset threshold interval refers to the predefined effective range of the node trust evaluation value. Nodes below the lower limit are considered untrusted, and nodes above the upper limit may be overloaded.
[0101] First, for each edge node, collect the dynamic load parameter sequence within a preset time window. For example, continuously collect the CPU occupancy data at 10 time points. Calculate the maximum and minimum values through the sliding window algorithm to obtain the fluctuation range. For example, if the maximum occupancy rate within the window is 80% and the minimum is 30%, then the fluctuation range is 50%. At the same time, obtain the node trust evaluation value generated in step S110. Compare the fluctuation range with the first preset threshold interval, which can be that the allowed fluctuation does not exceed 40%, and compare the node trust evaluation value with the second preset threshold interval, which can be from 0.6 to 0.9. If the fluctuation range is within the first threshold interval and the trust evaluation value is within the second threshold interval, then the node passes the preliminary screening.
[0102] Take the edge nodes that meet the condition that the fluctuation range of the dynamic load parameters is within the first preset threshold interval and the node trust evaluation value is within the second preset threshold interval as the candidate node set.
[0103] Traverse the screening results of all edge nodes, and add the nodes that meet the threshold conditions of both the fluctuation range and the trust evaluation value to the candidate node set. For example, there are a total of 20 edge nodes, and among them, 15 nodes have a fluctuation range within 40% and a trust evaluation value between 0.6 and 0.9, then these 15 nodes form the candidate set. The candidate node set will be the participating entity in the subsequent distributed consensus protocol.
[0104] In the distributed consensus protocol, confirm the real-time state consistency of each candidate node in the candidate node set through interactive voting among the edge nodes in the candidate node set, and select the edge nodes with a voting passing rate exceeding the preset ratio as the encrypted collaborative nodes.
[0105] The real-time state consistency refers to the consistency between the actual load of the candidate node at the current moment and the reported data, ensuring the authenticity of the node state. Interactive voting refers to a collaborative decision-making mechanism in which candidate nodes reach a consensus on each other's states through multiple rounds of information exchange and verification.
[0106] First, perform state information broadcasting. Each candidate node broadcasts its real-time load data and trust evaluation value to other nodes in the set, including the current CPU occupancy rate, task queue depth, etc. Then perform cross-verification. The receiving node verifies the broadcast data. For example, verify the timeliness of the data through the timestamp, or analyze abnormal fluctuations through the historical data trend. Then each node votes on other nodes according to the verification results. If the data is true and meets the threshold conditions, vote in favor, otherwise vote against. Finally, perform result statistics. Statistically calculate the proportion of votes in favor of each node. If it exceeds the preset ratio, such as 70%, then include it in the encrypted collaborative node set.
[0107] In an optical network, the fluctuation ranges of the dynamic load parameters of nodes X, Y, and Z are 35%, 45%, and 25% respectively, and the node trust evaluation values are 0.75, 0.65, and 0.85 respectively. The preset first threshold interval is that the fluctuation range ≤ 40%, and the second threshold interval is that the trust evaluation value ≥ 0.6. In the preliminary screening, nodes X (fluctuation 35%, trust value 0.75) and node Z (fluctuation 25%, trust value 0.85) meet the conditions, and node Y (fluctuation 45%) is excluded due to exceeding the load threshold. The candidate node set is {X, Z}. In the interactive voting stage, node X broadcasts a real-time CPU occupancy rate of 50% and a task queue depth of 10, and node Z broadcasts a CPU occupancy rate of 40% and a task queue depth of 5. Node X verifies the data of node Z (the historical CPU occupancy rate is usually lower than 45%, and the current data is reasonable) and casts a yes vote, and node Z verifies the data of node X (the task queue depth has increased by 8 compared to the previous period, but the fluctuation is within the allowable range) and casts a yes vote. Finally, both node X and Z receive 100% yes votes and are included in the encrypted collaboration node set.
