Quantum key distribution method and device, electronic equipment and computer storage medium

By obtaining network status information in real time through the quantum key distribution network control center, dynamically evaluating path weights and optimizing routing strategies, the problems of high resource consumption and security risks in the quantum key distribution network are solved, the robustness and resource utilization of the network are improved, and the risk of single point failure is reduced.

CN120602091AActive Publication Date: 2025-09-05中电信量子信息科技集团有限公司

Patent Information

Application Number
CN202511104047.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-09-05
Estimated Expiration
2045-08-07

AI Technical Summary

Technical Problem

Existing quantum key distribution networks have high resource consumption and low utilization in complex network environments, and there are security risks such as single point failure and relay node compromise.

Method used

The quantum key distribution network control center obtains network status information in real time, dynamically evaluates path weights, and uses a dual-variable optimization algorithm to simultaneously solve the optimal path and distribution method, realize the segmentation and reorganization of quantum keys, and optimize routing strategies to reduce redundant hops and node key pool load pressure.

Benefits of technology

It improves the anti-attack capability of quantum key distribution, improves the robustness and resource utilization of the network, reduces the risk of single point failure, and minimizes global resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602091A_ABST
    Figure CN120602091A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a quantum key distribution method and device, electronic equipment and a computer readable storage medium, and relates to the technical field of quantum key distribution, and the method comprises the steps that a quantum key distribution network control center responds to a quantum key distribution request, obtains the network state information of a quantum key distribution network, and sends the network state information to a server; the method comprises the steps of receiving network state information, determining a path set for distributing quantum keys based on the network state information, then determining a path weight of each reachable path based on the network state information, determining a distribution mode of the quantum keys based on the path weights, and determining a target path from the path set; and sending the distribution mode and the target path to a source node. According to the embodiment of the invention, the network state can be sensed in real time, the routing strategy can be adjusted, the problem of quantum link quality fluctuation or node resource shortage can be effectively solved, quantitative analysis of path security efficiency and resource efficiency is realized, and the robustness and flexibility of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of quantum key distribution, and particularly to a quantum key distribution method, a quantum key distribution device, an electronic device, and a computer-readable storage medium. Background Art

[0002] Quantum key distribution (QKD) is based on the principles of quantum no-cloning and uncertainty, and can achieve information-theoretically secure key negotiation. It is one of the core technologies for next-generation network security. As quantum communication develops from point-to-point transmission to multi-node networking, how to achieve efficient, reliable, and secure key distribution in a complex network environment has become a key problem to be solved urgently.

[0003] Most current quantum networks adopt a static single-path transmission mode. This mode relies on fixed links or simple load balancing algorithms, and there are significant hidden dangers. In the trusted relay mode, an attacker only needs to break through any relay node to easily steal the complete key information, and the risk of single-point failure is extremely high. To address the security risks of relay nodes, segmented routing technology has been proposed as a defense measure. Its core idea is to divide the complete key into multiple segments and transmit them independently through different paths. An attacker needs to intercept all sub-segments of all paths simultaneously to recover the key. For example, the secret sharing scheme based on Shamir threshold can divide the key into n segments, and only any t segments (t < n) are required to reconstruct the original key, thus significantly reducing the risk of single-path leakage.

[0004] This technology theoretically improves the ability to resist relay attacks. However, since both key segmentation and different paths need to be determined manually, the resource consumption of the quantum key distribution network is relatively high and the utilization rate is relatively low. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a quantum key distribution method, a quantum key distribution device, an electronic device, and a computer-readable storage medium that overcome the above problems or at least partially solve the above problems.

[0006] To solve the above problems, embodiments of the present invention disclose a quantum key distribution method applied to a quantum key distribution network control center. The method includes: Responding to a quantum key distribution request, obtaining network status information of the quantum key distribution network, and determining a path set for distributing the quantum key based on the network status information; the path set includes at least one reachable path; Determining the path weight of each reachable path based on the network status information; Determining the distribution method of the quantum key based on the path weight, and determining a target path from the path set; The distribution method and the target path are sent to a source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to a destination node based on the target path, so that the destination node reassembles each of the quantum key segments to obtain the quantum key when obtaining the quantum key segments.

[0007] In one or more embodiments, determining a set of paths for distributing quantum keys based on the network state information includes: Using the network state information to construct a network topology of a quantum distribution network; Calculating at least one reachable path between the source node and the destination node in the network topology using a preset algorithm; Combine all reachable paths to obtain a path set.

[0008] In one or more embodiments, before obtaining the network status information of the quantum key distribution network, the method further includes: Verifying the legitimacy of the quantum key distribution request; If the verification is successful, the total amount of the quantum key and the destination node are obtained from the quantum key distribution request.

[0009] In one or more embodiments, determining the path weight of each reachable path based on the network state information includes: Determining network status information of each node in each reachable path from the network status information; Calculate the security score and resource consumption of each reachable path based on the network status information of each node; The path weight of each reachable path is calculated based on the security score and resource consumption of each reachable path.

[0010] In one or more embodiments, the network status information includes quantum bit error rate, key generation rate, number of path nodes, and amount of remaining keys in the key pool; The calculation of the security score and resource consumption of each reachable path based on the network status information of each node includes: Calculating a security score for each node using the quantum bit error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes of each node and the remaining key amount of the key pool.

[0011] In one or more embodiments, determining the quantum key distribution method based on the path weight, and determining the target path from the path set, includes: Constructing an optimization model; the optimization model includes a key distribution variable and a path selection variable; Inputting the path weight of each reachable path into the optimization model; Solving the optimization model using a preset algorithm to obtain an optimal path selection result and an optimal key distribution result; The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method.

[0012] Accordingly, an embodiment of the present invention discloses a quantum key distribution method, which is applied to a source node. The method includes: generating a quantum key distribution request in response to the quantum key distribution instruction; sending the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node; Obtaining the allocation method and the target path; Splitting the quantum key based on the distribution method to obtain a plurality of quantum key segments; the number of the quantum key segments is the same as the number of the target paths; Each quantum key segment is sent to a destination node through a corresponding target path, so that when the destination node obtains each quantum key segment, it recombines each quantum key segment to obtain the quantum key.

