A segmented key distribution method and system for a hybrid relay QKD network

By using a segmented key distribution method in QKD networks and leveraging trusted relay nodes for key reconstruction and hop-by-hop encryption/decryption, the problem of key vulnerability at relay nodes in long-distance QKD networks is solved, improving security and reducing resource consumption.

CN116155492BActive Publication Date: 2026-03-31UNIV OF SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-22
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing QKD networks, user keys are stored in plaintext on relay nodes during long-distance key distribution, making them vulnerable to attacks. Furthermore, existing multipath key distribution schemes fail to effectively utilize trusted relays, resulting in insufficient security and significant key resource consumption.

Method used

A segmented key distribution method is adopted, which divides the key distribution path into segments and performs key distribution in parallel on each segment. Trusted relay nodes are used for key reconstruction and forwarding. The key is transmitted by hop-by-hop encryption and decryption through trusted relay nodes, which reduces the impact of attacks on a single node on the overall path.

Benefits of technology

It improves the security of key distribution, reduces the consumption of key resources, and enhances network security and resource utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116155492B_ABST
    Figure CN116155492B_ABST
Patent Text Reader

Abstract

The application relates to a segmented key distribution method and system for a hybrid relay QKD network, and the method comprises the following steps: S1: after a user key distribution request is sent by an arbitrary terminal node in a QKD network, a key distribution path and segmented paths thereof are constructed; wherein the key distribution path comprises a source node, a destination node, trusted and untrusted relay nodes; each segmented path comprises at least one sub-segmented path; S2: key distribution is carried out on each sub-segmented path in parallel, and keys are reconstructed at the end nodes of the segmented paths to synchronously generate segmented keys; S3: along the key distribution path, the first segmented key is used as a user key of the key distribution path, and the remaining segmented keys are used as encryption keys, the user key is forwarded through the trusted relay, and key distribution from the source node to the destination node is completed. The method provided by the application can reduce the path length of key distribution, thereby providing security, and reducing the consumption of key resources on the link.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum key distribution technology, and specifically to a segmented key distribution method and system for hybrid relay QKD networks. Background Technology

[0002] Information security is a critical concern in the digital age, and classical cryptography offers a variety of algorithms for encryption, authentication, and integrity protection. However, with the development of quantum information technology, the enormous computing power of quantum computers and the proof of quantum supremacy have rendered classical cryptography, based on mathematical problems such as prime factorization and discrete logarithms, insecure. To address the quantum threat, quantum key distribution (QKD) technology, combined with one-time pad encryption, can theoretically achieve unconditional security between communicating parties.

[0003] Several QKD protocols have been developed, but they can only distribute QKD keys between nodes that are directly connected in close proximity. To distribute keys between any two parties across nodes over long distances, a common approach is to use relay technology to form a QKD network. Trusted relays are widely used commercially due to their flexibility and applicability. However, in long-distance key distribution, the final user key is encrypted and protected by the link-level key at each hop. Each relay node on the path must first decrypt the message containing the encrypted user key to obtain the user key, then encrypt it again and send it to the next hop. Therefore, the user key exists in plaintext form at the relay nodes. Considering the increasing number of attacks targeting relay nodes that could steal the user keys forwarded by them, the security of relay nodes must be addressed. To solve the impact of untrusted relay nodes on the security of user key distribution in QKD networks, existing work has attempted to improve key security by using a multi-path key distribution method, XORing the keys distributed on multiple paths to obtain the final key. However, these schemes do not take into account the full utilization of trusted relays in the network. Especially in the scenario of long-distance key distribution, the existing multi-path key distribution schemes cannot effectively improve security and reduce the consumption of key resources on the link. Summary of the Invention

[0004] To address the aforementioned technical problems, this invention provides a segmented key distribution method and system for hybrid relay QKD networks.

