Method and apparatus for providing security service, electronic device, and storage medium

By constructing data communication and key negotiation services in optical networks, generating data and quantum channels, the problems of key generation and scheduling in optical networks are solved, achieving efficient and secure service carrying, and improving resource utilization and security.

CN116132856BActive Publication Date: 2026-03-31BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-10
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing technologies cannot effectively address the need for on-demand key generation and scheduling in optical networks. Traditional dark fiber optic infrastructure is insufficient to meet the new demands of optical network security, and frequent fiber optic eavesdropping incidents affect the security of information infrastructure.

Method used

By constructing data communication services and key negotiation services, data service bearer channels and quantum service bearer channels are generated, enabling adaptive collaborative bearing of data and quantum channels, reducing mutual interference between classical strong light and quantum weak light, and dynamically planning channel deployment to meet user needs.

Benefits of technology

It improves the utilization rate of optical network resources, realizes efficient integrated carrying of data communication and key negotiation, and enhances the security and reliability of optical networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132856B_ABST
    Figure CN116132856B_ABST
Patent Text Reader

Abstract

The present disclosure provides a secure service provisioning method and device, electronic equipment and storage medium, comprising: receiving a service request of a user, and constructing a data communication service and a key negotiation service; processing the data communication service and the key negotiation service to obtain a data service bearer channel and a quantum service bearer channel; and adaptively bearing the service based on the data service bearer channel and the quantum service bearer channel. The present disclosure constructs a data communication service and a key negotiation service through a service request of a user, and then obtains a data service bearer channel and a quantum service bearer channel. Finally, the service request is adaptively borne through the data service bearer channel and the quantum service bearer channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of converged optical network technology, and more particularly to a method, apparatus, electronic device, and storage medium for providing secure services. Background Technology

[0002] In 2009, the IETF proposed security requirements for optical path establishment in multi-domain optical networks in RFC 5520, but did not propose an effective solution. Meanwhile, in data (classical) communication, represented by data transmission, with the introduction of the F5G concept and technological evolution, data bearers, primarily focused on deterministic services, are moving towards larger capacities of 400G / 800G. A large number of users' data communication services are being encapsulated and transmitted uniformly on backbone optical transport networks (OTN) lines.

[0003] However, the frequent occurrence of various fiber optic eavesdropping incidents in recent years has raised public concerns about the security of optical networks as information infrastructure. With the evolution of capacity, security has become a core issue that users cannot avoid. In the field of quantum communication, represented by key negotiation, quantum key distribution networks (QKDN) have gradually evolved from technological exploration to practical applications. Standardization work has been put on the agenda of standardization organizations such as ITU-T and CCSA, and basic equipment, links, and network frameworks have been established.

[0004] However, whether in academic research or industrial standardization applications, traditional offline key supply facilities, represented by dark fiber transmission, are no longer sufficient to meet the new demands of optical network security for on-demand key generation and scheduling. QKDN deployment is gradually pointing towards integration with data (classic) communication optical network facilities as the basic development direction. Summary of the Invention

[0005] In view of this, the purpose of this disclosure is to provide a method, apparatus, electronic device and storage medium for the supply of secure services.

[0006] As one aspect of this disclosure, a method for providing secure services is provided, characterized by comprising: receiving a user's service request and constructing a data communication service and a key negotiation service;

[0007] The data communication service and the key negotiation service are processed to obtain the data service bearer channel and the quantum service bearer channel;

[0008] Adaptive service carrying is performed based on the data service carrying channel and the quantum service carrying channel.

[0009] Optionally, receiving user service requests and constructing data communication services and key negotiation services includes:

[0010] Based on the aforementioned service request, a data transmission communication service is constructed and a data channel is generated;

[0011] The encryption protocol of the service request is determined based on the user requirements in the service request;

[0012] The number of keys and key rate required for the service request are determined based on the encryption protocol.

[0013] Based on the number of keys and the key rate, a key negotiation service is constructed, and a quantum channel is generated;

[0014] The key rate is expressed as:

[0015] R key / R data =k

[0016] The value of k is determined by the encryption protocol (such as the AES-256 encryption algorithm), R key / data This is expressed as key negotiation rate / data transmission rate.

[0017] Optionally, the processing of the data communication service and the key negotiation service to obtain the data service bearer channel and the quantum service bearer channel includes:

[0018] Several transmission links are generated based on the data channel and the quantum channel;

[0019] The data service bearer channel and the quantum service bearer channel are determined based on the aforementioned transmission links.

