Switch secure communication encryption method based on quantum key distribution
Through quantum key distribution technology, using the Q-IDL description language and AI self-healing mechanism, quantum keys are generated and managed, solving the problem that traditional encryption systems cannot meet the needs of high-frequency transactions and multi-node switching architectures, and achieving low-latency, efficient end-to-end encryption and automated management.
Patent Information
- Application Number
- CN202511006169.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-10-03
AI Technical Summary
In existing technologies, traditional encryption systems cannot meet the requirements of high-frequency trading and supercomputing centers for microsecond-level updates of "one-time password". Quantum key distribution (QKD) in multi-node, high-concurrency exchange architectures has a mismatch between key generation rate and throughput, large fluctuations in bit error rate and lack of self-healing mechanism, making it difficult to achieve end-to-end zero-trust management and control. In addition, device stacking leads to a surge in power consumption, making it difficult to achieve automated orchestration and cloud-native management.
Submit security requirements through the Quantum Intent Description Language (Q-IDL), evaluate the quality of fiber-optic quantum channels and classical ultra-high-speed channels, generate root quantum keys and inject them into on-chip quantum memory, use HMAC-SHA3 to derive session keys, continuously monitor channel bit error rates, achieve second-level audit and forensics, combine AI anomaly scores and graph neural networks for self-healing, and use quantum immutable ledgers and blockchains to anchor key lifecycle events.
It achieves microsecond-level updates of quantum keys, end-to-end encryption delay of less than 7 microseconds, throughput loss of less than 2.1%, automatic switching of bit error rates, meets regulatory requirements for second-level evidence collection, and realizes automated management of "security policy as code".
Smart Images

Figure CN120750601A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum communication technology, and in particular to a switch secure communication encryption method based on quantum key distribution. Background Art
[0002] As data centers, financial transaction networks, and government private networks continue to increase their requirements for information security, traditional encryption systems based on mathematical assumptions (such as RSA, AES, and ECC) are facing unprecedented challenges:
[0003] The introduction and continuous optimization of Shor's algorithm and Grover's algorithm have made the time complexity of large integer decomposition and symmetric key exhaustiveness decrease exponentially; traditional switches generally adopt two modes: "long-term fixed key + manual rotation" or "software-level DH / ECDH session key". The former has a long key life cycle, and once leaked, historical data can be traced back; the latter is limited by CPU performance, and the key update delay is usually in the hundreds of microseconds to milliseconds, which cannot meet the stringent requirements of high-frequency trading, supercomputing centers and other businesses for "one-time one-key" microsecond updates; although QKD can theoretically achieve information-theoretic security, there are three major bottlenecks in existing commercial deployments: mainly point-to-point links, which are difficult to adapt to multi-node and high-concurrency switching architectures, the key generation rate (typically 2-10Mbps) is seriously mismatched with the switch's T-bit throughput, the quantum channel is affected by optical fiber loss, ambient temperature, vibration, etc., the bit error rate fluctuates greatly, and there is a lack of automatic switching and self-healing mechanisms. , resulting in a high risk of business interruption; most of the existing switch security solutions remain at the "link-level encryption" level, lacking end-to-end zero-trust management of "user-application-data"; at the same time, key lifecycle events are scattered in the logs of various devices, making it difficult to meet the compliance requirements of regulations such as the "Regulations on the Security Protection of Critical Information Infrastructure", "PCI-DSS", and "GDPR" for "second-level evidence collection, non-tamperability, and full traceability"; the traditional "QKD box + switch + firewall" multi-level cascade solution leads to device stacking and a surge in power consumption, and requires professionals to maintain the quantum layer, network layer, and security layer respectively, making it difficult to achieve automated orchestration and cloud-native management. Summary of the Invention
[0004] In order to solve the above-mentioned technical problems, the present invention provides a switch secure communication encryption method based on quantum key distribution.
[0005] The technical solution of the present invention is achieved as follows:
[0006] A switch secure communication encryption method based on quantum key distribution, characterized by comprising the following steps:
[0007] S1: The business party submits the "security-latency-bandwidth" intent to the Zero Trust Brain through the Quantum Intent Description Language (Q-IDL);
[0008] S2: Evaluate the real-time quality, key margin, and topological accessibility of fiber quantum channels, classical ultra-high-speed channels, and radio frequency spatial channels based on intended requirements;
[0009] S3: Triggering the QKD transmitter and receiver along the optimal quantum path to transmit polarization- and OAM-encoded quantum states, completing basis vector alignment, error correction, and privacy amplification, generating the root quantum key K_root and injecting it into the on-chip quantum memory;
[0010] S4: When the data packet arrives at the switch port, the pipeline takes K_root from the primary key pool and derives the one-time session key K_sess through HMAC-SHA3;
[0011] S5: Continuously monitor the quantum channel bit error rate, key pool margin, and AI anomaly score;
[0012] S6: The sender and receiver simultaneously confirm the destruction of the session key through "two handshakes + one hash challenge", write all key lifecycle events into the quantum immutable ledger (Q-Ledger), anchor it with the blockchain hash, and achieve audit and evidence collection in seconds.
[0013] Preferably, the step S1 further comprises:
[0014] S101: The business party submits the Q-IDL description file through REST, CLI, or Portal.