[0013] In one or more embodiments, generating a quantum key distribution request includes: Obtaining the total amount of keys and the destination node in the quantum key distribution instruction; A quantum key distribution request is generated using the total key amount and the destination node.

[0014] Accordingly, an embodiment of the present invention discloses a quantum key distribution method, which is applied to a destination node. The method includes: Obtaining at least one quantum key segment ciphertext; Decrypting each quantum key segment ciphertext to obtain at least one quantum key segment; The individual quantum key segments are recombined to obtain the quantum key.

[0015] In one or more embodiments, decrypting each quantum key segment ciphertext to obtain at least one quantum key segment includes: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key of each previous hop node; Each shared key is used to decrypt the corresponding quantum key segment ciphertext to obtain each quantum key segment.

[0016] In one or more embodiments, further comprising: verifying the quantum key; If the verification fails, an alarm message is generated.

[0017] Accordingly, an embodiment of the present invention discloses a quantum key distribution device, which is applied to a quantum key distribution network control center. The device includes: A first acquisition module is configured to acquire network status information of a quantum key distribution network in response to a quantum key distribution request; A first computing module is configured to determine a path set for distributing a quantum key based on the network state information; the path set includes at least one reachable path; a second calculation module, configured to determine a path weight of each reachable path based on the network state information; a third computing module, configured to determine a distribution mode of the quantum key based on the path weight, and to determine a target path from the path set; a first sending module, configured to send the distribution method and the target path to a source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to a destination node based on the target path, so that the destination node reassembles each of the quantum key segments to obtain the quantum key when obtaining the quantum key segments.

[0018] In one or more embodiments, the first computing module is specifically configured to: Using the network state information to construct a network topology of a quantum distribution network; Calculating at least one reachable path between the source node and the destination node in the network topology using a preset algorithm; Combine all reachable paths to obtain a path set.

[0019] In one or more embodiments, further comprising: A first verification module is configured to verify the legitimacy of the quantum key distribution request before obtaining the network status information of the quantum key distribution network; An extraction module is configured to obtain the total amount of the quantum key and the destination node from the quantum key distribution request if the verification is successful.

[0020] In one or more embodiments, the second computing module includes: a determination submodule, configured to determine the network status information of each node in each reachable path from the network status information; A first calculation submodule is used to calculate the security score and resource consumption of each reachable path based on the network status information of each node; The second calculation submodule is configured to calculate a path weight of each reachable path based on the security score and resource consumption of each reachable path.

[0021] In one or more embodiments, the network status information includes quantum bit error rate, key generation rate, number of path nodes, and amount of remaining keys in the key pool; The first calculation submodule is specifically configured to: Calculating a security score for each node using the quantum bit error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes of each node and the remaining key amount of the key pool.

[0022] In one or more embodiments, the third computing module is specifically configured to: Constructing an optimization model; the optimization model includes a key distribution variable and a path selection variable; Inputting the path weight of each reachable path into the optimization model; Solving the optimization model using a preset algorithm to obtain an optimal path selection result and an optimal key distribution result; The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method.

[0023] Accordingly, an embodiment of the present invention discloses a quantum key distribution device, which is applied to a source node. The device includes: A first generating module is configured to generate a quantum key distribution request in response to a quantum key distribution instruction; a second sending module, configured to send the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node; A second acquisition module, configured to acquire the allocation method and the target path; a splitting module, configured to split the quantum key based on the distribution method to obtain a plurality of quantum key segments, wherein the number of the quantum key segments is the same as the number of the target paths; The third sending module is used to send each quantum key segment to a destination node through a corresponding target path, so that when the destination node obtains each quantum key segment, it reassembles each quantum key segment to obtain the quantum key.

[0024] In one or more embodiments, the generating module is specifically configured to: Obtaining the total amount of keys and the destination node in the quantum key distribution instruction; A quantum key distribution request is generated using the total key amount and the destination node.

[0025] Accordingly, an embodiment of the present invention discloses a quantum key distribution device, which is applied to a destination node. The device includes: A third acquisition module is used to obtain at least one quantum key segment ciphertext; A decryption module, configured to decrypt each quantum key segment ciphertext to obtain at least one quantum key segment; The recombining module is used to recombine the various quantum key segments to obtain the quantum key.

[0026] In one or more embodiments, the decryption module is specifically configured to: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key of each previous hop node; Each shared key is used to decrypt the corresponding quantum key segment ciphertext to obtain each quantum key segment.

[0027] In one or more embodiments, further comprising: A second verification module, configured to verify the quantum key; The second generating module is used to generate an alarm message if the verification fails.

[0028] Accordingly, an embodiment of the present invention discloses an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the various steps of the above-mentioned quantum key distribution method embodiment are implemented.

[0029] Accordingly, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various steps of the above-mentioned quantum key distribution method embodiment are implemented.

[0030] The embodiments of the present invention include the following advantages: In response to a quantum key distribution request, the quantum key distribution network control center obtains network status information of the quantum key distribution network and, based on the network status information, determines a set of paths for distributing quantum keys. Furthermore, based on the network status information, it determines a path weight for each reachable path and, based on the path weight, determines a quantum key distribution method. Furthermore, it determines a target path from the set of paths. The distribution method and target path are then sent to a source node, causing the source node to split the quantum key based on the distribution method to obtain multiple quantum key segments. The source node then sends each quantum key segment to a destination node based on the target path, causing the destination node to reassemble each quantum key segment upon obtaining the quantum key. In this way, by dynamically evaluating path weights based on the network status information obtained in real time by the quantum key distribution network, the network status can be perceived in real time and routing strategies can be adjusted. This effectively addresses fluctuations in quantum link quality or node resource constraints, enabling quantitative analysis of path security performance and resource efficiency, and improving the robustness and flexibility of the system.