[0020] Optionally, determining the data service bearer channel based on the plurality of transmission links includes:

[0021] The two transmission links with the shortest distance among the plurality of transmission links are set as the final transmission links;

[0022] The final transmission links are sorted in ascending order according to the number of hops in the final transmission path to obtain the sorted final transmission links;

[0023] Calculate the quantum service loss value generated when the sorted final transmission link carries the data channel;

[0024] The transmission path with the smallest quantum service loss value among the sorted final transmission paths is determined as the data service bearer channel.

[0025] Optionally, the calculation of the quantum service loss value generated when the sorted final transmission link carries the data channel includes:

[0026] Calculate the number of Raman scattering crosstalk photons generated when the sorted final transmission link carries the data channel;

[0027] Calculate the number of adjacent channel crosstalk photons generated when the sorted final transmission link carries the data channel;

[0028] The number of Raman scattering crosstalk photons and the number of adjacent channel crosstalk photons are used as quantum service loss values;

[0029] The number of Raman scattering crosstalk photons is expressed as:

[0030]

[0031] in, This represents the number of crosstalk photons caused by Raman scattering during signal co-fiber transmission, where n represents the nth data channel, m represents the mth quantum channel, and R represents Raman. This represents the crosstalk power caused by Raman scattering. T represents the wavelength (nm) of the quantum channel. d η represents the time window interval of the quantum detector. d The quantum efficiency of the quantum detector is represented by h, Planck's constant is represented by c, and the speed of light in a vacuum is represented by c.

[0032] The calculation of the number of photons in adjacent channel crosstalk is expressed as follows:

[0033]

[0034] in, This represents the number of crosstalk photons caused by power leakage between adjacent channels during signal exchange, where n represents the nth data channel, m represents the mth quantum channel, C represents crosstalk, and g represents the number of crosstalk photons. a This represents the average transfer function of the narrowband filter in adjacent channel intervals, where I represents the signal power (of the data signal to be measured), α represents the fiber loss coefficient, L represents the fiber length, and e represents a constant, defaulting to 2.718. Indicates the wavelength interval between the data channel and the quantum channel. Indicates the wavelength of the quantum channel. γ represents the wavelength of the data (classical) channel. a This indicates the isolation between adjacent channels of the wavelength division multiplexer. Δ represents the set guard wavelength band, which is usually set between 50GHz and 200GHz depending on the loss situation, with 200GHz being the default.

[0035] Optionally, determining the quantum service bearer channel based on the plurality of transmission links includes:

[0036] Calculate the data service loss value generated when the sorted final transmission path carries the quantum channel;

[0037] The data service loss values ​​are sorted in ascending order to obtain the first data service loss value and the second data service loss value.

[0038] The sorted final transmission path corresponding to the first data service loss value is determined as the first quantum service bearer channel.

[0039] Optionally, determining the quantum service bearer channel based on the plurality of transmission links further includes:

[0040] In response to determining that the number of keys is greater than the number of quantum service bearer channels, the sorted final transmission path corresponding to the second quantum service loss value is determined as the second quantum service bearer channel.

[0041] As a second aspect of this disclosure, this disclosure also provides a security service delivery device, comprising:

[0042] The service receiving module is configured to receive user service requests and construct data communication services and key negotiation services.

[0043] The service deployment module is configured to process the data communication service and the key negotiation service to obtain the data service bearer channel and the quantum service bearer channel.

[0044] The service bearer module is configured to perform adaptive service bearer based on the data service bearer channel and the quantum service bearer channel.

[0045] As a third aspect of this disclosure, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor executes the program to implement the method for providing the aforementioned security services provided by this disclosure.

[0046] As a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is also provided, the non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the methods described in any of the above-mentioned methods.

[0047] As described above, this disclosure provides a method, apparatus, electronic device, and storage medium for providing secure services. In this disclosure, a data communication service and a key negotiation service are first constructed based on the user's service request, thereby obtaining a data service bearer channel and a quantum service bearer channel. Finally, the service request is adaptively carried out using the data service bearer channel and the quantum service bearer channel. Attached Figure Description

[0048] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0049] Figure 1A This disclosure provides a method for supplying secure services according to an embodiment of the present disclosure.

[0050] Figure 1B This is a schematic diagram illustrating a method for constructing a data channel and a quantum channel provided in an embodiment of this disclosure.

[0051] Figure 1C This is a schematic diagram illustrating a method for an example of node topology in an optical network provided by an embodiment of this disclosure.

