Data transmission method based on quantum key seed, communication system and storage medium
Patent Information
- Application Number
- CN202611020318.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-09
- Publication Date
- 2026-08-28
AI Technical Summary
[0005]然而,在现有的共纤传输方案中,量子信号仅用于生成密钥,不参与数据传输过程的动态控制,量子密钥仅用于对经典数据进行对称加密,密钥消耗速率与数据速率成正比,当数据速率达到Tbps级别时,密钥供应存在严重瓶颈
[0026]The technical solution of the above embodiment divides the original data stream into data frames, encodes each data frame with fountain codes to generate an encoded symbol stream, generates a quantum key seed, and uses the quantum key seed as input to generate a time-hopping control sequence through a cryptographically secure pseudo-random number generator. The encoded symbol stream is then sent to the receiving end according to the time-hopping control sequence. The receiving end recovers the original data stream data frames based on the fountain code encoding, the quantum key seed, and the encoded symbol stream. This technical solution, by using the quantum key seed as input to the cryptographically secure pseudo-random number generator, can drive the secure transmission of high-speed data streams with a small amount of quantum key consumption, avoiding the "scissors difference" defect between quantum key rate and data rate, meeting the requirements of real-time communication. Furthermore, the time-hopping pattern generation driven by the quantum key seed ensures that security is simultaneously established on both quantum randomness and time uncertainty, thereby improving the security of data communication.
Smart Images

Figure CN122660874A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a data transmission method, apparatus, communication system, and computer-readable storage medium based on quantum key seeds. Background Technology
[0002] Quantum key distribution (QKD) utilizes the Heisenberg uncertainty principle and the no-cloning theorem in quantum mechanics to generate information-theoretically secure shared keys between communicating parties. It is considered a key means to address the threat of quantum computing. Currently, QKD systems have been commercially deployed in metropolitan areas, and quantum key distribution is approaching industrial maturity. However, its integration with high-power classical signals in shared optical fibers is hindered by noise generated by nonlinear effects such as spontaneous Raman scattering and four-wave mixing.
[0003] In practical deployment, QKD systems face a dilemma: if deployed with independent optical fibers, the construction cost is too high; if transmitted with classical signals on the same fiber, they face noise interference introduced by nonlinear effects such as spontaneous Raman scattering and four-wave mixing, making them difficult to be compatible with existing high-capacity optical communication networks.
[0004] The development of hollow-core fiber technology has provided a new physical basis for quantum-classical co-fiber transmission. Hollow-core fiber confines light within an air core, greatly suppressing nonlinear effects such as Raman scattering and four-wave mixing. Experimental results show that stable co-transmission of ultra-high-capacity classical optical communication (40 Tbps, 50×800 Gbps) and a commercial quantum key distribution system has been achieved over 100 kilometers of hollow-core fiber, with a secure key rate of 9.56 kbps.
[0005] However, in existing co-fiber transmission schemes, quantum signals are only used to generate keys and do not participate in the dynamic control of the data transmission process. Quantum keys are only used for symmetric encryption of classical data. The key consumption rate is proportional to the data rate. When the data rate reaches the Tbps level, there is a serious bottleneck in key supply.
[0006] Existing QKD systems have a security key rate of only kbps (for example, a 100km hollow-core fiber co-transmission scheme has a security key rate of approximately 9.56kbps), while classical optical communication data rates have reached Tbps (e.g., the single-fiber capacity of current commercial dense wavelength division multiplexing systems has reached over 40Tbps), a difference of about nine orders of magnitude. Given this order of magnitude difference, if a Tbps-level data stream is encrypted using a one-time pad method, the required key consumption rate would need to reach the Tbps level, far exceeding the supply capacity of QKD systems. If the encryption frequency is reduced, the requirements of information theory security cannot be met. Therefore, existing technologies cannot directly protect high-speed real-time data streams, exhibiting a "scissors difference" defect between quantum key rate and data rate.
[0007] Furthermore, when data is transmitted in multiple fragments, the receiving end must wait for all fragments to arrive before it can reconstruct the data, introducing uncontrollable buffering delays that cannot meet the requirements of real-time communication and presenting a "waiting delay" problem in fragmented transmission. Strong classical optical signals generate a large number of noise photons in the quantum channel through fiber nonlinear effects (Raman scattering, four-wave mixing), causing the QKD bit error rate to soar and the security key rate to drop, presenting a "co-fiber interference" problem between quantum signals and classical signals. Furthermore, the security of existing QKD systems relies solely on the keys generated by QKD. Once the key is stolen or the quantum channel is interfered with, the security of the entire system fails, resulting in a single security dimension. At the same time, the direct use of quantum keys for data encryption consumes them at a rate far exceeding the generation rate, leading to a waste of key resources and inefficient utilization. Moreover, the interfaces between the quantum key generation module, data encryption module, and transmission module are not standardized, requiring extensive customization during system integration, which increases the difficulty of engineering implementation and maintenance costs. Summary of the Invention
[0008] In view of this, and in response to at least one of the aforementioned technical deficiencies, this application provides a data transmission method, apparatus, communication system, and computer-readable storage medium based on quantum key seeds.
[0009] A data transmission method based on quantum key seeds, applied at the sending end, includes: The original data stream is divided into data frames, and each data frame is fountain-coded to generate an encoded symbol stream; Generate a quantum key seed and send it to the receiver; Using the quantum key seed as input, a time-hopping control sequence is generated by a cryptographically secure pseudo-random number generator; wherein, the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information for each coded symbol; The encoded symbol stream is transmitted to the receiving end through the transmission channel according to the time-hopping control sequence; wherein the receiving end recovers the original data stream based on the fountain code encoding, the quantum key seed, and the data frame of the original data stream from the encoded symbol stream.
[0010] In some embodiments, dividing the original data stream into data frames includes: Determine the current data transmission latency parameters based on data throughput requirements; Calculate the data frame size based on the delay parameters; The original data stream is divided into data frames according to the data frame size.
[0011] In some embodiments, fountain code encoding is performed on each data frame to generate an encoded symbol stream, including: Each data frame is continuously encoded, from K Randomly selected from the original data symbols d Each element undergoes an XOR operation to generate an encoded symbol, forming an encoded symbol stream; where... 1≤d≤K .
[0012] In some embodiments, the data transmission method based on a quantum key seed further includes: The channel error rate, calculated and fed back by the receiver in real time, is obtained through the feedback channel, and the decoding overhead ε value of the fountain code is dynamically adjusted according to the channel error rate.
[0013] In some embodiments, using the quantum key seed as input, a time-jump control sequence is generated by a cryptographically secure pseudo-random number generator, including: Initialize the cryptographically secure pseudo-random number generator using the quantum key seed and the current frame number as input; For each encoded symbol, two random numbers are drawn from the cryptographically secure pseudo-random number generator, and the time slot number and wavelength channel number are calculated based on the two random numbers to obtain the time hopping control sequence.
[0014] In some embodiments, the time slot number and wavelength channel number are calculated as follows: T i =r 1 mod N slots W i = r 2 mod N wavelengths in, T i The timeslot number, r1 For a random number, N slots The total number of time slots, W i For wavelength channel number, r 2 For another random number, N wavelengths Number of wavelength channels mod It is the modulo operator.
[0015] In some embodiments, the optical fiber transmission includes a data channel and a quantum key channel; wherein the data channel uses the C-band, the quantum key channel uses the O-band, and the data channel and the quantum key channel achieve wavelength isolation through wavelength division multiplexing.
[0016] In some embodiments, the coded symbol stream is transmitted to the receiving end using a time-division duplex method; Specifically, encoded symbols are sent during the data window, and the quantum key signal corresponding to the quantum key seed is transmitted during the quantum window; and the data channel is silent during the quantum window.