[0108] Exemplarily, in an optical network, the fluctuation ranges of the dynamic load parameters of nodes X, Y, and Z are 35%, 45%, and 25% respectively, and the trust evaluation values are 0.75, 0.65, and 0.85 respectively. According to the preset rules, nodes with a dynamic load lower than or equal to 40% and a trust value higher than or equal to 0.6 can enter the screening. Among them, node X passes because both the fluctuation of 35% and the trust value of 0.75 meet the standards, node Y is eliminated because the fluctuation of 45% exceeds the threshold, and node Z is selected because both the fluctuation of 25% and the trust value of 0.85 meet the conditions, forming a candidate set {X, Z}. In the interactive voting stage, node X reports a real-time CPU occupancy rate of 50% and a task queue depth of 10, and node Z reports a CPU occupancy rate of 40% and a task queue depth of 5. Based on historical data analysis, node X determines that the CPU occupancy rate of node Z conforms to its normal trend of being lower than 45%, and the data credibility is reasonable; node Z confirms that the task queue depth of node X has only increased by 8 compared to the previous period, which belongs to the allowable range of load fluctuation. Finally, both sides vote in favor of each other, and both node X and Z are included in the encrypted collaboration node set with a 100% support rate.
[0109] In an implementable embodiment, step S130: Generate a master key splitting factor based on the node trust evaluation value of the encrypted collaboration node, split the master key into multiple sub-key segments according to the master key splitting factor, and after dividing the optical network mutual backup video data into blocks, respectively bind and encrypt the blocks with multiple sub-key segments to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including:
[0110] Sort the node trust evaluation values of the encrypted collaboration nodes according to their numerical magnitudes, and assign corresponding splitting factor weights to each encrypted collaboration node. Among them, the splitting factor weight is inversely proportional to the ranking position of the node trust evaluation value.
[0111] The splitting factor weight is a weight coefficient assigned according to the sorting result of the node trust evaluation value, and is used to quantify the contribution degree of the node in the key splitting process. The ranking position refers to the descending order of the node trust evaluation values. The earlier the position, the higher the node trust degree. First, sort the trust evaluation values of the encrypted collaboration nodes in descending order. For example, nodes N1(0.9), N2(0.8), N3(0.7). Adopt an inverse weight assignment strategy according to the ranking position. For example, assign a weight of 0.2 to the 1st position, 0.3 to the 2nd position, and 0.5 to the 3rd position to ensure that nodes with lower positions obtain higher weights. The sum of the weights needs to be normalized to 1. For example, adjust the weight distribution by the linear interpolation method. The finally generated splitting factor weights will be used for subsequent key splitting and storage allocation.
[0112] Calculate the target length of each sub-key segment according to the splitting factor weight, and split the master key into multiple sub-key segments according to the target length.
[0113] Suppose the master key length is 1024 bits, and the splitting factor weights are 0.2, 0.3, and 0.5. Then the target lengths are 205 bits, 307 bits, and 512 bits respectively. Adopt the Shamir secret sharing algorithm or threshold splitting technology to split the master key into sub-key segments according to the target length. The splitting process needs to ensure that the master key cannot be recovered when the number of any subset segments does not reach the preset threshold. For example, adopt a 3-out-of-2 threshold mechanism.
[0114] Divide the optical network mutual backup video data into data blocks with the same number as the sub-key segments, and perform a bit-by-bit logical operation on each data block and the corresponding sub-key segment to generate mutual backup encrypted data blocks.
[0115] The bit-by-bit logical operation refers to performing exclusive OR, permutation, or modular addition operations on each bit of the data block and the sub-key to generate encrypted data blocks. Split the video data into the corresponding number of blocks according to the number of sub-key segments. For example, 3 sub-keys correspond to 3 data blocks. Adopt exclusive OR operation for bit-by-bit encryption: the data block D1 is exclusive ORed with the sub-key K1 to generate E1, D2 and K2 generate E2, and so on. The encrypted data blocks need to satisfy irreversibility, that is, the original data or sub-key cannot be deduced from the encrypted blocks.