[0052] Figure 1D This is a schematic diagram illustrating a method for link carrying in an optical network according to an embodiment of this disclosure.

[0053] Figure 1E This is a schematic diagram of a method for constructing a bearer channel provided in an embodiment of this disclosure.

[0054] Figure 2 This is a schematic diagram of the structure of a security service supply device provided in an embodiment of this disclosure.

[0055] Figure 3 This is a schematic diagram of an electronic device structure for a method of providing secure services according to an embodiment of this disclosure. Detailed Implementation

[0056] To make the objectives, technical solutions, and advantages of this disclosure clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.

[0057] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0058] In existing technologies, research has conducted experiments and deployment verifications on scenarios where data (classical) / quantum signals coexist, specifically testing the feasibility and performance of fusion under different deployment schemes. However, in actual networking processes, service attributes and deployment are decoupled; that is, the underlying deployment and service attributes, transmission switching and control are not related, resulting in low network resource utilization.

[0059] To address the aforementioned issues, this disclosure provides a method, apparatus, electronic device, and storage medium for supplying secure services. To achieve efficient resource utilization, this disclosure considers coordinating data (classical) side communication needs (represented by data transmission) with quantum side communication needs (represented by key negotiation) using optical network services. In a strong-weak optical collaborative network scenario based on data (classical) / quantum collaboration, the service format changes from the previously separate data and key services to a coupled collaborative secure service.

[0060] This allows for the clear matching of deterministic data communication services (where the data transmission volume is predetermined) with key requirements at the control logic level, while minimizing resource losses caused by mutual interference between classical strong light and quantum weak light at the physical level. The two types of channels are encapsulated and dynamically planned and deployed in the network to meet users' dual needs for data communication and key encryption.

[0061] After introducing the basic principles of this disclosure, various non-limiting embodiments of this disclosure will be described in detail below.

[0062] Figure 1A This disclosure provides a method for supplying secure services according to an embodiment of the present disclosure.

[0063] Figure 1A The method for providing security services, as shown, further includes the following steps:

[0064] Step S10: Receive the user's service request and construct data communication service and key negotiation service.

[0065] In some embodiments, upon receiving a service request from a user, the optical network manager can first be coordinated and configured into a waiting state. Then, based on the manager, a data communication service is constructed at the logical level, and the application layer of the optical transport network is accessed to obtain the encryption protocol specified by the user protocol. The number of keys and key rate required for the data transmission service are calculated according to the protocol (in this invention, it is assumed that the data transmission and key negotiation service provision time are consistent).

[0066] In some embodiments, once the number of keys and the key rate are obtained, a suitable key distribution protocol can be selected according to the optical network operator's established strategy to construct an end-to-end key negotiation service. Finally, the two types of services (data communication service and key negotiation service) are input into the network controller for routing calculation.

[0067] Figure 1B This is a schematic diagram illustrating a method for constructing a data channel and a quantum channel provided in an embodiment of this disclosure.

[0068] Figure 1C This is a schematic diagram illustrating a method for an example of node topology in an optical network provided by an embodiment of this disclosure.

[0069] In some embodiments, please refer to Figure 1B The diagram shows a further explanation of step S10, which specifically includes the following steps:

[0070] S101: Construct data transmission communication services and generate data channels based on the service request.

[0071] In some embodiments, combined with Figure 1C As shown, a user data communication request arrives from source node A to destination node D, indicating an existing user service request. At this point, the network manager can be coordinated and configured to wait, while simultaneously informing the controller to begin spectrum resource allocation.

[0072] In some embodiments, the path distance from source node A to node B can be 15km, the path distance from source node A to node C can be 10km, the path distance from node C to destination node D can be 15km, and the path distance from node B to destination node D can be 20km.

[0073] In some embodiments, please refer to Figure 1B and Figure 1CAs shown, when the manager constructs a 10Gbps data communication service between source node A and destination node D at the logical level, the manager can allocate one data channel for this data communication service. It is understood that the manager can also allocate more data channels for this data communication service; this embodiment only uses one data channel as an example for illustration.

[0074] S102: Determine the encryption protocol of the service request based on the user requirements in the service request.

[0075] S103: Determine the number of keys and key rate required for the service request based on the encryption protocol.

[0076] S104: Construct a key negotiation service based on the number of keys and the key rate, and generate a quantum channel.

