Proprietary and shared protection methods and related equipment for quantum key provisioning
By constructing a non-crossing protection path and quantum key synchronization switching mechanism, the problem of survival differences in quantum key distribution networks under optical network failure is solved, and the rapid recovery of quantum key distribution networks and the timeliness of service transmission are realized.
Patent Information
- Application Number
- CN202210853501.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-08
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-07-08
AI Technical Summary
The prior art fails to effectively consider the survival differences in quantum key distribution networks in the optical network failure scenario, resulting in insufficient timeliness in the protection and recovery of quantum key distribution services.
Build a protection path that does not intersect the target path, generate quantum keys synchronously, and switch to the keys of the protection path in time when there is a problem with the target path to ensure the timeliness of service transmission; for multiple paths, set priority to redistribute quantum keys to ensure that the most urgent service is restored first.
It realizes the rapid recovery of the quantum key distribution network in the event of failure, ensuring the timeliness and security of service transmission, especially for services with high timeliness requirements.
Smart Images

Figure CN115426104B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum key provisioning technology, and in particular to a proprietary and shared protection method and related equipment for quantum key provisioning. Background Art
[0002] Quantum key distribution uses the properties of quantum mechanics to ensure communication security. It enables two communicating parties to generate and share a random, secure key to encrypt and decrypt messages.
[0003] Current research often considers joint protection strategies in scenarios where data services and key services are coupled when quantum key distribution is applied to optical networks, such as protection path setting schemes for the two types of services in optical network failure scenarios, and joint service rerouting mechanisms in multi-domain optical network scenarios. In actual application, these schemes still choose the perspective of traditional optical services to protect and restore quantum key distribution services, while ignoring the inherent characteristics of quantum key distribution, and not considering them independently from the perspective of quantum key distribution network scenarios. In addition, they do not consider the differences in survivability between optical networks and quantum key distribution networks, that is, the instant switching of data services in optical network protection scenarios cannot be fully applied in quantum key distribution networks. Summary of the Invention
[0004] In view of this, the purpose of this application is to propose a proprietary and shared protection method and related equipment for quantum key provisioning.
[0005] Based on the above objectives, the present application provides a proprietary protection method for quantum key provisioning, which is characterized by including:
[0006] Constructing a first protection path according to the acquired physical topology information of the first target path;
[0007] generating a first user key according to the first target path;
[0008] generating a first protection key according to the first protection path;
[0009] In response to the interruption of the supply of the first user key, the first protection key is retrieved to replace the first user key, so as to restore the key supply of the first target path.
[0010] In one possible implementation, a first rate at which the first target path generates the first user key is the same as a second rate at which the first protection path generates the first protection key;
[0011] The method further comprises:
[0012] In response to the first user key regeneration, the first protection key is regenerated.
[0013] In a possible implementation, the first target path generating a first user key includes:
[0014] At least one pair of nodes of the first target path generates at least one first quantum key;
[0015] performing formatting processing on the at least one first quantum key to obtain at least one first formatted key;
[0016] Key relay processing is performed on the at least one first formatted key to obtain a first user key.
[0017] In a possible implementation, the first protection path generating a first protection key includes:
[0018] At least one pair of nodes of the first protection path generates at least one second quantum key;
[0019] performing formatting processing on the at least one second quantum key to obtain at least one second formatted key;
[0020] Key relay processing is performed on the at least one second formatted key to obtain a first protection key.
[0021] In a possible implementation, the length of the second formatted key is the same as the length of the first user key;
[0022] The length of the first protection key is the same as the length of the first user key.
[0023] In a possible implementation manner, links of the first target path and the first protection path do not overlap.
[0024] Based on the same inventive concept, this application also provides a shared protection method for quantum key provisioning, including:
[0025] Constructing a second protection path according to the acquired physical topology information of at least two second target paths;
[0026] Setting priorities of at least two of the second target paths;
[0027] generating at least two second user keys according to the at least two second target paths;
[0028] In response to the interruption of at least two second user key supplies, the path with the highest priority among the at least two second target paths is used as the third target path, a second protection key is generated according to the second protection path, and the second protection key is called to replace the second user key of the third target path to restore the key supply of the third target path.
[0029] In a possible implementation, the method further includes:
[0030] In response to normal provisioning of at least two of the second user keys, the second protection path generates a third user key; the third user key serves the traffic transport of the second protection path.
[0031] Based on the same inventive concept, one or more embodiments of this specification also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the program, it implements the proprietary and shared protection method for quantum key provision as described in any one of the above items.
