Security encryption communication method based on quantum key management
By building a digital twin model of the distribution network and dynamic quantum key management, the problem that traditional encryption algorithms are unable to cope with quantum attacks and multi-terminal access is solved, and the security and anti-attack capabilities of distribution network communications are improved.
Patent Information
- Application Number
- CN202510975137.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-15
- Publication Date
- 2025-10-14
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional encryption algorithms cannot cope with quantum-level attacks, and it is difficult to dynamically adjust key management when multiple terminals are connected, resulting in insufficient communication security and anti-attack capabilities in the distribution network.
Build a digital twin model of the distribution network, dynamically evaluate the status of the communication channel, pre-generate the initial quantum key, formulate a quantum key management strategy, dynamically update and allocate key resources, and record the actual feedback iteration strategy.
It improves the ability to deal with quantum-level attacks, dynamically generates and distributes quantum key resources, reduces the risk of key leakage in traditional encryption methods, and improves the security, stability, and real-time risk response capabilities of distribution network communications.
Smart Images

Figure CN120785529A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the field of secure encryption technology, and particularly relates to a secure encryption communication method based on quantum key management. BACKGROUND
[0002] The quantum key management refers to a technology for uniformly regulating the life cycle of a key, such as generation, distribution, use, update and revocation, in a quantum secure communication network.
[0003] In a secure encryption communication method and system based on quantum key management, the configuration method comprises the following steps: acquiring system state data, generating node state data, network connection graph data and a system state matrix; receiving a communication request data packet, generating a request feature vector, a service weight coefficient and a service demand matrix; collecting real-time network state data, constructing an enhanced Bayesian network model, and generating a network state score matrix; collecting key pool state data, establishing a key consumption prediction model, and generating a key resource distribution matrix; constructing a multi-objective optimization model, and generating a scheduling strategy matrix; and executing the scheduling strategy and performing performance evaluation. Through the establishment of a complete evaluation and prediction system, efficient management and safe distribution of quantum keys are realized.
[0004] In the field of secure encryption technology, although the problems of insufficient prediction accuracy of the Bayesian network model and unreasonable resource allocation in the multi-objective optimization process are solved, in the power distribution network communication scenario, when transmitting commands and data, the traditional encryption algorithm cannot cope with quantum-level attacks, and there is a risk that the key may be leaked. On the other hand, the traditional key update and management lack real-time performance, and it is difficult to adjust according to the dynamic changes of the communication channel when multiple terminals are accessed. Therefore, a quantum key management communication method with dynamic key collaborative update capability is needed to improve the security and stability of the power distribution network communication and the anti-attack capability. SUMMARY
[0005] The application provides a secure encryption communication method based on quantum key management, which aims to solve the problems that the traditional encryption algorithm cannot cope with quantum-level attacks and it is difficult to dynamically adjust when multiple terminals are accessed. The technical scheme adopted by the application to solve the above technical problems is to provide a secure encryption communication method based on quantum key management: a power grid digital twin model is constructed, the state of the communication channel is dynamically evaluated, an initial quantum key is generated in advance, a quantum key management strategy is formulated, the key resources are dynamically updated and distributed, and the actual feedback iteration strategy is recorded.
[0006] As a preferred embodiment, the specific steps of constructing the digital twin model of the power grid are as follows: collecting data from multiple sources, different formats and structures from various terminals, sensors and historical databases of the distribution network system, preliminarily dividing them into normal data and dynamic data according to the update cycle and content attributes, converting the static data into a unified format, performing consistency check, sorting the dynamic data by timestamp, setting the time window to calculate the mean and variance, marking abnormal data according to the specified threshold, finding the points where data is missing, and replacing the missing items with the average of the valid values of the previous and next data; establishing a corresponding simulation node for each device in the distribution network system, setting parameters according to the collected static data, forming a logical mapping according to the physical topology, and collecting real-time data to verify the operating status, connection path, etc. of the simulation model, so that the simulation model and the physical distribution network system are in the same frequency and state.