[0017] In some embodiments, the data transmission method based on a quantum key seed further includes: The switching period of the time-division duplex of the optical fiber channel is determined based on the current data transmission delay parameters and the quantum key seed.
[0018] In some embodiments, transmitting the quantum key signal corresponding to the quantum key seed during the quantum window includes: Lasers that shut down the data channel; Waiting for the residual photons in the optical path to dissipate; Send the quantum key signal corresponding to the quantum key seed. Resume the transmission of the encoded symbols of the data channel.
[0019] In some embodiments, the data transmission method based on a quantum key seed further includes: The encoding matrix of the fountain code and the generation parameters of the degree distribution function are generated in real time using the quantum key seed and the cryptographically secure pseudo-random number generator.
[0020] In some embodiments, the quantum key seed is refreshed at a frequency of 0.5 to 10 times per second, and the seed length is 128 to 512 bits each time. The clock synchronization between the sending and receiving ends is achieved through the White Rabbit time synchronization protocol; The value of K ranges from 512 to 2048; The decoding overhead ε ranges from 3% to 5%.
[0021] In some embodiments, the receiving end regenerates the same time hopping control sequence as the sending end based on the quantum key seed and the cryptographically secure pseudo-random number generator; receives encoded symbols in the corresponding time slot channel and / or wavelength channel according to the time hopping control sequence, and performs fountain code decoding on the collected encoded symbols to recover the data frames of the original data stream.
[0022] A communication system includes a transmitter and a receiver connected via an optical fiber channel, wherein the transmitter is configured to perform the steps of the quantum key seed-based data transmission method.
[0023] In some embodiments, the sending end includes: The data framing module is used to divide the raw data stream into data frames; The fountain code encoding module is used to perform fountain code encoding on each data frame to generate an encoded symbol stream; The quantum key acquisition module is used to generate a quantum key seed and send it to the receiving end; A time-hopping pattern generation module is used to generate a time-hopping control sequence by means of a cryptographically secure pseudo-random number generator, using the quantum key seed as input; wherein the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information for each coded symbol; The timing control and transmission module is used to transmit the coded symbol stream to the receiving end through the transmission channel according to the time hopping control sequence.
[0024] In some embodiments, the transmitting end further includes: a wavelength division multiplexing module and a first White Rabbit time synchronization module; The receiver also includes: a wave decomposition and multiplexing module and a second White Rabbit time synchronization module; The wavelength division multiplexing module and the wavelength demultiplexing module are used to realize the multiplexing and demultiplexing of the data channel and the quantum key channel, respectively; the first White Rabbit time synchronization module and the second White Rabbit time synchronization module are used to realize clock synchronization between the transmitting end and the receiving end.
[0025] A computer-readable storage medium storing at least one instruction, at least one program, a code set, or an instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded by a processor and the steps of the quantum key seed-based data transmission method are executed.
[0026] The technical solution of the above embodiment divides the original data stream into data frames, encodes each data frame with fountain codes to generate an encoded symbol stream, generates a quantum key seed, and uses the quantum key seed as input to generate a time-hopping control sequence through a cryptographically secure pseudo-random number generator. The encoded symbol stream is then sent to the receiving end according to the time-hopping control sequence. The receiving end recovers the original data stream data frames based on the fountain code encoding, the quantum key seed, and the encoded symbol stream. This technical solution, by using the quantum key seed as input to the cryptographically secure pseudo-random number generator, can drive the secure transmission of high-speed data streams with a small amount of quantum key consumption, avoiding the "scissors difference" defect between quantum key rate and data rate, meeting the requirements of real-time communication. Furthermore, the time-hopping pattern generation driven by the quantum key seed ensures that security is simultaneously established on both quantum randomness and time uncertainty, thereby improving the security of data communication.
[0027] Additional aspects and advantages of this application will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this application. Attached Figure Description
[0028] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein: Figure 1 This is a schematic diagram of an example data transmission link; Figure 2 This is a flowchart of a data transmission method based on a quantum key seed, as shown in one embodiment. Figure 3 This is a flowchart illustrating the steps of a sending method. Figure 4 This is a flowchart of an example method for generating time-jump control sequences; Figure 5 This is a schematic diagram illustrating the decoding process at the sending end and the decoding process at the receiving end; Figure 6 This is a timing diagram of a transmission channel according to one embodiment; Figure 7 This is a schematic diagram of a communication system structure according to one embodiment; Figure 8 This is a schematic diagram of the communication system structure of another embodiment; Figure 9 This is a schematic diagram of the architecture of a sample White Rabbit time synchronization module. Detailed Implementation
[0029] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.
[0030] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the word “comprising” as used in this application’s specification means the presence of the stated feature, integer, step, or operation, but does not preclude the presence or addition of one or more other features, integers, steps, or operations.
[0031] This application provides a data transmission scheme that enables secure and efficient data communication between the sending and receiving ends. (Refer to...) Figure 1 As shown, Figure 1 This is a schematic diagram of an example data transmission link. As shown in the figure, the original data from the external network is input to the sending end, and then after being segmented, encrypted, and encoded, the resulting encoded symbols are sent to the receiving end through the transmission channel. The receiving end then decodes and decrypts the received encoded symbols to recover the original data for use by the upper-layer application.
[0032] refer to Figure 2 and Figure 3 As shown, Figure 2 This is a flowchart of a data transmission method based on a quantum key seed, which is applied at the sending end. Figure 3 This is a flowchart of the steps for executing a method on the sending end.
[0033] The data transmission method based on quantum key seeds in this embodiment mainly includes the following steps: Step S10: Divide the original data stream into data frames, and encode each data frame using fountain code to generate an encoded symbol stream.
[0034] In this step, the sending end can divide the original data stream into data frames and perform fountain code encoding on each frame to generate an encoded symbol stream.
[0035] For example, fountain codes can be LT (Luby Transform) codes or Raptor codes. LT codes are the first practical implementation of digital fountain codes. The encoded symbols are generated independently, and the performance is independent of channel parameters. Compared with other erasure codes, such as Reed-Solomon codes and LDPC codes, LT codes have lower encoding and decoding times.
[0036] In some embodiments, the method for dividing the original data stream into data frames may be as follows: Determine the latency parameter for the current data transmission based on the data throughput requirement; calculate the data frame size based on the latency parameter; and segment the original data stream into data frames based on the data frame size.
[0037] For example, the sending end divides the original data stream into micro-burst frames, the frame size of which is preferably 16KB, corresponding to the number of original data symbols K=1024 (each symbol is 16 bytes), and the value of K ranges from 512 to 2048.
[0038] In some embodiments, fountain code encoding of each data frame to generate an encoded symbol stream may include the following: Each data frame is continuously encoded, from K Randomly selected from the original data symbols d Each element undergoes an XOR operation to generate a encoded symbol, forming an encoded symbol stream; where, 1≤d≤K .
[0039] Specifically, for LT Code encoding, the encoder randomly draws degrees from a robust soliton distribution. d , and then from K Randomly selected from the original data symbols d Perform an XOR operation on each symbol to generate one encoded symbol; repeat the above process to generate an encoded symbol stream until a decoding confirmation is received from the receiving end or a preset redundancy threshold is reached.
[0040] For example, the correspondence between frame size and K value can be: 4KB corresponds to K≈512 (suitable for latency-sensitive scenarios), 8KB corresponds to K≈1024 (suitable for balanced scenarios), and 16KB corresponds to K≈2048 (suitable for high-throughput scenarios). In practical applications, appropriate parameter configurations can be selected within the above range according to the channel conditions and latency requirements of the actual application scenario.
[0041] Preferably, the decoding overhead ε of the fountain code is in the range of 3% to 5%; the decoding overhead ε is the core parameter in fountain codes (such as LT codes and Raptor codes), that is, the proportion of redundant encoded packets that the receiver needs to receive in order to successfully recover all the original data.