[0015] S102: The Zero Trust Brain performs syntax, policy conflict, and compliance checks on the Q-IDL;
[0016] S103: Quantify the natural language indicators into measurable KPIs. The end-to-end latency formula is:
[0017] L_total=L_qkd+L_classical+L_switch+L_crypto, where L_total≤L_max=5ms;
[0018] Key consumption rate formula:
[0019] R_key = α·B_min, where α is determined by the encryption algorithm. For AES-256-GCM, α is ≈ 1.05×10 -5 bit / bit;
[0020] S104: Query real-time network topology, channel quality, and available computing power through KCR-Orchestrator;
[0021] S105: The solver outputs the optimal path and resource allocation with the goal of "minimum delay + minimum key gap + minimum number of hops";
[0022] S106: If multiple attempts are made to seize the same quantum link simultaneously, the system will arbitrate based on security level, service priority, and time slice.
[0023] S107: Generate and distribute Kubernetes CRD, and finally generate the orchestration object QuantumSl ice, which is pushed to the switch cluster through the GitOps pipeline to complete intent registration and policy orchestration.
[0024] Preferably, the step S2 further includes:
[0025] S201: Periodically initiate a lightweight detection to all candidate channels;
[0026] S202: Mapping the original physical quantity into an available coefficient A(e) between 0 and 1;
[0027] S203: Subtract the service required key rate R_key given in step S103 from the current channel coding rate;
[0028] S204: Add up the quantum, classical, exchange, and encryption / decryption delays of each candidate path and compare with the SLA upper limit L_max in step S103;
[0029] S205: For each active link, automatically search for 1-N backup links that can quickly take over, calculate the KPIs after the takeover, and rank them using the formula: Priority = α·A(e)–β·ΔL–γ·ΔR;
[0030] S206: Dynamically generate a trigger threshold based on the "availability coefficient + supply-demand gap" and write it into the switch register;
[0031] S207: Package all results into JSON and push them to the zero-trust brain and local switch agent via gRPC. After receiving the results, the agent writes the threshold into the local register and sends an ACK.
[0032] Preferably, the step 3 further comprises:
[0033] S301: A QKD-Mesh is formed, where each switch and its corresponding QKD module is considered a QKD node. A unified trusted CA issues a public-private key pair and a domain server certificate for each node, and the node certificate is pre-installed in the PUF security zone of the switch π-SoC.
[0034] S302: The source switch broadcasts its QKD capability vector QV = {λ_qkd, R_max, BER_min} via LLDP-Q (Quantum LLDP). The peer switch that receives the broadcast writes the reachable nodes into the local QKD-ARP table.
[0035] S303: Source node A generates a random number r_A and a timestamp t_A, and constructs a request message M_req = SM2Encrypt(PK_B, r_A||t_A);
[0036] Calculate the signature of SM3(r_A||t_A) σ_A=SM2Sign(SK_A,M_req);
[0037] Send {M_req,σ_A} to peer B via the classic channel UDP / 8472;
[0038] S304: Node B decrypts M_req using SK_B and verifies σ_A;
[0039] Generate r_B and construct a response message M_resp = SM2Encrypt(PK_A, r_B||t_B||Hash(r_A));
[0040] Calculate signature σ_B = SM2Sign(SK_B, M_resp);
[0041] Echo {M_resp,σ_B};
[0042] Both parties complete bidirectional identity authentication and share the random seed r = r_A ⊕ r_B;
[0043] S305: Generate synchronization parameters based on the seed r: laser pulse period Δτ, basis vector selection table B(r);
[0044] The QKD modules of both parties enter the synchronization window at the same time:
[0045] Δτ_sync=2×RTT_classical+100ns;
[0046] S306: Select the decoy state strength {μ1, μ2, μ3} according to the real-time BER:
[0047] When BER < 1%, the decoy state strength is selected as {0, 0.2, 0.6};
[0048] When 1%≤BER<4%, the decoy state strength is selected as {0, 0.25, 0.75};
[0049] Sending a calibration frame through the OAM channel:
[0050] TuningFrame={μ_set,Δτ_sync,FEC_code=LDPC(64800)};
[0051] S307: Both parties send N=2×10 consecutively 7 photon pulses;
[0052] After basis vector alignment, we get the sifted key K_sift≈N(1-2BER) / 2;
[0053] Privacy amplification with Toeplitz Hash:
[0054] K_priv=Ext(K_sift,seed_priv);
[0055] |K_priv|=n_priv=n_sift·(1-H(2p))-log2(1 / ε_sec);
[0056] S308: K_priv is directly written into the on-chip quantum storage SRAM-QL1 of the π-SoC via a dedicated SerDes interface;
[0057] Once the write is complete, the flag "QL1_ready=1" is set for subsequent key derivation pipeline reading;
[0058] S309: Report via QKD-BFD (Bidirectional Forwarding Detection) message every 100ms:
[0059] Health={BER_life,QBER,KeyRate,L_path};
[0060] Once any indicator of Health exceeds the preset threshold in step S2, multi-dimensional elastic switching is immediately triggered.
[0061] Preferably, the step S4 further comprises:
[0062] S401: After receiving the data packet arrival interrupt, the encryption engine takes out a 256-bit quantum root key from the primary key pool (SRAM-QL1) of the π-SoC according to the FIFO;
[0063] Hardware guarantees atomicity, that is, only one port is allowed to access the same K_root in the same clock cycle;
[0064] S402: Use HKDF-SHA3-256 to derive the port-level session key from K_root and the dynamic nonce:
[0065] K_sess = HKDF(K_root, nonce||port_id||vlan||t_now, 256), where nonce is taken from the switch ASIC's embedded quantum true random number generator (QRNG) and is updated for each packet.
