Key switching method, device, terminal and computer-readable storage medium
By configuring and sending key switching parameters in the OTN network, the symmetry and delay of key switching are achieved, and the service interruption caused by failure of key synchronization switching is solved, ensuring the continuity of data transmission and user experience.
Patent Information
- Application Number
- CN201911097227.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-11-11
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2039-11-11
AI Technical Summary
In OTN networks, when the key timing synchronization switching fails, it may cause service interruption and affect user data transmission. It is difficult for the prior art to effectively handle this situation.
By configuring the first key switching parameters and sending them to the target terminal, key switching is realized, ensuring the symmetry of the encryption and decryption ends, and delaying the key switching time to avoid service interruption.
When the key synchronization switching fails, by delaying the key switching, the continuity of service data transmission is ensured, the user experience influence is avoided, and the reliability of the key switching process is improved.
Smart Images

Figure CN112787802B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to, but are not limited to, the field of communication transmission, and specifically, relate to, but are not limited to, a key switching method, device, and computer-readable storage medium. Background Art
[0002] With the rapid development of network communication technology, various types of services are emerging, bandwidth demand and network capacity are showing explosive growth, and more and more services are beginning to use OTN networks (Optical Transmission Network) to transmit data. However, in the process of the continuous popularization of OTN networks, it is inevitable to encounter services with higher requirements for the security of network transmission. Encrypting data transmitted in OTN networks and improving the security of OTN network data transmission have become one of the main directions of OTN network development.
[0003] OTN service encryption can be divided into two key sources: internally generated keys and externally acquired keys. Due to the development of quantum key technology, external key provision represented by quantum keys has gradually entered the practical use stage. Since the quantum key mechanism does not have the risk of losing keys during key transmission, the security of externally acquired quantum keys is obviously more advantageous than the internal self-negotiation generated keys. With the timed key switching function supported by OTN itself, as the key switching speed increases, it can theoretically approach the security level of one-time one-key. However, the key switching function itself also requires that the encryption end and the decryption end can synchronize the key switching well to ensure that paired keys are used to encrypt and decrypt the service. However, this key synchronization process may cause the failure of key timing synchronization switching due to some abnormal conditions, resulting in abnormalities in the decryption process, causing direct interruption of services and affecting user data transmission. Therefore, it is urgent to propose a method that can be selected according to user needs to ensure that corresponding processing is performed after the failure of key timing synchronization switching, without affecting user experience. Summary of the invention
[0004] The key switching method and device provided by the embodiment of the present invention mainly solve the technical problem of ensuring that selection can be made according to user needs and ensuring that the key timing and synchronization switching can meet user needs.
[0005] In order to solve the above technical problems, an embodiment of the present invention provides a key switching method, comprising:
[0006] configuring a first key switching parameter, and sending the first key switching parameter to a target terminal as a key switching parameter of the target terminal;
[0007] Key switching is performed according to the first key switching parameter.
[0008] The embodiment of the present invention also provides a key switching device, comprising: a configuration unit, a transmission unit and a processing unit;
[0009] A configuration unit, configured to configure a first key switching parameter;
[0010] A transmission unit, configured to send the first key switching parameter to a target terminal as a key switching parameter of the target terminal;
[0011] A processing unit is used to perform key switching according to the first key switching parameter.
[0012] An embodiment of the present invention further provides a terminal, the terminal comprising a processor and a memory;
[0013] The processor is used to execute one or more computer programs stored in the memory to implement the steps of the key switching method as described above.
[0014] An embodiment of the present invention further provides a computer storage medium, wherein the computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the key switching method as described above.
[0015] The beneficial effects of the present invention are:
[0016] According to the key switching method, device, terminal and computer storage medium provided by the embodiments of the present invention, by configuring the first key switching parameter, the key switching is performed according to the first key switching parameter, and the first key switching parameter is sent to the target terminal as the key switching parameter of the target terminal; in certain implementation processes, the symmetry of encryption and decryption at both ends can be guaranteed, and the synchronous switching of the keys can be realized at the same time, ensuring that the business is not affected during the key switching process.