[0032] Based on the same inventive concept, one or more embodiments of this specification also provide a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute any of the above-mentioned proprietary and shared protection methods for quantum key provision.
[0033] As can be seen from the above, the proprietary, shared protection method for quantum key provisioning provided by the embodiments of the present application constructs a protection path that does not intersect with the target path, generates quantum keys synchronously with the target path as a backup, and when problems arise with the quantum key provisioning of the target path, promptly switches to the quantum key of the protection path to ensure real-time service transmission. When there are multiple target paths, the priority of the target paths is set in advance. When multiple target paths have problems at the same time, the quantum keys are redistributed in descending order of priority to ensure that the most urgent services are restored first, thus ensuring the timeliness of service transmission. In addition, the protection key generated by the protection path will be updated in real time with the key of the target path to ensure the timeliness and security of the quantum key. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions in this application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are merely embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0035] Figure 1 A flowchart of a proprietary protection method for quantum key provisioning according to an embodiment of the present application;
[0036] Figure 2 A schematic diagram of an application scenario of a proprietary protection method for quantum key provisioning according to an embodiment of the present application;
[0037] Figure 3This is a flow chart of a shared protection method for quantum key provisioning according to an embodiment of the present application;
[0038] Figure 4 A schematic diagram of an application scenario of the shared protection method for quantum key provisioning according to an embodiment of the present application;
[0039] Figure 5 This is a structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0040] In order to make the objectives, technical solutions and advantages of this application more clear, this application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0041] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the usual meanings understood by people with ordinary skills in the field to which this application belongs. The "first", "second" and similar words used in the embodiments of the present application do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0042] As described in the background technology section, existing technologies often consider joint protection strategies in scenarios where data services and key services are coupled when quantum key distribution is applied to optical networks. In actual application, these solutions do not take into account the differences in survivability between optical networks and quantum key distribution networks. That is, the timely switching of data services in optical network protection scenarios cannot be fully applicable to quantum key distribution networks, because when problems occur in quantum key distribution, new quantum keys need to be regenerated, and the key generation process requires a series of operations. The additional overhead brought by these operations has a non-negligible impact on the timeliness of protection.
[0043] Taking the above into consideration, the embodiments of the present application propose a proprietary, shared protection method for quantum key provisioning. By constructing a protection path that does not intersect with the target path, the protection path and the target path generate quantum keys synchronously. When a problem occurs with the quantum key provisioning of the target path, the quantum key of the protection path is promptly retrieved to ensure the secure transmission of the target path service. When there are multiple target paths, the priority of the target paths is set in advance, and the quantum keys are redistributed in order of priority from high to low. When problems occur on multiple target paths at the same time, the most urgent services are restored first, ensuring the timeliness of service transmission. In addition, the protection key generated by the protection path will be updated in real time with the key of the target path to ensure the timeliness and security of the quantum key.
[0044] The technical solutions of the embodiments of the present application are described in detail below through specific examples.
[0045] refer to Figure 1 The proprietary protection method for quantum key provisioning according to the embodiment of the present application may include the following steps:
[0046] Step S101: constructing a first protection path according to the acquired physical topology information of the first target path;
[0047] Step S102: Generate a first user key according to the first target path;
[0048] Step S103: Generate a first protection key according to the first protection path;
[0049] Step S104 : In response to the interruption of the supply of the first user key, the first protection key is retrieved to replace the first user key, so as to restore the key supply of the first target path.
[0050] For step S101, refer to Figure 2 , which is a schematic diagram of an application scenario of the proprietary protection method for quantum key provisioning in an embodiment of the present application.
[0051] The figure shows a QKDN controller (quantum key distribution network controller), KM1-KM4, which are key managers. In the key management layer, QKD modules 1-4 are nodes of the target path or protection path. In the quantum layer, the quantum layer and the key management layer are connected to the quantum key distribution network manager.
[0052] In this embodiment, the controller obtains the physical topology within the domain, traverses the physical link information within the domain, and abstracts the two-segment node numbers of the link within the domain into the x and y coordinates of the array in the form of a two-dimensional array. Then, based on the physical topology information of the first target path (working path) obtained, in this embodiment, it is node 1-node 2-node 4. For the key supply on the quantum key distribution path of the above path, node 1-node 3-node 4 is selected as the dedicated protection path for key supply protection. It should be noted that the links of the constructed first protection path and the links of the first target path need not overlap, that is, the two paths have no intersection.