[0066] S403: Use K_root to perform another one-time packaging on K_sess to form a quantum envelope:
[0067] Env=AES-256-GCM(K_root,IV=nonce,AAD=Header,PT=K_sess);
[0068] The envelope is sent along with the data packet header for the peer to depacketize;
[0069] S404: Use K_sess+AES-256-CTR to encrypt the service payload P:
[0070] Ciphertext=AES-256-CTR(K_sess,Counter=seq_num)⊕P;
[0071] The encryption engine works in zero-copy DMA mode with a latency of less than 0.1μs;
[0072] S405: Compare the lifecycle tag of the current K_sess with the policy slice generated in step S1:
[0073] If (t_now>ExpireTime), discard and re-obtain a new K_root;
[0074] S406: Within 2 clock cycles (≈15ns) after the data packet is sent through the classic channel, the ASIC automatically triggers the clear circuit;
[0075] At the same time, the reference counter of the used K_root is reduced by 1; when the counter returns to zero, it is recycled to the queue for privacy amplification;
[0076] S407: After receiving the packet header, the peer switch uses the local K_root to decrypt the envelope, restore the K_sess, and decrypt the payload with the K_sess. It then uses the GCM Tag for integrity verification.
[0077] S408: Write "encryption delay + packet loss + anomaly count" into QKD-BFD Telemetry:
[0078] Metric={port_id,enc_latency_ns,drop_cnt,err_cnt};
[0079] When err_cnt>0, it will be reported to the Zero Trust Brain immediately. When enc_latency>15μs, it will be reported to the Zero Trust Brain immediately to trigger adaptive elasticity.
[0080] Preferably, the step S5 further comprises:
[0081] S501: collect a set of four-tuples every 100ms;
[0082] S502: Set a dynamic threshold for each dimension: Th_i(t). If any dimension exceeds the threshold, set the alarm vector Alert[i] = 1;
[0083] S503: Calculate the comprehensive risk score:
[0084] RiskScore=Σw_i·Alert[i]·Severity_i;
[0085] w={0.35, 0.2, 0.3, 0.15} corresponding to Q, C, K, A respectively;
[0086] S504: Locating the minimum cut set using graph neural network (GNN):
[0087] G = (V, E), edge weight w_e = 1-A_e;
[0088] Output suspected fault edge list FaultEdges;
[0089] S505: Calculate K=3 shortest paths in the virtual topology using the KSP-K algorithm;
[0090] Calculate the modulation factor w_mod for each path:
[0091] w_mod=(Hops+α·Latency) / Avai lBW;
[0092] Take the path with the smallest w_mod as the new main path;
[0093] S506: When the end-to-end KeyRate is insufficient, Dijkstra is called to find the key relay chain:
[0094] Cost(e)=1 / KeyRate_e+γ·Loss_e;
[0095] Generate a new key relay queue RelayPath;
[0096] S507: The Zero Trust Brain packages the new path, new key relay, and new algorithm into a CRD through gRPC;
[0097] S508: Self-healing action execution: After receiving the patch, the switch agent switches to the classic routing table (SR-v6), renegotiates the quantum key, and then hot-loads the Kyber768 instructions to the π-SoC;
[0098] S509: Within 50ms after self-healing, the four-dimensional indicators are sampled again. If RiskScore < 0.1, it is marked as "recovered". Otherwise, a new round of self-healing cycle is triggered. The self-healing cycle can be repeated up to 3 times.
[0099] Preferably, the step S6 further includes:
[0100] S601: Session key instant erase: After the data packet is sent, the ASIC triggers the hardware clear circuit within 2 clock cycles and performs a row-level write of 0x00…00 to the port-level SRAM-Ksess;
[0101] Clear width = 256 bits, meeting the NIST SP 800-88 "single-pass" requirement. The formula is:
[0102]
[0103] S602: Each time K_root is used up, atomically decrement the reference counter RefCnt(K_root);
[0104] When RefCnt=0 and the global time window T_ttl expires, the secondary erase is triggered;
[0105] S603: Quantum memory deep erase: The on-chip rare-earth doped waveguide quantum memory starts the 3-pass DoD 5220.22-M algorithm 1 minute after the key expires;
[0106] S604: Double-end key consistency confirmation: The sender and receiver each send a Hash Chal length to confirm that both parties have destroyed the session key at the same time. Specifically, an abnormal alarm is triggered when H_local ≠ H_peer. An abnormal alarm is triggered when either party times out for 100 μs.
[0107] S605: Generate key event record E = {event_id, port, K_sess_id, destroyed_ts, hash_proof};
[0108] Calculate the signature of E using the SM2 private key:
[0109] σ=SM2Sign(SK_node,SHA3-256(E));
[0110] S606: Use {E,σ} as transaction Tx and generate a 256-bit random seed r_beacon through the quantum random beacon;
[0111] Calculate the ledger hash:
[0112] block_hash=SHA3-256(prev_hash||Tx||r_beacon);
[0113] Use threshold BLS signature to anchor block_hash to the consortium chain to ensure forward tamper-proof;
[0114] S607: Compliance audit retrieval and certification: The regulator queries through the REST API, and then the regulator verifies locally.
[0115] The beneficial effects of the present invention are:
[0116] 1. This invention solders the quantum key directly into the switch chip and uses a one-time pad to individually lock each service flow. Even if a quantum cracker were to emerge in the future, it would only be able to crack one key, and it would be impossible to reconstruct the entire historical data.