[0077] In some embodiments, after receiving a user's service request, the application layer can be accessed to obtain the encryption protocol specified by the user agreement and the required number of keys. In this embodiment, it is assumed that 5 quantum channels are required. Then, the key rate required for data transmission is calculated according to the encryption protocol.

[0078] The key rate can be expressed as:

[0079] R key / R data =k

[0080] The value of k is determined by the encryption protocol (such as the AES-256 encryption algorithm), R key / data This is expressed as key negotiation rate / data transmission rate.

[0081] It is understood that the channel configuration process in the secure service provisioning method described in this embodiment is general, that is, the configuration of different numbers of data (classical) / quantum channels according to service requirements is the same. Here, only the carrying of 1 data channel and 5 quantum channels is selected to illustrate the specific implementation of the collaborative configuration method.

[0082] In some embodiments, after the quantum channel and the data channel are generated, the key negotiation service of five quantum channels from source node A to destination node D can be constructed at the logical level according to the network operator's predetermined strategy, and the two types of services (data communication service and key negotiation service) are input into the network controller for routing calculation.

[0083] Step S20: Process the data communication service and the key negotiation service to obtain the data service bearer channel and the quantum service bearer channel.

[0084] In some embodiments, since the source and destination nodes for data communication and key negotiation services are the same, the cooperative optical network controller can find K shortest paths from the source to the destination node (using the general KSP algorithm) and then determine the available wavelength channels (i.e., data service bearer channels and quantum service bearer channels) on the K shortest paths. These K shortest paths are applicable to both data communication and key negotiation services. It is understood that the bearer channels searched in the above method must satisfy the wavelength consistency condition, that is, the idle available wavelengths of each link on a single available path should be consistent.

[0085] Figure 1D This is a schematic diagram illustrating a method for link carrying in an optical network according to an embodiment of this disclosure.

[0086] Figure 1E This is a schematic diagram of a method for constructing a bearer channel provided in an embodiment of this disclosure.

[0087] In some embodiments, such as Figure 1E The diagram shows a further explanation of step S20, which specifically includes the following steps:

[0088] S201: Generate several transmission links based on the data channel and the quantum channel.

[0089] S202: Determine the data service bearer channel and the quantum service bearer channel based on the aforementioned transmission links.

[0090] In some embodiments, after obtaining the data channel and the quantum channel, several transmission links can be constructed based on them, and then the data service bearer channel and the quantum service bearer channel can be determined through the several transmission links.

[0091] In some embodiments, S202 above further includes the following steps:

[0092] S2021: Set at least two of the several transmission links with the shortest distance as the final transmission links.

[0093] In some embodiments, please combine Figure 1E , Figure 1C and Figure 1D For reference, the default configuration of the cooperative optical network controller uses Yen's K Shortest Path Algorithm (KSP algorithm) to find the K shortest paths (final transmission paths) between the source node and the destination node, namely paths ABD and ACD. It is understood that although only two of the K shortest paths (final transmission paths) exist in this disclosure, more shortest paths may exist in different optical networks. While this disclosure does not specifically address the case of more shortest paths, it does not negate the existence of such a form.

[0094] In some embodiments, after determining the K shortest paths (final transmission paths), the available wavelength channels of the K shortest paths (final transmission paths) can also be determined based on the wavelength channels carried by each link.

[0095] In some embodiments, Figure 1D The schematic diagram of the link carrying configuration in the optical network illustrates four link configurations (link AB, link BD, link AC, and link CD) and several wavelength channels (f) carried on these four links respectively. 0-10 f 18-35 f 48-59 f 60-70 f 3-12 f 43-48 f 24-38 f 58-68 (etc.) It is understood that the wavelength channels carried by the four links can also be set to other frequencies. This disclosure does not fully describe them in detail, but it does not mean that this disclosure does not cover other possible frequencies.

[0096] In some embodiments, for paths ABD and ACD, the available wavelength channels are as shown in Table 1 (default network has 80 wavelengths per link, f i (This represents the (i+1)th wavelength channel of the current link):

[0097] Table 1. K links and available wavelength channels between source node A and destination node D

[0098] Topology Path Available wavelength channels ABD <![CDATA[f 0-2 、f 13-17 、f 36-47 、f 71-79 ]]> ACD <![CDATA[f 13-23 、f 39-42 、f 49-57 、f 69-79 ]]>

[0099] S2022: Sort the final transmission links in ascending order according to the number of hops in the final transmission path to obtain the sorted final transmission links.