[0053] With respect to step S102, in this embodiment, nodes 1, 2, and 4 on the first target path generate quantum keys, and then the quantum keys of nodes 1 and 2 are synchronized, and the subkeys of nodes 2 and 4 are synchronized. The obtained quantum keys are all first quantum keys. The synchronization process should be known to those skilled in the art and will not be described in detail here.
[0054] The key management agent module then formats the first quantum key between nodes 1 and 2 to obtain a first formatted key. It also formats the first quantum key between nodes 2 and 4 to obtain a first formatted key. The key management agent module then performs key relay processing on these two first formatted keys to obtain the first user key for nodes 1-2-4. The key relay process enables the source and sink nodes to share quantum keys. Specifically, node 2 encrypts the quantum key of node 1-2 with the quantum key of node 2-4 and transmits it to nodes 1 and 4, allowing node 1 to obtain the quantum key of node 2-4, or node 4 to obtain the quantum key of node 1-2. After the key relay process, the first user key is obtained and stored in the key provisioning agent module.
[0055] Regarding step S103, in this embodiment, nodes 1, 3, and 4 on the first protection path generate quantum keys, and then the quantum keys of nodes 1 and 3 are synchronized, and the subkeys of nodes 3 and 4 are synchronized. The obtained quantum keys are all second quantum keys. The synchronization process should be known to those skilled in the art and will not be described in detail here.
[0056] The key management agent module then formats the second quantum key of nodes 1 and 3 to obtain a second formatted key. It also formats the second quantum key of nodes 3 and 4 to obtain a second formatted key. The key management agent module then performs key relay processing on these two second formatted keys to obtain the first protection key of nodes 1-3-4. The key relay process is to enable the source node and the sink node to share quantum keys. Specifically, the key relay process involves node 3 encrypting the quantum key of nodes 1-3 with the quantum key of node 3-4 and transmitting it to nodes 1 and 4, allowing node 1 to obtain the quantum key of nodes 3-4, or node 4 to obtain the quantum key of nodes 1-3. After the key relay process, the first protection key is obtained and stored in the key provisioning agent module.
[0057] Steps S102 and S103 are performed simultaneously. During the formatting process, the length of the second formatted key needs to be the same as that of the first user key. The purpose of the formatting process is to ensure that the first user key and the first protection key have the same length so that they can be used for subsequent key supply switching. The key length can be set as required.
[0058] The rate at which the first user key is generated by the first target path in step S102 is the same as the rate at which the first protection key is generated by the first protection path in step S103, and both are generated synchronously. That is, when the first user key is regenerated, the first protection key is also regenerated. The first protection key is periodically updated synchronously over the lifecycle of the quantum key distribution network. Furthermore, the key provisioning agent module partitions and stores the first user key and the first protection key generated in the above steps. The first user key is normally provisioned to the service, while the first protection key is reserved in the key provisioning agent module awaiting subsequent key switching. During this waiting period, it will, of course, be updated together with the first user key, as described above.
[0059] Afterwards, when the key supply of node 1-2-4 is interrupted during business transportation, the quantum key distribution network can ignore the specific cause of the failure and directly retrieve the first protection key in the storage to replace the first user key to ensure the secure transmission of the node 1-2-4 business. In this process, compared with the prior art that requires the regeneration of the quantum key, the embodiment of the present application only needs to retrieve the first protection key from the storage, which effectively shortens the business interruption time and ensures the timeliness of business transmission.
[0060] It should be noted that the first protection key generated in the above-mentioned first protection path cannot serve other services during the normal key generation process of the first target path. This is to ensure that the first target path can resume supply as soon as possible when a key supply failure occurs, so that the service can be transmitted in time. Therefore, the above-mentioned proprietary protection method of quantum key supply is generally used to transmit services with high timeliness requirements.
[0061] Based on the same inventive concept, an embodiment of the present application also provides a shared protection method for quantum key provisioning.
[0062] refer to Figure 3 The shared protection method for quantum key provisioning according to the embodiment of the present application may include the following steps:
[0063] Step S301: construct a second protection path based on the acquired physical topology information of at least two second target paths;
[0064] Step S302: setting the priorities of at least two of the second target paths;
[0065] Step S303: Generate at least two second user keys according to at least two of the second target paths;
[0066] Step S304: In response to the interruption of the supply of at least two second user keys, the path with the highest priority among the at least two second target paths is used as the third target path, and a second protection key is generated according to the second protection path. The second protection key is retrieved to replace the second user key of the third target path to restore the key supply of the third target path.