[0116] Assign redundant storage locations to each mutual backup encrypted data block according to the splitting factor weight, where the redundant storage location is a physical storage node in the heterogeneous node that matches the splitting factor weight.
[0117] The redundant storage locations are pre-configured heterogeneous storage nodes, and their reliability levels are positively correlated with the weights of the splitting factors. The encrypted data blocks corresponding to the sub-keys with higher weights are stored in nodes with higher reliability, such as nodes with multi-link backup or geographical dispersion. According to the sorting of the weights of the splitting factors, the data block corresponding to the sub-key with the highest weight is allocated to the node with the highest reliability. For example, the sub-key with a weight of 0.5 is stored in a remote active-active data center, the one with a weight of 0.3 is stored in a local highly available cluster, and the one with a weight of 0.2 is stored in an edge node. The storage location mapping table is maintained by a distributed configuration management module to ensure the matching of data blocks and nodes.
[0118] Exemplarily, assume that the optical network mutual backup system includes three encryption cooperation nodes N1, N2, and N3, and their node trust evaluation values are 0.9, 0.8, and 0.7 respectively. The weights of the splitting factors are allocated in reverse order, with N3 having a weight of 0.5, N2 having a weight of 0.3, and N1 having a weight of 0.2. The length of the master key is 1024 bits, which is split into three sub-key segments with lengths of 512 bits, 307 bits, and 205 bits respectively. The video data is divided into three data blocks D1, D2, and D3, which are respectively XOR-encrypted with the sub-keys K3, K2, and K1 to generate encrypted blocks E1, E2, and E3. According to the weight allocation, the storage locations are as follows: E1 (weight 0.5) is stored in a remote disaster recovery node, E2 (weight 0.3) is stored in a local highly available cluster, and E3 (weight 0.2) is stored in an edge node. This design ensures that the encrypted blocks with high weights are stored in more reliable nodes, improves the reliability of the overall redundant storage, and at the same time adapts to the key distribution requirements in a dynamic network environment.
[0119] Figure 3 The flowchart of the method for generating a target encryption path provided by an embodiment of the present application is shown. As Figure 3 shown, it includes steps S310 to S340.
[0120] In an implementable embodiment, step S140: Generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path that adapts to the mutual backup storage requirements, and distribute the mutually backed-up encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path, including:
[0121] S310: Extract the transmission delay and available bandwidth in the link state parameters, and mark the links with a transmission delay less than the preset delay threshold and an available bandwidth greater than the preset bandwidth threshold as candidate transmission links.
[0122] First, set the transmission delay threshold and the bandwidth threshold. The delay threshold is determined according to the requirements of service continuity, such as the maximum tolerable delay for video data transmission; the bandwidth threshold is calculated based on the data block size and the transmission period. Extract the real-time transmission delay and available bandwidth parameters of each link from the optical network topology data, and judge one by one whether they simultaneously meet the conditions that the delay is less than the threshold and the bandwidth is greater than the threshold. For the links that meet the conditions, mark them as candidate transmission links and record the information of their two end nodes. For example, if the delay of link L1 is 30 milliseconds and the bandwidth is 8 Gbps, and the preset delay threshold is 50 milliseconds and the bandwidth threshold is 5 Gbps, then L1 is marked as a candidate link.
[0123] S320: Generate an initial encrypted path according to the physical positions of the two end nodes of the candidate transmission link. The initial encrypted path is composed of at least two non-overlapping candidate transmission links connected in series.