[0005] The technical solution of this invention is: a segmented key distribution method for hybrid relay QKD networks, comprising:

[0006] Step S1: After any terminal node in the QKD network sends a user key distribution request, it constructs a key distribution path and its segmented paths; wherein, the key distribution path includes: source node, destination node, trusted relay node and untrusted relay node; each segmented path contains at least one sub-segmented path;

[0007] Step S2: Perform key distribution in parallel on each sub-segment path contained in each segmented path, and reconstruct the key using a key reconstruction function at the end node of the segmented path to synchronously generate the segmented key corresponding to each segmented path;

[0008] Step S3: Along the key distribution path, the first segment key is used as the user key for the key distribution path, and the remaining segment keys are used as encryption keys. The user key is forwarded via the trusted relay to complete the distribution of the user key from the source node to the destination node.

[0009] Compared with the prior art, the present invention has the following advantages:

[0010] This invention discloses a segmented key distribution method for hybrid relay QKD networks. The key distribution path is segmented based on trusted relays, thus distributing the risk of key leakage of a key distribution path to each segment. This avoids the impact of an attack on a single node on the path on the security of key distribution throughout the entire path. At the same time, it makes full use of the security features of trusted relays, reduces the length of the key distribution path, thereby improving the security of the key distribution process and reducing the consumption of key resources on the link. Attached Figure Description

[0011] Figure 1 This is a flowchart of a segmented key distribution method for a hybrid relay QKD network according to an embodiment of the present invention;

[0012] Figure 2 This is a schematic diagram of a QKD network in an embodiment of the present invention;

[0013] Figure 3 This is a schematic diagram of a non-segmented key distribution method in an embodiment of the present invention;

[0014] Figure 4 This is a schematic diagram of the segmented key distribution method in an embodiment of the present invention;

[0015] Figure 5 This is a block diagram of a segmented key distribution system for a hybrid relay QKD network according to an embodiment of the present invention. Detailed Implementation

[0016] This invention provides a segmented key distribution method for hybrid relay QKD networks, which fully utilizes the security features of trusted relays, reduces the path length of key distribution to improve security, and reduces the consumption of key resources on the link.

[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below through specific implementations and in conjunction with the accompanying drawings.

[0018] Example 1

[0019] like Figure 1 As shown in the figure, an embodiment of the present invention provides a segmented key distribution method for hybrid relay QKD networks, comprising the following steps:

[0020] Step S1: After any terminal node in the QKD network sends a user key distribution request, it constructs a key distribution path and its segmented paths; wherein, the key distribution path includes: source node, destination node, trusted relay node and untrusted relay node; each segmented path contains at least one sub-segmented path;

[0021] Step S2: Perform key distribution in parallel on each sub-segment path contained in each segmented path, and use the key reconstruction function to reconstruct the key at the end node of the segmented path to synchronously generate the segmented key corresponding to each segmented path.

[0022] Step S3: Along the key distribution path, the first segment key is used as the user key for that key distribution path, and the remaining segment keys are used as encryption keys. The user key is forwarded through a trusted relay to complete the user key distribution from the source node to the destination node.

[0023] In one embodiment, step S1 above: After any terminal node in the QKD network sends a user key distribution request, a key distribution path and its segmented paths are constructed; wherein, the key distribution path includes: a source node, a destination node, a trusted relay node, and an untrusted relay node; each segmented path contains at least one sub-segmented path, specifically including:

[0024] The central controller obtains the location information of trusted relay nodes, which serve as the aggregation points, and constructs a key distribution path based on a routing algorithm. This key distribution path contains N trusted relay nodes, forming N+1 segmented paths. Each segmented path's endpoint can be a source node, a destination node, or a trusted relay node. When a segmented path contains multiple sub-segmented paths, these sub-segmented paths are parallel paths, meaning they share the starting and ending endpoints of the segmented path. Specifically, when N=0, the path between the source and destination nodes consists of a single segmented path.

