Physical Layer Encryption Method for Digital Orthogonal Filtering Multiple Access Passive Optical Network
Through the advanced modulation and digital filter security design based on the Y-00 protocol, the eavesdropping problem of the DFMA-PON system is solved, and the three-dimensional dynamic encrypted transmission of the system is realized, which enhances security and reduces the complexity of electrical signal processing.
Patent Information
- Application Number
- CN202211484687.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-24
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-11-24
AI Technical Summary
The existing DFMA-PON system is susceptible to eavesdropping interference at optical fibers and beam splitters, and traditional encryption methods are highly complex or difficult to effectively protect digital filters, resulting in insufficient security.
The high-order modulation and digital filter security design based on the Y-00 protocol are adopted. By performing M-fold upsampling, digital orthogonal molding and addition processing at the transmitting end, corresponding downsampling and decoding modulation are performed on the receiving end, and the original bit data is subjected to high-order mapping encryption, and the random phase of the digital filter and the start intercept position of the filtered output signal are designed for encryption.
It enhances the security of the DFMA-PON system, can resist eavesdropping, reduces the complexity of electrical signal processing, and improves the security and cost-effectiveness of the system without increasing the complexity of the system.
Smart Images

Figure CN116248199B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of optical communication encryption, and relates to a physical layer encryption method for a digital orthogonal filtering multiple access passive optical network (DFMA-PON) based on high-order modulation encryption of the Y-00 protocol and secure design of digital filters. Background Technique
[0002] With the advent of the 5G era, significant changes have occurred in the major indicators of communication networks, and the requirement for bandwidth in 5G fronthaul technology is also continuously increasing. To meet the growing demand for bandwidth, among the different options provided for end-users, the advantages of deploying an economical and efficient Passive Optical Network (PON) have been widely recognized and considered a reliable solution.
[0003] Among the various multiple access candidate technologies of PON systems that have been proposed, the Digital Filtering Multiple Access Passive Optical Network (DFMA-PON) proposed by relevant researchers at Bangor University in the UK in 2015 has attracted great attention due to its flexible and simple bandwidth allocation, good compatibility with existing PON networks, low cost, etc., and has become one of the solutions that may be applicable to 5G fronthaul.
[0004] Like other PON networks, the DFMA-PON system is also vulnerable to security threats. There is a risk of fiber and splitter eavesdropping and interference during the process of broadcasting information to all users in the downstream direction, such as fiber bending eavesdropping or splitter Quality of Service (QoS) attack interference, etc. Therefore, it is necessary to study the secure transmission scheme of this system.
[0005] To achieve secure transmission in the access network, the current secrecy communication technologies in the main optical access network can be mainly divided into two types: one is to perform complex transformation processing on electrical signals using Digital Signal Processing (DSP) technology; the other is to hide the signal light through optical signal processing, making it difficult to analyze and identify the transmitted signal on the line. Currently, physical layer protection achieved by utilizing the diverse physical characteristics of the optical network has become a new research hotspot. For physical layer security, the proposed solutions mainly include optical quantum noise encryption, optical code division multiple access technology, covert optical communication technology, chaotic laser secrecy communication technology, and digital chaos encryption. Using a chaotic system to generate a scrambling matrix for mixing time-frequency domain information and digital filter phase masking can enhance the physical layer security of the DFMA-PON system to a certain extent. However, since the DSP complexity of generating a scrambling matrix using a hyperchaotic Chen system is relatively high; similarly, for the signal encryption method combining optical quantum noise and the Y-00 encryption protocol, multi-polarization base encryption of the constellation map of the transmitted data mapping can well hide the original data in a high-order constellation map affected by noise, but the traditional Y-00 protocol only encrypts and transmits the original data and it is difficult to perform secure design on the digital filter of the DFMA technology.
[0006] Therefore, there is an urgent need for a new DFMA-PON physical layer encryption method to solve the above problems. Summary of the Invention
[0007] In view of this, the purpose of the present invention is to provide a DFMA-PON physical layer encryption method based on high-order modulation encryption and secure design of digital filters using the Y-00 protocol, to achieve three-dimensional dynamic encrypted transmission of the entire DFMA-PON system, while enhancing the transmission security of the entire system and being able to resist malicious eavesdropping by eavesdroppers.