[0042] Step S20: Generate a truly random quantum key seed and send it to the receiving end.
[0043] In this step, the sending end obtains a true random key seed through a quantum key distribution system or a quantum random number generator. The quantum random number generator is a true random number source based on the principles of quantum mechanics. The sending end then sends the generated quantum key seed to the receiving end through a transmission channel.
[0044] For example, a shared quantum key seed can be generated through negotiation with the receiver via a QKD system, or 256 bits can be extracted from a truly random number generated by a QRNG chip as the quantum key seed.
[0045] As a preferred implementation, the quantum key seed can be refreshed periodically at a frequency of 0.5 to 10 times per second, with each seed being 128 to 512 bits long.
[0046] For example, based on the 9.56 kbps security key rate of a 100-kilometer hollow-core fiber QKD system, the quantum key consumption rate is only 0.256 kbps, and the supply / consumption ratio is about 37:1, with the key supply far exceeding the consumption. The quantum key seed is transmitted through the QKD system during the quantum window, and the transmission direction is opposite to the data direction (reverse transmission), utilizing the silent window of time division duplex to avoid strong light interference.
[0047] Step S30: Using the quantum key seed as input, a time-hopping control sequence is generated by a cryptographically secure pseudo-random number generator; wherein the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information for each coded symbol.
[0048] In this step, the transmitter takes the quantum key seed as input and generates a time-hopping control sequence through a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG). The time-hopping control sequence determines the transmission time slot and / or wavelength channel for each coded symbol.
[0049] In some embodiments, as shown in Figure 4 Figure 4 Here is a flowchart of an example method for generating time-skip control sequences, which may include the following: The cryptographically secure pseudo-random number generator is initialized using the quantum key seed S and the frame number F of the data frame to be transmitted as input. For each encoded symbol, two random numbers are drawn from the cryptographically secure pseudo-random number generator according to a deterministic random algorithm. r 1 and r 2 And based on random numbers r 1 and r 2 Calculate the time slot number T i and wavelength channel number W i Obtain the jump control sequence.
[0050] For example, the formulas for calculating the time slot number and wavelength channel number are as follows: T i =r 1 mod N slots W i = r 2 mod N wavelengths in, T i The timeslot number, r 1 For a random number, N slots The total number of time slots, W i For wavelength channel number, r 2 For another random number, N wavelengths Number of wavelength channels mod It is the modulo operator, used to calculate the remainder after dividing two numbers.
[0051] Specifically, the initial seed of a cryptographically secure pseudo-random number generator can be constructed by concatenating the quantum key seed S (256 bits) and the current frame number F (32 bits) as inputs. Seed=S || F (Total 288 bits) Initialize the encrypted secure pseudo-random number generator. The encrypted secure pseudo-random number generator can use the AES-256-CTR mode, that is, use the first 256 bits of Seed as the AES-256 key, and use the last 32 bits of Seed (padded with zeros to 128 bits) as the initial counter value. For each control information of the encoded symbol generated, perform an AES-256 encryption operation, output a 128-bit random number block, and extract the required random bits from it.
[0052] For example, the implementation process can be as follows: (1) The AES-256 encryption operation is implemented in the FPGA (Field Programmable Gate Array) using a pipelined architecture. The single encryption delay is about 10-15 clock cycles. Calculated at a clock frequency of 250MHz, the single encryption delay is about 40-60ns. It can support the generation of control information of about 16 million encoded symbols per second, which meets the real-time scheduling requirements of Tbps-level data streams.
[0053] (2) When N slots When =1024, the timeslot number T i Requires 10 bits (210 =1024); when N wavelengths When =50, wavelength channel number W i Requires 6 bits (2 6 =64); the control information for each encoded symbol requires 16 bits; AES-256-CTR outputs a 128-bit random number block each time, which can extract the control information of 8 encoded symbols (128 / 16=8), which can further improve the generation efficiency.
[0054] (3) The sending and receiving ends need to maintain synchronization of the frame sequence number F, which is a 32-bit unsigned integer. It is automatically incremented by 1 after each frame of data is sent. When F overflows (reaches 2^30), it will be automatically incremented by 1. 32 When -1), a forced refresh of the quantum key seed is triggered to ensure the long-term unpredictability of the time-jumping pattern.
[0055] For each coded symbol i Random numbers are drawn from an encrypted secure pseudo-random number generator. r 1 and r 2 The calculation process is as follows: Time slot number T i =r 1 mod 1024 ( N slots =1024); Wavelength channel number W i =r 2 mod 50 ( N wavelengths =50); Since the transmitter and receiver share the same quantum key seed S and frame number F, and use the same random number generation algorithm, they can independently regenerate the exact same time-hopping control sequence.
[0056] In some embodiments, a truly random quantum key seed can also be used to dynamically generate the encoding matrix of the fountain code and the generation parameters of the degree distribution function in real time.
[0057] Specifically, after the sending end inputs the quantum key seed S into the cryptographically secure pseudo-random number generator, a portion of the random numbers output by the cryptographically secure pseudo-random number generator are used to determine the key parameters (including the c value and δ value) in the robust soliton distribution, and another portion of the random numbers are used to drive the random sampling in the coding symbol selection process.
[0058] As in the above embodiments, since the encoding matrices and degree distributions generated by different quantum key seeds are different, attackers cannot pre-construct the decoding matrix without knowing the seed, thus ensuring data security.
[0059] Step S40: The encoded symbol stream is transmitted to the receiving end through the transmission channel according to the time hopping control sequence; wherein the receiving end uses the fountain code encoding, quantum key seed and data frames to recover the original data stream from the encoded symbol stream.
[0060] In this step, the transmitting end sends the encoded symbols of the encoded symbol stream to the receiving end through the transmission channel according to the time hop control sequence. The receiving end, based on the quantum key seed-based data transmission method executed by the transmitting end, recovers the original data stream data frame from the encoded symbol stream according to the fountain code encoding, the quantum key seed, and the data frame.
[0061] In some embodiments, the receiver can maintain clock synchronization with the transmitter through the White Rabbit protocol. The White Rabbit protocol is based on the IEEE 1588 Precision Time Protocol (PTP) extension and combines Synchronous Ethernet (SyncE) and Digital Dual Mixer Time Difference Measurement (DDMTD) technology to achieve sub-nanosecond time deviation and nanosecond-level synchronization between the master and slave clocks.
[0062] In practical applications, the transmitting and receiving ends can each be equipped with a White Rabbit switch to transmit time signals through optical fiber and automatically compensate for the asymmetry of optical fiber transmission delay using a bidirectional time comparison method. The synchronization accuracy on a 100km optical fiber link can be better than 1ns.
[0063] For example, the transmission channel between the transmitter and receiver can be an optical fiber channel to transmit data; preferably, the optical fiber channel can be hollow optical fiber, and the transmission channel can include a data channel and a quantum key channel. The data channel is used to transmit encoded symbols, and the quantum key channel is used to transmit quantum key seeds; wherein, the data channel uses the C-band, the quantum key channel uses the O-band, and the data channel and the quantum key channel achieve wavelength isolation through wavelength division multiplexing.
[0064] Preferably, the encoded symbol stream is transmitted to the receiving end using a time-division duplex method; wherein, encoded symbols are transmitted during the data window period, and the quantum key signal corresponding to the quantum key seed is transmitted during the quantum window period; and the data channel is silent during the quantum window period.