[0031] Moreover, a dual-variable optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve the optimal path and optimal distribution method. This not only solves the problem of total decision-making fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relays and the load pressure of the node key pool, improves the overall resource utilization of the network, and minimizes global resource consumption.

[0032] Furthermore, by adjusting the routing strategy in real time, the risk of single point failure or relay node compromise can be significantly reduced, thereby improving the anti-attack capability of quantum key distribution. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 This is a flowchart of the steps of Embodiment 1 of a quantum key distribution method of the present invention; Figure 2 This is a flowchart of the steps of Embodiment 2 of a quantum key distribution method of the present invention; Figure 3 This is a flowchart of the steps of Embodiment 3 of a quantum key distribution method of the present invention; Figure 4 is a schematic diagram of quantum key distribution of the present invention; Figure 5 This is a structural block diagram of a quantum key distribution device according to a first embodiment of the present invention; Figure 6 This is a block diagram of a quantum key distribution device according to a second embodiment of the present invention; Figure 7 This is a structural block diagram of a third embodiment of a quantum key distribution device of the present invention. DETAILED DESCRIPTION

[0034] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0035] One of the core concepts of the embodiments of the present invention is to dynamically evaluate path weights by acquiring network status information from the quantum key distribution network in real time. This allows for real-time perception of network status and adjustment of routing strategies, effectively addressing fluctuations in quantum link quality or node resource constraints. This enables quantitative analysis of path security performance and resource efficiency, and improves the robustness and flexibility of the system.

[0036] Moreover, a dual-variable optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve the optimal path and optimal distribution method. This not only solves the problem of total decision-making fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relays and the load pressure of the node key pool, improves the overall resource utilization of the network, and minimizes global resource consumption.

[0037] Furthermore, by adjusting the routing strategy in real time, the risk of single point failure or relay node compromise can be significantly reduced, thereby improving the anti-attack capability of quantum key distribution.

[0038] Reference Figure 1 The figure shows a flowchart of the steps in Example 1 of a quantum key distribution method according to the present invention, which is applied to the quantum key distribution network construction (QKDNC). QKDNC is a key functional module in the quantum key distribution network (QKDN), located in the QKDN control layer. It is responsible for managing and controlling the operation of the quantum key distribution network, including routing control, configuration management, policy control, and access control. QKDNC works in conjunction with other functional modules (such as the QKD module in the quantum layer and the key management module in the key management layer) to ensure the secure generation, distribution, and management of quantum keys, supporting efficient and stable quantum secure communication services.

[0039] The method may specifically include the following steps: Step 101: In response to a quantum key distribution request, obtain network state information of a quantum key distribution network, and determine a path set for distributing quantum keys based on the network state information; the path set includes at least one reachable path.

[0040] After receiving the quantum key distribution request sent by the source node, the quantum key distribution network control center can obtain the network status information of the quantum key distribution network at the current moment, and then determine the set of paths (for the convenience of description, referred to as "reachable paths") between the source node and the destination node that can be used to distribute quantum keys (referred to as "path set") based on the network status information. That is, the path set includes at least one reachable path.

[0041] In an embodiment of the present invention, determining a path set for distributing a quantum key based on the network state information includes: Using the network state information to construct a network topology of a quantum distribution network; Calculating at least one reachable path between the source node and the destination node in the network topology using a preset algorithm; Combine all reachable paths to obtain a path set.

[0042] Specifically, after obtaining the network status information at the current moment, the quantum key distribution network control center can use the network status information to construct the network topology of the quantum key distribution network at the current moment. This network topology can clearly show the connection relationship between each node in the quantum key distribution network.

[0043] Then, a preset algorithm is used to calculate all reachable paths between the source node and the destination node, and all reachable paths are combined to obtain a path set.

[0044] It should be noted that when calculating a reachable path, a path search algorithm, such as the Dijkstra algorithm, can be used, or other algorithms can be used. In practical applications, the specific algorithm used to calculate the reachable path can be set according to actual needs, and the embodiment of the present invention does not limit this.

[0045] In an embodiment of the present invention, before obtaining the network status information of the quantum key distribution network, the method further includes: Verifying the legitimacy of the quantum key distribution request; If the verification is successful, the total amount of the quantum key and the destination node are obtained from the quantum key distribution request.

[0046] Specifically, after receiving a quantum key distribution request, the quantum key distribution network control center can verify the legitimacy of the quantum key distribution request. If the verification is successful, the total quantum key quantity and the destination node can be obtained from the quantum key distribution request to facilitate the subsequent transmission process. If the verification fails, the process can be terminated.

[0047] Furthermore, when performing legitimacy verification, user identity, authority and reachability of the destination node can be verified, and other information can also be verified. In actual applications, specific verification information can be set according to actual needs, and the embodiments of the present invention do not limit this.

[0048] Step 102: Determine the path weight of each reachable path based on the network status information.

[0049] After determining the network status information, the weight of each path in the path set (referred to as "path weight") can be calculated using various information in the network status information, so that a path that meets the needs can be determined from the path set based on the path weight.

[0050] In an embodiment of the present invention, determining the path weight of each reachable path based on the network state information includes: Determining network status information of each node in each reachable path from the network status information; Calculate the security score and resource consumption of each reachable path based on the network status information of each node; The path weight of each reachable path is calculated based on the security score and resource consumption of each reachable path.

[0051] Specifically, the network status information of each node in each reachable path can be determined first, and then the security score and resource consumption of each reachable path can be calculated based on the network status information of each node. The security score reflects the security of each reachable path, and the resource consumption reflects the consumption of keys by each reachable path.

[0052] The network status information includes quantum bit error rate, key generation rate, number of path nodes and amount of remaining keys in the key pool; The calculation of the security score and resource consumption of each reachable path based on the network status information of each node includes: Calculating a security score for each node using the quantum bit error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes of each node and the remaining key amount of the key pool.

[0053] Specifically, the network status information may include quantum bit error rate (QBER), key generation rate (R), number of path nodes (N), and the amount of remaining keys in the key pool (S).