[0017] Other features and corresponding beneficial effects of the present invention are described in the latter part of the specification, and it should be understood that at least part of the beneficial effects become obvious from the description in the specification of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 Schematic diagram of a key switching method according to the first embodiment of the present invention;
[0019] Figure 2 The process diagram of the key switching method according to the second embodiment of the present invention is as follows Figure 1 ;
[0020] Figure 3 The process diagram of the key switching method according to the second embodiment of the present invention is as follows Figure 2 ;
[0021] Figure 4 The process diagram of the key switching method according to the second embodiment of the present invention is as follows Figure 3 ;
[0022] Figure 5 Schematic diagram of a key switching method according to Embodiment 3 of the present invention;
[0023] Figure 6 This is a schematic diagram of the structure of a key switching device according to Embodiment 5 of the present invention;
[0024] Figure 7 This is a schematic diagram of the structure of the encryption configuration content under normal encryption in Embodiment 5 of the present invention;
[0025] Figure 8 This is a structural diagram of the encrypted configuration content under abnormal operation according to the fifth embodiment of the present invention. DETAILED DESCRIPTION
[0026] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the following is a further detailed description of the embodiments of the present invention through specific implementation methods combined with the accompanying drawings. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0027] Embodiment 1:
[0028] In order to solve the problem of ensuring that the key can be switched synchronously at the timing according to the user's needs after the selection is made according to the needs, thereby meeting the user's needs, an embodiment of the present invention proposes a key switching method.
[0029] See also Figure 1 , Figure 1 The following is a flow chart of a key switching exception handling method according to an embodiment of the present invention, which is as follows:
[0030] S101. Configure a first key switching parameter, and send the first key switching parameter to a target terminal as a key switching parameter of the target terminal.
[0031] In the embodiment of the present invention, the first key switching parameter is configured as the source end, which serves as the encryption end, and the target terminal is the decryption end.
[0032] In the embodiment of the present invention, the key switching process involves two ends, the first terminal and the second terminal, as two ends of encryption, the service is bidirectional, in one service direction, the first terminal is the encryption end, the second terminal is the decryption end, at this time, the first terminal is the source end, and the second terminal is the target terminal; in the other service direction, the second terminal is the encryption end, the first terminal is the decryption end, at this time, the second terminal is the source end, and the first terminal is the target terminal. It should be noted that the encryption processing in the two directions is relatively independent.
[0033] For bidirectional services, the encryption configuration of the first terminal as the encryption end is determined by the encryption configuration of the first terminal, and the encryption configuration of the second terminal as the encryption end is determined by the encryption configuration of the second terminal. The two directions are relatively independent. In this way, when the encryption configurations of the first terminal and the second terminal are different, the configurations of the one-way encryption end and the decryption end are guaranteed to be consistent, and the key switching parameters of the encryption end and the decryption end of the one-way service encryption function are consistent.
[0034] In the embodiment of the present invention, the source terminal sends the first key switching parameter to the target terminal, and the target terminal performs corresponding encryption configuration according to the first key switching parameter, thereby ensuring the symmetry of encryption and decryption at both ends and realizing synchronous switching of keys.
[0035] In this embodiment, the first key switching parameters include the first key switching period, encryption enable, encryption mode, key source, key ID and other related parameters that affect the symmetry of the encryption configuration.
[0036] It should be noted that the key switching parameters can be sent to the target terminal through the internal communication channel. Specifically, the key switching parameters can be represented by the content of a fixed overhead, directly using the overhead value, such as STAT overhead processing, or the overhead value in the form of a multi-frame, such as PSI overhead processing; the overhead channel can also be used to define encryption-related protocol messages within the channel, such as GCC overhead processing.
[0037] S102: Perform key switching according to a first key switching parameter.
[0038] In this embodiment, the source terminal switches the encryption key according to the first key switching parameter, and correspondingly, the target terminal synchronously switches the decryption key according to the first key switching parameter.
[0039] It should be noted that the first key switching parameter is used as an indication of key switching and is also used to ensure that the encryption configurations of the source and target terminals are consistent. After the source terminal configures the first key switching parameter, it needs to send the first key switching parameter to the target terminal.
[0040] The following describes the key switching method in detail by taking the first key switching parameter being the first key switching period as an example.