[0065] For example, the sending end follows the time hop control sequence ( T i , W iThe data channel uses the C-band (1530-1565 nm), with 50 wavelength channels and a channel spacing of 100 GHz (approximately 0.8 nm), conforming to the ITU-T G.694.1 Dense Wavelength Division Multiplexing (DWDM) standard frequency grid. The transmission power of each wavelength channel is determined based on the link budget: for a 100 km hollow fiber link (loss approximately 0.5 dB / km), the preferred single-channel transmission power is 0 dBm to +3 dBm, and the total transmission power (for all 50 channels) is approximately +17 dBm to +20 dBm. The transmission window duty cycle is 90%, meaning that the data channel is in transmission mode for 90% of the time period within a switching cycle.
[0066] In some embodiments, the switching period of the time-division duplex of the optical fiber channel can be determined based on the delay parameters of the current data transmission and the quantum key seed.
[0067] In some embodiments, during the quantum window (duty cycle 10%), the data channel is completely silent (all C-band lasers are turned off or their output power is attenuated to below -30dBm), and the transmitter transmits the quantum key signal corresponding to the quantum key seed to the receiver via the O-band (1270-1330 nm).
[0068] In some embodiments, the specific timing design of the quantum window can be as follows: switching period T switch The preferred time is 10 μs, with the data window occupying 9 μs and the quantum window occupying 1 μs. Within the 1 μs time of the quantum window...
[0069] For example, the sending end performs the following operations: (1) Turn off the data channel laser (rise edge <100ns); (2) Wait for the residual photons in the optical path to dissipate (waiting time is about 200 ns); (3) Send the quantum key signal (duration approximately 500 ns); (4) Restore the transmission of encoded symbols of the data channel (falling edge <100ns).
[0070] As in the above embodiment, the quantum window is designed with a duty cycle of 10%, and the effective transmission capacity of the data channel is lost by about 10%, but this is done in exchange for an interference-free transmission environment for quantum signals.
[0071] For example, the process executed by the receiving end can be as follows: Step S501: The same time-hopping control sequence is locally regenerated using the quantum key seed shared with the sender and the same cryptographically secure pseudo-random number generator algorithm.
[0072] Specifically, the receiver uses the same quantum key seed S and frame number F of the currently received data frame as the transmitter, and regenerates the time-hopping control sequence using the same random number generation algorithm. T i , W i ).
[0073] Step S502: Receive coded symbols in the corresponding time slot and wavelength channel.
[0074] Specifically, the receiving end receives coded symbols in the corresponding time slot and / or wavelength channel according to the time hopping control sequence.
[0075] Step S503: Decode the collected coded symbols using fountain codes to recover the original data frame.
[0076] refer to Figure 5 As shown, Figure 5 This is a schematic diagram of the decoding process at the sending end and the receiving end. The receiving end uses the belief propagation algorithm to decode the collected coded symbols. When a coded symbol with a degree of 1 is found, the original coded symbol is decoded immediately. The decoded original coded symbol is removed from the XOR of other coded symbols. The above process is repeated until all K original coded symbols are decoded. The decoded data frames are then reassembled in order to obtain the original data stream, which is output to the application layer.
[0077] In some embodiments, the fountain code utilizes a short code length optimization scheme (K=512-2048), and the decoding overhead ε is controlled at 3%-5%. Accordingly, the receiver only needs to receive K(1+ε) encoded symbols to complete the decoding, without waiting for the encoded symbols corresponding to all K original data symbols.
[0078] In some embodiments, during fountain code encoding, the transmitting end can also obtain the channel bit error rate calculated and fed back by the receiving end in real time through a feedback channel, and dynamically adjust the decoding overhead ε value of the fountain code encoding according to the channel bit error rate. The specific adjustment strategy can be as follows: When the channel bit error rate (BER) is < 10 -6 At this time, the ε value can be set to 2%-3% to improve transmission efficiency; When the channel bit error rate is 10 -6 ≤BER < 10 -4 At this time, the ε value can be set to 3%-5% to balance efficiency and reliability; When the channel bit error rate (BER) is ≥ 10 -4 At this time, ε can be set to 5%-8% to ensure decoding success rate.
[0079] In this process, the receiver calculates the bit error rate in real time during decoding and notifies the transmitter to adjust the ε value through the feedback channel, thus forming a closed-loop adaptive control.
[0080] In some embodiments, reference Figure 6 As shown, Figure 6 This is a timing diagram of a transmission channel in one embodiment. The quantum key seed is transmitted through a QKD system within a quantum window, in the opposite direction to the data direction (reverse transmission). The time-division duplex silent window avoids strong light interference. During transmission, the quantum key seed exists as a single-photon-level signal; any eavesdropping will alter the quantum state and be immediately detected (based on the Heisenberg uncertainty principle). After the original data symbols are encoded using fountain codes at the transmitting end, they are transmitted within the data window as encoded symbols. The encoded symbols themselves do not contain the complete information of the original data; that is, a single encoded symbol is... K Randomly selected from the original symbols d The receiving end needs to collect the XOR operation result of each. K (1+ε) Only after the encoded symbols are obtained can the original data be recovered through the belief propagation algorithm. Therefore, even if the encoded symbols are intercepted during transmission, attackers cannot extract the original data content from them, thus realizing a natural privacy protection mechanism in the data transmission process. At the same time, it does not involve the collection, storage or processing of personal privacy data. All key generation and transmission processes are completed between the two communicating parties without going through a third-party platform, which has a higher effect on data security and privacy protection.
[0081] As described in the above embodiments, the quantum key is used as a true random source to drive the out-of-order transmission and recombination of data fragments in the time dimension, making it impossible for attackers to predict the temporal position of any data fragment without possessing the key. At the same time, to address the "fragment collection waiting" problem caused by out-of-order transmission, fountain code encoding is introduced, enabling the receiving end to decode and recover the data after receiving any sufficient number of fragments without waiting for specific fragments to arrive. The out-of-order transmission and fountain code decoding work together to solve the contradiction between security and real-time performance in traditional data transmission schemes.
[0082] In some embodiments, during the fountain code encoding process at the transmitting end and the fountain code decoding process at the receiving end, the encoding and decoding engine can implement XOR operations based on FPGA, with encoding and decoding latency at the nanosecond level. A streaming processing architecture is adopted, with each frame being encoded and decoded independently, and the total end-to-end latency is approximately the optical propagation delay plus 100 microseconds.
[0083] In some embodiments, the parameters of the sending end and receiving end of this application can be configured as follows:
[0084] Specifically, the interrelationships between the above parameters can be summarized as follows: (a) Relationship between K value and latency: The smaller the K value (e.g., 512), the fewer the number of encoded symbols per frame and the lower the decoding latency, which is suitable for latency-sensitive scenarios (e.g., financial transactions); the larger the K value (e.g., 2048), the higher the encoding efficiency, but the higher the single-frame collection latency, which is suitable for high-throughput scenarios (e.g., data center interconnection).
[0085] (b) Relationship between decoding overhead ε and reliability: The smaller the ε value (e.g., 2%), the higher the transmission efficiency, but the lower the packet loss resistance; the larger the ε value (e.g., 8%), the stronger the packet loss resistance, but the more transmission redundancy.
[0086] (c)N slots Relationship between value and security: N slots The larger the value, the more difficult it is for an attacker to guess the timeslot number (the search space is 1 / N). slots The higher the security, the higher the requirements for time synchronization accuracy.
[0087] In practical applications, the specific values of each parameter can be determined based on the above constraints, combined with the channel conditions and security requirements of the actual application scenario.