[0124] According to the physical positions of the two end nodes of the candidate transmission link, use the shortest path algorithm in graph theory, such as the Dijkstra algorithm, or it can also be a redundant path generation algorithm, to construct multiple transmission paths from the source node to the target node. Each path needs to meet the following conditions: the path length does not exceed the maximum hop count limit; there are no shared links or nodes between paths. For example, there are two candidate paths from the source node S to the target node T: path P1 is composed of links L1 - L2 - L3, and path P2 is composed of links L4 - L5 - L6, and there are no overlapping links between them. The set of initial encrypted paths is {P1, P2}.
[0125] S330: Generate a dynamic perturbation factor based on the chaotic mapping sequence, and periodically rearrange the transmission priorities of each candidate transmission link in the initial encrypted path according to the dynamic perturbation factor to generate the target encrypted path.
[0126] Use the Logistic chaotic mapping model to generate a dynamic perturbation factor sequence, and its iterative formula is: \(x_{n + 1}=\mu\times x_n(1 - x_n)\), where \(\mu\) is the control parameter and \(x_n\in(0,1)\). Set the initial value \(x_0\) and the control parameter \(\mu\) to generate the perturbation factor sequence. In each perturbation period, multiply the current perturbation factor by the initial priority of the link (calculated based on delay and bandwidth) to obtain the updated priority. For example, for a link with an initial priority of 0.8, if the perturbation factor is 0.9, the updated priority is 0.72. Sort the priorities of all links to generate the target encrypted path.
[0127] S340: According to the real-time transmission load ratio of the target encrypted path, distribute the mutually backup encrypted data blocks to the corresponding heterogeneous nodes in sequence, where the real-time transmission load ratio is the ratio of the occupied bandwidth to the total bandwidth in the target encrypted path.
[0128] Monitor the occupied bandwidth of each link in the target encrypted path in real time, and calculate the real-time load rate of each path. Arrange the paths in descending order of priority, and preferentially select the path with high priority and low load rate to transmit the mutual backup encrypted data blocks. For example, if the priority of path P1 is 0.8 and the load rate is 60%, and the priority of path P2 is 0.7 and the load rate is 40%, then P2 is preferentially selected to transmit the data block. If the path load rate exceeds the preset threshold, which can be 80%, then suspend using this path and trigger path reconstruction.
[0129] Exemplarily, the optical network mutual backup system includes a source node S, a target node T, and intermediate nodes A, B, C, and D. Among the link state parameters, the link S-A delay is 20 ms and the bandwidth is 10 Gbps, the A-T delay is 35 ms and the bandwidth is 8 Gbps, the S-B delay is 25 ms and the bandwidth is 9 Gbps, and the B-T delay is 40 ms and the bandwidth is 7 Gbps. The preset delay threshold is 50 ms and the bandwidth threshold is 5 Gbps, and S-A, A-T, S-B, and B-T are screened out as candidate transmission links. Construct the initial encrypted paths P1 (S-A-T) and P2 (S-B-T), and there are no overlapping links between them. Use the Logistic chaotic map to generate a sequence of perturbation factors, with the initial value x_0 = 0.3 and μ = 3.9, and generate perturbation factors 0.6 and 0.8. The initial priority of path P1 is 0.85 (low delay, high bandwidth), and the priority of P2 is 0.75. After applying the perturbation factors, the priority of P1 is updated to 0.85×0.6 = 0.51, and P2 is updated to 0.75×0.8 = 0.6. After rearrangement, the priority of P2 is higher than that of P1. Monitor the real-time load rate. If the load rate of P1 is 70% and that of P2 is 45%, then preferentially distribute the encrypted data blocks to heterogeneous nodes through P2. When the load rate of P2 rises to 75%, trigger the chaotic map to regenerate the perturbation factors and dynamically adjust the path priorities.
[0130] Based on the same concept, an embodiment of the present application provides an optical network mutual backup video data encryption system based on a distributed system. The following combines Figure 4 to elaborate in detail on the optical network mutual backup video data encryption system provided by the embodiment of the present application.
[0131] Figure 4 It is a structural block diagram of an optical network mutual backup video data encryption system shown in an embodiment of the present application.