[0054] In quantum key distribution (QKD), QBER reflects the error rate of quantum bits during transmission. The higher the bit error rate, the greater the possibility that the link is subject to noise or potential eavesdropping attacks. When the QBER exceeds a certain threshold, the communicating parties can determine that there is a security risk in the link and take measures accordingly.

[0055] The key generation rate R reflects the number of security keys that a node can generate per unit time. A higher key generation rate usually means better link quality and higher security.

[0056] Based on this, when a reachable path with N path nodes is selected for key relay, it can be considered that the security of the reachable path is determined by the path node with the worst security. Then, the security score of the reachable path can be calculated using the following formula:

[0057] in, i Indicates the reachable path i nodes, and It is the weight coefficient, which can be adjusted according to actual needs.

[0058] When the QKD link performs key relay, relaying the key at any node in the link requires consuming key resources. The longer the selected path, that is, the more path nodes N there are, the more key resources it will consume, further reducing the resource utilization of the entire network.

[0059] QKD link nodes generally have a low key generation rate, and the remaining key amount S in the link node key pool and the key amount requirements of each node are also different. Therefore, in order to alleviate the nodes with tight key resources, the embodiment of the present invention introduces a key amount penalty factor to alleviate the nodes with tight resources.

[0060] Based on this, choose a N When the key is relayed using a reachable path with the number of path nodes, assuming that the total amount of quantum key is L , then the resource consumption of the reachable path can be calculated using the following formula:

[0061] in, is the key penalty factor of the path node, which can be adjusted according to the degree of node resource shortage.

[0062] After calculating the security score and resource consumption of each reachable path, the path weight of each reachable path can be calculated using the security score and resource consumption of each reachable path. The path weight reflects the security effectiveness and resource consumption efficiency of the reachable path.

[0063] It should be noted that, in actual applications, the specific method of calculating the path weight using the security score and resource consumption can be set according to actual needs, and the embodiment of the present invention does not limit this.

[0064] Step 103: Determine a distribution method of the quantum key based on the path weight, and determine a target path from the path set.

[0065] After calculating the path weight of each reachable path, and provided that security is met, the quantum key distribution method can be determined with the goal of minimizing the resources of the entire quantum key distribution network, as well as the path used to transmit the quantum key (referred to as the "target path") from the path set.

[0066] In an embodiment of the present invention, determining the quantum key distribution method based on the path weight, and determining the target path from the path set, includes: Constructing an optimization model; the optimization model includes a key distribution variable and a path selection variable; Inputting the path weight of each reachable path into the optimization model; Solving the optimization model using a preset algorithm to obtain an optimal path selection result and an optimal key distribution result; The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method.

[0067] Specifically, define the path selection variable and key distribution variables The path selection variable indicates whether to select the reachable path, and the key distribution variable indicates the quantum key segment assigned to the reachable path accounts for the total key L proportion.

[0068] Path selection variables ,in, P is a set of paths, =1 means select a reachable path p , otherwise 0.

[0069] Key distribution variables , indicating that it is assigned to a reachable path p The quantum key segment accounts for the total key L proportion.

[0070] Using path selection variables and key distribution variables Set the objective function (including the above resource consumption formula):

[0071] in, Any reachable path p The number of hops, Represents a reachable path p The set of all path nodes on .

[0072] And, set the constraints: Key integrity constraints (ensuring the total amount of keys L are all allocated):

[0073] Security Constraints ( is the overall lowest safety score, including the safety scores above):

[0074] Path selection and allocation associated constraints (when reachable paths p Only when selected can the key be assigned to this reachable path):

[0075] Multipath constraints (select at least achievable paths to mitigate risk):

[0076] At this point, the optimization model is built.

[0077] Then, parameters such as the path weight of each reachable path, the number of hops on the reachable path, and the set of all path nodes on the reachable path are input into the optimization model. The optimization model uses the MILP (Mixed Integer Linear Programming) algorithm to solve the optimization model to obtain the optimal path selection result and the optimal key distribution result. The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method to obtain the final distribution plan.

[0078] It should be noted that, in addition to the MILP algorithm, the optimization model can also be solved by other algorithms. In practical applications, the specific algorithm can be set according to actual needs, and the embodiment of the present invention does not limit this.

[0079] Step 104: Send the distribution method and the target path to the source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to the destination node based on the target path, so that the destination node reassembles each of the quantum key segments when obtaining the quantum key segments to obtain the quantum key.

[0080] Specifically, after obtaining the final distribution plan, it can be sent to the source node. After obtaining the distribution plan, the source node uses the distribution method in the distribution plan to split the quantum key into multiple quantum key segments. Since the number of quantum key segments is the same as the number of target paths and there is a one-to-one correspondence between them, each quantum key segment can be sent to the destination node via the corresponding target path.

[0081] Each node in each target path can encrypt the quantum key segment using a one-time pad (OTP). Therefore, each quantum key segment received by the destination node is an encrypted quantum key segment ciphertext. Therefore, the destination node needs to decrypt each quantum key segment ciphertext to obtain the individual quantum key segments. Then, by reassembling the quantum key segments in the correct order, the complete quantum key is obtained.

[0082] Furthermore, between any two adjacent nodes on any target path, the next-hop node shares the key of the current node, but the current node does not share the key of the next-hop node. For example, the target path includes four nodes, A, B, C, and D. B shares A's key with A, C shares B's key with B, and D shares C's key with C. In this way, A encrypts a quantum key segment and sends it to B. B decrypts the quantum key segment using A's key, encrypts the quantum key segment using B's key, and sends it to C. C decrypts the quantum key segment using B's key, encrypts the quantum key segment using C's key, and sends it to D. D decrypts the quantum key segment using C's key.