[0117] 2. This invention uses chip-level direct connection to reduce key update latency to less than 7 microseconds. At 400Gb / s financial market traffic, the throughput loss caused by encryption is less than 2.1%, and users hardly notice any lag.
[0118] 3. This invention simultaneously maintains three "escape channels": fiber quantum, classical ultra-high-speed, and radio frequency free space. Once the AI detects an indicator exceeding the standard, it automatically switches channels within 10 milliseconds, ensuring that no frames of business video or trading information are lost.
[0119] 4. When using this invention, the phrase "financial dedicated line delay <5ms, leakage <10 -18 The system translates the natural language description of the resource into a Kubernetes resource list, automatically finding the optimal link, optimal computing power, and optimal key slice, thus realizing "security policy as code";
[0120] 5. Every time a key is generated and destroyed, it will be written into the "quantum immutable ledger" and anchored with the blockchain; if regulatory authorities need to audit, 30-day key events can be retrieved within 1 second, meeting regulatory requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0121] Figure 1 This is a schematic diagram of the workflow of a switch secure communication encryption method based on quantum key distribution in the present invention. DETAILED DESCRIPTION
[0122] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0123] like Figure 1 As shown, the present invention provides a switch secure communication encryption method based on quantum key distribution, comprising the following steps:
[0124] S1: The business party submits the "security-latency-bandwidth" intent to the Zero Trust Brain through the Quantum Intent Description Language (Q-IDL);
[0125] S2: Evaluate the real-time quality, key margin, and topological accessibility of fiber quantum channels, classical ultra-high-speed channels, and radio frequency spatial channels based on intended requirements;
[0126] S3: Triggering the QKD transmitter and receiver along the optimal quantum path to transmit polarization- and OAM-encoded quantum states, completing basis vector alignment, error correction, and privacy amplification, generating the root quantum key K_root and injecting it into the on-chip quantum memory;
[0127] S4: When the data packet arrives at the switch port, the pipeline takes K_root from the primary key pool and derives the one-time session key K_sess through HMAC-SHA3;
[0128] S5: Continuously monitor the quantum channel bit error rate, key pool margin, and AI anomaly score;
[0129] S6: The sender and receiver simultaneously confirm the destruction of the session key through "two handshakes + one hash challenge", write all key lifecycle events into the quantum immutable ledger (Q-Ledger), anchor it with the blockchain hash, and achieve audit and evidence collection in seconds.
[0130] Furthermore, the step S1 further includes:
[0131] S101: The business side submits a Q-IDL description file through REST, CLI, or Portal. The business side writes the security requirements into a Q-IDL file, which is equivalent to giving the system a "five-tuple". The formula is:
[0132] I=<Src,Dst,L_max,B_min,P_max> For example, the Shanghai-Tokyo financial line can be expressed as: I = <Shanghai-FX,Tokyo-FX,5ms,400Gb / s,10 -18 >
[0133] S102: Zero Trust Brain performs syntax, policy conflict, and compliance checks on Q-IDL. If the system finds leakProb:1e -18 The national secret SM9 derived key is required, but the current node has not loaded the SM9 instruction and is marked as "missing algorithm";
[0134] S103: Quantify the natural language indicators into measurable KPIs; for example, quantify the key rotation period less than or equal to 5ms as the key pool margin greater than or equal to 3×10 5 bits, quantizes end-to-end RTT less than or equal to 5ms as path length less than or equal to 1000km of optical fiber plus 1 relay;
[0135] S104: Query real-time network topology, channel quality, and available computing power through KCR-Orchestrator;
[0136] S105: The solver outputs the optimal path and resource allocation with the goal of "minimum delay + minimum key gap + minimum number of hops";
[0137] S106: If multiple attempts to seize the same quantum link simultaneously occur, the system arbitrates based on security level, service priority, and time slice. For example, if the Metaverse rendering slice has a priority of 3 and the financial transaction slice has a priority of 5, the system will give 70% of the bandwidth in Q1 to financial transactions.
[0138] S107: Generate and distribute Kubernetes CRD, and finally generate the orchestration object QuantumSl ice, which is pushed to the switch cluster through the GitOps pipeline to complete intent registration and policy orchestration.
[0139] Furthermore, the step S2 further includes:
[0140] S201: Periodically initiate a lightweight detection to all candidate channels;
[0141] S202: Mapping the original physical quantity into an available coefficient A(e) between 0 and 1;
[0142] S203: Subtract the service required key rate R_key given in step S103 from the current channel coding rate;
[0143] S204: Add up the quantum, classical, exchange, and encryption / decryption delays of each candidate path and compare with the SLA upper limit L_max in step S103;
[0144] S205: For each active link, automatically search for 1-N backup links that can quickly take over, calculate the KPI after the takeover, and use the formula to rank them. The formula is: Priority = α·A(e)–β·ΔL–γ·ΔR; for example:
[0145] Main e1 optical fiber;
[0146] Backup 1: e2 radio (A = 0.57, ΔL = -0.6ms, ΔR = +3.2Mbps);
[0147] Backup 2: e3 another optical fiber (A = 0.98, ΔL = +0.4ms, ΔR = -0.5Mbps);
[0148] Sorting result: e3>e2;
[0149] S206: Dynamically generate a trigger threshold based on the "availability coefficient + supply-demand gap" and write it into the switch register;
[0150] S207: Package all results into JSON and push them to the zero-trust brain and local switch agent via gRPC. After receiving the results, the agent writes the threshold into the local register and sends an ACK.