[0025] Centralized controllers are widely used in existing QKD networks, such as Figure 2 As shown, the centralized controller can acquire the network status of the entire QKD network, including network topology and the trustworthiness of relay nodes, and issue routing information and reconfiguration commands to the relay nodes. The centralized controller establishes a key distribution path and its segmented paths based on the source node, destination node, and actual network status included in the key distribution request from any terminal node in the QKD network. The key distribution path consists of several segmented paths serially, and each segmented path contains several parallel sub-segmented paths.

[0026] The steps of the segmentation-based routing algorithm in this embodiment of the invention are as follows:

[0027] 1) Find the segmented trusted relay nodes. The initial trusted relay set is empty. Use Dijkstra's algorithm to find the trusted relay node with the smallest sum of hops between the source and destination nodes that is not in the trusted relay set. Then, use the extended Dijkstra's algorithm with the path's key distribution security probability as the path cost to find the two optimal paths between the source and destination nodes and calculate the security probability of user key distribution between the source and destination nodes. Similarly, find the two optimal segmented paths from the source node to the trusted relay node and from the trusted relay node to the destination node and calculate the security probability of user key distribution after segmentation. If the security probability after segmentation is greater, add the trusted relay node to the set and set it as the new source node to continue running step 1); otherwise, step 1) is terminated.

[0028] 2) Find the path within the segment. Using the set of trusted relays found in step 1) as the path convergence point, begin iteratively searching for available paths within the segment. In each iteration, find a sub-segment path on each segment and update the topology, until no redundant paths are found in a single iteration or the security requirements are met, at which point the algorithm terminates.

[0029] The embodiments of the present invention calculate the security of each sub-segment path according to the following formula:

[0030]

[0031] Among them, P l ρ represents the security probability of the distribution key for a sub-segment path within a segmented path; l represents the set of relay nodes included in the sub-segment path, including trusted and untrusted relay nodes; i Let ρ be the security probability of relay node i on the sub-segment path, representing the probability that relay node i is not controlled by an attacker. i The higher the value, the more secure relay node i is. When relay node i is a trusted relay node, ρ i =1 indicates that the trusted relay node is absolutely secure;

[0032] The security of each segmented path is calculated using the following formula:

[0033]

[0034] Among them, s j Let MP be the set of sub-segment paths on the j-th segment path; j Let be the security probability of the segment key obtained by key reconstruction from the keys on multiple parallel sub-segment paths on the j-th segment path.

[0035] The security of user keys along the key distribution path is calculated using the following formula:

[0036]

[0037] in, is the set of segmented paths; SP is the security probability of the user key obtained through segmented key distribution.

[0038] like Figure 3 In the QKD network shown, all relay nodes other than the source node S, the destination node D, and a trusted relay node R are untrusted relay nodes, meaning the number of trusted relay nodes N=1. Therefore, the network contains two segmented paths, SR and RD. The segmented path SR contains three parallel sub-segmented paths: SAR, SBR, and SCR. The segmented path RD contains two parallel sub-segmented paths: RHD and RGD.

[0039] In one embodiment, step S2 above: key distribution is performed in parallel on each sub-segment path contained in each segmented path, and the key is reconstructed using a key reconstruction function at the end node of the segmented path, synchronously generating the segmented key corresponding to each segmented path, specifically including:

[0040] Step S21: For each sub-segment path in each segmented path, the key shared between the starting node and the next adjacent relay node of the segmented path is used as the key of the sub-segment path, and the key shared between the remaining relay nodes on the sub-segment path is used as the encryption key. The key is forwarded through the relay nodes on the sub-segment path in a hop-by-hop encryption and decryption manner. That is, the nodes on the sub-segment path use the key shared with the previous adjacent node to decrypt and use the key shared with the next adjacent node to encrypt, and forward the key until it reaches the ending node of the segmented path. Thus, the key distribution process is completed in parallel on all sub-segment paths of each segmented path. At this time, the starting node and the ending node on the segmented path share the keys distributed on all the sub-segment paths it contains.