[0067] For step S301, refer to Figure 4 , which is a schematic diagram of the application scenario of the shared protection method for quantum key provisioning in an embodiment of the present application.
[0068] The figure shows a QKDN controller (quantum key distribution network controller), KM1-KM5, which are key managers. In the key management layer, QKD modules 1-5 are nodes of the target path or protection path. In the quantum layer, the quantum layer and the key management layer are connected to the quantum key distribution network manager.
[0069] In this embodiment, the controller obtains the physical topology within the domain, traverses the physical link information within the domain, and abstracts the two-segment node numbers of the link within the domain into the x and y coordinates of the array in the form of a two-dimensional array. Then, based on the physical topology information of at least two second target paths (working paths) obtained, in this embodiment, nodes 1-2-5 and nodes 1-3-5, for the key supply on the quantum key distribution path of the above path, nodes 1-4-5 are selected as the shared protection path for key supply protection. It should be noted that the links of the constructed second protection path need not overlap with the links of all the second target paths, that is, the second protection path has no intersection with any second target path.
[0070] Furthermore, priorities of at least two second target paths are set, and the priorities depend on the importance of the customer's business and the timeliness of the business transmission.
[0071] Furthermore, in this embodiment, nodes 1, 2, and 5 on the second target path of nodes 1-2-5 generate quantum keys, then synchronize the quantum keys of nodes 1 and 2, and synchronize the keys of nodes 2 and 5, and all of the obtained keys are second quantum keys. Nodes 1, 3, and 5 on the second target path of nodes 1-3-5 generate quantum keys, then synchronize the quantum keys of nodes 1 and 3, and synchronize the quantum keys of nodes 3 and 5, and all of the obtained keys are second quantum keys. Those skilled in the art should be aware of the above synchronization process and will not be described in detail here.
[0072] The key management agent module then formats the second quantum key of node 1-node 2 to obtain a third formatted key. It also formats the second quantum key of node 2-node 5 to obtain a third formatted key. The key management agent module then performs key relay processing on the two third formatted keys to obtain the second user key of node 1-2-5. The key relay process is to enable the source node and the destination node to share quantum keys. Specifically, the key relay process is as follows: node 2 encrypts the quantum key of node 1-2 with the quantum key of node 2-5 and transmits it to node 1 and node 5 so that node 1 can obtain the quantum key of node 2-5, or node 5 can obtain the quantum key of node 1-2. After the key relay process, the second user key is obtained and stored in the key provisioning agent module. Similarly, the second target path of node 1-3-5 generates the second user key. The specific generation process is the same as the second target path generation process of node 1-2-5 described above, so it will not be repeated here.
[0073] Regarding step S303, when at least two second target paths generate second user keys, the second protection path synchronously generates a third user key. It should be noted that the second protection path only generates the third user key when the second user keys of all second target paths are normally supplied. The third user key can be used to transmit other services. When the second protection path generates the third user key, its key generation speed does not need to be consistent with that of the second target path. Of course, the second protection path can generate the second protection key as in the aforementioned proprietary protection method, that is, setting the second protection path to an idle state and waiting for the second target path to fail before replacing it. It should be noted that at this time, the speed at which the second protection path generates the second protection key needs to be the same as the speed at which the second target path generates the second user key.
[0074] Furthermore, when at least two second user key supply interruptions are detected, the priority of the second target path corresponding to the second user key is first determined, and the path with the highest priority is selected as the third target path. In this embodiment, it can be seen that key supply interruptions occur on the nodes 1-2 and 3-5 paths, resulting in key supply interruptions on the nodes 1-2-5 and 1-3-5 paths. The protection priorities of the nodes 1-2-5 and 1-3-5 paths are obtained, and the priority of the 1-2-5 path is higher. In this case, the 1-2-5 path is selected as the third target path. Next, the second protection path generates a second protection key. In this case, the second protection path generates a third user key due to normalization. At this time, if the third user key is in the supply state, the supply of the third user key is stopped, and key relay processing is performed on the fourth formatted key on the second protection path; the fourth formatted key here is the formatted key used when generating the third user key. The second protection key is obtained and stored, and then the stored second protection key is used to replace the second user key, and service transmission on the second target path continues. The above-mentioned third user key can be the key used for node 1-4 path service transmission, the key used for node 4-5 path service transmission, or the key used for node 1-4-5 path service transmission. Therefore, after the quantum key supply of the target path is interrupted, the protection path needs to perform key relay first to ensure key sharing between the source node and the destination node.