[0007] As a preferred embodiment, the specific steps of the dynamic evaluation of the communication channel state are as follows: deploying detection modules on the simulation nodes, regularly sending data packets between the detection modules, recording the round-trip delay and packet loss rate, taking 100ms as a sampling period, and calculating the total signal power P within the sampling period. signal and noise power P noise , calculate the signal-to-noise ratio The average signal-to-noise ratio is calculated by accumulating the signal-to-noise ratio of multiple sampling periods, counting the round-trip delay of m data packets, and calculating the average round-trip delay. Get the jitter situation Where i represents the i-th data packet, RTT i The RTT of the i-th data packet is represented. The signal-to-noise ratio and jitter of each sampling period are recorded and stored. The sliding window average is used for smoothing multiple sampling periods. The channel state level is set. The channel state score formula is: Where ω1, ω2, and ω3 are the weights of the signal-to-noise ratio (SNR), jitter, and average round-trip delay (RTD), respectively. ω1+ω2+ω3=1, k represents channel k, the SNR is in decibels (dB), the average round-trip delay is in milliseconds (ms), and the jitter is in milliseconds (ms). Only the numerical value is used to calculate the channel status score. When S < 1.5, the channel status is poor; when 1.5 ≤ S < 2.5, the channel status is fair; when 2.5 ≤ S < 3.5, the channel status is good; and when S ≥ 3.5, the channel status is excellent.
[0008] As a preferred embodiment, the specific steps of pre-generating the initial quantum key are as follows: deploying a key management system into the distribution network system; before the distribution network devices formally transmit data, a quantum channel is established between the communicating parties using a single-mode optical fiber; quantum states are sent through the quantum channel; data is exchanged through a conventional channel; the sender sends a set of test pulses to the receiver; the attenuation is calculated based on the ideal transmission power of the channel and the actual reception power of the receiver; and an adjustable attenuator is inserted to adjust the attenuation to the ideal transmission power; the sender sends a reference pulse, and the receiver measures the interference fringe visibility V using an interferometer, according to the formula: Among them L max Indicates the maximum power received by the detector, L min It represents the minimum power received by the detector, and the visibility of the interference fringes reaches more than 99% by adjusting the phase modulator of the sender; the communicating parties calculate the round-trip delay through the conventional channel, and correct the local clock deviation according to the round-trip delay. After completing the above-mentioned quantum channel calibration, the receiver records the received bit value and the measurement value used to obtain the initial key bit. The sender uses the measurement value used to compare with the sent bit value and the initial key bit of the receiver, and retains the bit string with consistent corresponding values to form a screening key. The sender and receiver use an interactive error correction protocol to estimate the bit error rate of the quantum bit, and correct the error of the screening key until it is consistent. The formed correction key is compressed and mapped to obtain the initialized quantum key, and a number and a timestamp are assigned to store it in the key management system.
[0009] As a preferred embodiment, the specific steps of formulating the quantum key management strategy are as follows: clarifying the links that need to use quantum keys, such as links that carry key data such as control, scheduling, and monitoring, setting the roles and responsibilities of the management system, the administrator is responsible for formulating and implementing the quantum key strategy, supervising the entire life cycle of the quantum key, the operator is responsible for obtaining the quantum key, and determining the distribution to the required links and devices, and making real-time responses to the usage, the recorder is responsible for regularly checking the operation logs recorded in the management system for any illegal operations; for links whose channel status has been evaluated, if the channel status is poor, reduce the number of quantum keys generated, rotate the quantum keys regularly, and combine other encryption methods to protect communications; if the channel status is medium, dynamically adjust the quantum key through an adaptive algorithm The sub-key generation strategy adjusts the quantum key generation rate in real time according to the channel conditions. When the channel state is good, the quantum bit transmission amount is increased and the quantum key update frequency is delayed. When the channel state is excellent, the parallelism of quantum key generation is improved and the quantum key generation rate is accelerated. The generated quantum keys are classified into initial quantum keys, short-term quantum keys, and long-term quantum keys according to their uses. The initial quantum keys are the basis for the generation of short-term and long-term keys and require further processing. Short-term quantum keys are used to protect the data security of communications in a certain period of time and are destroyed after the session ends. Long-term quantum keys are used for identity authentication and system integrity protection. The generated initialization quantum keys are stored using the AES strong encryption algorithm, and different types of quantum keys are stored in different storage intervals.