[0041] Step S22: Use the same key reconstruction function at the end nodes of the segmented path, namely the starting end node and the ending end node, to generate the segmented key for the segmented path;

[0042] When using existing multi-path, non-segmented key distribution methods, to prevent attackers from controlling a single untrusted relay node and stealing multiple keys, the paths sought are all non-intersecting. For example... Figure 3 As shown, when source node S needs to send user key Ka to destination node D, only two disjoint paths can be found between source node S and destination node D. Taking paths SARHD and SCEFGD as examples, keys a1 and a2 are distributed through them respectively. Finally, source node S and destination node D can obtain a consistent user key Ka by performing an XOR operation on keys a1 and a2. Assume that the unit key quantity generated between adjacent links is 128 bits, and the security probability ρ of untrusted relay nodes... i =0.9. Considering that the number of hops for the two paths are 4 hops and 5 hops respectively, the amount of key required to achieve end-to-end user key distribution on the key distribution path using the one-time pad method is 9*128 bits. The security probability of key a1 after hop-by-hop encryption and forwarding through path SARHD is 1*0.9*1*0.9*1 = 0.81. The security probability of key a2 after hop-by-hop encryption and forwarding through path SCEFGD is 1*0.9*0.9*0.9*0.9*1 = 0.6561. Therefore, the security probability of the final user key after XOR reconstruction is 1-(1-0.81)*(1-0.6561) = 0.9347.

[0043] like Figure 4 The diagram illustrates the segmented path-based key distribution method proposed in this invention. A trusted relay node R is used as the segmentation point. Three parallel sub-segmented paths, SAR, SBR, and SCR, are established between the source node S and the trusted relay node R to distribute keys a1, a2, and a3, respectively. A shared segmented key Ka is reconstructed between the source node S and the trusted relay node R. Two parallel sub-segmented paths, RHD and RGD, are constructed between the trusted relay node R and the destination node D to distribute path keys b1 and b2, respectively. A shared segmented key Kb is then reconstructed between the trusted relay node R and the destination node D. Finally, the trusted relay node R uses Ka and Kb to distribute the user key Ka to the destination node D using an encrypted forwarding method.

[0044] First, even if only two parallel sub-segment paths, SAR and SBR, are used between the source node S and the trusted relay node R, according to the security calculation formula, the security probabilities of keys a1 and a2 distributed through the two parallel sub-segment paths SAR and SBR are both 1*0.9*1=0.9. After the XOR reconstruction operation, the security probability of the segment key Ka is 1-(1-0.9)*(1-0.9)=0.99. Similarly, two parallel sub-segment paths, RHD and RGD, are used between the trusted relay node R and the destination node D. According to the security calculation formula, the security probability of keys b1 and b2 distributed through the two parallel sub-segment paths RHD and RGD is 1*0.9*1 = 0.9. After the XOR reconstruction operation, the security probability of the segment key Kb is 1-(1-0.9)*(1-0.9) = 0.99. Therefore, the security probability of the user key obtained by forwarding via the trusted relay node R with Ka as the user key and Kb as the encryption key is 0.99*0.99 = 0.9801. Assuming that the unit key quantity generated between adjacent links is 128 bits, the segment-based key distribution method adopted in this invention uses a total of four sub-segment paths with a hop count of 2, namely SAR, SBR, RHD, and RGD, thus consuming 8*128 bits of key. Compared to existing methods, the method provided by this invention not only consumes less link key resources, but also offers superior security for key distribution compared to conventional multipath distribution methods.

[0045] Secondly, the method provided by this invention offers a more secure option. When further employing the sub-segment path (SCR), security can be further improved even with the consumption of more key resources (10*128 bits). At this point, according to the security calculation formula, the security probability of keys a1, a2, and a3 is 0.9. After the XOR reconstruction operation, the security probability of segment key Ka is 1 - (1 - 0.9)*(1 - 0.9)*(1 - 0.9) = 0.999. The security probability of keys b1 and b2 is 0.9. After the XOR reconstruction operation, the security probability of segment key Kb is 1 - (1 - 0.9)*(1 - 0.9) = 0.99. Therefore, the final security probability of the user key obtained by forwarding via trusted relay node R using Ka as the user key and Kb as the encryption key is 0.999*0.99 = 0.98901.