[0008] To achieve the above purpose, the present invention provides the following technical solutions:
[0009] A physical layer encryption system for a digital orthogonal filtering multiple access passive optical network, comprising: an optical signal transmitting end, an optical fiber channel, and an optical receiving end. Among them, the optical signal transmitting end includes: a signal generation module, an upsampling module, a digital orthogonal shaping filter (Shaping Filter, SF), a digital-to-analog converter (Digital to Analog Converter, DAC), and a Mach-Zehnder modulator (Mach Zehnder Modulator, MZM); the optical receiving end includes: a photodetector, an analog-to-digital converter (ADC), a digital orthogonal matching filter (Matching Filter, MF), a downsampling module, and a receiving end signal processing. Among them, the SF filter pair and the digital orthogonal matching filter MF filter pair are orthogonal filter pairs constructed based on the Hilbert pair to ensure strict orthogonality, and include two types of digital filters, namely the in-phase filter and the quadrature filter.
[0010] Furthermore, the encryption method of the above system includes:
[0011] At the transmitting end, in each sub-channel, the original data is first encoded and modulated, and then an operation of inserting M - 1 zeros between adjacent data samples is performed to achieve M-fold upsampling of the modulated signal, and then digital orthogonal shaping filtering is performed; finally, after adding in the digital domain, the signal is output through a digital-to-analog converter (DAC), and the output signal is modulated onto an optical carrier through an electro-optical conversion unit (such as MZM) for transmission;
[0012] At the receiving end, the above reverse operations are performed, the received signal is subjected to corresponding digital orthogonal matching filtering, and one value is taken from every M data samples for corresponding downsampling, and finally decoding and modulation are performed;
[0013] During the above encoding modulation and decoding modulation processes, it is necessary to process the starting truncation position of the filtered output signal and the phase of the digital filter.
[0014] Furthermore, processing the starting truncation position of the filtered output signal specifically includes: setting the starting truncation position in advance for the shaping filter and the matching filter according to the truncation processing mechanism, and at the same time performing high-order mapping encryption processing on the original bit data and the digital filter using the Y-00 encryption protocol.
[0015] Furthermore, the high-order mapping encryption processing based on the Y-00 encryption protocol specifically includes: using a linear shift register as the most common key expansion method in Y-00 encryption, that is, equally dividing the generated long key stream and the original plaintext sequence into N groups, and generating ciphertext signals according to the encryption function of the following formula; then using the generated ciphertext signals as the data transmitted at the transmitting end of the DFMA-PON system for subsequent operations;
[0016]
[0017] Among them, D is the quaternary plaintext data, E is the generated ciphertext, Pol(B) takes different values according to the parity of the key base B. When the key base is odd, the value is 1, otherwise it is 0.
[0018] Furthermore, for the phase processing of the digital filter, that is, the random phase of the digital filter satisfies:
[0019]
[0020]
[0021] Among them, is the random phase corresponding to the I-subband digital orthogonal shaping filter (SF), is the random phase corresponding to the I-subband digital orthogonal matching filter (MF), is the random phase corresponding to the Q-subband filter digital orthogonal shaping filter (SF).
[0022] The beneficial effects of the present invention are as follows: Compared with the traditional digital filtering multiple access passive optical network system, the present invention uses the Y-00 protocol and newly designed filter parameters to complete the multi-dimensional encryption of the source signal and the digital filter, which not only enhances the security of the entire system to a certain extent and can resist malicious eavesdropping by eavesdroppers, but also does not overly increase the complexity of the original system DSP. Specifically, it is reflected in the following aspects:
[0023] 1) When the key in the Y-00 protocol is mapped according to specific rules in the "encryption round", the present invention designs a random phase that can be used for the digital orthogonal filter by using the angle sequence generated by encrypting and mapping the original data at different shift angles, and performs the first layer of encryption on the digital filter of the DFMA-PON system.
[0024] 2) The present invention uses the Y-00 encryption protocol to encrypt the source signal and performs multi-polarization base encryption on the constellation diagram of the transmitted data mapping, which can well hide the original data in a high-order constellation diagram affected by noise, and performs the second layer of encryption on the source signal of the DFMA-PON system. Compared with the digital chaos encryption technology, under the action of the Y-00 encryption protocol, the processing complexity of the entire encrypted electrical signal is relatively low, and for the DFMA system with a large number of ONU units, the cost is relatively low.