[0088] Based on the technical solution of this application, a QK-TST system was built on a 10km hollow-core optical fiber link. For performance indicators over distances exceeding 100km, reasonable calculations were made based on measured data and an optical fiber loss model. However, actual deployment requires calibration according to specific optical fiber parameters. The main parameters are as follows: K=1024, ε=3%, quantum key seed length 256 bits, seed refresh rate 1 time / second. N slots =1024, N wavelengths =50, data window duty cycle 90%, actual measured data are as follows: (1) Key consumption rate: During a 24-hour continuous test, the quantum key consumption rate remained constant at 0.256 kbps (256 bits / second). Compared to the traditional QKD encryption scheme, which requires a key consumption rate of 1 Tbps to protect the same data rate (1 Tbps) using a one-time pad method, the two differ by about 6 orders of magnitude. In the scheme of this application, the key supply / consumption ratio is approximately 37:1 (based on a QKD security key rate of 9.56 kbps), indicating that the key supply is much greater than the consumption.
[0089] (2) End-to-end transmission delay: On a 10km hollow fiber link, the theoretical optical propagation delay is about 50μs (fiber refractive index 1.47), and the measured end-to-end total delay is about 52-58μs. The additional delay (encoding / decoding delay + collection delay) is controlled within 8μs. On a 100km link, the end-to-end total delay is expected to be about 0.52-0.58ms.
[0090] (3) Decoding success rate: Under the condition that the signal-to-noise ratio (SNR) is greater than or equal to 10dB, 10,000 frames of data (each frame contains K = 1024 raw symbols) are sent. After the receiver receives K(1+ε) = 1055 encoded symbols, it begins decoding. The statistical results show that the decoding success rate is 99.97%, the average number of decoding iterations is 12.3, and the single-frame decoding delay is <10μs.
[0091] (4) Security verification: If the attacker does not know the quantum key seed S, the success probability of their time-jumping pattern (time slot number + wavelength channel number) is 1 / ( N slots × N wavelengths Substituting the specific parameters into the calculation, we get 1 / (1024×50)≈1.95×10 -5 When the quantum key seed is refreshed once per second, the attack window is compressed to less than 1 second.
[0092] The above-mentioned experimental data shows that the technical solution of this application can achieve real-time high-speed secure communication with extremely low quantum key consumption. The end-to-end latency meets the requirements of real-time communication, and the security is based on the dual dimensions of quantum randomness and time uncertainty.
[0093] The technical solution of this application has the following beneficial effects: Extremely high key utilization: Secure transmission of Tbps-level data streams can be driven with a quantum key consumption of only 256 bits / second, fundamentally solving the "scissors difference" problem between quantum key rate and data rate.
[0094] Real-time performance guarantee: Through the collaborative design of confidence propagation decoding, the end-to-end latency can be controlled within 100 microseconds of optical propagation delay, meeting the requirements of real-time communication. Multi-dimensional security mechanism: Through quantum key-driven time-hopping pattern generation, security is built on both quantum randomness and time uncertainty. Even if an attacker breaks one dimension, they still cannot break the other.
[0095] Co-fiber transmission compatibility: Through wavelength division multiplexing plus time division duplexing scheme of hollow fiber, quantum signals and classical signals can coexist in the same fiber without monopolizing fiber resources, which greatly reduces deployment costs.
[0096] Highly scalable: Based on mature technology components (hollow fiber, White Rabbit, QRNG chip, commercial QKD, FPGA), it can be quickly engineered and deployed at scale.
[0097] Resistance to quantum computing attacks: Security is built upon the fundamental principles of quantum mechanics through the physical layer security mechanism of quantum key distribution and the generation of time-jumping patterns driven by quantum true random numbers. The security of quantum key distribution is based on the Heisenberg uncertainty principle and the no-cloning theorem; no quantum computing attack can break the security mechanism based on physical laws. The unpredictability of the time-jumping patterns stems from quantum true random numbers. Even if an attacker possesses quantum computing capabilities, they cannot complete an exhaustive search of the time-jumping patterns within the seed refresh cycle (1 second) (the search space is...). N slots ×N wavelengths Typical value ≥ 5 × 10 4 The probability of an attacker successfully guessing the time-jump pattern is approximately 1.95 × 10⁻⁶. -5 .
[0098] The dynamic encoding matrix enhances the anti-interception capability: The encoding matrix and degree distribution function of the fountain code are dynamically generated in real time by a quantum true random seed. Even if the attacker intercepts all the encoded symbols, they cannot know the specific structure of the decoding matrix without the quantum key seed. They cannot reverse-engineer the original data by collecting a sufficient number of encoded symbols, which further increases the computational complexity of offline cracking.
[0099] Physical layer active defense mechanism: Real-time monitoring of the qubit error rate and photon loss rate of the quantum key distribution channel. When abnormal loss or error rate is detected, physical layer circuit breaking is triggered - immediately shutting down the data channel, destroying the current session key and issuing a security alarm, realizing "one-touch disconnection" physical layer active security defense.
[0100] The following describes an embodiment of the communication system.
[0101] The communication system described in this application, such as Figure 7 As shown, Figure 7 This is a schematic diagram of a communication system structure according to an embodiment, including a transmitter 01 and a receiver 02. The transmitter 01 and the receiver 02 are connected through an optical fiber channel 03. The transmitter 01 is configured to execute the steps of the data transmission method based on quantum key seed in any of the foregoing embodiments.
[0102] In some embodiments, such as Figure 7 As shown, the transmitter 01 may include: a data framing module 101, a fountain code encoding module 102, a quantum key acquisition module 103, a time-hopping pattern generation module 104, and a timing control and transmission module 105.
[0103] The data framing module 101 is used to divide the raw data stream into data frames; for example, the raw data stream can be divided into micro-burst frames (e.g., one frame per 16KB).
[0104] Fountain code encoding module 102 is used to perform fountain code encoding on each data frame to generate an encoded symbol stream.
[0105] For example, fountain codes can be LT codes or Raptor codes. LT codes are the first practical implementation of digital fountain codes. The encoded symbols are generated independently, and their performance is independent of channel parameters. Preferably, each frame of data is encoded with LT codes to generate an encoded symbol stream.
[0106] The quantum key acquisition module 103 is used to generate quantum key seeds.
[0107] For example, a quantum key seed can be obtained through a quantum key distribution system or a quantum random number generator for sharing with the receiving end; the quantum random number generator is a true random number source based on the principles of quantum mechanics, which can be implemented through a QKD system or a QRNG chip.
[0108] The time-hopping pattern generation module 104 is used to generate a time-hopping control sequence by means of a cryptographically secure pseudo-random number generator, with a quantum key seed as input; wherein the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information of each coded symbol.
[0109] Specifically, using the quantum key seed as input, a cryptographically secure pseudo-random number generator generates a time-hopping control sequence, which determines the transmission time slot and / or wavelength channel for each coded symbol.
[0110] For example, the time-skip pattern generation module 104 can construct an initial seed by taking the quantum key seed S (256 bits) and the current frame number F (32 bits) as inputs and performing a splicing operation. Seed = S || F (Total 288 bits), the time-skipping pattern generation module 104 is implemented in the FPGA using the following pipeline architecture: (a) Seed loading stage: The quantum key acquisition module provides a new 256-bit quantum key seed every second. After detecting the seed update signal, the time-skipping pattern generation module 104 loads the new quantum key seed into the internal register and concatenates it with the current frame number as the initial key and counter value of the AES-256-CTR encryption engine.
[0111] (b) Random number generation stage: The AES-256-CTR encryption engine employs a fully pipelined design. Each clock cycle (4ns@250MHz) completes one MixColumn transformation operation in a round of AES encryption. The latency of a single AES-256 encryption (14 rounds) is 14×4ns=56ns. Adding the pipeline latency of key expansion, the total latency is approximately 80ns. The encryption engine runs continuously, constantly outputting 128-bit random number blocks.
[0112] (c) Control information extraction stage: Control information for 8 coded symbols is extracted from each 128-bit random number block. The extraction logic is as follows: the 10-bit timeslot number of the first symbol is taken from bits [9:0] of the random number block, and the 6-bit wavelength number is taken from bits [15:10]. Subsequent symbols are shifted 16 bits to the right. The extracted control information is then delimited by (timeslot number). T i Wavelength channel number W i The information is written into the control information FIFO queue in the form of ).