[0100] In some embodiments, after determining the K shortest paths (final transmission paths), the K shortest paths (final transmission paths) can be sorted in ascending order according to their hop count to obtain the sorted final transmission links. It is understood that the K shortest paths (final transmission paths) can also be sorted in descending order.

[0101] S2023: Calculate the quantum service loss value generated when the sorted final transmission link carries the data channel.

[0102] In some embodiments, after obtaining the sorted final transmission links and determining the available wavelength channels of the sorted final transmission links, the data service bearer channels and quantum service bearer channels of the sorted final transmission links can be further determined.

[0103] In some embodiments, when determining the data service carrying channel, the mutual loss value (quantum service loss value) caused by the data (classical) channels carried by path ABD and path ACD to the quantum services being carried on other channels along that path can be calculated first. In this embodiment, the channel with the minimum mutual loss value (quantum service loss value) obtained by ABD calculation is f. 43 The wavelength channel (mutual loss value approximately equal to 3.767 * 10⁻⁴), the minimum channel for ACD path mutual loss value (quantum service loss value) is f. 53 The wavelength channel has a mutual loss value of approximately 6.616 * 10⁻⁵. Therefore, in this disclosure, ACD is selected as the data (classical) channel bearer path, and the network manager records the result of it being used as the data (classical) channel bearer.

[0104] In some embodiments, when calculating the quantum service loss value generated when the sorted final transmission link carries the data channel, the number of Raman scattering crosstalk photons generated when the sorted final transmission link carries the data channel can be calculated, and then the number of adjacent channel crosstalk photons generated when the sorted final transmission link carries the data channel can be calculated. Finally, the number of Raman scattering crosstalk photons and the number of adjacent channel crosstalk photons are used as the quantum service loss value.

[0105] The number of Raman scattering crosstalk photons can be expressed as:

[0106]

[0107] in, This represents the number of crosstalk photons caused by Raman scattering during signal co-fiber transmission, where n represents the nth data channel, m represents the mth quantum channel, and R represents Raman. This represents the crosstalk power caused by Raman scattering. T represents the wavelength (nm) of the quantum channel. d η represents the time window interval of the quantum detector. d The quantum efficiency of the quantum detector is represented by h, Planck's constant is represented by c, and the speed of light in a vacuum is represented by c.

[0108] The calculation of the number of photons involved in crosstalk between adjacent channels can be expressed as:

[0109]

[0110] in, This represents the number of crosstalk photons caused by power leakage between adjacent channels during signal exchange, where n represents the nth data channel, m represents the mth quantum channel, C represents crosstalk, and g represents the number of crosstalk photons. a This represents the average transfer function of the narrowband filter in adjacent channel intervals, where I represents the signal power (of the data signal to be measured), α represents the fiber loss coefficient, L represents the fiber length, and e represents a constant, defaulting to 2.718. Indicates the wavelength interval between the data channel and the quantum channel. Indicates the wavelength of the quantum channel. γ represents the wavelength of the data (classical) channel. a This indicates the isolation between adjacent channels of the wavelength division multiplexer. Δ represents the set guard wavelength band, which is usually set between 50GHz and 200GHz depending on the loss situation, with 200GHz being the default.

[0111] S2024: The transmission path with the smallest quantum service loss value among the sorted final transmission paths is determined as the data service bearer channel.

[0112] In some embodiments, once the quantum service loss values ​​of the sorted final transmission paths are obtained, the sorted final transmission path corresponding to the minimum loss value among the sorted final transmission paths can be set as the data service bearer channel.

[0113] S2025: Calculate the data service loss value generated when the sorted final transmission path carries the quantum channel.

[0114] S2026: Sort the data service loss values ​​in ascending order to obtain the first data service loss value and the second data service loss value.

[0115] S2027: The sorted final transmission path corresponding to the first data service loss value is determined as the first quantum service bearer channel.

[0116] S2028: In response to determining that the number of keys is greater than the number of quantum service bearer channels, the sorted final transmission path corresponding to the second quantum service loss value is determined as the second quantum service bearer channel.

[0117] In some embodiments, after carrying data (classical) channels, the mutual loss value (data service loss value) that each channel of path ABD and path ACD will suffer is calculated. In this embodiment, the channel with the minimum mutual loss value (data service loss value) calculated by ABD is f. 40-44For wavelength channels (mutual loss value approximately 4.846*10⁻³ to 5.266*10⁻³), the minimum mutual loss value (data service loss value) for the ACD path is f. 17-19 f 49-50 It is composed of wavelength channels (mutual loss values ​​are approximately 3.354*10-3~3.398*10-3 and 5.602*10-3~5.743*10-3 respectively).