[0041] In the embodiment of the present invention, an OTN (Optical Transmission Network) transmission device is used to implement the encryption and decryption functions of the payload. It should be understood that the methods for encrypting and decrypting OTN data on both sides of the OTN network are mainly divided into asymmetric algorithms and symmetric algorithms. In the embodiment of the present invention, a symmetric encryption algorithm is used; at the same time, a pair of encryption keys and decryption keys are synchronously provided to the encryption end and the decryption end through quantum key distribution (Quantum Key Distribution, QKD) technology.
[0042] For the OTN transmission system, key switching can be performed at a specific OTN multiframe boundary. This method is convenient for hardware implementation. In the embodiment of the present invention, the configured first key switching parameter is the first key switching period, and what is actually sent to the target terminal is the first key switching trigger value. The relationship between the first key switching period and the first key switching trigger value is specifically: starting the multiframe counter, and the multiframe counter is used to calculate the first key switching trigger value according to the first key switching period.
[0043] In an embodiment of the present invention, the first key switching period is pre-set. When data transmission begins, the multi-frame counter is started. The first key switching trigger value of the multi-frame counter for key switching can be calculated according to the set first key switching period. The first key switching trigger value can be used as an indication of switching the key when the first key switching period arrives, that is, the key switching can be performed directly after the multi-frame counter reaches the first key switching trigger value.
[0044] It should be noted that the multi-frame counter transmits the multi-frame period count value as a monitoring indicator of key switching, and the key switching trigger value is a threshold indicator of key switching. The multi-frame period count value can ensure that the decryption end and the encryption end achieve processing synchronization, and the key switching trigger value can ensure that the encryption end and the decryption end switch keys at the same time.
[0045] The source and target terminals implement simultaneous key switching according to the multi-frame counter and the key switching trigger value, thereby ensuring lossless key switching process.
[0046] During the key switching process, the source and target terminals are required to synchronize the key switching well to ensure that paired keys are used to encrypt and decrypt the business. However, this key synchronization process may cause key synchronization switching failure due to some abnormal situations. In the case of synchronization failure, no new key is available to perform the switch. Usually, there are two ways to deal with it. One is to continue to use the previous key in an abnormal situation and keep the previous key unchanged. This non-updated key policy will reduce security and can be called the "business priority" mode; the other is to continue to update the key independently, but due to the existence of abnormalities, there is no normal key, which will cause business interruption due to key asymmetry, but ensure security requirements, which is called the "security priority" mode. That is, in the key switching strategy, users are allowed to set it to business priority or security priority according to the security requirements of the data they need to transmit.
[0047] In order to ensure that the service is not interrupted when an abnormality occurs in the service priority mode, when the source end key application fails, the first key switching parameter is changed to the second key switching parameter to delay the key switching time, and the second key switching parameter is sent to the target terminal as the decryption key switching parameter of the target terminal. In this way, the source end and the target terminal can synchronously switch the key according to the second key switching parameter.
[0048] Specifically, in business priority mode, when the source end key application fails, the key cannot be switched according to the configured first key switching cycle, and the encryption key fails to be obtained. When the first key switching cycle is reached, the source end will modify the first key switching trigger value, and modify the first key switching trigger value to the second key switching trigger value to delay the key switching time, and send the second key switching trigger value to the target terminal.
[0049] It should be understood that since the key has not been updated, the previous set of paired keys is still used, which will not affect the encryption and decryption processing and can ensure the normal transmission of business data.
[0050] In some application scenarios of the embodiments of the present invention, when the key is not switched on time, a key switching abnormality warning is generated to notify the user.
[0051] It should be noted that by modifying the key switching trigger value, the key switching period will be changed accordingly. Specifically, increasing the key switching trigger value will extend the key switching period; decreasing the key switching trigger value will shorten the key switching period. If the key switching trigger value is changed, the key switching period will also be changed accordingly. In order to keep the business uninterrupted, the key switching period is extended, that is, in abnormal circumstances, a group of paired keys before the abnormality are still used for business data transmission. Therefore, the changed key switching trigger value should be greater than the preset key switching trigger value, increase the value, and delay the key switching time.
[0052] In an embodiment of the present invention, when an exception occurs in the security priority mode, the source terminal key application fails, and the first key switching parameter is sent to the target terminal. The target terminal cannot obtain the key under the first key switching parameter, resulting in an exception in the encryption and decryption function, thereby interrupting the service between the source and target terminals.