[0132] As Figure 4 shown, the optical network mutual backup video data encryption system based on a distributed system may include:
[0133] An acquisition module 410 is configured to acquire optical network topology data and dynamic load parameters of edge nodes, generate a node trust evaluation value of an edge node based on the optical network topology data and the dynamic load parameters, where the optical network topology data includes link state parameters;
[0134] A determination module 420 is configured to determine edge nodes that meet the mutual backup condition as encryption cooperation nodes through a distributed consensus protocol, where the mutual backup condition includes that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet a preset threshold range;
[0135] A generation module 430 is configured to generate a master key splitting factor based on the node trust evaluation value of the encryption cooperation nodes, split the master key into multiple sub-key segments according to the master key splitting factor, and perform binding encryption on the optical network mutual backup video data after block division with the multiple sub-key segments respectively to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations;
[0136] A distribution module 440 is configured to generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on a chaotic mapping sequence, generate a target encryption path adapted to the mutual backup storage requirement, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.
[0137] In one embodiment, the distribution module 440 is further configured to, during the transmission of the target encryption path, obtain the link error rate parameter in real time through a quantum channel; determine whether the link error rate parameter is greater than a predetermined code rate threshold, and when the link error rate parameter is greater than the predetermined code rate threshold, trigger joint decryption verification based on the encryption cooperation nodes, and obtain the updated dynamic load parameters; regenerate the master key splitting factor according to the updated dynamic load parameters and the optical network topology data, and complete the key synchronization of the mutual backup encrypted data blocks through the distributed consensus protocol.
[0138] In one embodiment, the distribution module 440 is specifically configured to recalculate the target node trust evaluation value of each encryption cooperation node based on the change amount of the computing resource occupancy rate in the updated dynamic load parameters and the optical network topology data; superimpose and correct the target node trust evaluation value and the historical master key splitting factor to generate a target master key splitting factor, where the historical master key splitting factor is the key splitting factor generated last time before triggering the joint decryption verification; in the distributed consensus protocol, broadcast the target master key splitting factor to all encryption cooperation nodes, and perform majority confirmation on the target master key splitting factor and the historical master key splitting factor by the encryption cooperation nodes. When more than a preset proportion of the encryption cooperation nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the association constraint, the key synchronization of the mutual backup encrypted data blocks is completed.
[0139] In one embodiment, the obtaining module 410 is specifically configured to calculate the node connection weight of each edge node based on the distance between nodes and the link bandwidth in the optical network topology data, where the distance between nodes is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate; calculate the load balancing factor of each edge node based on the computing resource occupancy rate and the task queue depth in the dynamic load parameters, where the task queue depth is the cumulative number of unprocessed tasks; superimpose the node connection weight and the load balancing factor according to a preset ratio to generate a node trust evaluation value, and the preset ratio is determined by the global node distribution density of the optical network topology data.
[0140] In one embodiment, the determining module 420 is specifically configured to, for each edge node, respectively determine whether the fluctuation range of the dynamic load parameters is within a first preset threshold interval and whether the node trust evaluation value is within a second preset threshold interval, where the fluctuation range is the difference between the maximum value and the minimum value of the dynamic load parameters within a preset time window; use the edge nodes that satisfy the condition that the fluctuation range of the dynamic load parameters is within the first preset threshold interval and the node trust evaluation value is within the second preset threshold interval as the candidate node set; in the distributed consensus protocol, confirm the real-time state consistency of each candidate node in the candidate node set through interactive voting among the edge nodes in the candidate node set, and select the edge nodes with a voting passing rate exceeding a preset ratio as the encryption collaboration nodes.