[0083] In an embodiment of the present invention, a quantum key distribution network control center, in response to a quantum key distribution request, obtains network state information of the quantum key distribution network and, based on the network state information, determines a set of paths for distributing quantum keys. Furthermore, based on the network state information, it determines a path weight for each reachable path and, based on the path weight, determines a distribution method for the quantum key. Furthermore, it determines a target path from the set of paths. The distribution method and the target path are sent to a source node, causing the source node to segment the quantum key based on the distribution method to obtain multiple quantum key segments. The source node then sends each quantum key segment to a destination node based on the target path, causing the destination node to reassemble each quantum key segment upon receiving it to obtain the quantum key. In this way, by dynamically evaluating path weights based on the network state information obtained in real time by the quantum key distribution network, the network state can be perceived in real time and routing strategies can be adjusted. This effectively addresses fluctuations in quantum link quality or node resource constraints, achieves quantitative analysis of path security performance and resource efficiency, and improves the robustness and flexibility of the system.

[0084] Moreover, a dual-variable optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve the optimal path and optimal distribution method. This not only solves the problem of total decision-making fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relays and the load pressure of the node key pool, improves the overall resource utilization of the network, and minimizes global resource consumption.

[0085] Furthermore, by adjusting the routing strategy in real time, the risk of single point failure or relay node compromise can be significantly reduced, thereby improving the anti-attack capability of quantum key distribution.

[0086] Reference Figure 2 , shows a flowchart of the steps of embodiment 2 of a quantum key distribution method of the present invention, which is applied to a source node and may specifically include the following steps: Step 201: Generate a quantum key distribution request in response to a quantum key distribution instruction.

[0087] A client can be installed in the source node, and users can use the client to trigger quantum key distribution instructions. After the source node obtains the quantum key distribution instruction, it can generate a quantum key distribution request.

[0088] Furthermore, in addition to being triggered by users, quantum key distribution instructions can also be triggered by other tasks or third-party clients. In actual applications, the specific method of triggering quantum key distribution requests can be set according to actual needs, and the embodiments of the present invention do not limit this.

[0089] In this embodiment of the present invention, generating a quantum key distribution request includes: Obtaining the total amount of keys and the destination node in the quantum key distribution instruction; A quantum key distribution request is generated using the total key amount and the destination node.

[0090] Specifically, when triggering a quantum key distribution instruction, it is necessary to specify the total key amount and destination node of the transmitted quantum key. Therefore, the total key amount and destination node can be obtained from the quantum key distribution instruction, and the total key amount and destination node can be used to generate a quantum key distribution request.

[0091] Step 202: Send the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node.

[0092] After generating a quantum key distribution request, the source node sends it to the quantum key distribution network control center. In response to the request, the quantum key distribution network control center determines the quantum key distribution method and target path, and returns these to the source node. The specific determination method is detailed in steps 101 through 104 and will not be detailed here.

[0093] Step 203: Acquire the allocation method and the target path.

[0094] Step 204: Split the quantum key based on the distribution method to obtain multiple quantum key segments; the number of the quantum key segments is the same as the number of the target paths.

[0095] Step 205 : Send each quantum key segment to a destination node through a corresponding target path, so that when the destination node obtains each quantum key segment, it reassembles each quantum key segment to obtain the quantum key.

[0096] Specifically, after obtaining the distribution plan, the source node uses the distribution method in the distribution plan to split the quantum key to obtain multiple quantum key segments. Since the number of quantum key segments is the same as the target path and corresponds one to one, each quantum key segment can be sent to the destination node through the corresponding target path.

[0097] Each node in each target path can encrypt the quantum key segment using a one-time pad (OTP). Therefore, each quantum key segment received by the destination node is an encrypted quantum key segment ciphertext. Therefore, the destination node needs to decrypt each quantum key segment ciphertext to obtain the individual quantum key segments. Then, by reassembling the quantum key segments in the correct order, the complete quantum key is obtained.

[0098] Furthermore, among any two adjacent path nodes of any target path, the next-hop path node shares the key of the current path node, but the current path node does not share the key of the next-hop path node.

[0099] In an embodiment of the present invention, a source node generates a quantum key distribution request in response to a quantum key distribution instruction and sends the request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and target path in response to the quantum key distribution request and sends the distribution method and target path to the source node. The source node then obtains the distribution method and target path and, based on the distribution method, splits the quantum key into multiple quantum key segments, the number of which is the same as the number of target paths. The source node then sends each quantum key segment to a destination node via the corresponding target path, so that upon receiving each quantum key segment, the destination node reassembles the quantum key segments to obtain the quantum key. In this way, a dual-variable optimization algorithm for quantum key distribution method and path selection is employed to simultaneously solve the optimal path and optimal distribution method. This not only solves the problem of total decision fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the number of redundant hops in key relays and the load pressure on the node key pool, thereby improving the overall resource utilization of the network and minimizing global resource consumption.

[0100] Furthermore, by adjusting the routing strategy in real time, the risk of single point failure or relay node compromise can be significantly reduced, thereby improving the anti-attack capability of quantum key distribution.

[0101] Reference Figure 3 , shows a flowchart of the steps of embodiment 3 of a quantum key distribution method of the present invention, which is applied to a destination node and may specifically include the following steps: Step 301: Obtain at least one quantum key segment ciphertext.

[0102] Step 302: decrypt each quantum key segment ciphertext to obtain at least one quantum key segment.

[0103] After the destination node obtains each quantum key segment ciphertext through each target path, it can use the key corresponding to each quantum key segment ciphertext to decrypt it, thereby obtaining each quantum key segment.

[0104] In an embodiment of the present invention, decrypting each quantum key segment ciphertext to obtain at least one quantum key segment includes: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key of each previous hop node; Each shared key is used to decrypt the corresponding quantum key segment ciphertext.

[0105] Specifically, each node in each target path can encrypt the quantum key segment using a one-time pad (OTP). Therefore, each quantum key segment received by the destination node is an encrypted quantum key segment ciphertext. Therefore, the destination node needs to decrypt each quantum key segment ciphertext to obtain the individual quantum key segments. Then, by reassembling the quantum key segments in the correct order, the complete quantum key is obtained.