[0113] (d) Timing calibration: The output of the time-jumping pattern generation module 104 is aligned with the clock signal of the first White Rabbit time synchronization module 107; the start time of each switching cycle is determined by the PPS (pulses per second) signal provided by the first White Rabbit time synchronization module 107 after frequency division, ensuring that the time-jumping patterns of the transmitter 01 and receiver 02 are precisely aligned in time; preferably, the quantum key seed is refreshed periodically at a refresh frequency of once per second, and the length of the quantum key seed is 256 bits each time.
[0114] The timing control and transmission module 105 is used to transmit the coded symbol stream to the receiving end through the transmission channel according to the time hopping control sequence.
[0115] Specifically, according to the time-hopping control sequence, the tunable laser is controlled to send coded symbols in designated time slots and / or wavelength channels.
[0116] In some embodiments, such as Figure 7 As shown, the receiver 02 may include: a time-skipping pattern regeneration module 201, a timing alignment receiving module 202, and a fountain code decoding module 203.
[0117] The time-skipping pattern regeneration module 201 is used to regenerate the time-skipping control sequence using the same quantum key seed and cryptographically secure pseudo-random number generator algorithm as the transmitter.
[0118] The timing alignment receiving module 202 is used to receive encoded symbols in the corresponding time slot and / or wavelength channel according to the time hopping control sequence.
[0119] The fountain code decoding module 203 is used to decode the collected encoded symbols to recover the original data frame.
[0120] In some embodiments, the optical fiber channel 03 includes a hollow fiber, which confines light to an air core for transmission, greatly suppressing nonlinear effects.
[0121] In some embodiments, reference Figure 8 As shown, Figure 8 This is a schematic diagram of a communication system structure according to another embodiment; the transmitting end 01 may also include a wavelength division multiplexing module 106 for realizing the multiplexing of the data channel (C-band) and the quantum key channel (O-band); correspondingly, the receiving end 02 may also include a wavelength demultiplexing module 204 for realizing the demultiplexing of the data channel (C-band) and the quantum key channel (O-band).
[0122] In some embodiments, such as Figure 8 As shown, the first White Rabbit time synchronization module 107 of the transmitting end 01 and the second White Rabbit time synchronization module 205 of the receiving end 02 achieve sub-nanosecond clock synchronization.
[0123] In some embodiments, the interface definitions between the various modules of the transmitter 01 can be as follows: The data frames between the data framing module 101 and the fountain code encoding module 102 are transmitted using the standard AXI-Stream bus protocol. The data width is 512 bits, and the accompanying signals include control information such as frame start, frame end, and number of valid bytes.
[0124] The encoding symbols between the fountain code encoding module 102 and the time jump pattern generation module 104 are transmitted in the form of symbol index + symbol data. The symbol index is used by the time jump pattern generation module to calculate the corresponding time slot and wavelength.
[0125] Control information between the time-skip pattern generation module 104 and the timing control and transmission module 105 is expressed in terms of (time slot number). T i Wavelength channel number W i The encoded symbols are transmitted in triplet form through a FIFO queue with a queue depth of not less than 1024 to buffer the rate fluctuations between the generation and transmission of encoded symbols.
[0126] The quantum key seed between the quantum key acquisition module 103 and the time-skipping pattern generation module 104 is transmitted in the form of 256 bits of parallel data, accompanied by a seed validity signal and a seed refresh indication signal.
[0127] In some embodiments, the communication system of this application may employ time-division duplex mode, wherein encoded symbols are transmitted during the data window period, quantum key signals are transmitted during the quantum window period, and the data channel is completely silent during the quantum window period.
[0128] In some embodiments, the fountain code encoding module 102 and the fountain decoding module 203 can be implemented based on FPGA, with encoding and decoding delays in the nanosecond range.
[0129] Among them, the fountain code encoding module 102 adopts LT code, and the original number of symbols is set to K=1024. The encoder randomly draws the degree from the robust soliton distribution. d (1≤ d ≤ K ),from K Randomly selected from the original data symbols d Each element undergoes an XOR operation to generate one encoded symbol.
[0130] The fountain code decoding module 203 employs a belief propagation algorithm to find the encoded symbol with a degree of 1, immediately decodes the original encoded symbol, and removes the decoded original encoded symbol from the XOR operation of other encoded symbols; this process is repeated until all original encoded symbols are decoded. The decoding overhead ε is controlled within 3%-5%.
[0131] For example, the fountain code encoding module 102 is implemented in the FPGA using the following architecture: The fountain code encoding module 102 consists of three parts: a degree distribution sampler (DDS), a sign selector, and an XOR operator. The degree distribution sampler uses a lookup table (LUT) to sample robust soliton distributions, pre-computes and stores the cumulative distribution function (CDF) of K degree values, and quickly determines the degree by comparing random numbers with the CDF table. d The single sampling delay is 1 clock cycle (4ns); the symbol selector uses a linear feedback shift register (LFSR) to pseudo-randomly select d symbols from K original coded symbols, with a selection delay of... d The XOR operator uses a tree-structured XOR operation to perform an XOR operation on the selected d encoded symbols, with a delay of log2(d) clock cycles. For a typical configuration with K=1024 and an average degree d≈15, the delay for a single encoding operation is approximately 20-30 clock cycles (80-120ns). Regarding resource estimation, for a K=1024 configuration, the fountain code encoding module 102 requires approximately 5000 LUTs and 2000 registers.
[0132] For example, the fountain code decoding module 203 is implemented in an FPGA using the following architecture: The fountain code decoding module 203 employs a hardware-accelerated implementation of the belief propagation algorithm. It maintains a K-bit decoding state vector (each bit indicating whether the corresponding original symbol has been decoded) and a degree array (recording the current degree of each encoded symbol). In each iteration, the module scans all undecoded encoded symbols, identifies symbols with a degree of 1, decodes their corresponding original symbols, updates the state vector, and removes the original symbol from the XOR operation of other encoded symbols. The scanning logic uses a parallel comparator array, and a single iteration can be completed within K / 8 clock cycles. For K=1024, a single iteration takes approximately 128 clock cycles (512ns), and typical decoding requires 10-15 iterations, with a total decoding latency of approximately 5-8μs. Regarding resource estimation, for a K=1024 configuration, the fountain code decoding module 203 requires approximately 15,000 LUTs, 8,000 registers, and 32KB of block RAM (BRAM).
[0133] In some embodiments, the transmitting end 01 and the receiving end 02 communicate through a co-fiber transmission subsystem of hollow optical fiber, which is hollow photonic bandgap fiber (NANF or anti-resonant type) with a loss of <0.5 dB / km@1550nm.
[0134] For example, the selection of hollow optical fiber can be as follows:
[0135] For example, the selection parameters for a wavelength division multiplexer can be as follows: Insertion loss: <1.0dB (C-band to O-band); Isolation: >60dB (between C-band and O-band); Channel bandwidth: C-band ≥ 30nm, O-band ≥ 20nm; Operating temperature range: -5°C to +55°C.
[0136] For example, the optical amplifier can be configured as follows: Data channel (C-band): Erbium-doped fiber amplifier (EDFA) is used, with a gain of 20-30 dB and a noise figure of <5 dB. Quantum channel (O-band): No optical amplifier is configured (single-photon signals cannot be amplified), and reception is guaranteed by low-loss optical fiber and high-efficiency detector.