[0141] In one embodiment, the generating module 430 is specifically configured to sort the node trust evaluation values of the encryption collaboration nodes according to the numerical size, and assign corresponding splitting factor weights to each encryption collaboration node, where the splitting factor weight is inversely proportional to the sorting position of the node trust evaluation value; calculate the target length of each sub-key segment according to the splitting factor weight, and split the main key into multiple sub-key segments according to the target length; divide the optical network mutual backup video data into data blocks with the same number as the sub-key segments, and perform a bitwise logical operation on each data block and the corresponding sub-key segment to generate a mutual backup encrypted data block; assign redundant storage locations to each mutual backup encrypted data block according to the splitting factor weight, where the redundant storage location is a physical storage node in the heterogeneous nodes that matches the splitting factor weight.
[0142] In one embodiment, the distribution module 440 is specifically configured to extract the transmission delay and available bandwidth from the link state parameters, mark the links with a transmission delay less than a preset delay threshold and an available bandwidth greater than a preset bandwidth threshold as candidate transmission links; generate an initial encrypted path based on the physical locations of the two end nodes of the candidate transmission links, where the initial encrypted path is composed of at least two non-overlapping candidate transmission links connected in series; generate a dynamic perturbation factor based on a chaotic mapping sequence, and periodically rearrange the transmission priorities of each candidate transmission link in the initial encrypted path according to the dynamic perturbation factor to generate a target encrypted path; and distribute the mutually backup encrypted data blocks to the corresponding heterogeneous nodes in sequence according to the real-time transmission load ratio of the target encrypted path, where the real-time transmission load ratio is the ratio of the occupied bandwidth to the total bandwidth in the target encrypted path.
[0143] Figure 4 Each module in the system shown has the function of implementing Figures 1 to 3 each step in and can achieve its corresponding technical effects. For the sake of brevity, they will not be described herein again.
[0144] Figure 5 FIG. shows a schematic hardware structure diagram of an electronic device provided in an embodiment of the present application.
[0145] The electronic device may include a processor 510 and a memory 520 storing computer program instructions.
[0146] Specifically, the processor 510 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0147] The memory 520 may include a mass storage for data or instructions. By way of example and not limitation, the memory 520 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In a suitable case, the memory 520 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 520 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 520 is a non-volatile solid state memory.
[0148] The memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to the first aspect of the present disclosure.
[0149] The processor 510 reads and executes the computer program instructions stored in the memory 520 to implement any one of the above-described optical network mutual backup video data encryption methods based on a distributed system.
[0150] In one example, the electronic device may further include a communication interface 530 and a bus 540. Among them, as Figure 5 shown, the processor 510, the memory 520, and the communication interface 530 are connected through the bus 540 and complete communication with each other.
[0151] The communication interface 530 is mainly used to implement communication between each module, device, unit, and / or device in the embodiments of the present application.
[0152] The bus 540 includes hardware, software, or both, and couples the components of the online data flow billing device to each other. By way of example and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses or a combination of two or more of these. In a suitable case, the bus 540 may include one or more buses. Although the embodiments of the present application describe and illustrate a specific bus, the present application contemplates any suitable bus or interconnect.
[0153] The electronic device can execute the optical network mutual backup video data encryption method based on a distributed system in the embodiments of the present application, thereby implementing the optical network mutual backup video data encryption method based on a distributed system described in combination with Figures 1 to 3 description.
[0154] In addition, in combination with the optical network mutual backup video data encryption method based on a distributed system in the above embodiments, an embodiment of the present application can provide a computer-readable storage medium to implement. Computer program instructions are stored on the computer-readable storage medium; when the computer program instructions are executed by a processor, any one of the optical network mutual backup video data encryption methods based on a distributed system in the above embodiments is implemented.
[0155] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.
[0156] The functional blocks shown in the structural block diagrams described above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present application are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted via a data signal carried in a carrier wave on a transmission medium or a communication link. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.
[0157] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.
[0158] As described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems) and computer program products according to embodiments of the present application. It should be understood that each block in the flowchart and / or block diagram, and the combination of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general purpose processor, a special purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0159] As described above, the above is only the specific implementation manner of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again. It should be understood that the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application.