[0053] Specifically, when an exception occurs in the key application of the source end, the key cannot be switched according to the configured first key switching cycle, and the encryption key cannot be obtained. When the first key switching cycle is reached, the source end notifies the target terminal according to the first key switching parameters, and the target terminal performs key switching according to the first key switching parameters. However, there is no available key under the first key switching parameters, and the encryption and decryption functions cannot be implemented normally. In order to ensure the security of business data transmission, the business is interrupted.
[0054] In some application scenarios of the embodiments of the present invention, there are no available keys, and the encryption and decryption functions cannot be implemented normally, resulting in business interruption, generating a key switching abnormality warning and a business interruption warning to notify the user.
[0055] In an embodiment of the present invention, when the first key switching cycle is reached, the first key switching trigger value will not be modified, and the target terminal will be notified according to the first key switching parameter. The target terminal performs key switching according to the first key switching cycle. There is no available key under the first key switching parameter, and the encryption and decryption functions cannot be implemented normally. In order to ensure the security of business data transmission, the business will be interrupted.
[0056] In the embodiment of the present invention, when the first terminal as the encryption end has a key application exception, the first terminal as the decryption end will also have problems when performing decryption processing. It should be noted that the current quantum key application mechanism can ensure that when the first terminal decrypts abnormally, the second terminal encryption application will also be in an abnormal state. Therefore, there is no need to add a separate processing flow, and the reverse second terminal encryption abnormality processing flow can be used.
[0057] The key switching method provided in an embodiment of the present invention configures a first key switching parameter, performs key switching according to the first key switching parameter, and sends the first key switching parameter to a target terminal as a key switching parameter of the target terminal; in certain implementation processes, the symmetry of encryption and decryption at both ends can be guaranteed, and synchronous switching of keys can be achieved at the same time, ensuring that the business is not affected during the key switching process.
[0058] Embodiment 2:
[0059] Based on the above embodiments, the embodiment of the present invention provides a detailed flowchart of the key switching method in the service priority mode, see Figure 2 , specifically including the following steps:
[0060] S201, the first terminal configures a first key switching parameter and sends the first key switching parameter to the second terminal;
[0061] S202, the second terminal performs corresponding encryption configuration according to the received first key switching parameter;
[0062] S203, the first terminal switches the encryption key according to the first key switching parameter, and the second terminal simultaneously switches the decryption key according to the first key switching parameter;
[0063] S204: When the key application of the first terminal fails, the first key switching parameter is changed to a second key switching parameter to delay the key switching time, and the second key switching parameter is sent to the second terminal;
[0064] S205. The second terminal changes a corresponding encryption configuration according to the received second key switching parameter.
[0065] In the embodiment of the present invention, the first key switching parameter is a first key switching period.
[0066] In an embodiment of the present invention, when the key application of the first terminal fails, the key cannot be switched according to the configured first key switching period, and the encryption key cannot be obtained. When the first key switching period is reached, the first terminal will modify the first key switching trigger value, modify the first key switching trigger value to the second key switching trigger value to delay the key switching time, and send the second key switching trigger value to the second terminal.
[0067] In the embodiment of the present invention, after receiving the changed second key switching trigger value, the second terminal makes corresponding changes, that is, follows the configuration of the first terminal and also postpones the key switching time to ensure that the configuration of the first terminal and the second terminal are consistent.
[0068] It should be understood that since the key has not been updated, the previous set of paired keys is still used, which will not affect the encryption and decryption processing and can ensure the normal transmission of business data.
[0069] In some application scenarios of the embodiments of the present invention, when the key is not switched on time, a key switching abnormality warning is generated to notify the user.
[0070] In some application scenarios of the embodiments of the present invention, there are some special operations in the service priority mode, such as encryption configuration changes, modification of key update cycle, or single board software upgrades, single board resets, etc. These special operations require special processing to ensure that the service is not interrupted. In order to ensure that the service is not interrupted, a key switching method for special operations without interrupting the service in the service priority mode is proposed. Please refer to Figure 3 , the specific process is as follows:
[0071] S301: A first terminal receives a special operation command and estimates the time required for the special operation.