[0151] Furthermore, the step S3 further includes:
[0152] S301: A QKD-Mesh is formed, where each switch and its corresponding QKD module is considered a QKD node. A unified trusted CA issues a public-private key pair and a domain server certificate for each node, and the node certificate is pre-installed in the PUF security zone of the switch π-SoC.
[0153] S302: The source switch broadcasts its QKD capability vector QV = {λ_qkd, R_max, BER_min} via LLDP-Q (Quantum LLDP). The peer switch that receives the broadcast writes the reachable nodes into the local QKD-ARP table.
[0154] S303: Source node A generates a random number r_A and a timestamp t_A, and constructs a request message M_req = SM2Encrypt(PK_B, r_A||t_A);
[0155] Calculate the signature of SM3(r_A||t_A) σ_A=SM2Sign(SK_A,M_req);
[0156] Send {M_req,σ_A} to peer B via the classic channel UDP / 8472;
[0157] S304: Node B decrypts M_req using SK_B and verifies σ_A;
[0158] Generate r_B and construct a response message M_resp = SM2Encrypt(PK_A, r_B||t_B||Hash(r_A));
[0159] Calculate signature σ_B = SM2Sign(SK_B, M_resp);
[0160] Echo {M_resp,σ_B};
[0161] Both parties complete bidirectional identity authentication and share the random seed r = r_A ⊕ r_B;
[0162] S305: Generate synchronization parameters based on the seed r: laser pulse period Δτ, basis vector selection table B(r);
[0163] The QKD modules of both parties enter the synchronization window at the same time:
[0164] Δτ_sync=2×RTT_classical+100ns;
[0165] S306: Select the decoy state strength {μ1, μ2, μ3} according to the real-time BER:
[0166] When BER < 1%, the decoy state strength is selected as {0, 0.2, 0.6};
[0167] When 1%≤BER<4%, the decoy state strength is selected as {0, 0.25, 0.75};
[0168] Sending a calibration frame through the OAM channel:
[0169] TuningFrame={μ_set,Δτ_sync,FEC_code=LDPC(64800)};
[0170] S307: Both parties send N=2×10 consecutively 7 photon pulses;
[0171] After basis vector alignment, we get the sifted key K_sift≈N(1-2BER) / 2;
[0172] Privacy amplification with Toeplitz Hash:
[0173] K_priv=Ext(K_sift,seed_priv);
[0174] |K_priv|=n_priv=n_sift·(1-H(2p))-log2(1 / ε_sec);
[0175] S308: K_priv is directly written into the on-chip quantum storage SRAM-QL1 of the π-SoC via a dedicated SerDes interface;
[0176] Once the write is complete, the flag "QL1_ready=1" is set for subsequent key derivation pipeline reading;
[0177] S309: Report via QKD-BFD (Bidirectional Forwarding Detection) message every 100ms:
[0178] Health={BER_life,QBER,KeyRate,L_path};
[0179] Once any indicator of Health exceeds the preset threshold in step S2, multi-dimensional elastic switching is immediately triggered;
[0180] At this point, the quantum key distribution link is officially established and can provide the root key K_priv for the business at any time.
[0181] Furthermore, the step S4 further includes:
[0182] S401: After receiving the data packet arrival interrupt, the encryption engine takes out a 256-bit quantum root key from the primary key pool (SRAM-QL1) of the π-SoC according to the FIFO;
[0183] Hardware guarantees atomicity, that is, only one port is allowed to access the same K_root in the same clock cycle;
[0184] S402: Use HKDF-SHA3-256 to derive the port-level session key from K_root and the dynamic nonce:
[0185] K_sess = HKDF(K_root, nonce||port_id||vlan||t_now, 256), where nonce is taken from the switch ASIC's embedded quantum true random number generator (QRNG) and is updated for each packet.
[0186] S403: Use K_root to perform another one-time packaging on K_sess to form a quantum envelope:
[0187] Env=AES-256-GCM(K_root,IV=nonce,AAD=Header,PT=K_sess);
[0188] The envelope is sent along with the data packet header for the peer to depacketize;
[0189] S404: Use K_sess+AES-256-CTR to encrypt the service payload P:
[0190] Ciphertext=AES-256-CTR(K_sess,Counter=seq_num)⊕P;
[0191] The encryption engine works in zero-copy DMA mode with a latency of less than 0.1μs;
[0192] S405: Compare the lifecycle tag of the current K_sess with the policy slice generated in step S1:
[0193] If (t_now>ExpireTime), discard and re-obtain a new K_root;
[0194] S406: Within 2 clock cycles (≈15ns) after the data packet is sent through the classic channel, the ASIC automatically triggers the clear circuit;
[0195] At the same time, the reference counter of the used K_root is reduced by 1; when the counter returns to zero, it is recycled to the queue for privacy amplification;
[0196] S407: After receiving the packet header, the peer switch uses the local K_root to decrypt the envelope, restore the K_sess, and decrypt the payload with the K_sess. It then uses the GCM Tag for integrity verification.
[0197] S408: Write "encryption delay + packet loss + anomaly count" into QKD-BFD Telemetry:
[0198] Metric={port_id,enc_latency_ns,drop_cnt,err_cnt};
[0199] When err_cnt>0, it will be reported to the Zero Trust Brain immediately. When enc_latency>15μs, it will be reported to the Zero Trust Brain immediately to trigger adaptive elasticity.