[0118] In some embodiments, the calculation method for the data service loss value in this example can be equivalent to the calculation method used for the quantum service loss value. Therefore, the calculation process for the data service loss value in this embodiment can also be completed using the quantum service loss value calculation process described above.

[0119] In some embodiments, since the quantum channel can be used as a key generation channel and thus can be opened separately, the wavelength channel f on ACD is selected based on the mutual loss value (data service loss value) after comprehensively considering the combined carrying of the quantum channel in paths ACD and ABD, and sorting by mutual loss value. 17-19 ABD wavelength channel f 40-41 The combination serves as the quantum channel bearer scheme, and the network manager records the results of the user key negotiation channel bearer.

[0120] In some embodiments, a quantum service bearer channel with the same number of keys can be selected. Specifically, if there are two keys determined in step S10 of this disclosure, then two quantum service bearer channels need to be selected. The specific selection method can still be the same as the data service bearer channel selection method described above. That is, the two quantum channels with the smallest data service loss value are selected as the first quantum service bearer channel and the second quantum service bearer channel.

[0121] In some embodiments, through the network state analysis and bearer scheme design described above, a set of data (classical) channels for data communication and a set of quantum channels for key negotiation are matched and bound to users as a cooperative service bearer scheme. Specific bearer results are shown in Table 2.

[0122] Table 2 User Data / Quantum Collaborative Service Configuration

[0123]

[0124]

[0125] Step S30: Perform adaptive service carrying based on the data service carrying channel and the quantum service carrying channel.

[0126] In some embodiments, based on the bearer routing scheme searched by the collaborative network controller (i.e., the scheme used in this disclosure), the manager performs actual network deployment based on the above calculation results, and sends signaling to the controller to enable the underlying resources to synchronously bear user data and key services. The key generated on the quantum channel is used by management entities such as the network key manager to encrypt the transmitted data, and the user service is thus integrated and carried.

[0127] In summary, this disclosure constructs data communication services and key negotiation services based on user service requests, thereby obtaining data service bearer channels and quantum service bearer channels. Finally, the service requests are adaptively carried out through the data service bearer channels and quantum service bearer channels, thus enabling the user service to be carried in an integrated manner.

[0128] Based on the same technical concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a security service supply device, through which the security service supply method described in any of the above embodiments can be implemented.

[0129] Figure 2 This is a schematic diagram of a security service supply device provided in an embodiment of this disclosure.

[0130] Figure 2 The security service supply device shown further includes the following modules:

[0131] Service receiving module 10, service deployment module 20, and service carrying module 30;

[0132] The service receiving module 10 is configured to receive user service requests and construct data communication and key negotiation services. Specifically, it executes the following steps:

[0133] Based on the aforementioned service request, a data transmission communication service is constructed and a data channel is generated;

[0134] The encryption protocol of the service request is determined based on the user requirements in the service request;

[0135] The number of keys and key rate required for the service request are determined based on the encryption protocol.

[0136] Based on the number of keys and the key rate, a key negotiation service is constructed, and a quantum channel is generated;

[0137] The key rate is expressed as:

[0138] R key / R data =k

[0139] The value of k is determined by the encryption protocol (such as the AES-256 encryption algorithm), R key / data This is expressed as key negotiation rate / data transmission rate.

[0140] The service deployment module 20 is configured to process the data communication service and the key negotiation service to obtain the data service bearer channel and the quantum service bearer channel. Specifically, the following steps are performed:

[0141] Several transmission links are generated based on the data channel and the quantum channel;

[0142] Determining the data service bearer channel and the quantum service bearer channel based on the aforementioned transmission links includes:

[0143] The two transmission links with the shortest distance among the plurality of transmission links are set as the final transmission links;

[0144] The final transmission links are sorted in ascending order according to the number of hops in the final transmission path to obtain the sorted final transmission links;

[0145] Calculating the quantum service loss value generated when the sorted final transmission link carries the data channel includes:

[0146] Calculate the number of Raman scattering crosstalk photons generated when the final transmission link carries the data channel;

[0147] Calculate the number of adjacent channel crosstalk photons generated when the final transmission link carries the data channel;

[0148] The number of Raman scattering crosstalk photons and the number of adjacent channel crosstalk photons are used as quantum service loss values;

[0149] The number of Raman scattering crosstalk photons is expressed as:

[0150]

[0151] in, This represents the number of crosstalk photons caused by Raman scattering during signal co-fiber transmission, where n represents the nth data channel, m represents the mth quantum channel, and R represents Raman. This represents the crosstalk power caused by Raman scattering. T represents the wavelength (nm) of the quantum channel. d η represents the time window interval of the quantum detector. d The quantum efficiency of the quantum detector is represented by h, Planck's constant is represented by c, and the speed of light in a vacuum is represented by c.