[0072] In the embodiment of the present invention, special operations such as encryption configuration change, key update cycle modification, single board software upgrade, single board reset, etc. will affect the encryption and decryption processing. Therefore, when the first terminal receives a special operation command, the time required for the special operation can be estimated.
[0073] S302: The first terminal changes the first key switching parameter to a third key switching parameter according to the estimated time to delay the key switching time.
[0074] Specifically, the first key switching trigger value is modified to the third key switching trigger value according to the estimated time, and accordingly, the first key switching period is also changed to the third key switching period, delaying the key switching time, thereby ensuring that key switching does not occur during special operations.
[0075] S303: The first terminal sends the third key switching parameter to the second terminal, and sends the forced synchronization information to the second terminal.
[0076] In the embodiment of the present invention, the forced synchronization state information is used as the target terminal forced synchronization reverse key switching parameter.
[0077] Specifically, the first terminal modifies the key switching trigger value of the multi-frame counter, and sends the key switching trigger value from the first terminal to the second terminal. It should be noted that when performing special operations, the second terminal does not receive the relevant command and will not start the reverse exception handling process. Therefore, it is necessary to add additional processing procedures to ensure that there are no problems in the decryption direction of the first terminal. Specifically, in the internal encrypted information communication channel from the first terminal to the second terminal, it is necessary to send an additional forced synchronization status information to notify the second terminal to modify the reverse encryption configuration to be consistent with the configuration of the first terminal.
[0078] In some application scenarios of the embodiments of the present invention, forced synchronization information indicates that the reverse key switching period from the second terminal as an encryption end to the first terminal as a decryption end and the forward configuration content from the first terminal as an encryption end to the second terminal as a decryption end are consistent, the amount of information is small, and single-bit information transmission can be used; the configuration content that needs to be reverse synchronized can also be specifically given, which has a large amount of information and is more flexible.
[0079] S304: The second terminal receives the forced synchronization information and the third key switching parameter, and changes the encryption configuration accordingly according to the third key switching parameter.
[0080] In an embodiment of the present invention, the second terminal makes corresponding changes after receiving the modified third key switching parameter. Specifically, after receiving the third key switching trigger value, the key switching period is also changed from the first key switching period to the third key switching period accordingly, that is, following the configuration of the encryption end of the first terminal, and also delaying the key switching time to ensure that the configuration of the first terminal and the second terminal are consistent.
[0081] In step S301 to step S304, the first terminal serves as an encryption terminal that configures first key parameters, and the target terminal serves as a second terminal that serves as a decryption terminal.
[0082] In an embodiment of the present invention, the service is bidirectional. After the second terminal receives the changed third key switching parameter and the forced synchronization information notification, the second terminal sends the third key switching parameter to the first terminal, and the first terminal performs encryption configuration according to the received third key switching parameter. Specifically, after the second terminal receives the changed third key switching trigger value and the forced synchronization information notification, the reverse information content is modified according to the received third key switching trigger value, specifically, the key switching trigger value of the second terminal as the encryption end is modified to the third key switching trigger value and sent from the second terminal to the first terminal, the target terminal as the decryption end. In this way, it can be ensured that the configuration of the second terminal as the encryption end and the first terminal as the encryption end are consistent.
[0083] In an embodiment of the present invention, the first terminal as a decryption end receives the modified key switching trigger value of the second terminal as an encryption end, and performs key switching according to the modified key switching trigger value, thereby realizing the change of the key switching period from the second terminal as an encryption end to the first terminal as a decryption end, ensuring that the key switching scenario does not occur during special operations.
[0084] It should be understood that after the modification, the key switching trigger values of the respective key switching multi-frame counters in the direction from the first terminal as an encryption end to the second terminal as a decryption end and in the direction from the second terminal as an encryption end to the first terminal as a decryption end are updated to special values under special operating conditions.
[0085] In some application scenarios of the embodiments of the present invention, after the special operation is completed, the first terminal and the second terminal resume normal configuration. For a flowchart of the method, see Figure 4 As shown, the specific steps include:
[0086] S401. A first terminal restores a third key switching parameter to a first key switching parameter.