[0075] It can be seen from the above embodiments that the proprietary and shared protection method for quantum key supply described in the embodiments of the present application constructs a protection path that does not intersect with the target path, and generates quantum keys synchronously with the target path as a backup. When a problem occurs in the quantum key supply of the target path, it is promptly switched to the quantum key of the protection path to ensure real-time transmission of the service. When there are multiple target paths, the priority of the target path is set in advance. When problems occur in multiple target paths at the same time, the quantum keys are redistributed in order of priority from high to low to ensure that the most urgent services are restored first, thereby ensuring the timeliness of service transmission.
[0076] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario and performed by multiple devices working together. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the method.
[0077] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0078] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements the proprietary and shared protection method for quantum key provision described in any of the above embodiments.
[0079] Figure 5 10 is a schematic diagram showing a more specific hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other within the device via the bus 1050.
[0080] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0081] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0082] The input / output interface 1030 is used to connect input / output modules to implement information input and output. The input / output modules can be configured as components within the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0083] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0084] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).
[0085] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0086] The electronic device of the above embodiment is used to implement the corresponding proprietary and shared protection method of quantum key provision in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0087] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the proprietary and shared protection method for quantum key provision as described in any of the above embodiments.
[0088] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0089] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the proprietary and shared protection method for quantum key provisioning as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0090] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. Within the scope of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.
[0091] In addition, for simplicity of description and discussion, and in order not to make the present application embodiment difficult to understand, the known power supply / ground connection with integrated circuit (IC) chip and other components may or may not be shown in the accompanying drawings provided. In addition, the device can be shown in the form of a block diagram to avoid making the present application embodiment difficult to understand, and this also takes into account the following fact, that is, the details of the embodiment of these block diagram devices are highly dependent on the platform to be implemented in the embodiment of the application (that is, these details should be fully within the scope of understanding of those skilled in the art). When specific details (for example, circuit) are set forth to describe exemplary embodiments of the present application, it will be apparent to those skilled in the art that the present application embodiment can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.
[0092] Although the present invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may utilize the embodiments discussed.
[0093] The embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of this application.
Claims
1. A proprietary protection method for quantum key provisioning, characterized in that: include: Constructing a first protection path according to the acquired physical topology information of the first target path; generating a first user key according to the first target path; generating a first protection key according to the first protection path; In response to the interruption of the supply of the first user key, the first protection key is retrieved to replace the first user key, so as to restore the key supply of the first target path.
2. The method according to claim 1, characterized in that A first rate at which the first target path generates the first user key is the same as a second rate at which the first protection path generates the first protection key; The method further comprises: In response to the first user key regeneration, the first protection key is regenerated.
3. The method according to claim 1, characterized in that Generating a first user key according to the first target path includes: generating at least one first quantum key according to at least one pair of nodes of the first target path; performing formatting processing on the at least one first quantum key to obtain at least one first formatted key; Key relay processing is performed on the at least one first formatted key to obtain a first user key.
4. The method according to claim 1, wherein Generating a first protection key according to the first protection path includes: generating at least one second quantum key according to at least one pair of nodes of the first protection path; performing formatting processing on the at least one second quantum key to obtain at least one second formatted key; Key relay processing is performed on the at least one second formatted key to obtain a first protection key.
5. The method according to claim 4, characterized in that The length of the second formatting key is the same as that of the first user key; the length of the first protection key is the same as that of the first user key.
6. The method according to claim 1, wherein Links of the first target path and the first protection path do not overlap.
7. A shared protection method for quantum key provisioning, characterized in that: include: Constructing a second protection path according to the acquired physical topology information of at least two second target paths; Setting priorities of at least two of the second target paths; generating at least two second user keys according to the at least two second target paths; In response to the interruption of at least two second user key supplies, the path with the highest priority among the at least two second target paths is used as the third target path, a second protection key is generated according to the second protection path, and the second protection key is called to replace the second user key of the third target path to restore the key supply of the third target path.
8. The method according to claim 7, characterized in that The method further comprises: In response to normal provisioning of at least two of the second user keys, the second protection path generates a third user key; the third user key serves the traffic transport of the second protection path.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 8 is implemented.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Quantum key distribution system, method and device based on trusted relay
CN105827397A
A method and a system for protecting key service in a quantum network
CN109005030A