[0046] Once path key distribution is completed on all paths between the two endpoints of a segmented path, a key reconstruction function is used to generate the key for that segment based on the path keys on all paths of that segment. The segmented key reconstruction method in this embodiment includes, but is not limited to, XOR, HASH, and (t,n) threshold algorithms. Figure 4As shown, path keys a1, a2, and a3 are reconstructed to generate segment key Ka, and path keys b1, b2, and b3 are reconstructed to generate segment key Kb.

[0047] The segmented key distribution method for hybrid relay QKD networks proposed in this invention can utilize more residual paths in the network and shorten path length by reusing trusted relay nodes, thereby reducing the risk of key leakage, improving the security of key distribution, and reducing the consumption of key resources on the link.

[0048] In one embodiment, step S3 above: along the key distribution path, using the first segment key as the user key for that key distribution path and the remaining segment keys as encryption keys, the user key is forwarded via a trusted relay to complete the user key distribution from the source node to the destination node, specifically including:

[0049] Starting from the source node, the first segment key is used as the user key for the key distribution path. Along the key distribution path, the trusted relay node uses a hop-by-hop encryption and decryption method. That is, the trusted relay node uses the segment key of the previous segment path to decrypt and uses the segment key of the next segment path to encrypt, and then passes it to the next trusted relay node, until it reaches the destination node and obtains the user key for the key distribution path.

[0050] For a key distribution path consisting of several segments, the segment key of the first segment is used as the user key for the key distribution path. Subsequent trusted relay nodes distribute the key hop-by-hop. During forwarding, this key is encrypted and decrypted using the segment keys of each segment. For example... Figure 4 As shown, if a segmented key Ka is used as the user key Ka for the key distribution path, then the trusted relay node R encrypts Ka using the segmented key Kb and sends the encrypted result to the destination node D over the network. The destination node D uses Kb to decrypt the received encrypted information to obtain Ka. Finally, a user key Ka for the key distribution path that meets certain security requirements is obtained.

[0051] In this embodiment of the invention, assuming that the same untrusted relay node is controlled by an attacker, when using the segmented key distribution method of the present invention, if nodes A and G are attacked at this time, the sub-segment path keys a1 and b2 will be leaked, but the segment keys Ka and Kb remain secure. When using the existing non-segmented key distribution method based on multiple paths, again assuming that nodes A and G are attacked, the keys a1 and a2 distributed on both paths will be leaked, and the final user key is reconstructed from keys a1 and a2, thus no longer secure.

[0052] This invention discloses a segmented key distribution method for hybrid relay QKD networks. The key distribution path is segmented based on trusted relays, thus distributing the risk of key leakage of a key distribution path to each segment. This avoids the impact of an attack on a single node on the path on the security of key distribution throughout the entire path. At the same time, it makes full use of the security features of trusted relays, reduces the length of the key distribution path, thereby improving the security of the key distribution process and reducing the consumption of key resources on the link.

[0053] Example 2

[0054] like Figure 5 As shown, this embodiment of the invention provides a segmented key distribution system for hybrid relay QKD networks, comprising the following modules:

[0055] The routing module 41, which constructs the key distribution path and its segmented paths, is used to construct the key distribution path and its segmented paths after any terminal node in the QKD network sends a user key distribution request. The key distribution path includes: source node, destination node, trusted relay node and untrusted relay node; each segmented path contains at least one sub-segmented path.

[0056] The segmented path key distribution and reconstruction module 42 is used to perform key distribution in parallel on each sub-segmented path contained in each segmented path, and to reconstruct the key using a key reconstruction function at the end node of the segmented path, and synchronously generate the segmented key corresponding to each segmented path.

[0057] The segmented key forwarding module 43 is used to forward the user key from the source node to the destination node along the key distribution path, using the first segmented key as the user key of the key distribution path and the remaining segmented keys as encryption keys.