[0087] In the embodiment of the present invention, the process of restoring the third key switching parameter to the first key switching parameter of the first terminal is specifically to restore the third key switching trigger value to the first key switching trigger value, and correspondingly, the third key switching period is restored to the first key switching period.
[0088] S402: The first terminal sends the first key switching parameter to the second terminal, and cancels the sending of the forced synchronization information.
[0089] Specifically, the first terminal sends the first key switching trigger value to the second terminal.
[0090] S403: The second terminal performs corresponding configuration according to the first key switching parameter.
[0091] Specifically, the second terminal receives the first key switching trigger value, and restores the key switching period to the first key switching period according to the first key switching trigger value.
[0092] In the embodiment of the present invention, after the special operation is completed, the first terminal as the encryption end resumes normal configuration, and the second terminal as the decryption end will follow the first terminal to resume normal configuration. At the same time, the first terminal will cancel the sending of the forced synchronization state information. If the second terminal does not receive the forced synchronization state information, it will cancel the modification of the reverse information from the second terminal as the encryption end to the first terminal as the decryption end, use the second terminal local configuration information to set the configuration content of the second terminal as the encryption end, and synchronize it to the first terminal.
[0093] Specifically, when the special operation is completed, the second terminal as the encryption end restores the third key switching parameter to the locally configured key switching parameter and synchronizes it to the first terminal as the target terminal for decryption.
[0094] In some application scenarios of the embodiments of the present invention, the second terminal is set with a timeout mechanism for forced synchronization information. If the normal maintenance command processing time is exceeded, it will automatically exit the forced synchronization state and use local configuration information to set the key switching trigger value in the direction from the second terminal as the encryption end to the first terminal as the decryption end. It will not always follow the setting of the first terminal and not switch the key to ensure security requirements.
[0095] The key switching method provided by the embodiment of the present invention ensures that service data transmission is not interrupted when an abnormal situation occurs or a special operation is performed in the service priority mode, and ensures that the configurations of the first terminal and the second terminal are consistent.
[0096] Embodiment three:
[0097] The embodiment of the present invention proposes a method for handling an abnormality in a user-set security priority mode, which has high security.
[0098] The embodiment of the present invention takes the first terminal as the encryption terminal for configuring the first key parameter and the decryption terminal as the target terminal second terminal as an example for description. Figure 5 , Figure 5 The key switching method provided by the embodiment of the present invention is as follows:
[0099] S501, a first terminal configures a first key switching parameter and sends the first key switching parameter to a second terminal;
[0100] S502, the second terminal performs corresponding encryption configuration according to the received first key switching parameter;
[0101] S503, the first terminal switches the encryption key according to the first key switching parameter, and the second terminal switches the decryption key according to the first key switching parameter at the same time;
[0102] S504: When the key application of the first terminal fails, the first key switching parameter is sent to the second terminal;
[0103] S505: The second terminal interrupts the service between the second terminal and the first terminal.
[0104] In an embodiment of the present invention, when an exception occurs in the key application of the first terminal as an encryption end, the key cannot be switched according to the configured update time, and the encryption key acquisition fails. When the key switching period arrives, the first terminal notifies the second terminal according to the first key switching parameter, and the second terminal performs the key switching according to the first key switching parameter. However, there is no available key under the first key switching parameter, and the encryption and decryption functions cannot be implemented normally. In order to ensure the security of business data transmission, the business is interrupted.
[0105] In some application scenarios of the embodiments of the present invention, there are no available keys, and the encryption and decryption functions cannot be implemented normally, resulting in business interruption, generating a key switching abnormality warning and a business interruption warning to notify the user.
[0106] It should be understood that the first key switching parameter includes the first key switching period and the first key switching trigger value; in the embodiment of the present invention, when the key switching period is reached, the first key switching trigger value will not be modified, the second terminal is notified according to the first key switching parameter, and the second terminal performs key switching according to the first key switching period.
[0107] In the embodiment of the present invention, the service is bidirectional, the first terminal can be used as an encryption end or a decryption end, and the second terminal can be used as an encryption end or a decryption end. When an exception occurs in the key application of the first terminal as an encryption end, a problem will also occur in the first terminal as a decryption end. It should be noted that the current quantum key application mechanism can ensure that when the first terminal is used as a decryption exception, the second terminal will also be in an abnormal state as an encryption application. Therefore, there is no need to add a separate processing flow, and the reverse second terminal encryption exception processing flow can be used.