[0152] The calculation of the number of photons in adjacent channel crosstalk is expressed as follows:

[0153]

[0154] in, This represents the number of crosstalk photons caused by power leakage between adjacent channels during signal exchange, where n represents the nth data channel, m represents the mth quantum channel, C represents crosstalk, and g represents the number of crosstalk photons. a This represents the average transfer function of the narrowband filter in adjacent channel intervals, where I represents the signal power (of the data signal to be measured), α represents the fiber loss coefficient, L represents the fiber length, and e represents a constant, defaulting to 2.718. Indicates the wavelength interval between the data channel and the quantum channel. Indicates the wavelength of the quantum channel. γ represents the wavelength of the data (classical) channel. a This indicates the isolation between adjacent channels of the wavelength division multiplexer. Δ represents the set guard wavelength band, which is usually set between 50GHz and 200GHz depending on the loss situation, with 200GHz as the default.

[0155] The transmission path with the minimum quantum service loss value in the final transmission path is determined as the data service bearer channel;

[0156] Calculate the data service loss value generated when the final transmission path carries the quantum channel;

[0157] The data service loss values ​​are sorted in ascending order to obtain the first data service loss value and the second data service loss value.

[0158] The final transmission path corresponding to the first data service loss value is determined as the first quantum service bearer channel;

[0159] In response to determining that the number of keys is greater than the number of quantum service bearer channels, the final transmission path corresponding to the second quantum service loss value is determined as the second quantum service bearer channel.

[0160] The service carrying module 30 is configured to perform adaptive service carrying based on the data service carrying channel and the quantum service carrying channel.

[0161] Based on the same technical concept, corresponding to any of the above embodiments, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for providing security services as described in any of the above embodiments.

[0162] Figure 3This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.

[0163] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0164] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0165] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0166] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0167] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.

[0168] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0169] The electronic devices described above are used to implement the corresponding security service provisioning method in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0170] Based on the same technical concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a non-transitory computer-readable storage medium that stores computer instructions for causing the computer to execute the method for providing security services as described in any of the above embodiments.

[0171] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0172] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the security service provisioning method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0173] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this disclosure (including the claims) is limited to these examples; within the framework of this disclosure, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this disclosure as described above, which are not provided in detail for the sake of brevity.

[0174] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this disclosure, the provided drawings may or may not show well-known power / ground connections to integrated circuit (IC) chips and other components. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this disclosure, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this disclosure will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuitry) have been set forth to describe exemplary embodiments of this disclosure, it will be apparent to those skilled in the art that the embodiments of this disclosure may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0175] Although this disclosure has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0176] This disclosure is intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method of provisioning of a secure service, characterized by, The method comprises the following steps: receiving a service request of a user, and constructing a data communication service and a key negotiation service; processing the data communication service and the key negotiation service to obtain a data service bearing channel and a quantum service bearing channel; performing adaptive service bearing based on the data service bearing channel and the quantum service bearing channel; the receiving of the service request of the user and the constructing of the data communication service and the key negotiation service comprises: constructing a data transmission communication service based on the service request, and generating a data channel and a quantum channel; the processing of the data communication service and the key negotiation service to obtain the data service bearing channel and the quantum service bearing channel comprises: generating a plurality of transmission paths based on the data channel and the quantum channel; determining the data service bearing channel and the quantum service bearing channel based on the plurality of transmission paths; the determination of the data service bearing channel based on the plurality of transmission paths comprises: setting at least two transmission paths with the shortest distance in the plurality of transmission paths as final transmission paths; performing ascending order sorting on the final transmission paths according to the hop number of the final transmission paths to obtain sorted final transmission paths; calculating quantum service loss values generated when the sorted final transmission paths bear the data channel; determining a transmission path with the minimum quantum service loss value in the sorted final transmission paths as the data service bearing channel; the determination of the quantum service bearing channel based on the plurality of transmission paths comprises: calculating data service loss values generated when the sorted final transmission paths bear the quantum channel; performing ascending order sorting on the data service loss values to obtain a first data service loss value and a second data service loss value with the minimum loss; determining the sorted final transmission path corresponding to the first data service loss value as a first quantum service bearing channel.