[0200] At this point, a piece of business data completes the entire life cycle of quantum root key-session key-encryption-destruction at the port layer, meeting the requirements of "one-time one password, zero trust, and microsecond level".
[0201] Furthermore, the step S5 further includes:
[0202] S501: Collect a set of four-tuples every 100ms. Specifically:
[0203] Q(t) quantum channel: BER_qkd(t), KeyRate_qkd(t);
[0204] C(t) classical channel: Util_class(t), RTT_class(t);
[0205] K(t) key pool: KeyRemain(t), KeyConsumeRate(t);
[0206] A(t) AI anomaly: AnomalyScore(t)∈[0,1];
[0207] S502: Set a dynamic threshold for each dimension: Th_i(t), specifically:
[0208] Th_ber(t)=5%-α·σ_ber(t);
[0209] Th_key(t)=β·KeyConsumeRate(t)·Δt;
[0210] Th_uti l(t)=90%;
[0211] Th_anomaly(t)=0.7;
[0212] If any dimension exceeds the threshold, the alarm vector Alert[i] is set to 1;
[0213] S503: Calculate the comprehensive risk score:
[0214] RiskScore=Σw_i·Alert[i]·Severity_i;
[0215] w={0.35, 0.2, 0.3, 0.15} corresponding to Q, C, K, A respectively;
[0216] S504: Locating the minimum cut set using graph neural network (GNN):
[0217] G = (V, E), edge weight w_e = 1-A_e;
[0218] Output suspected fault edge list FaultEdges;
[0219] S505: Calculate K=3 shortest paths in the virtual topology using the KSP-K algorithm;
[0220] Calculate the modulation factor w_mod for each path:
[0221] w_mod=(Hops+α·Latency) / Avai lBW;
[0222] Take the path with the smallest w_mod as the new main path;
[0223] S506: When the end-to-end KeyRate is insufficient, Dijkstra is called to find the key relay chain:
[0224] Cost(e)=1 / KeyRate_e+γ·Loss_e;
[0225] Generate a new key relay queue RelayPath;
[0226] S507: The Zero Trust Brain packages the new path, new key relay, and new algorithm into a CRD through gRPC;
[0227] S508: Self-healing action execution: After receiving the patch, the switch agent switches to the classic routing table (SR-v6), renegotiates the quantum key, and then hot-loads the Kyber768 instructions to the π-SoC;
[0228] S509: Within 50ms after self-healing, the four-dimensional indicators are sampled again. If RiskScore < 0.1, it is marked as "recovered". Otherwise, a new round of self-healing cycle is triggered. The self-healing cycle can be repeated up to 3 times.
[0229] Furthermore, the step S6 further includes:
[0230] S601: Session key instant erase: After the data packet is sent, the ASIC triggers the hardware clear circuit within 2 clock cycles and performs a row-level write of 0x00…00 to the port-level SRAM-Ksess;
[0231] Clear width = 256 bits, meeting the NIST SP 800-88 "single-pass" requirement. The formula is:
[0232]
[0233] S602: Each time K_root is used up, atomically decrement the reference counter RefCnt(K_root);
[0234] When RefCnt=0 and the global time window T_ttl expires, the secondary erase is triggered;
[0235] S603: Quantum memory deep erase: The on-chip rare-earth doped waveguide quantum memory starts the 3-pass DoD 5220.22-M algorithm 1 minute after the key expires;
[0236] S604: Double-end key consistency confirmation: The sender and receiver each send a Hash Chal length to confirm that both parties have destroyed the session key at the same time:
[0237] H_local=SHA3-256(K_sess||nonce_local);
[0238] H_peer=SHA3-256(K_sess||nonce_peer);
[0239] Specifically, an abnormal alarm is triggered when H_local≠H_peer, and an abnormal alarm is triggered when either party times out for 100μs;
[0240] S605: Generate key event record E = {event_id, port, K_sess_id, destroyed_ts, hash_proof};
[0241] Calculate the signature of E using the SM2 private key:
[0242] σ=SM2Sign(SK_node,SHA3-256(E));
[0243] S606: Use {E,σ} as transaction Tx and generate a 256-bit random seed r_beacon through the quantum random beacon;
[0244] Calculate the ledger hash:
[0245] block_hash=SHA3-256(prev_hash||Tx||r_beacon);
[0246] Use threshold BLS signature to anchor block_hash to the consortium chain to ensure forward tamper-proof;
[0247] S607: Compliance audit retrieval and certification: The regulator queries through the REST API; the system returns the complete event record E, signature σ and public key certificate, blockchain height & Merkle path; the regulator then verifies locally.
[0248] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations that come within the meaning and range of equivalents of the claims be embraced therein.
Claims
1. A switch secure communication encryption method based on quantum key distribution, characterized by: The following steps are involved: S1: The business party submits the "security-latency-bandwidth" intent to the Zero Trust Brain through the Quantum Intent Description Language (Q-IDL); S2: Evaluate the real-time quality, key margin, and topological accessibility of fiber quantum channels, classical ultra-high-speed channels, and radio frequency spatial channels based on intended requirements; S3: Triggering the QKD transmitter and receiver along the optimal quantum path to transmit polarization- and OAM-encoded quantum states, completing basis vector alignment, error correction, and privacy amplification, generating the root quantum key K_root and injecting it into the on-chip quantum memory; S4: When the data packet arrives at the switch port, the pipeline takes K_root from the primary key pool and derives the one-time session key K_sess through HMAC-SHA3; S5: Continuously monitor the quantum channel bit error rate, key pool margin, and AI anomaly score; S6: The sender and receiver simultaneously confirm the destruction of the session key through "two handshakes + one hash challenge", write all key lifecycle events into the quantum immutable ledger (Q-Ledger), anchor it with the blockchain hash, and achieve audit and evidence collection in seconds.