[0106] Furthermore, for any two adjacent nodes on any target path, the next-hop node shares the key of the current node, but the current node does not share the key of the next-hop node. Based on this, the destination node can determine the previous-hop node corresponding to each quantum key segment ciphertext, and thus determine the key of each previous-hop node (referred to as the "shared key"). It then uses each shared key to decrypt each quantum key segment ciphertext to obtain the individual quantum key segments.

[0107] It should be noted that the specific method for determining the target path and the allocation method is detailed in steps 101 to 104, which will not be repeated here.

[0108] Step 303: reorganize the quantum key segments to obtain the quantum key.

[0109] After obtaining each quantum key segment, the destination node reorganizes the quantum key segments in the correct order to obtain the complete quantum key.

[0110] In an embodiment of the present invention, the following further comprises: verifying the quantum key; If the verification fails, an alarm message is generated.

[0111] Specifically, after obtaining the complete quantum key, the destination node can perform integrity check and security verification on the quantum key to ensure that the quantum key has not been tampered with or leaked during transmission.

[0112] If the verification passes, the quantum key can be used to execute subsequent processes; if the verification fails, an alarm message can be generated.

[0113] It should be noted that when performing integrity check and security verification on quantum keys, the specific verification method can be set according to actual needs, and the embodiments of the present invention do not limit this.

[0114] In this embodiment of the present invention, the destination node obtains at least one quantum key segment ciphertext via each target path, decrypts each quantum key segment ciphertext to obtain at least one quantum key segment, and then reassembles each quantum key segment to obtain the quantum key. Each target path is determined in real time by the quantum key distribution network control center based on the network status information of the quantum key distribution network. This allows for dynamic evaluation of path weights based on the network status information obtained in real time from the quantum key distribution network, enabling real-time perception of network status and adjustment of routing strategies. This effectively addresses fluctuations in quantum link quality or node resource constraints, enabling quantitative analysis of path security performance and resource efficiency, and improving the robustness and flexibility of the system.

[0115] Furthermore, by adjusting the routing strategy in real time, the risk of single point failure or relay node compromise can be significantly reduced, thereby improving the anti-attack capability of quantum key distribution.

[0116] To facilitate understanding, the complete process of an embodiment of the present invention is described below by way of example.

[0117] (1) User initiates a request: The user sends a key transfer request to the Quantum Key Distribution Network Control Center (QKDNC) through the client in the source node, clearly specifying the total amount of key L to be transferred and the destination node.

[0118] (2) System verification request: After receiving the request, QKDNC verifies the legitimacy of the request, including verifying the user identity, authority, and reachability of the destination node.

[0119] (3) Determine the key requirements: After verification, QKDNC determines that the total amount of quantum key to be transmitted this time is L, and prepares to start the subsequent transmission process.

[0120] (4) Obtaining network status information: QKDNC sends status query instructions to each node in the quantum key distribution network to collect network status information including parameters such as quantum bit error rate (QBER), key generation rate R, number of path nodes N, and the remaining key amount S in the key pool.

[0121] (5) Construct a network topology diagram: Based on the collected network status information, construct a topology diagram of the current quantum key distribution network to clearly show the relationship between the connections of each node.

[0122] (6) Calculate the reachable path set: Based on the constructed network topology graph, use the path search algorithm (such as Dijkstra algorithm, etc.) to calculate all reachable paths from the source node to the destination node, and form these reachable paths into the path set P.

[0123] (7) Collect and analyze security node information: For each reachable path in the path set P, collect the QBER and key generation rate R of each node on the reachable path; calculate the security score of each reachable path based on the quantum link security calculation model, where QBER reflects the possibility of the link being attacked by noise or potential eavesdropping, and the key generation rate R reflects the quality and security of the link.

[0124] (8) Collect and analyze node resource information: collect the link hop count N and the remaining key amount S of the key pool of each node on each reachable path; calculate the resource consumption of each reachable path based on the quantum link resource calculation model, considering the impact of the link hop count N on the key relay resource consumption and the role of the node key amount penalty factor in alleviating resource-constrained nodes.

[0125] (9) Comprehensive calculation of path weight: Combining the quantum link security calculation model and the quantum link resource calculation model, a comprehensive weight is calculated for each reachable path. This weight reflects the security effectiveness and resource consumption efficiency of the reachable path.

[0126] (10) Construct an optimization model: Define path selection variables and key distribution variables. The path selection variable indicates whether a certain reachable path is selected, and the key distribution variable indicates the proportion of the key quantity allocated to the reachable path to the total key quantity L. Set the objective function, that is, to minimize the resource consumption of the entire quantum distribution network while satisfying security constraints and key integrity constraints. Determine the constraints, including key integrity constraints, security constraints, path selection and distribution association constraints, and multipath constraints.

[0127] (11) Input parameters to the model: Input parameters such as the weight of each reachable path, the number of link hops, and the node set into the constructed optimization model.

[0128] (12) Solving the optimization model: Use the mixed integer linear programming (MILP) algorithm to solve the optimization model and obtain the optimal path selection and key distribution results.

[0129] (13) Generate optimization results: Based on the optimal solution obtained, generate a specific plan including the reachable path to the selected target and the corresponding key distribution ratio, and send the plan to the source node.

[0130] (14) The source node prepares to distribute the key: After receiving the path selection result and the key distribution result, the source node divides the total quantum key Q of L into multiple sub-key segments according to the distribution ratio. The length of each sub-key segment is determined according to the distribution ratio of the corresponding path.

[0131] (15) The source node distributes the key through the optimization result: the source node distributes each sub-key segment according to the path selection result (i.e., the target path).

[0132] (16) Relay node encryption and forwarding: After receiving the sub-key segment, the relay node on each path uses the locally generated quantum key to encrypt the quantum key segment using a one-time pad (OTP) encryption method. The relay node forwards the encrypted quantum key segment to the next node until the quantum key segment safely reaches the destination node.

[0133] (17) Destination node receives the key: The destination node receives the quantum key segment ciphertext from different target paths through the quantum key network.

[0134] (18) Decrypting the quantum key segment ciphertext: The destination node uses the quantum key shared with the relay node to decrypt the received quantum key segment ciphertext and restore the original quantum key segment.