[0010] As a preferred embodiment, the specific steps of dynamically updating and allocating key resources are as follows: combining data sensitivity, link priority, and real-time requirements, scoring and grading communication requirements into three levels: high priority, represented by a value of 9; medium priority, represented by a value of 6; and low priority, represented by a value of 3; dynamically determining the key update frequency based on changes in channel data transmission volume and communication requirements, using the formula: Where f0 represents the key update frequency in the basic case, S represents the channel state score, ∝1, ∝2 represent the weights of the corresponding items, Bps represents the channel data transmission volume, T represents the unit time window, and D priority Indicates the level of communication demand; the key management system grants quantum key distribution and usage rights to devices and roles according to permissions, dynamically allocates required quantum key resources to those with high communication priority and high data transmission volume, combines multi-channel parallel distribution, transmits quantum bits in parallel through multiple channels, and uses virtual channels for transmission on the same physical channel. It monitors quantum resource usage and channel conditions in real time, deploys regression models, and inputs historical and real-time data to obtain strategies for allocating quantum keys.
[0011] As a preferred embodiment, the specific steps of recording the actual feedback iteration strategy are: collecting the state data of the communication link in real time for the link allocated with quantum key resources, recording the data transmission of the link, monitoring the quantum key resource quantity and survival period in the management system, calculating the usage rate and generation rate of the quantum key, comparing the evaluated channel state with the actual key generation rate, re-evaluating the channel state to adjust the quantum key generation strategy, comparing the derived channel key update frequency with the actual communication demand and transmission amount, modifying the weight of the quantum key update frequency, inputting the feedback information and historical data into a regression model, and iteratively optimizing the update frequency and allocation strategy.
[0012] The beneficial effects of the present application are:
[0013] 1. The present application can improve the ability to cope with quantum-level attacks through quantum key distribution technology, dynamically generate and allocate quantum key resources, and reduce the risk of key leakage of traditional encryption methods.
[0014] 2. By building a digital twin model of the power distribution network, the channel state is evaluated in real time, the key update frequency and resource allocation strategy are dynamically adjusted, and the ability of the system to cope with real-time risks is improved. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 A flowchart of a secure encryption communication method based on quantum key management. DETAILED DESCRIPTION
[0016] In order to make the technical means, creative features, purposes and effects achieved by the present application easy to understand, the present application will be further described below in conjunction with specific embodiments, but the following embodiments are only preferred embodiments of the present application, not all. Based on the embodiments in the embodiments, other embodiments obtained by those skilled in the art without creative labor also belong to the protection scope of the present application.