[0025] 3) Compared with traditional DFMA-PON, a new digital filter parameter is designed in the present invention (although the design of this parameter enhances the security of the system while introducing more inter-symbol interference terms, due to the design of the inter-symbol interference-free function, the increased interference terms will not cause significant interference to the entire system, so this parameter can be used to enhance the security of the digital filter of the DFMA-PON system) - the starting truncation position of the filtered output signal. The starting truncation position is preset for the shaping filter and the matching filter according to certain rules, and the third-layer encryption is performed on the digital filter of the DFMA-PON system.
[0026] Other advantages, objectives, and features of the present invention will be described to some extent in the subsequent specification, and to some extent, will be obvious to those skilled in the art based on the study of the following text, or can be learned from the practice of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the following specification. Brief Description of the Drawings
[0027] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be described in detail preferably with reference to the accompanying drawings, where:
[0028] Figure 1 is the schematic diagram of the DFMA-PON downlink communication principle of the present invention;
[0029] Figure 2 is the schematic diagram of the implementation principle of the Y-00 protocol encryption and decryption of the present invention;
[0030] Figure 3 is the schematic diagram of the transmission structure of the DFMA-PON system with the high-order modulation and digital filter security processing mechanism based on the Y-00 protocol of the present invention;
[0031] Figure 4 is the error rate curve graph of the received signal of the present invention system under different received optical powers;
[0032] Figure 5 is the constellation diagram of the legal receiving end and the illegal receiving end of the present invention system. Detailed Embodiments
[0033] The following describes the implementation manners of the present invention through specific examples. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0034] Please refer to Figures 1 to 5 , as Figure 1 shown, the DFMA-PON system designed by the present invention mainly includes an optical signal transmitting end (signal generation, upsampling, SF filter, digital-to-analog converter (DAC), Mach-Zehnder modulator (MZM), optical fiber channel, and an optical receiving end (photodetector, analog-to-digital converter (ADC), digital orthogonal matching filter (MF), downsampling, and receiving end signal processing). Among them, the SF filter pair and the MF filter pair are orthogonal filter pairs constructed based on the Hilbert pair to ensure strict orthogonality, and include two types of digital filters, namely the in-phase filter and the quadrature filter.
[0035] At the transmitting end, in each sub-channel, the original data is first encoded and modulated, then an operation of inserting M - 1 zeros between adjacent data samples is performed to achieve M-fold upsampling of the modulated signal, and then shaping filtering is carried out. Finally, after adding in the digital domain, the signal is output through a digital-to-analog converter (DAC), and the output signal is modulated onto an optical carrier through an electro-optic conversion unit (such as MZM) for transmission; at the receiving end, the above reverse operations are performed, the received signal is subjected to corresponding matched filtering, and one value is taken from every M data samples for corresponding downsampling, and finally decoding and modulation are performed.
[0036] The initial phase of the filter used in the traditional DFMA-PON system is zero, and there is a risk that an illegal receiver can estimate the center frequency from the spectrogram and guess all the filters. If a random phase is introduced to the digital filter at the transmitting end, the receiving end needs to ensure that, on the basis of the filter type and center frequency matching the transmitting end filter, the phase matching between the two is also satisfied to correctly filter, thereby improving the security of the system. The derivation formula satisfied by the system is:
[0037]
[0038]
[0039] It is necessary to ensure that the I and Q sub-band filters are strictly orthogonal, that is, the integral of the product of the functions over the specified region is zero. It can be deduced that the following is satisfied: For convenience, here k = 0 is taken, that is
[0040] Corresponding to the transmitter, the impulse response expressions of a pair of orthogonal matched filter pairs can be obtained as:
[0041]
[0042]
[0043] To ensure that the signal can be demultiplexed, the time-domain convolution of the impulse responses of the MF filter at the receiver and the SF filter at the transmitter should satisfy the Nyquist inter-symbol interference-free condition. Here, for the sake of simplicity in calculation, it is analyzed in the frequency domain. Taking the I channel as an example, that is and It is sufficient that the product after Fourier transform satisfies the inter-symbol interference-free law.