2. A switch secure communication encryption method based on quantum key distribution according to claim 1, characterized in that: The step S1 further includes: S101: The business party submits the Q-IDL description file through REST, CLI, or Portal. S102: The Zero Trust Brain performs syntax, policy conflict, and compliance checks on the Q-IDL; S103: Quantify the natural language indicators into measurable KPIs. The end-to-end latency formula is: L_total=L_qkd+L_classical+L_switch+L_crypto, where L_total≤L_max=5ms; Key consumption rate formula: R_key = α·B_min, where α is determined by the encryption algorithm. For AES-256-GCM, α is ≈ 1.05×10 -5 bit / bit; S104: Query real-time network topology, channel quality, and available computing power through KCR-Orchestrator; S105: The solver outputs the optimal path and resource allocation with the goal of "minimum delay + minimum key gap + minimum number of hops"; S106: If multiple attempts are made to seize the same quantum link simultaneously, the system will arbitrate based on security level, service priority, and time slice. S107: Generate and distribute Kubernetes CRD, and finally generate the orchestration object QuantumSl ice, which is pushed to the switch cluster through the GitOps pipeline to complete intent registration and policy orchestration.
3. The switch secure communication encryption method based on quantum key distribution according to claim 1, characterized in that: The step S2 further includes: S201: Periodically initiate a lightweight detection to all candidate channels; S202: Mapping the original physical quantity into an available coefficient A(e) between 0 and 1; S203: Subtract the service required key rate R_key given in step S103 from the current channel coding rate; S204: Add up the quantum, classical, exchange, and encryption / decryption delays of each candidate path and compare with the SLA upper limit L_max in step S103; S205: For each active link, automatically search for 1-N backup links that can quickly take over, calculate the KPIs after the takeover, and rank them using the formula: Priority = α·A(e)–β·ΔL–γ·ΔR; S206: Dynamically generate a trigger threshold based on the "availability coefficient + supply-demand gap" and write it into the switch register; S207: Package all results into JSON and push them to the zero-trust brain and local switch agent via gRPC. After receiving the results, the agent writes the threshold into the local register and sends an ACK.
4. A switch secure communication encryption method based on quantum key distribution according to claim 1, characterized in that: The step 3 further comprises: S301: A QKD-Mesh is formed, where each switch and its corresponding QKD module is considered a QKD node. A unified trusted CA issues a public-private key pair and a domain server certificate for each node, and the node certificate is pre-installed in the PUF security zone of the switch π-SoC. S302: The source switch broadcasts its QKD capability vector QV = {λ_qkd, R_max, BER_min} via LLDP-Q (Quantum LLDP). The peer switch that receives the broadcast writes the reachable nodes into the local QKD-ARP table. S303: Source node A generates a random number r_A and a timestamp t_A, and constructs a request message M_req = SM2Encrypt(PK_B, r_A||t_A); Calculate the signature of SM3(r_A||t_A) σ_A=SM2Sign(SK_A,M_req); Send {M_req,σ_A} to peer B via the classic channel UDP / 8472; S304: Node B decrypts M_req using SK_B and verifies σ_A; Generate r_B and construct a response message M_resp = SM2Encrypt(PK_A, r_B||t_B||Hash(r_A)); Calculate signature σ_B = SM2Sign(SK_B, M_resp); Echo {M_resp,σ_B}; Both parties complete bidirectional identity authentication and share the random seed r = r_A ⊕ r_B; S305: Generate synchronization parameters based on the seed r: laser pulse period Δτ, basis vector selection table B(r); The QKD modules of both parties enter the synchronization window at the same time: Δτ_sync=2×RTT_classical+100ns; S306: Select the decoy state strength {μ1, μ2, μ3} according to the real-time BER: When BER < 1%, the decoy state strength is selected as {0, 0.2, 0.6}; When 1%≤BER<4%, the decoy state strength is selected as {0, 0.25, 0.75}; Sending a calibration frame through the OAM channel: TuningFrame={μ_set,Δτ_sync,FEC_code=LDPC(64800)}; S307: Both parties send N=2×10 consecutively 7 photon pulses; After basis vector alignment, we get the sifted key K_sift≈N(1-2BER) / 2; Privacy amplification with Toeplitz Hash: K_priv=Ext(K_sift,seed_priv); |K_priv|=n_priv=n_sift·(1-H(2p))-log2(1 / ε_sec); S308: K_priv is directly written into the on-chip quantum storage SRAM-QL1 of the π-SoC via a dedicated SerDes interface; Once the write is complete, the flag "QL1_ready=1" is set for subsequent key derivation pipeline reading; S309: QKD-BFD (Bidirectional Forwarding Detection) every 100ms Message report: Health={BER_life,QBER,KeyRate,L_path}; Once any indicator of Health exceeds the preset threshold in step S2, multi-dimensional elastic switching is immediately triggered.