[0017] Example 1, as Figure 1It is a secure encryption communication method based on quantum key management, which includes building a digital twin model of the power grid, dynamically evaluating the status of the communication channel, pre-generating the initial quantum key, formulating the quantum key management strategy, dynamically updating and allocating key resources, and recording the actual feedback iteration strategy. The following are the specific implementation steps: A secure encryption communication method based on quantum key management, constructing a digital twin model of the power grid, and dynamically evaluating the communication channel status. The specific steps of constructing the digital twin model of the power grid are: collecting data from multiple sources, different formats and structures from various terminals, sensors and historical databases of the distribution network system, and preliminarily dividing them into normal data and dynamic data according to the update cycle and content attributes, converting the static data into a unified format, performing consistency checks, sorting the dynamic data by timestamp, setting the time window to calculate the mean and variance, marking abnormal data according to the specified threshold, finding the points where data is missing, and replacing the missing items with the average of the valid values of the previous and next data; establishing a corresponding simulation node for each device in the distribution network system, setting parameters according to the collected static data, forming a logical mapping according to the physical topology, and collecting real-time data to verify the operating status and connection path of the simulation model, so that the simulation model and the physical distribution network system are in the same frequency and state; the specific steps of dynamically evaluating the communication channel status are: deploying detection modules on the simulation nodes, regularly sending data packets between the detection modules, recording the round-trip delay and packet loss rate, and taking 100ms as a sampling period to count the total signal power P within the sampling period. signal and noise power P noise , calculate the signal-to-noise ratio The average signal-to-noise ratio is calculated by accumulating the signal-to-noise ratio of multiple sampling periods, counting the round-trip delay of m data packets, and calculating the average round-trip delay. Get the jitter situation Where i represents the i-th data packet, RTT i The RTT of the i-th data packet is represented. The signal-to-noise ratio and jitter of each sampling period are recorded and stored. The sliding window average is used for smoothing multiple sampling periods. The channel state level is set. The channel state score formula is: Where ω1, ω2, and ω3 are the weights of the signal-to-noise ratio (SNR), jitter, and average round-trip delay (RTD), respectively. ω1+ω2+ω3=1, k represents channel k, the SNR is in decibels (dB), the average round-trip delay is in milliseconds (ms), and the jitter is in milliseconds (ms). Only the numerical value is used to calculate the channel status score. When S < 1.5, the channel status is poor; when 1.5 ≤ S < 2.5, the channel status is fair; when 2.5 ≤ S < 3.5, the channel status is good; and when S ≥ 3.5, the channel status is excellent.
[0018] Based on the above steps, the initial quantum key is generated in the following steps: deploying a key management system to the power distribution network system, before the formal transmission of data in the power distribution network equipment, a single-mode optical fiber is selected to establish a quantum channel between the two communicating parties, quantum states are sent through the quantum channel, data is exchanged through the conventional channel, a group of test pulses are sent from the sender to the receiver, the attenuation is calculated according to the ideal transmission power of the channel and the actual received power of the receiver, and the adjustable attenuator is inserted to adjust the attenuation to the ideal transmission power; the sender sends a reference pulse, and the receiver measures the interference fringe visibility V through an interferometer, and the formula is: where L max represents the maximum power received by the detector, L minRepresents the minimum power received by the detector, and the interference fringe visibility reaches more than 99% by adjusting the sender's phase modulator; the communicating parties calculate the round-trip delay through the conventional channel, and correct the local clock deviation according to the round-trip delay. After completing the above-mentioned quantum channel calibration, the receiver records the received bit value and the measurement value used to obtain the initial key bit. The sender uses the measurement value used to compare with the sent bit value and the receiver's initial key bit, retaining the bit string with the same corresponding value to form a screening key. The sender and receiver use an interactive error correction protocol to estimate the bit error rate of the quantum bit, and correct the error of the screening key until it is consistent. The formed corrected key is compressed and mapped to obtain the initialized quantum key, and a number plus a timestamp is assigned to store it in the key management system; the specific steps for formulating a quantum key management strategy are: clarifying the links that need to use quantum keys, such as links that carry key data such as control, scheduling, and monitoring, setting the roles and responsibilities of the management system, the administrator is responsible for the formulation and implementation of the quantum key strategy, and supervising the entire life cycle of the quantum key, the operator is responsible for obtaining the quantum key and determining the distribution to the required links and The equipment responds to usage in real time. The recorder is responsible for regularly checking the operation logs recorded in the management system for any violations. For links that have evaluated the channel status, if the channel status is poor, reduce the number of quantum keys generated, rotate the quantum keys regularly, and combine other encryption methods to protect communications. If the channel status is medium, dynamically adjust the quantum key generation strategy through an adaptive algorithm, and adjust the quantum key generation rate in real time according to the channel conditions. If the channel status is good, increase the quantum bit transmission volume and delay the quantum key update frequency. If the channel status is excellent, improve the parallelism of quantum key generation and accelerate the quantum key generation rate. Classify the generated quantum keys and divide them into initial quantum keys, short-term quantum keys, and long-term quantum keys according to their purpose. The initial quantum key is the basis for the generation of short-term and long-term keys and requires further processing. The short-term quantum key is to protect the data security of communications in a certain period of time and is destroyed after the session ends. The long-term quantum key is used for identity authentication and system integrity protection. The generated initialization quantum key is stored using the AES strong encryption algorithm, and different types of quantum keys are stored in different storage intervals.