[0044]
[0045]
[0046] Among them, represents the linear convolution operation. When the Nyquist inter-symbol interference-free condition needs to be satisfied, The result should be one that only relates to P 2 Here, P(t) can be selected as the response function of the baseband pulse in the form of a square root raised cosine. From this, it can be deduced that the random phases of the SF filter and the MF filter satisfy:
[0047] For convenience, here k = 0 is taken, that is
[0048] That is, the random phase of the digital filter satisfies:
[0049]
[0050]
[0051] The encryption part of the entire system can be subdivided into three parts: processing the starting truncation position of the filtered output signal, processing the original signal, and processing the phase of the digital filter. Based on the high-order mapping encryption scheme of Y-00, after the digital filter and the original signal are securely processed in the DFMA-PON system, the influence of amplified optical noise in the system is enhanced, and the influence of the noise formed by redundant information on the source signal is utilized. As a result, when an illegal receiver does not know the phase sequence satisfied by the receiver's matched filter and the starting truncation position of the filtered signal, and when the key sequence of the plaintext information and the signal base mapping rule are more affected by the inherent noise of the optical device, the received constellation diagram is more easily affected by noise, making it more difficult to recover the original signal. At the same time, the security of the plaintext and the DFMA system is ensured, and finally, a secure transmission technology applicable to the DFMA-PON system is achieved.
[0052] For the DFMA-PON system, the present invention designs a new digital filter parameter - the starting truncation position of the filtered output signal. The starting truncation position is preset according to certain rules in the shaping filter and the matched filter. In this way, when designing the shaping filter at the transmitting end, the starting truncation position (TruncationStart) is preset. The legitimate receiver can obtain the target signal based on the pre-shared truncation start position and correctly demultiplex the signal. However, the illegal receiver does not know this parameter, and misalignment will occur during truncation, resulting in serious error codes.
[0053] According to the formula derivation and analysis of the DFMA-PON system described above, it can be known that during the process of introducing random phases to the filter of this system, two phase conditions of the digital filters at the legitimate transceiver ends are required to correctly perform matched filtering. Since the illegal receiver does not master this phase sequence, it cannot obtain the correct information. From a physical perspective, the Y-00 protocol is the exclusive OR encryption of the highest bit of the plaintext sequence and the key base, which can also be called the "encryption round". The long key sequence is equally divided into N groups of short keys, called key bases. Different key bases have different shift deflection angles. The present invention uses different deflection angles to design the encrypted phase sequence.
[0054] Figure 2 It is the schematic diagram of the Y-00 protocol for 64QAM. Figure 2In the high - order QAM mapping, the I - path key base is used from left to right and the Q - path key base is used from bottom to top. Every four out of every 4 symbols correspond to 00, 01, 10, and 11. Different key bases correspond to different angles. The entire encryption process is equivalent to performing QPSK mapping on the original quaternary data and then performing different shifts in the high - order QAM constellation diagram. The rotation angle can be regarded as the different deflection angles formed by different mapped key bases. Using the above - mentioned angle sequence as the random phase introduced by the digital filter in the DFMA - PON system, during the processing, it is ensured that the phase sequences of digital filters with different center frequencies are different, and digital filters with the same center frequency also perform block - encryption of the phase for the entire output signal length. According to the continuously changing angles of the key base, the update of the phase - encryption sequence of the digital filter is completed.
[0055] The encryption of the plaintext data is carried out according to the traditional Y - 00 protocol. The key generation process is to perform key expansion using the seed key, and the seed key can be obtained through absolutely secure quantum key distribution. The linear shift register adopted in the present invention is used as the most common key - expansion method in Y - 00 encryption, with a simple structure and low cost. The generated long key stream and the original plaintext sequence are equally divided into N groups, and the ciphertext signal is generated according to the encryption function of the following formula. Then, the generated ciphertext signal is used as the data transmitted by the transmitting end in the DFMA - PON system for subsequent operations.
[0056]
[0057] Among them, D is the quaternary plaintext data, E is the generated ciphertext, Pol(B) takes different values according to the parity of the key base B. When the key base is odd, the value is 1, otherwise it is 0.
[0058] As Figure 3 shown, the physical - layer encryption method designed for the DFMA - PON system in the present invention is specifically as follows: At the transmitting end, the source signal and the digital filter are encrypted using the Y - 00 encryption protocol, and the corresponding signal - interception conditions satisfied by the shaping filter at the transmitting end and the matching filter at the receiving end are designed using the truncation - processing mechanism, and relevant digital - filter security designs are carried out.