[0137] For example, wavelength selection can be as follows: Data channels: C-band (1530-1565 nm), 50 wavelength channels, 800 Gbps per wavelength, total capacity 40 Tbps; Quantum key channel: O-band (1270-1330 nm), single-photon level transmission; Synchronization channel: Shares fiber with data / quantum signals, transmits time signals via the White Rabbit protocol; For example, the timing settings can be as follows: Data window: 90% duty cycle, sending data fragments (high power); Quantum window: 10% duty cycle, data channel silent, transmitting quantum key signals (single photon level). Switching cycle: microseconds, completely transparent to upper-layer applications.
[0138] In some embodiments, the first White Rabbit time synchronization module 107 and the second White Rabbit time synchronization module 205 are extended based on the Precision Time Protocol (PTP). By introducing synchronous Ethernet and digital dual-mixer time difference measurement (DDMTD) technology, sub-nanosecond time deviation and nanosecond-level synchronization uncertainty between the master and slave clocks are achieved. Both the transmitter 01 and the receiver 02 are equipped with WR (White Rabbit) switches or WR slave nodes to transmit time signals through optical fibers. Rubidium atomic clocks or GPS are used as backup reference sources and automatically switch when the master synchronization link fails.
[0139] refer to Figure 9 As shown, Figure 9 This is a schematic diagram of the architecture of a White Rabbit time synchronization module. The architecture design between time synchronization modules can be as follows: (a) WR network topology: In a point-to-point communication scenario, receiver 02 is configured with a WR master node (Grandmaster), and sender 01 is configured with a WR slave node (Slave). The master node sends synchronization messages to the slave node through optical fiber. The slave node calculates the time deviation and transmission delay with the master node through bidirectional time comparison and calibrates its local clock accordingly.
[0140] (b) Synchronization accuracy verification: After system deployment, a Time Interval Analyzer (TIA) should be used to measure the synchronization accuracy between master and slave nodes. The acceptance criteria are: during 24 hours of continuous operation, the time synchronization error should be <500ps for more than 95% of the time synchronizations and <1ns for the maximum synchronization error.
[0141] (c) Redundancy design: The master node is equipped with a rubidium atomic clock (frequency stability better than 1×10⁻⁶). -11The system uses a local frequency reference (@1s) and simultaneously receives GPS / BeiDou satellite signals as a backup time source. When the WR fiber optic link is interrupted, the system automatically switches to GPS / BeiDou time synchronization mode to maintain synchronization accuracy at the microsecond level (at this time, the time slot width of the time hopping pattern needs to be widened accordingly, or the system degrades to non-time hopping mode). When the fiber optic link is restored, the system automatically relocks WR synchronization.
[0142] (4) Long-distance compensation: For fiber optic links exceeding 50km, changes in fiber length due to ambient temperature variations (approximately 1ppm / °C) can cause a slow drift in transmission delay; the WR protocol automatically tracks and compensates for this drift through continuous bidirectional time comparisons without human intervention.
[0143] In some embodiments, the parameter settings of the communication system of this application can be as follows:
[0144] The interrelationships between the parameters in the table above can be summarized as follows: The relationship between K value and latency: The smaller the K value (e.g., 512), the fewer the number of encoded symbols per frame and the lower the decoding latency, which is suitable for latency-sensitive scenarios (e.g., financial transactions); The larger the K value (e.g., 2048), the higher the encoding efficiency, but the higher the single-frame collection latency, which is suitable for high-throughput scenarios (e.g., data center interconnection).
[0145] The relationship between ε value and reliability: The smaller the ε value (e.g., 2%), the higher the transmission efficiency, but the lower the packet loss resistance; the larger the ε value (e.g., 8%), the stronger the packet loss resistance, but the more transmission redundancy. In actual deployment, the ε value should be determined based on the channel bit error rate statistics.
[0146] N slots Relationship with security: N slots The larger the number of slots, the more difficult it is for attackers to guess the slot number (the search space is 1 / N slots Higher security requires higher time synchronization accuracy. Those skilled in the art can determine the specific values of each parameter through conventional experiments, based on the above constraints and the channel conditions and security requirements of the actual application scenario.
[0147] In some embodiments, the overall architecture of the communication system of this application can adopt a modular design, with each module connected through a standardized interface: wherein: Data interface: The data framing module 101 uses a 100GE / 400GE optical module interface with the external network, which conforms to the IEEE 802.3 standard.
[0148] Inter-module interface: The FPGA modules use the AXI-Stream bus protocol with a data width of 512 bits. Accompanying signals include control information such as frame start, frame end, and number of valid bytes.
[0149] Optical interface: The wavelength division multiplexing module 106 and the hollow fiber use a standard FC / APC fiber optic connector with an insertion loss of <0.5dB.
[0150] Time synchronization interface: The first White Rabbit time synchronization module 107 and the second White Rabbit time synchronization module 205 are connected to the master and slave nodes through an optical fiber time signal interface, with a synchronization accuracy better than 1ns.
[0151] Preferably, a 2U rack-mount device is deployed in a standard 19-inch rack, with an operating temperature range of 0°C to 40°C and a total power consumption of <500W.
[0152] In some embodiments, the communication system of this application may also be equipped with a fault handling mechanism, which may specifically include the following: (1) Quantum key seed synchronization failure handling mechanism: When receiver 02 fails to receive the quantum key seed update signal from sender 01, or when receiver 02 does not detect a valid seed update signal at the preset seed refresh time, receiver 02 continues to use the quantum key seed from the previous cycle for decoding, and at the same time sends a seed retransmission request to sender through the transmission channel. If the retransmission request fails three times in a row, the quantum channel is determined to be abnormal, a security alarm is triggered, and data transmission is suspended.
[0153] (2) Handling mechanism for pattern loss during jump: When the timing pattern of receiver 02 deviates from that of transmitter 01 due to clock drift or accumulated synchronization error, receiver 02 may fail to receive the coded symbol in the expected time slot or detect a signal in an unexpected time slot. Receiver 02 then initiates a sliding window search mode, scanning for valid signals within ±10 time slots and re-locking the timing pattern phase using the frame header identifier (the first coded symbol of each data frame carries a special identifier). If the phase cannot be locked after scanning more than 100 time slots, a resynchronization process is triggered.
[0154] (3) Fountain code decoding failure handling mechanism; When the receiver 02 receives K(1+ε) encoded symbols and the confidence propagation algorithm has iterated for more than the preset maximum number of times (e.g., 50 times) without completing the decoding, the state machine timeout or decoding failure flag of the fountain code decoding module 203 is set. The receiver 02 continues to collect more encoded symbols (increasing redundancy ε). When K(1+2ε) symbols are collected, the decoding process is restarted. If it still fails, the receiver requests the sender to retransmit the current data frame through the transmission channel.
[0155] (4) Data channel optical power anomaly handling mechanism: When receiver 02 detects that the optical power of the data channel is lower than a preset threshold, it samples the received optical power of each wavelength channel in real time through the optical power monitoring module (OPM). If the optical power of a single channel drops by more than 3dB, a channel-level alarm is triggered and the channel is marked as unavailable. The system automatically switches the service of the channel to a backup channel (if any). If the total optical power drops by more than 5dB, a link-level alarm is triggered, and the system degrades to non-time-hopping mode (transmission according to a fixed timing sequence) to reduce system complexity and improve fault tolerance.
[0156] (5) Quantum channel physical layer circuit breaker mechanism: When the receiver detects that the quantum bit error rate (QBER) of the quantum key distribution channel exceeds a preset security threshold (preferably 8%), or the photon loss rate changes by more than a preset threshold (preferably 3 times the normal value) within a unit time window (preferably 100ms), it is determined that there is active eavesdropping behavior in the quantum key channel.
[0157] When active eavesdropping is detected, the physical layer circuit breaker is triggered, immediately stopping the reception of encoded symbols and data processing; the quantum key seed used in the current session and all time-hopping control sequences derived therefrom are destroyed; a security alarm is sent to the network management system, the attack timestamp and abnormal parameters are recorded, and the system enters a secure standby state.