[0019] Based on the above steps, the specific steps for dynamically updating and allocating key resources are as follows: Based on data sensitivity, link priority, and real-time requirements, the communication requirements are scored and divided into three levels: high priority, represented by a value of 9, medium priority, represented by a value of 6, and low priority, represented by a value of 3; based on the changes in channel data transmission volume and communication requirements, the key update frequency is dynamically determined. The formula is: wherein f0 represents the key update frequency under the basic condition, S represents the channel state score, a1, a2 represent the weight of the corresponding item, Bps represents the channel data transmission volume, T represents the unit time window, D priority The key management system grants the allocation and use permission of quantum keys to devices and roles according to the permissions, dynamically allocates the required quantum key resources for the communication demand priority and the high data transmission volume, combines the multi-channel parallel allocation mode, transmits quantum bits through multiple channels in parallel, transmits through a virtual channel in the same physical channel, monitors the quantum resource usage and the channel condition in real time, deploys a regression model, inputs the historical data and real-time data to obtain the quantum key allocation strategy; the specific steps of the actual feedback iteration strategy are as follows: real-time collection of the state data of the communication link of the allocated quantum key resource link, recording of the link data transmission, monitoring of the quantum key resource quantity and survival period in the management system, calculation of the quantum key usage rate and generation rate, comparison of the evaluated channel state with the actual key generation rate, re-evaluation of the channel state to adjust the quantum key generation strategy, comparison of the derived channel key update frequency with the actual communication demand and transmission volume, modification of the weight of the quantum key update frequency, input of the feedback information and historical data into the regression model, and iteration optimization of the update frequency and allocation strategy.
[0020] Embodiment 2, based on the above embodiment 1, the actual application of the quantum key management-based secure encryption communication method in the power distribution network communication scenario, specifically the following scheme:
[0021] Step one, connect each device in the power distribution network system to the cloud digital twin platform through a wireless link, load the topological structure, device parameters and other static data, access physical quantities, communication indicators and other dynamic data, construct the corresponding simulation unit, and combine the dynamic and static data to establish a simulation model. Every 30s, a probe packet is sent to the power distribution terminal unit to measure the round-trip delay. The signal-to-noise ratio weight is set to 0.5, the average round-trip delay weight is set to 0.3, and the jitter condition weight is set to 0.2. The comprehensive score is mapped to four categories: excellent, good, medium and poor.
[0022] Step two, deploy quantum key distribution devices between the control center and the substation of the power distribution network, use quantum states for key transmission through optical fiber connection, calculate the quantum bit error rate, and use a detector and dynamic adjustment to reduce the error rate to meet the reliability requirements; in each quantum key session, quantum bits are exchanged through a quantum channel to obtain the initial quantum key, which is stored in the management system. Different key generation strategies are executed according to the link state, quantum keys are allocated between different links and devices according to the communication demand, and the keys are periodically rotated and destroyed to ensure system security without key leakage.
[0023] Step three: Divide the communication requirements of each link on the simulation platform, and dynamically adjust the key resource allocation of the device based on the channel status, data transmission volume, and task priority. Set the communication requirement threshold and quantum bit error rate threshold in advance. When the threshold is exceeded, it indicates that the quantum key frequency generated by the current link is out of the controllable range. Therefore, the weight needs to be adjusted. Generally, it is set to 0.5 and 0.5. The ∝2 weight is adjusted according to the communication demand, and the ∝1 weight is adjusted according to the quantum bit error rate. Deploy a reinforcement learning model such as a regression model, input the actual execution of the allocation strategy, obtain the error situation, update the parameters, and re-execute the allocation strategy to iterate the model.
[0024] The above describes the embodiments of the present invention. Without departing from the embodiments of the present invention and its broader aspects, those skilled in the art may make data modifications and method changes based on the above in specific operations. The attached claims are intended to include all such data modifications and method changes in the implementation examples that do not depart from the present invention.