2. The method of claim 1, wherein, the constructing of the data transmission communication service based on the service request and the generating of the data channel and the quantum channel comprise: constructing the data transmission communication service based on the service request, and generating the data channel; determining an encryption protocol of the service request according to a user demand in the service request; determining a key quantity and a key rate required by the service request based on the encryption protocol; constructing a key negotiation service based on the key quantity and the key rate, and generating the quantum channel; wherein the key rate is represented as: where k is determined by the encryption protocol, denotes the key agreement rate, denotes the data transfer rate.

3. The method of claim 2, wherein, the calculation of the quantum service loss values generated when the sorted final transmission paths bear the data channel comprises: calculating a Raman scattering crosstalk photon number generated when the sorted final transmission paths bear the data channel; calculating an adjacent channel crosstalk photon number generated when the sorted final transmission paths bear the data channel; taking the Raman scattering crosstalk photon number and the adjacent channel crosstalk photon number as quantum service loss values; wherein the Raman scattering crosstalk photon number is represented as: wherein, represents the number of crosstalk photons caused by Raman scattering in the process of signal co-fiber transmission, n represents the nth data channel, m represents the mth quantum channel, R represents Raman, represents the crosstalk power caused by Raman scattering, represents the wavelength at which the quantum channel is located, represents the time window interval of the quantum detector, represents the quantum efficiency of the quantum detector, represents the Planck constant, represents the speed of light in vacuum; the adjacent channel crosstalk photon number is calculated as: wherein, represents the crosstalk photon number caused by the adjacent channel power leakage in the signal exchange process, n represents the nth data channel, m represents the mth quantum channel, and C represents crosstalk, represents the average value of the transfer function of the narrowband filter in the adjacent channel interval, represents the signal power of the data signal to be measured, represents the fiber loss coefficient, represents the fiber length, the value of e is 2.718, represents the wavelength interval between the data channel and the quantum channel, represents the wavelength at which the quantum channel is located, represents the wavelength at which the data channel is located, represents the adjacent channel isolation of the wavelength division multiplexer, represents the set protection wavelength band, which is set to 200 GHz.

4. The method of claim 3, wherein, the determination of the quantum service bearing channel based on the plurality of transmission paths further comprises: In response to determining that the number of keys is greater than the number of quantum service carrying channels, the final transmission path corresponding to the second data service loss value is determined as a second quantum service carrying channel.

5. A device for supplying a secure service, characterized by Comprise: The service receiving module is configured to receive the service request of the user, and construct the data communication service and the key negotiation service; The service deployment module is configured to process the data communication service and the key negotiation service to obtain a data service carrying channel and a quantum service carrying channel; The service carrying module is configured to adaptively carry services based on the data service carrying channel and the quantum service carrying channel; The receiving of the service request of the user and the construction of the data communication service and the key negotiation service comprise: Based on the service request, a data transmission communication service is constructed, and a data channel and a quantum channel are generated; The processing of the data communication service and the key negotiation service to obtain a data service carrying channel and a quantum service carrying channel comprises: Based on the data channel and the quantum channel, a plurality of transmission paths are generated; Based on the plurality of transmission paths, a data service carrying channel and a quantum service carrying channel are determined; The determination of the data service carrying channel based on the plurality of transmission paths comprises: At least two transmission paths with the shortest distance in the plurality of transmission paths are set as final transmission paths; The final transmission paths are sorted in ascending order according to the hop number of the final transmission paths, and sorted final transmission paths are obtained; The quantum service loss value generated when the sorted final transmission paths carry the data channel is calculated; The transmission path with the minimum quantum service loss value in the sorted final transmission paths is determined as a data service carrying channel; The determination of the quantum service carrying channel based on the plurality of transmission paths comprises: The data service loss value generated when the sorted final transmission paths carry the quantum channel is calculated; The data service loss values are sorted in ascending order, and the first data service loss value and the second data service loss value with the minimum loss are obtained; The final transmission path corresponding to the first data service loss value is determined as a first quantum service carrying channel.

6. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to realize the method of any one of claims 1 to 4.

7. A non-transitory computer readable storage medium storing computer instructions for causing a computer to execute the method of any one of claims 1 to 4.

Citation Information

Patent Citations

  • Adaptive channel allocation method in dynamic DWDM-QKD network based on machine learning

    CN110601826A

  • Quantum key distribution channel allocation method and device, electronic equipment and storage medium

    CN112564818A