[0108] The key switching method provided by the embodiment of the present invention configures a first key switching parameter through a first terminal and sends the first key switching parameter to a second terminal; the second terminal performs corresponding encryption configuration according to the received first key switching parameter; the first terminal switches the encryption key according to the first key switching parameter, and the second terminal simultaneously switches the decryption key according to the first key switching parameter; when the key application of the first terminal fails, the first key switching parameter is sent to the second terminal; the second terminal does not have a corresponding decryption key under the configuration of the first key switching parameter, and the service between the encryption end and the decryption end is interrupted; the security of service data transmission is improved.
[0109] Embodiment 4:
[0110] The embodiment of the present invention also provides a key switching device, which includes a configuration unit, a transmission unit and a processing unit;
[0111] A configuration unit, configured to configure a first key switching parameter;
[0112] A transmission unit, configured to send the first key switching parameter to a target terminal as a key switching parameter of the target terminal;
[0113] The processing unit is configured to perform key switching according to a first key switching parameter.
[0114] It should be noted that the key switching device is used to implement the key switching method as described in the above embodiment, which will not be described in detail here.
[0115] Embodiment five:
[0116] An embodiment of the present invention further provides a terminal, which includes a processor and a memory; the processor is used to execute one or more computer programs stored in the memory to implement the steps of the key switching method in the above embodiment.
[0117] See Figure 6This terminal includes a first terminal 100 and a second terminal 200, wherein the first terminal 100 includes a first terminal encryption end 101 and a first terminal decryption end 102, and the second terminal 200 includes a second terminal decryption end 201 and a second terminal encryption end 202; in the encryption direction from the first terminal 100 to the second terminal 200, the first terminal encryption end 101 performs encryption operations, and the second terminal decryption end 201 performs decryption operations, and in the encryption direction from the second terminal 200 to the first terminal 100, the second terminal encryption end 202 performs encryption operations, and the first terminal decryption end 102 performs decryption operations.
[0118] In the embodiment of the present invention, the first terminal 100 and the second terminal 200 perform bidirectional service transmission. Figure 6 The arrow directions in the figure respectively represent the service transmission path connecting the first terminal encryption end 101 and the second terminal decryption end 201 and the service transmission path connecting the second terminal encryption end 202 and the first terminal decryption end 102.
[0119] It should be understood that the service transmission path transmits information through the associated overhead.
[0120] See also Figure 7 , Figure 7 This is a structural diagram of encryption configuration content synchronization under normal encryption conditions. Specifically, the encryption configuration content configured to the first terminal 100 is mainly applied to the first terminal encryption end 101, and the encryption configuration content is sent to the second terminal decryption end 201, so that the configuration content of the second terminal decryption end 201 is consistent with the configuration content of the first terminal encryption end 101; the encryption configuration content configured to the second terminal 200 is mainly applied to the second terminal encryption end 202, and the encryption configuration content is sent to the first terminal decryption end 102, so that the configuration content of the first terminal decryption end 102 is consistent with the configuration content of the second terminal encryption end 202.
[0121] In some application scenarios of the embodiments of the present invention, there are also some special operations that affect the encryption processing. These operations are generally single-ended operations, such as encryption configuration changes, key update cycle modification, or single-board software upgrades, single-board resets, etc. See Figure 8 , Figure 8The present invention is a structural diagram of synchronizing the encrypted configuration content under abnormal circumstances of special operations. Specifically, the first terminal 100 receives a special operation command request, modifies the encryption configuration parameters of the first terminal encryption terminal 101, and sends the modified encryption configuration parameters to the second terminal decryption terminal 201. At the same time, it sends a forced synchronization message to notify the second terminal decryption terminal 201 to perform reverse configuration synchronization. After receiving the forced synchronization message, the second terminal decryption terminal 201 modifies the setting of the second terminal encryption terminal 202 so that the encryption configuration of the second terminal encryption terminal 202 is consistent with that of the first terminal encryption terminal 101. At the same time, the second terminal encryption terminal 202 sends the encrypted configuration content to the first terminal decryption terminal 102. This can ensure that the two-way key switching is not performed until the special operation is completed.