Claims
1. A secure encryption communication method based on quantum key management, characterized by: To build a digital twin model of the power grid and dynamically evaluate the status of the communication channel, the collected data is preprocessed and divided, a simulation model of the corresponding equipment is established, channel data is collected and calculated, and the channel status level is classified; Generate the initial quantum key in advance and formulate a quantum key management strategy. This involves establishing a quantum channel between the communicating parties, calibrating the quantum channel, obtaining the quantum key, clarifying management responsibilities and link requirements, dynamically generating quantum keys based on channel conditions, and differentiating and storing quantum keys by purpose. Dynamically updating and allocating key resources and recording actual feedback iteration strategies are to pre-classify the communication requirements of the channel, dynamically determine the key update frequency based on data transmission volume and demand changes, dynamically allocate key resources based on real-time needs, input the key update and allocation strategy and actual conditions into the reinforcement learning model, and update and iterate the strategy parameters based on feedback.
2. A secure encryption communication method based on quantum key management according to claim 1, characterized in that: The specific steps of constructing the digital twin model of the power grid are as follows: collecting data from multiple sources, in different formats and structures, from various terminals, sensors, and historical databases of the distribution network system; preliminarily dividing the data into normal data and dynamic data according to the update cycle and content attributes; converting the static data into a unified format, performing consistency checks, sorting the dynamic data by timestamp, setting a time window to calculate the mean and variance, marking abnormal data according to the specified threshold, finding the points where data is missing, and replacing the missing items with the average of the valid values of the previous and next data; establishing a corresponding simulation node for each device in the distribution network system, setting parameters according to the collected static data, forming a logical mapping according to the physical topology, and collecting real-time data to verify the simulation model, so that the simulation model and the physical distribution network system are synchronized. The specific steps of the dynamic evaluation of the communication channel state are as follows: deploying detection modules on the simulation nodes, regularly sending data packets between the detection modules, recording the round-trip delay and packet loss rate, taking 100ms as a sampling period, and calculating the total signal power P in the sampling period. signal and noise power P noise , calculate the signal-to-noise ratio The average signal-to-noise ratio is calculated by accumulating the signal-to-noise ratio of multiple sampling periods, counting the round-trip delay of m data packets, and calculating the average round-trip delay. Get the jitter situation Where i represents the i-th data packet, RTT i The RTT of the i-th data packet is represented. The signal-to-noise ratio and jitter of each sampling period are recorded and stored. The sliding window average is used for smoothing multiple sampling periods. The channel state level is set. The channel state score formula is: Where ω1, ω2, and ω3 are the weights of the signal-to-noise ratio, jitter, and average round-trip delay, respectively, and ω1+ω2+ω3=1, and k represents channel k.
3. The secure encryption communication method based on quantum key management according to claim 2, characterized in that: The specific steps of dynamically evaluating the communication channel status also include: grading the channel status scores, when S<1.5, the channel status is poor, when 1.5≤S<2.5, the channel status is medium, when 2.5≤S<3.5, the channel status is good, and when S≥3.5, the channel status is excellent.
4. The secure encryption communication method based on quantum key management according to claim 1, characterized in that: The specific steps of pre-generating the initial quantum key are as follows: deploying a key management system into the distribution network system; before the distribution network devices officially transmit data, a quantum channel is established between the communicating parties using a single-mode optical fiber; quantum states are sent through the quantum channel; data is exchanged through a conventional channel; the sender sends a set of test pulses to the receiver; the attenuation is calculated based on the ideal transmission power of the channel and the actual reception power of the receiver; and an adjustable attenuator is inserted to adjust the attenuation to the ideal transmission power; the sender sends a reference pulse, and the receiver uses an interferometer to measure the interference fringe visibility V, according to the formula: Among them L max Indicates the maximum power received by the detector, L min It represents the minimum power received by the detector, which is adjusted by the phase modulator of the transmitter to make the interference fringe visibility reach 99%.