[0058] The above embodiments are provided merely for the purpose of describing the present invention and are not intended to limit the scope of the invention. The scope of the invention is defined by the appended claims. Various equivalent substitutions and modifications made without departing from the spirit and principles of the invention should be covered within the scope of the invention.

Claims

1. A segmented key distribution method for a hybrid relay QKD network, characterized in that, Comprise: Step S1: after any terminal node in the QKD network sends a user key distribution request, a key distribution path and its segmented path are constructed; wherein the key distribution path comprises: a source node, a destination node, a trusted relay node and an untrusted relay node; each segment of the segmented path contains at least one sub-segmented path, wherein the key distribution path comprises: a source node, a destination node, a trusted relay node and an untrusted relay node; each segment of the segmented path contains at least one sub-segmented path, specifically comprising: The topology connection information of the trusted relay nodes and untrusted relay nodes as the convergence points is acquired by the centralized controller, and a key distribution path is constructed according to a routing algorithm, wherein the key distribution path contains a plurality of the trusted relay nodes, thereby forming a plurality of segment paths; wherein the end nodes of each of the segment paths are the source node, the destination node or the trusted relay nodes, and when the segment path contains a plurality of the sub-segment paths, each of the sub-segment paths is a parallel path, i.e. each of the sub-segment paths shares the start end node and the end end node of the segment path. Wherein the routing algorithm comprises: 1) find the segmented trusted relay node: the initial trusted relay set is empty; find the trusted relay node that is not in the trusted relay set and has the minimum sum of the number of hops between the source node and the destination node using the Dijkstra algorithm; then find the optimal two paths between the source node and the destination node using the extended Dijkstra algorithm with the key distribution security probability of the path as the path cost and calculate the security probability of the user key distribution between the source node and the destination node, then also find the optimal two segmented paths from the source node to the trusted relay node and from the trusted relay node to the destination node and calculate the security probability of the segmented user key distribution; if the security probability after segmentation is greater, then add the trusted relay node to the set, and set the node as the new source node to continue repeating step 1), otherwise step 1) is terminated; 2) find the segmented path: use the trusted relay set found in step 1) as the path convergence point to start the loop search for available paths within the segmentation; find a sub-segmented path on each segment in each round of loop and update the topology until the algorithm is terminated when no more paths are found in a round of loop or the security requirement is met; Step S2: perform key distribution on each sub-segmented path contained in each segment of the segmented path in parallel, and reconstruct the key at the end nodes of the segmented path using a key reconstruction function to generate a segmented key corresponding to each segment of the segmented path in synchronization, specifically comprising: Step S21: for each sub-segmented path in each segment of the segmented path, the key shared between the starting end node of the segmented path and the next adjacent relay node is used as the key of the sub-segmented path, and the key shared between the remaining relay nodes on the sub-segmented path is used as the encryption key, and the key is forwarded via the relay nodes on the sub-segmented path in a hop-by-hop encryption and decryption manner, that is, the nodes on the sub-segmented path perform key forwarding in a manner of decrypting with the key shared with the previous adjacent node and encrypting with the key shared with the next adjacent node, until the terminal end node of the segmented path is reached; thereby completing the key distribution process on all sub-segmented paths of each segment of the segmented path in parallel, at which time the starting end node and the terminal end node on the segmented path share the key distributed on all sub-segmented paths contained therein; Step S22: the end nodes on the segmented path, i.e. the starting end node and the terminal end node, generate the segmented key of the segmented path using the same key reconstruction function; Step S3: forwarding the user key via the trusted relay along the key distribution path with the first segment key as the user key of the key distribution path and the rest of the segment keys as encryption keys, to complete the user key distribution from the source node to the destination node.

2. The method of claim 1, wherein, The step S3: forwarding the user key via the trusted relay along the key distribution path with the first segment key as the user key of the key distribution path and the rest of the segment keys as encryption keys, to complete the user key distribution from the source node to the destination node, specifically comprises: Starting from the source node, the first segment key is taken as the user key of the key distribution path, and the trusted relay node adopts hop-by-hop encryption and decryption along the key distribution path, that is, the trusted relay node decrypts the segment key of the previous segment path and encrypts the segment key of the next segment path, and then passes to the next trusted relay node until the destination node is reached to obtain the user key of the key distribution path.