[0158] After the circuit breaker is triggered, both communicating parties need to re-execute QKD negotiation to generate a new quantum key seed before communication can be restored. The QBER security threshold and photon loss rate mutation threshold can be configured according to the channel quality of the actual deployment scenario.
[0159] This application utilizes a truly random quantum key seed to drive a cryptographically secure pseudo-random number generator to generate a time-hopping control sequence, enabling out-of-order transmission of encoded symbols in the time-frequency dimension. Combined with dynamic fountain code encoding, the receiver can decode by collecting any sufficient subset, eliminating fragmentation waiting delays. The quantum key seed is used for time-series concealment and dynamic encoding matrix driving, consuming only 0.256 kbps and supporting Tbps-level data co-fiber transmission. Hollow-core fiber and wavelength division / time division multiplexing are used to suppress nonlinear noise, and the White Rabbit protocol is combined to achieve sub-nanosecond synchronization between the transmitter and receiver, thus constructing a three-in-one architecture of content encryption, key distribution, and time-series concealment. The end-to-end latency is less than 60 μs, effectively solving the rate gap between quantum key seed and high-speed data, and is suitable for high real-time security scenarios such as finance and government affairs.
[0160] The following describes an embodiment of a computer-readable storage medium.
[0161] The computer-readable storage medium provided in this application is used to implement the related functions of a MEMS inertial navigation data processing method for indoor robot positioning. This computer-readable storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded by a processor and executes the steps of the data transmission method based on a quantum key seed in any embodiment.
[0162] In an exemplary embodiment, the computer-readable storage medium may be a non-transitory computer-readable storage medium that includes instructions, such as a memory that includes instructions. For example, a non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0163] The above description is only a partial embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A data transmission method based on quantum key seeds, applied at the transmitting end, characterized in that, include: The original data stream is divided into data frames, and each data frame is fountain-coded to generate an encoded symbol stream; Generate a truly random quantum key seed and send it to the receiving end; Using the quantum key seed as input, a time-hopping control sequence is generated by a cryptographically secure pseudo-random number generator; wherein, the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information for each coded symbol; The encoded symbol stream is transmitted to the receiving end through the transmission channel according to the time-hopping control sequence; wherein the receiving end recovers the original data stream based on the fountain code encoding, the quantum key seed, and the data frame of the original data stream from the encoded symbol stream.
2. The data transmission method based on quantum key seed according to claim 1, characterized in that, The raw data stream is divided into data frames, including: Determine the current data transmission latency parameters based on data throughput requirements; Calculate the data frame size based on the delay parameters; The original data stream is divided into data frames according to the data frame size.
3. The data transmission method based on quantum key seed according to claim 1, characterized in that, Fountain code encoding is performed on each data frame to generate an encoded symbol stream, including: Each data frame is continuously encoded, from K Randomly selected from the original data symbols d Each element undergoes an XOR operation to generate an encoded symbol, forming an encoded symbol stream; where... 1≤d≤K .
4. The data transmission method based on quantum key seed according to claim 1, characterized in that, Also includes: The channel error rate, calculated and fed back by the receiver in real time, is obtained through the feedback channel, and the decoding overhead ε value of the fountain code is dynamically adjusted according to the channel error rate.
5. The data transmission method based on quantum key seed according to claim 1, characterized in that, Using the quantum key seed as input, a time-jump control sequence is generated through a cryptographically secure pseudo-random number generator, including: Initialize the cryptographically secure pseudo-random number generator using the quantum key seed and the current frame number as input; For each encoded symbol, two random numbers are drawn from the cryptographically secure pseudo-random number generator, and the time slot number and wavelength channel number are calculated based on the two random numbers to obtain the time hopping control sequence; The formulas for calculating the time slot number and wavelength channel number are as follows: T i =r 1 mod N slots W i = r 2 mod N wavelengths in, T i The timeslot number, r 1 For a random number, N slots The total number of time slots, W i For wavelength channel number, r 2 For another random number, N wavelengths Number of wavelength channels mod It is the modulo operator.
6. The data transmission method based on quantum key seed according to claim 1, characterized in that, The transmission channel includes a data channel and a quantum key channel; wherein the data channel uses the C-band and the quantum key channel uses the O-band, and the data channel and the quantum key channel achieve wavelength isolation through wavelength division multiplexing.
7. The data transmission method based on quantum key seed according to claim 1, characterized in that, The encoded symbol stream is transmitted to the receiving end using a time-division duplex method. Specifically, encoded symbols are sent during the data window, and the quantum key signal corresponding to the quantum key seed is transmitted during the quantum window; and the data channel is silent during the quantum window.
8. The data transmission method based on quantum key seed according to claim 7, characterized in that, Also includes: The switching period of the time-division duplex of the optical fiber channel is determined based on the current data transmission delay parameters and the quantum key seed.
9. The data transmission method based on quantum key seed according to claim 6, characterized in that, The transmission of the quantum key signal corresponding to the quantum key seed during the quantum window includes: Lasers that shut down the data channel; Waiting for the residual photons in the optical path to dissipate; Send the quantum key signal corresponding to the quantum key seed. Resume the transmission of the encoded symbols of the data channel.
10. The data transmission method based on quantum key seed according to claim 1, characterized in that, Also includes: The encoding matrix of the fountain code and the generation parameters of the degree distribution function are generated in real time using the quantum key seed and the cryptographically secure pseudo-random number generator.
11. The data transmission method based on quantum key seed according to claim 1, characterized in that, The quantum key seed is refreshed at a frequency of 0.5 to 10 times per second, and the seed length is 128 to 512 bits each time. The clock synchronization between the sending and receiving ends is achieved through the White Rabbit time synchronization protocol; The value of K ranges from 512 to 2048; The decoding overhead ε ranges from 3% to 5%.
12. The data transmission method based on quantum key seed according to any one of claims 1 to 11, characterized in that, The receiving end regenerates the same time hopping control sequence as the sending end based on the quantum key seed and the cryptographically secure pseudo-random number generator; it receives encoded symbols in the corresponding time slot channel and / or wavelength channel according to the time hopping control sequence, and performs fountain code decoding on the collected encoded symbols to recover the data frames of the original data stream.
13. A communication system comprising a transmitter and a receiver, wherein the transmitter and receiver are connected via an optical fiber channel, characterized in that, The transmitting end is configured to perform the steps of the data transmission method based on quantum key seed as described in any one of claims 1 to 12.
14. The communication system according to claim 13, characterized in that, The sending end includes: The data framing module is used to divide the raw data stream into data frames; The fountain code encoding module is used to perform fountain code encoding on each data frame to generate an encoded symbol stream; The quantum key acquisition module is used to generate a quantum key seed and send it to the receiving end; A time-hopping pattern generation module is used to generate a time-hopping control sequence by means of a cryptographically secure pseudo-random number generator, using the quantum key seed as input; wherein the time-hopping control sequence includes at least the transmission time slot information and / or wavelength channel information for each coded symbol; The timing control and transmission module is used to transmit the coded symbol stream to the receiving end through the transmission channel according to the time hopping control sequence.
15. The communication system according to claim 14, characterized in that, The transmitting end also includes: a wavelength division multiplexing module and a first White Rabbit time synchronization module; The receiver also includes: a wave decomposition and multiplexing module and a second White Rabbit time synchronization module; The wavelength division multiplexing module and the wavelength demultiplexing module are used to realize the multiplexing and demultiplexing of the data channel and the quantum key channel, respectively; the first White Rabbit time synchronization module and the second White Rabbit time synchronization module are used to realize clock synchronization between the transmitting end and the receiving end.
16. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded by a processor and the processor executes the steps of the data transmission method based on quantum key seed as described in any one of claims 1-12.