[0135] (19) Recombination of key: The destination node recombines all decrypted quantum key segments in the correct order to obtain the complete quantum key Q.

[0136] (20) Verify the integrity and security of the key: Perform integrity check and security verification on the reorganized quantum key Q to ensure that the key has not been tampered with or leaked during transmission.

[0137] further, Figure 4 A schematic diagram of quantum key distribution (QKD) is shown. A source node sends a QKD request to a quantum key distribution network control center. The QKD control center determines the target path and distribution method and sends them to the source node. The source node then splits the quantum key Q into quantum key segments, K1, K2, …, Kn, according to the distribution method. Each of these segments is then sent to the destination node via each target path. Ki, Kj, …, Km are the shared keys used to encrypt and decrypt the quantum key segments in each target path. After the destination node receives the ciphertext of each quantum key segment via each target path, it decrypts each segment using the shared key of the previous node, obtaining K1, K2, …, Kn. K1, K2, …, Kn are then reassembled in sequence to obtain the quantum key Q.

[0138] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0139] Reference Figure 5 , shows a block diagram of a quantum key distribution device according to a first embodiment of the present invention, which is applied to a quantum key distribution network control center and may specifically include the following modules: A first acquisition module 501 is configured to obtain network status information of a quantum key distribution network in response to a quantum key distribution request; A first computing module 502 is configured to determine a path set for distributing a quantum key based on the network state information; the path set includes at least one reachable path; A second calculation module 503 is used to determine the path weight of each reachable path based on the network state information; a third calculation module 504, configured to determine a distribution mode of the quantum key based on the path weight, and to determine a target path from the path set; The first sending module 505 is configured to send the distribution method and the target path to a source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to a destination node based on the target path, so that the destination node reassembles each of the quantum key segments to obtain the quantum key when obtaining the quantum key segments.

[0140] In this embodiment of the present invention, the first calculation module is specifically configured to: Using the network state information to construct a network topology of a quantum distribution network; Calculating at least one reachable path between the source node and the destination node in the network topology using a preset algorithm; Combine all reachable paths to obtain a path set.

[0141] In an embodiment of the present invention, the following further comprises: A first verification module is configured to verify the legitimacy of the quantum key distribution request before obtaining the network status information of the quantum key distribution network; An extraction module is configured to obtain the total amount of the quantum key and the destination node from the quantum key distribution request if the verification is successful.

[0142] In this embodiment of the present invention, the second calculation module includes: a determination submodule, configured to determine the network status information of each node in each reachable path from the network status information; A first calculation submodule is used to calculate the security score and resource consumption of each reachable path based on the network status information of each node; The second calculation submodule is configured to calculate a path weight of each reachable path based on the security score and resource consumption of each reachable path.

[0143] In an embodiment of the present invention, the network status information includes quantum bit error rate, key generation rate, number of path nodes and amount of remaining keys in the key pool; The first calculation submodule is specifically configured to: Calculating a security score for each node using the quantum bit error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes of each node and the remaining key amount of the key pool.

[0144] In this embodiment of the present invention, the third calculation module is specifically configured to: Constructing an optimization model; the optimization model includes a key distribution variable and a path selection variable; Inputting the path weight of each reachable path into the optimization model; Solving the optimization model using a preset algorithm to obtain an optimal path selection result and an optimal key distribution result; The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method.

[0145] Reference Figure 6 , shows a block diagram of a second embodiment of a quantum key distribution device according to the present invention, which is applied to a source node and may specifically include the following modules: A first generating module 601 is configured to generate a quantum key distribution request in response to a quantum key distribution instruction; a second sending module 602, configured to send the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node; A second acquisition module 603 is used to acquire the allocation method and the target path; a splitting module 604, configured to split the quantum key based on the distribution method to obtain a plurality of quantum key segments; the number of the quantum key segments is the same as the number of the target paths; The third sending module 605 is configured to send each quantum key segment to a destination node via a corresponding target path, so that when the destination node obtains each quantum key segment, it reassembles the quantum key segments to obtain the quantum key.

[0146] In the embodiment of the present invention, the generating module is specifically configured to: Obtaining the total amount of keys and the destination node in the quantum key distribution instruction; A quantum key distribution request is generated using the total key amount and the destination node.

[0147] Reference Figure 7 , shows a block diagram of a third embodiment of a quantum key distribution device according to the present invention, which is applied to a destination node and may specifically include the following modules: A third acquisition module 701 is configured to acquire at least one quantum key segment ciphertext; A decryption module 702 is configured to decrypt each quantum key segment ciphertext to obtain at least one quantum key segment; The recombining module 703 is used to recombine the various quantum key segments to obtain the quantum key.

[0148] In an embodiment of the present invention, the decryption module is specifically configured to: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key of each previous hop node; Each shared key is used to decrypt the corresponding quantum key segment ciphertext to obtain each quantum key segment.

[0149] In an embodiment of the present invention, the following further comprises: A second verification module, configured to verify the quantum key; The second generating module is used to generate an alarm message if the verification fails.

[0150] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0151] An embodiment of the present invention further provides an electronic device, including: The system includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned quantum key distribution method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0152] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned quantum key distribution method embodiment are implemented and the same technical effects can be achieved. To avoid repetition, they will not be described here.

[0153] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0154] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatuses, or computer program products. Thus, embodiments of the present invention may take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.

[0155] The embodiments of the present invention are described with reference to flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0156] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0157] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0158] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0159] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0160] The above is a detailed introduction to a quantum key distribution method and a quantum key distribution device provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only intended to help understand the method and core concept of the present invention. At the same time, for those skilled in the art, according to the concept of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A quantum key distribution method, characterized in that: Applied to a quantum key distribution network control center, the method includes: In response to a quantum key distribution request, obtaining network state information of a quantum key distribution network, and determining a path set for distributing the quantum key based on the network state information; the path set includes at least one reachable path; determining a path weight of each reachable path based on the network state information; determining a distribution mode of the quantum key based on the path weight, and determining a target path from the path set; The distribution method and the target path are sent to a source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to a destination node based on the target path, so that the destination node reassembles each of the quantum key segments to obtain the quantum key when obtaining the quantum key segments.