3. A segmented key distribution system for a hybrid relay QKD network, characterized by, Comprise the following modules: A routing module for constructing a key distribution path and segment paths thereof, configured to construct a key distribution path and segment paths thereof after any terminal node in a QKD network sends a key distribution request; wherein the key distribution path comprises a source node, a destination node, trusted relay nodes and untrusted relay nodes; each segment path comprises at least one sub-segment path, and the key distribution path comprises a source node, a destination node, trusted relay nodes and untrusted relay nodes; each segment path comprises at least one sub-segment path, and the routing algorithm comprises: The topology connection information of the brawling said trusted relay node and untrusted relay node as the convergence point is acquired by the centralized controller, and a key distribution path is constructed according to a routing algorithm, wherein the key distribution path contains Said trusted relay node, thereby forming Segmented path; wherein the end node of each said segmented path is said source node, said destination node or said trusted relay node, when said segmented path contains multiple said sub-segmented paths, each said sub-segmented path is a parallel path, that is, each said sub-segmented path shares the starting end node and the terminating end node of said segmented path; The routing algorithm comprises: 1) finding a segmented trusted relay node: the initial trusted relay set is empty; using the Dijkstra algorithm to find a trusted relay node that is not in the trusted relay set and has the minimum sum of the number of hops between the source node and the destination node; then using the extended Dijkstra algorithm with the key distribution security probability of the path as the path cost to find the two optimal paths between the source node and the destination node and calculate the security probability of the user key distribution between the source node and the destination node, then also find the two optimal segment paths from the source node to the trusted relay node and from the trusted relay node to the destination node and calculate the security probability of the segmented user key distribution; if the security probability after segmentation is greater, then add the trusted relay node to the set, and set the node as a new source node to continue repeating step 1), otherwise step 1) is terminated; 2) finding a segmented path: using the trusted relay set found in step 1) as the path convergence point, starting a loop to search for available paths within the segment; find a sub-segment path on each segment in each loop and update the topology until the algorithm is terminated when no more paths are found in a loop or the security requirement is met; The segmented path key distribution and reconstruction module is configured to distribute keys on each sub-segment path included in each segment of the segmented path in parallel, and reconstruct the keys on end nodes of the segmented path using a key reconstruction function, thereby synchronously generating a segmented key corresponding to each segment of the segmented path. Specifically, the segmented path key distribution and reconstruction module comprises: Step S21: For each sub-segment path in each segment of the segmented path, a key shared between a start end node of the segment and a next adjacent relay node is taken as a key of the sub-segment path, and keys shared between the remaining relay nodes on the sub-segment path are taken as encryption keys. The keys are forwarded in a hop-by-hop encryption and decryption manner via the relay nodes on the sub-segment path. That is, the nodes on the sub-segment path decrypt the keys using the key shared with the previous adjacent node and encrypt the keys using the key shared with the next adjacent node, until the end node of the segment is reached. Thus, the key distribution process is completed on all the sub-segment paths of each segment of the segmented path in parallel. At this time, the start end node and the end node of the segmented path share the keys distributed on all the sub-segment paths included in the segmented path. Step S22: The end nodes of the segmented path, i.e., the start end node and the end node, generate a segmented key of the segmented path using the same key reconstruction function. The segmented key forwarding module is configured to forward the keys along the key distribution path, taking the first segmented key as a user key of the key distribution path and taking the remaining segmented keys as encryption keys, via the trusted relay, thereby completing the distribution of the user key from the source node to the destination node.

Citation Information

Patent Citations

  • Model and method for realizing request control and automatic implementation of quantum key distribution (QKD)

    CN102130769A

  • Quantum key distribution system, method and device based on trusted relay

    CN105827397A