Claims
1. An optical network mutual backup video data encryption method based on a distributed system, characterized in that, Including: Obtain optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge nodes based on the optical network topology data and the dynamic load parameters, where the optical network topology data includes link state parameters; Determine edge nodes that meet the mutual backup condition as encryption collaborative nodes through a distributed consensus protocol, where the mutual backup condition includes that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet a preset threshold range; Generate a master key splitting factor based on the node trust evaluation value of the encryption collaborative nodes, split the master key into multiple sub-key fragments according to the master key splitting factor, and bind and encrypt the optical network mutual backup video data in blocks respectively with the multiple sub-key fragments to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations; Generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on a chaotic mapping sequence to generate a target encryption path adapted to the mutual backup storage requirement, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.
2. The method according to claim 1, wherein The method further includes: During the transmission of the target encryption path, obtain the link error rate parameter in real time through a quantum channel; Judge whether the link error rate parameter is greater than a predetermined code rate threshold. When the link error rate parameter is greater than the predetermined code rate threshold, trigger the joint decryption verification based on the encryption collaborative nodes to obtain the updated dynamic load parameters; Regenerate the master key splitting factor according to the updated dynamic load parameters and the optical network topology data, and complete the key synchronization of the mutual backup encrypted data blocks through the distributed consensus protocol.
3. The method according to claim 2, wherein The regenerating the master key splitting factor according to the updated dynamic load parameters and the optical network topology data and completing the key synchronization of the mutual backup encrypted data blocks through the distributed consensus protocol includes: Based on the change amount of the computing resource occupancy rate in the updated dynamic load parameters and the optical network topology data, recalculate the target node trust evaluation value of each encryption collaborative node; Superpose and correct the target node trust evaluation value with the historical master key splitting factor to generate a target master key splitting factor, where the historical master key splitting factor is the key splitting factor generated last time before triggering the joint decryption verification; In the distributed consensus protocol, broadcast the target master key splitting factor to all the encryption collaborative nodes, and perform a majority confirmation on the target master key splitting factor and the historical master key splitting factor by the encryption collaborative nodes. When more than a preset proportion of the encryption collaborative nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the association constraint, complete the key synchronization of the mutual backup encrypted data blocks.
4. The method according to claim 1, characterized in that The generating a node trust evaluation value of the edge nodes based on the optical network topology data and the dynamic load parameters includes: Calculate the node connection weight of each edge node based on the distance between nodes and link bandwidth in the optical network topology data, where the distance between nodes is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate; Calculate the load balancing factor of each edge node based on the computing resource occupancy rate and task queue depth in the dynamic load parameters, where the task queue depth is the cumulative number of unprocessed tasks; Superimpose the node connection weight and the load balancing factor according to a preset ratio to generate the node trust evaluation value, where the preset ratio is determined by the global node distribution density of the optical network topology data.
5. The method according to claim 1, wherein Determine edge nodes that meet the mutual backup conditions as encryption collaboration nodes through a distributed consensus protocol. The mutual backup conditions include that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet the preset threshold range, including: For each edge node, respectively determine whether the fluctuation range of the dynamic load parameters is within the first preset threshold interval and whether the node trust evaluation value is within the second preset threshold interval, where the fluctuation range is the difference between the maximum value and the minimum value of the dynamic load parameters within a preset time window; Take the edge nodes that meet the condition that the fluctuation range of the dynamic load parameters is within the first preset threshold interval and the node trust evaluation value is within the second preset threshold interval as the candidate node set; In the distributed consensus protocol, confirm the real-time state consistency of each candidate node in the candidate node set through interactive voting among the edge nodes in the candidate node set, and select the edge nodes with a voting pass rate exceeding the preset ratio as the encryption collaboration nodes.