2. The quantum key distribution method according to claim 1, characterized in that: The determining, based on the network state information, a path set for distributing the quantum key, comprises: Using the network state information to construct a network topology of a quantum distribution network; Calculating at least one reachable path between the source node and the destination node in the network topology using a preset algorithm; Combine all reachable paths to obtain a path set.

3. The quantum key distribution method according to claim 1, characterized in that Before obtaining the network status information of the quantum key distribution network, the method further includes: Verifying the legitimacy of the quantum key distribution request; If the verification is successful, the total amount of the quantum key and the destination node are obtained from the quantum key distribution request.

4. The quantum key distribution method according to claim 1, wherein: The determining the path weight of each reachable path based on the network state information includes: Determining network status information of each node in each reachable path from the network status information; Calculate the security score and resource consumption of each reachable path based on the network status information of each node; The path weight of each reachable path is calculated based on the security score and resource consumption of each reachable path.

5. The quantum key distribution method according to claim 4, characterized in that: The network status information includes quantum bit error rate, key generation rate, number of path nodes and amount of remaining keys in the key pool; The calculation of the security score and resource consumption of each reachable path based on the network status information of each node includes: Calculating a security score for each node using the quantum bit error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes of each node and the remaining key amount of the key pool.

6. The quantum key distribution method according to claim 1, characterized in that: Determining the quantum key distribution method based on the path weight, and determining the target path from the path set, includes: Constructing an optimization model; the optimization model includes a key distribution variable and a path selection variable; Inputting the path weight of each reachable path into the optimization model; Solving the optimization model using a preset algorithm to obtain an optimal path selection result and an optimal key distribution result; The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method.

7. A quantum key distribution method, characterized in that: Applied to a source node, the method includes: generating a quantum key distribution request in response to the quantum key distribution instruction; sending the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node; Obtaining the allocation method and the target path; Splitting the quantum key based on the distribution method to obtain a plurality of quantum key segments; the number of the quantum key segments is the same as the number of the target paths; Each quantum key segment is sent to a destination node through a corresponding target path, so that when the destination node obtains each quantum key segment, it recombines each quantum key segment to obtain the quantum key.

8. The quantum key distribution method according to claim 7, characterized in that: Generating a quantum key distribution request includes: Obtaining the total amount of keys and the destination node in the quantum key distribution instruction; A quantum key distribution request is generated using the total key amount and the destination node.

9. A quantum key distribution method, characterized in that: Applied to the destination node, the method includes: Obtaining at least one quantum key segment ciphertext; Decrypting each quantum key segment ciphertext to obtain at least one quantum key segment; The individual quantum key segments are recombined to obtain the quantum key.

10. The quantum key distribution method according to claim 9, characterized in that: Decrypting each quantum key segment ciphertext to obtain at least one quantum key segment includes: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key of each previous hop node; Each shared key is used to decrypt the corresponding quantum key segment ciphertext to obtain each quantum key segment.

11. The quantum key distribution method according to claim 9, characterized in that: Also includes: verifying the quantum key; If the verification fails, an alarm message is generated.

12. A quantum key distribution device, characterized in that: Applied to a quantum key distribution network control center, the device includes: A first acquisition module is configured to acquire network status information of a quantum key distribution network in response to a quantum key distribution request; A first computing module is configured to determine a path set for distributing a quantum key based on the network state information; the path set includes at least one reachable path; a second calculation module, configured to determine a path weight of each reachable path based on the network state information; a third computing module, configured to determine a distribution mode of the quantum key based on the path weight, and to determine a target path from the path set; a first sending module, configured to send the distribution method and the target path to a source node, so that the source node divides the quantum key based on the distribution method to obtain multiple quantum key segments, and sends each of the quantum key segments to a destination node based on the target path, so that the destination node reassembles each of the quantum key segments to obtain the quantum key when obtaining the quantum key segments.

13. A quantum key distribution device, characterized in that: Applied to a source node, the device includes: A first generating module is configured to generate a quantum key distribution request in response to a quantum key distribution instruction; a second sending module, configured to send the quantum key distribution request to a quantum key distribution network control center, so that the quantum key distribution network control center determines a quantum key distribution method and a target path in response to the quantum key distribution request, and sends the distribution method and the target path to the source node; A second acquisition module, configured to acquire the allocation method and the target path; a splitting module, configured to split the quantum key based on the distribution method to obtain a plurality of quantum key segments, wherein the number of the quantum key segments is the same as the number of the target paths; The third sending module is used to send each quantum key segment to a destination node through a corresponding target path, so that when the destination node obtains each quantum key segment, it reassembles each quantum key segment to obtain the quantum key.

14. A quantum key distribution device, characterized in that: Applied to a destination node, the device comprises: A third acquisition module is used to obtain at least one quantum key segment ciphertext; A decryption module, configured to decrypt each quantum key segment ciphertext to obtain at least one quantum key segment; The recombining module is used to recombine the various quantum key segments to obtain the quantum key.

15. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the quantum key distribution method according to any one of claims 1 to 6, 7 to 8, or 9 to 11 are implemented.

16. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the quantum key distribution method according to any one of claims 1 to 6 or 7 to 8 or 9 to 11 are implemented.

Citation Information

Patent Citations

  • Model and method for realizing request control and automatic implementation of quantum key distribution (QKD)

    CN102130769A

  • Quantum key distribution method and device

    CN111404672A

  • Quantum key distribution relay path determination method, device and system and medium

    CN119341739A

  • Routing method suitable for quantum key distribution network and related equipment

    CN119766451A

  • Quantum key distribution apparatus and method

    WO2020125967A1

Cited By

  • Quantum key distribution system and system-based quantum key distribution method

    CN121418096A

  • Terminal network security situation awareness system and method based on quantum key distribution

    CN121508810A