5. The switch secure communication encryption method based on quantum key distribution according to claim 1, characterized in that: The step S4 further includes: S401: After receiving the data packet arrival interrupt, the encryption engine takes out a 256-bit quantum root key from the primary key pool (SRAM-QL1) of the π-SoC according to the FIFO; Hardware guarantees atomicity, that is, only one port is allowed to access the same K_root in the same clock cycle; S402: Use HKDF-SHA3-256 to derive the port-level session key from K_root and the dynamic nonce: K_sess=HKDF(K_root,nonce||port_id||vlan||t_now,256), where The nonce is taken from the switch ASIC’s embedded quantum true random number generator (QRNG) and is updated for each packet; S403: Use K_root to perform another one-time packaging on K_sess to form a quantum envelope: Env=AES-256-GCM(K_root,IV=nonce,AAD=Header,PT=K_sess); The envelope is sent along with the data packet header for the peer to depacketize; S404: Use K_sess+AES-256-CTR to encrypt the service payload P: Ciphertext=AES-256-CTR(K_sess,Counter=seq_num)⊕P; The encryption engine works in zero-copy DMA mode with a latency of less than 0.1μs; S405: Compare the lifecycle tag of the current K_sess with the policy slice generated in step S1: If (t_now>ExpireTime), discard and re-obtain a new K_root; S406: Within 2 clock cycles (≈15ns) after the data packet is sent through the classic channel, the ASIC automatically triggers the clear circuit; At the same time, the reference counter of the used K_root is reduced by 1; when the counter returns to zero, it is recycled to the queue for privacy amplification; S407: After receiving the packet header, the peer switch uses the local K_root to decrypt the envelope, restore the K_sess, and decrypt the payload with the K_sess. It then uses the GCM Tag for integrity verification. S408: Write "encryption delay + packet loss + anomaly count" into QKD-BFD Telemetry: Metric={port_id,enc_latency_ns,drop_cnt,err_cnt}; When err_cnt>0, it will be reported to the Zero Trust Brain immediately. When enc_latency>15μs, it will be reported to the Zero Trust Brain immediately to trigger adaptive elasticity.
6. A switch secure communication encryption method based on quantum key distribution according to claim 1, characterized in that: The step S5 further includes: S501: collect a set of four-tuples every 100ms; S502: Set a dynamic threshold for each dimension: Th_i(t). If any dimension exceeds the threshold, set an alarm vector Alert[i]=1; S503: Calculate the comprehensive risk score: RiskScore=Σw_i·Alert[i]·Severity_i; w={0.35, 0.2, 0.3, 0.15} corresponding to Q, C, K, A respectively; S504: Locating the minimum cut set using graph neural network (GNN): G = (V, E), edge weight w_e = 1-A_e; Output suspected fault edge list FaultEdges; S505: Calculate K=3 shortest paths in the virtual topology using the KSP-K algorithm; Calculate the modulation factor w_mod for each path: w_mod=(Hops+α·Latency) / Avai lBW; Take the path with the smallest w_mod as the new main path; S506: When the end-to-end KeyRate is insufficient, Dijkstra is called to find the key relay chain: Cost(e)=1 / KeyRate_e+γ·Loss_e; Generate a new key relay queue RelayPath; S507: The Zero Trust Brain packages the new path, new key relay, and new algorithm into a CRD through gRPC; S508: Self-healing action execution: After receiving the patch, the switch agent switches to the classic routing table (SR-v6). And renegotiate the quantum key and hot load the Kyber768 instructions into the π-SoC; S509: Within 50ms after self-healing, the four-dimensional indicators are sampled again. If RiskScore < 0.1, it is marked as "recovered". Otherwise, a new round of self-healing cycle is triggered. The maximum number of self-healing cycles is 3.
7. A switch secure communication encryption method based on quantum key distribution according to claim 2, characterized in that: The step S6 further includes: S601: Session key instant erase: After the data packet is sent, the ASIC triggers the hardware clear circuit within 2 clock cycles and performs a row-level write of 0x00…00 to the port-level SRAM-Ksess; Clear width = 256 bits, meeting the NIST SP 800-88 "single-pass" requirement. The formula is: S602: Each time K_root is used up, atomically decrement the reference counter RefCnt(K_root); When RefCnt=0 and the global time window T_ttl expires, the secondary erase is triggered; S603: Quantum memory deep erase: The on-chip rare-earth doped waveguide quantum memory starts the 3-pass DoD 5220.22-M algorithm 1 minute after the key expires; S604: Double-end key consistency confirmation: The sender and receiver each send a Hash Chal length to confirm that both parties have destroyed the session key at the same time. Specifically, an abnormal alarm is triggered when H_local ≠ H_peer. An abnormal alarm is triggered when either party times out for 100 μs. S605: Generate key event record E = {event_id, port, K_sess_id, destroyed_ts, hash_proof}; Calculate the signature of E using the SM2 private key: σ=SM2Sign(SK_node,SHA3-256(E)); S606: Use {E,σ} as transaction Tx and generate a 256-bit random seed r_beacon through the quantum random beacon; Calculate the ledger hash: block_hash=SHA3-256(prev_hash||Tx||r_beacon); Use threshold BLS signature to anchor block_hash to the consortium chain to ensure forward tamper-proof; S607: Compliance audit retrieval and certification: The regulator queries through the REST API, and then the regulator verifies locally.
Citation Information
Cited By
Method and device for determining update cycle of quantum key, method and device for evaluating security of update cycle of quantum key, and medium
CN121508856A
Key management method and key distribution system
CN121690568A
Distributed neural network security training method based on optical fiber direct connection and stage perception
CN122389970A
Distributed neural network security training method based on optical fiber direct connection and stage perception
CN122389970B