[0122] It should be understood that the encryption configuration content includes encryption enable, encryption mode, key source, key ID and other parameters that affect the symmetry of the encryption configuration.
[0123] Embodiment six:
[0124] The present embodiment also provides a computer-readable storage medium, which includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer.
[0125] The computer-readable storage medium in this embodiment can be used to store one or more computer programs, and the one or more computer programs stored therein can be executed by a processor to implement at least one step of the key switching method in the above embodiment.
[0126] It can be seen that those skilled in the art should understand that all or some of the steps, systems, and functional modules / units in the above disclosed methods can be implemented as software (which can be implemented with computer program code executable by a computing device), firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component can have multiple functions, or a function or step can be performed by several physical components in cooperation. Some or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit.
[0127] In addition, it is well known to those skilled in the art that communication media generally contain computer readable instructions, data structures, computer program modules or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery media. Therefore, the present invention is not limited to any specific hardware and software combination.
[0128] The above contents are further detailed descriptions of the embodiments of the present invention in combination with specific implementation methods, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the protection scope of the present invention.
Claims
1. A key switching method, include: configuring a first key switching parameter, and sending the first key switching parameter to a target terminal as a key switching parameter of the target terminal; Performing key switching according to the first key switching parameter; The method further comprises: When receiving a special operation command, changing the first key switching parameter to a third key switching parameter to delay the key switching time; Sending the forced synchronization state information and the third key switching parameter to the target terminal; wherein the third key switching parameter is used as the key switching parameter of the target terminal, and the forced synchronization state information is used as the forced synchronization reverse key switching parameter of the target terminal; Performing key switching according to the third key switching parameter; The special operation commands include encryption configuration change, key update cycle modification, board software upgrade, or board reset.
2. The key switching method according to claim 1, It is characterized in that The first key switching parameter includes at least one of the following: a first key switching period, encryption enable, encryption mode, key source, and key ID.
3. The key switching method according to claim 1, It is characterized in that The method further comprises: When the key application fails, changing the first key switching parameter to a second key switching parameter to postpone the key switching time, and sending the second key switching parameter to the target terminal as the key switching parameter of the target terminal; Key switching is performed according to the second key switching parameter.
4. The key switching method according to claim 1, It is characterized in that The method further comprises: When the special operation is completed, restoring the third key switching parameter to the first key switching parameter; The first key switching parameter is sent to the target terminal as the key switching parameter of the target terminal, and the sending of the forced synchronization state information is canceled.
5. The key switching method according to claim 1, It is characterized in that The method further comprises: It is detected that the forced synchronization state information runs for more than a preset time threshold, and the third key switching parameter is restored to a locally configured key switching parameter and synchronized to the target terminal.
6. The key switching method according to claim 1, It is characterized in that The method further comprises: When the key application fails, the first key switching parameter is sent to the target terminal; the target terminal cannot obtain the key according to the first key switching parameter.
7. A key switching device, comprising: a configuration unit, a transmission unit and a processing unit; A configuration unit, configured to configure a first key switching parameter; A transmission unit, configured to send the first key switching parameter to a target terminal as a key switching parameter of the target terminal; a processing unit, configured to perform key switching according to the first key switching parameter; The configuration unit is further configured to, upon receiving a special operation command, change the first key switching parameter to a third key switching parameter to delay the key switching time; The transmission unit is further used to send the forced synchronization state information and the third key switching parameter to the target terminal; wherein the third key switching parameter is used as the key switching parameter of the target terminal, and the forced synchronization state information is used as the forced synchronization reverse key switching parameter of the target terminal; The processing unit is further configured to perform key switching according to the third key switching parameter; The special operation commands include encryption configuration change, key update cycle modification, board software upgrade, or board reset.
8. A terminal comprising a processor and a memory; The processor is used to execute one or more computer programs stored in the memory to implement the steps of the key switching method according to any one of claims 1 to 6.
9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores one or more computer programs, and the one or more computer programs can be executed by one or more processors to implement the steps of the key switching method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Method for cryptographic key exchange of passive optical network system
CN101247220A
Key update method, apparatus and system based on optical transport network (OTN)
CN106301768A