[0059] Among them, the specific implementation of the digital - filter security design is as follows:
[0060] In the DFMA system structure, the output signal during digital shaping filtering is:
[0061]
[0062] Among them, x(n) is the input signal, h(n) is the impulse response of the filter in the time domain, denotes the linear convolution operation, and y(n) denotes the signal during shaping filtering. The data length of the linear convolution operation result is length[h(n)] + length[x(n)] - 1. To make the result consistent with the length of the input x(n), y(n) needs to be truncated. From linear convolution, assume the input signal x(n) has 4 sampling values, namely x(1), x(2), x(3), x(4), and the number of taps of the shaping filter is 3, assumed to be h(1), h(2), h(3). When x passes through h, the length of the output y is 6, namely y1 to y6. Then, after taking out y2 to y5 from y1 to y6 and performing matched filtering, 6 outputs are still obtained, and the results are z1 to z6.
[0063] Take out the middle part z2 to z5 to have the same length as the sender x. Observing z2 to z5, it can be found that each term contains h 2 (2)x(n). To obtain the source signals x1 to x4 from z2 to z5, taking z2 as an example, considering the ideal situation, only the coefficient of x1 of h in z2 is retained (h 2 (2)), and the coefficients of the remaining interference terms must be as small as possible. This requires h(2) to be as large as possible, and h(2)*h(1), h(1)*h(3), and h(1)*h(1) to be very small, that is, h(2) >> h(1), h(3). The filter function of the DFMA system satisfies the Nyquist intersymbol interference-free design, so that the source signal can be obtained as much as possible after matched filtering. From the intuitive result of linear convolution, to ensure the correct matched filtering of the system to the greatest extent, the middle data is generally intercepted because h(1) and h(3) are very small, and it is difficult to extract the original signal from both sides. However, this middle interception method will reduce the flexibility of the system to a certain extent and does not contribute to the security of the system.
[0064] The present invention adopts the method of circular convolution, and performs the processing of zero-padding and shift addition on the basis of the above linear convolution. Assume that the outputs during shaping filtering are Y1 to Y6. Here, we intercept Y1 to Y4 from Y1 to Y6 to perform matched filtering, and 6 outputs Z1 to Z6 are obtained. Similar to linear convolution, when h(n) satisfies the Nyquist intersymbol interference-free function design, that is, when h(2) >> h(1), h(3), it can be seen that the terms h 2 (2)x(n) are included in Z3 to Z6. When other interference terms are small enough, when obtaining the source signal from the matched filtering signal, intersymbol interference-free transmission can also be ensured as much as possible. The intersymbol interference-free function is an infinitely long function, and generally needs to be truncated. The sender x passes through the shaping filter and the matched filter to obtain the source signal and then perform subsequent operations.
[0065] The random key sequence of the digital filter is implemented using the rotation angle encrypted by Y-00. As Figure 2 shown in the encryption principle, the rotation angle can be regarded as different deflection angles formed by different mapped key bases. According to the derivation, the angle S n satisfies the formula:
[0066] S n = B[π / M b
[0067] where the key is B in base M b , and S n is the angle value of the nth key base. It can be considered that all S n constitute the phase sequence of the digital shaping filter in the DFMA-PON system. The phase sequence of the matching filter at the receiving end satisfies that the sum of the corresponding phases of the shaping filter at the sending end is 2kπ. During the processing, it is ensured that the phase sequences of digital filters with different center frequencies are different, and digital filters with the same center frequency also perform block encryption on the phase of the entire output signal length. According to the continuously changing angle of the key base, the update of the phase encryption sequence of the digital filter is completed.
[0068] For the encryption processing of the source signal, the generated long key stream and the original plaintext sequence are equally divided into N groups, and the ciphertext signal is generated according to the encryption function of the following formula. Then, the generated ciphertext signal is used as the data transmitted at the sending end in the DFMA-PON system for subsequent operations.