5. The secure encryption communication method based on quantum key management according to claim 4, characterized in that: The specific steps of pre-generating the initial quantum key also include: the communicating parties calculate the round-trip delay through a conventional channel, correct the local clock deviation according to the round-trip delay, and after completing the quantum channel calibration, the receiver records the received bit value and the used measurement value to obtain the initial key bit, the sender uses the used measurement value and the sent bit value to compare with the initial key bit of the receiver, retains the bit string with the corresponding consistent values, and forms a screening key, the sender and the receiver use an interactive error correction protocol to estimate the bit error rate of the quantum bit, and mutually correct the error of the screening key until it is consistent, compresses and maps the formed corrected key to obtain the initialized quantum key, assigns a number and adds a timestamp to store it in the key management system.
6. The secure encryption communication method based on quantum key management according to claim 1, characterized in that: The specific steps for formulating a quantum key management strategy are: clarifying the links that need to use quantum keys, setting the roles and responsibilities of the management system, the administrator supervising the entire life cycle of the quantum key, the operator determining the distribution to the required links and devices, and responding to usage in real time, and the recorder recording the operation log in the management system and regularly checking for any violations.
7. The secure encryption communication method based on quantum key management according to claim 6, characterized in that: The specific steps of formulating the quantum key management strategy also include: for links whose channel states have been evaluated, if the channel state is poor, reducing the number of quantum keys generated, regularly rotating quantum keys, and combining traditional encryption methods to protect communications; if the channel state is medium, dynamically adjusting the quantum key generation strategy through an adaptive algorithm, adjusting the quantum key generation rate in real time according to the channel conditions; if the channel state is good, increasing the quantum bit transmission amount and delaying the quantum key update frequency; if the channel state is excellent, improving the parallelism of quantum key generation and accelerating the quantum key generation rate; classifying the generated quantum keys into initial quantum keys, short-term quantum keys, and long-term quantum keys according to their uses, and storing different types of quantum keys in different storage intervals.
8. The secure encryption communication method based on quantum key management according to claim 1, characterized in that: The specific steps of dynamically updating and allocating key resources are as follows: combining data sensitivity, link priority, and real-time requirements, scoring and grading communication requirements into three levels: high priority, represented by a value of 9; medium priority, represented by a value of 6; and low priority, represented by a value of 3; dynamically determining the key update frequency based on changes in channel data transmission volume and communication requirements, using the formula: Where f0 represents the key update frequency in the basic case, S represents the channel state score, ∝1, ∝2 represent the weights of the corresponding items, Bps represents the channel data transmission volume, T represents the unit time window, and D priority Indicates the level of communication demand.
9. The secure encryption communication method based on quantum key management according to claim 8, characterized in that: The specific steps of dynamically updating and allocating key resources also include: the key management system grants quantum key allocation and usage permissions to devices and roles according to permissions, dynamically allocates required quantum key resources to communication needs with high priority and high data transmission volume, combines multi-channel parallel allocation methods, transmits quantum bits in parallel through multiple channels, uses virtual channels for transmission on the same physical channel, monitors quantum resource usage and channel conditions in real time, deploys regression models, and inputs historical data and real-time data to obtain strategies for allocating quantum keys.
10. The secure encryption communication method based on quantum key management according to claim 1, characterized in that: The specific steps of recording the actual feedback iteration strategy are: for the link to which quantum key resources are allocated, real-time collection of communication link status data is performed, link data transmission status is recorded, the quantum key resource quantity and lifetime are monitored in the management system, the quantum key usage rate and generation rate are calculated, the evaluated channel status is compared with the actual key generation rate, and the channel status is re-evaluated to adjust the quantum key generation strategy, the obtained channel key update frequency is compared with the actual communication demand and transmission volume, the weight of the quantum key update frequency is modified, the feedback information and historical data are input into the regression model, and the update frequency and allocation strategy are iteratively optimized.
Citation Information
Patent Citations
A secure encrypted communication method and system based on quantum key management
CN119316138B
Cited By
Anti-quantum cryptography migration optimization method for satellite communication
CN121356769A