6. The method according to claim 1, wherein Generate a master key splitting factor based on the node trust evaluation value of the encryption collaboration nodes, split the master key into multiple sub-key segments according to the master key splitting factor, and perform binding encryption on the optical network mutual backup video data after partitioning it with the multiple sub-key segments respectively to form mutual backup encrypted data blocks, where the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including: Sort the node trust evaluation values of the encryption collaboration nodes according to the numerical size, and assign corresponding splitting factor weights to each encryption collaboration node, where the splitting factor weight is inversely proportional to the sorting position of the node trust evaluation value; Calculate the target length of each sub-key segment according to the splitting factor weight, and split the master key into multiple sub-key segments according to the target length; Divide the optical network mutual backup video data into data blocks with the same number as the sub-key segments, and perform bitwise logical operations on each data block with the corresponding sub-key segment to generate the mutual backup encrypted data blocks; Assign redundant storage locations to each mutual backup encrypted data block according to the splitting factor weight, where the redundant storage location is the physical storage node in the heterogeneous nodes that matches the splitting factor weight.
7. The method according to claim 1, characterized in that Generating an initial encrypted path according to the link state parameters, dynamically perturbing the transmission priority of the initial encrypted path based on a chaotic mapping sequence to generate a target encrypted path adapted to the mutual backup storage requirements, and distributing the mutually backed-up encrypted data blocks to corresponding heterogeneous nodes through the target encrypted path includes: Extracting the transmission delay and available bandwidth in the link state parameters, and marking the links with a transmission delay less than a preset delay threshold and an available bandwidth greater than a preset bandwidth threshold as candidate transmission links; Generating an initial encrypted path according to the physical positions of the two end nodes of the candidate transmission link, where the initial encrypted path is composed of at least two non-overlapping candidate transmission links connected in series; Generating a dynamic perturbation factor based on the chaotic mapping sequence, and periodically rearranging the transmission priority of each candidate transmission link in the initial encrypted path according to the dynamic perturbation factor to generate the target encrypted path; According to the real-time transmission load rate of the target encrypted path, distributing the mutually backed-up encrypted data blocks to corresponding heterogeneous nodes in sequence, where the real-time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encrypted path.
8. An optical network mutual backup video data encryption system based on a distributed system, characterized in that, The system includes: An acquisition module, configured to acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge nodes based on the optical network topology data and the dynamic load parameters, where the optical network topology data includes link state parameters; A determination module, configured to determine edge nodes that meet the mutual backup condition as encryption cooperation nodes through a distributed consensus protocol, where the mutual backup condition includes that the fluctuation range of the dynamic load parameters and the node trust evaluation value simultaneously meet a preset threshold range; A generation module, configured to generate a master key splitting factor based on the node trust evaluation value of the encryption cooperation nodes, split the master key into multiple sub-key segments according to the master key splitting factor, and respectively bind and encrypt the optical network mutually backed-up video data blocks with the multiple sub-key segments to form mutually backed-up encrypted data blocks, where the mutually backed-up encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations; A distribution module, configured to generate an initial encrypted path according to the link state parameters, dynamically perturb the transmission priority of the initial encrypted path based on a chaotic mapping sequence to generate a target encrypted path adapted to the mutual backup storage requirements, and distribute the mutually backed-up encrypted data blocks to corresponding heterogeneous nodes through the target encrypted path.
9. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method for encrypting optical network mutually backed-up video data based on a distributed system according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, Computer program instructions are stored on a computer-readable storage medium, and when the computer program instructions are executed by a processor, they implement the method for encrypting optical network mutually backed-up video data based on a distributed system according to any one of claims 1-7.
Citation Information
Patent Citations
Network edge calculation method and communication device
CN119520156A
Communication transmission control cabinet based on big data
CN119603301A
Using a trusted execution environment for a proof-of-work key wrapping scheme that verifies remote device capabilities
US20210157904A1
Cited By
Multi-node joint encryption data transmission method based on Internet of Things
CN122137648A
A data transmission method based on multi-node joint encryption of an internet of things
CN122137648B