[0069]
[0070] In the formula, the quaternary plaintext data is D, and the generated ciphertext is E. Pol(B) takes different values according to the parity of the key base B. When the key base is odd, the number takes 1, otherwise it is 0. The original data corresponding to the same key base is at a relatively large distance interval. With the help of the key base and the mapping rule, the legitimate receiving end can decrypt the ciphertext and restore the plaintext information, while the illegal receiving end does not know the phase sequence of the matching filter and the key base and it is difficult to restore the plaintext information, thus realizing the confidentiality processing of the original data and the phase of the digital filter using the Y-00 protocol.
[0071] As Figure 3 shown, it is a schematic diagram of the transmission structure of the DFMA-PON physical layer encryption system based on the high-order modulation encryption and digital filter security design of the Y-00 protocol, including the optical transmitter end, the optical fiber channel, and the optical receiver end.
[0072] To verify the performance of the DFMA-PON physical layer encryption system for high-order modulation encryption and digital filter secure design based on the Y-00 protocol, at the transmitter, first, the pseudo-random number sequence (PRBS) is encrypted using the Y-00 protocol, and finally, an encrypted signal is generated. For the generated ciphertext signal, orthogonal frequency division multiplexing (OFDM) modulation is first performed, and then the upsampled data is shaped and filtered. The filter is encrypted with a random phase using the generated phase sequence to ensure the security of the filter phase. To reduce the risk that the starting interception position is guessed by an illegal eavesdropper, it is generally set at a position deviating from the midpoint and the starting point. After filtering, all the signals are summed, and a distributed feedback (DFB) laser with a wavelength of 1550 nm is used as the light source, and the modulated signal is sent to the SSMF for transmission.
[0073] At the receiver, the received optical signal is converted into an electrical signal using a PIN photodetector based on the square-law, and after corresponding matched filtering processing and downsampling, the encrypted signals of each channel are obtained. First, the inserted pilot is used to equalize each OFDM signal, and finally, Y-00 decryption is performed, and the bit error rate is calculated. To ensure correct decryption and matched filtering, the specific parameters in the corresponding channels need to be synchronized, and finally, the quaternary data stream at the receiver is obtained.
[0074] Figure 4 The BER curves of the received signals of the legitimate ONU and the illegal ONU in two transmission cases of BTB and through a 25-km SSMF link are shown when the original bit data is encrypted with Y 00-64QAM, the filter undergoes random phase processing, and the starting interception position of the filter is set for different received optical powers. It can be seen from the figure that when the BER reaches the FEC threshold, the received optical powers required by the legitimate ONU in both cases are approximately in the range of -16.5 dBm to -16.9 dBm. Generally speaking, for the encrypted signal, the BTB transmission performance is only slightly better than that through a 25-km optical fiber transmission because the OFDM signal has a certain tolerance to noise, has a certain ability to resist fiber dispersion, and can compensate for part of the dispersion attenuation of the 25-km optical fiber. For the illegal ONU, the BER is around 0.5, which is independent of the received optical power, indicating that the illegal receiver cannot correctly obtain the original data.
[0075] Figure 5 The constellation diagram shown presents the constellation diagram at the receiver after the encrypted data has been transmitted through a 25-km SSMF. Figure 5(a) The figure shows the constellation diagram received by the illegal receiver. Since the illegal receiver cannot know the correct phase sequence and the starting interception position, it is unable to perform correct matched filtering, and does not know the key basis and signal mapping rules. The illegal receiver is more affected by the inherent noise of the optical device, making it impossible to perform subsequent demapping of the encrypted signal and Y-00 decryption, and thus unable to recover the original signal. Figure 5 (b) The figure shows that the legitimate receiver performs correct matched filtering and sets a threshold according to the known key basis and mapping rules to perform Y-00 decryption on the original information. The feasibility of this scheme can be more intuitively seen from the constellation diagram.
[0076] Compared with the existing digital filtering technology, the newly added digital filter parameter in the present invention - the introduction of the starting interception position can provide a certain degree of security for the DFMA-PON system; although the design of this parameter enhances the security of the system while introducing more inter-symbol interference terms, it can be seen from the comparison derivation formula that because of the design of the inter-symbol interference-free function, the added interference terms will not cause great interference to the entire system. Therefore, this parameter can be used to enhance the filter security of the DFMA-PON system. The high-order mapping encryption scheme based on Y-00 designed by borrowing the encryption idea of QNSC in the present invention, after passing through the digital filter and the original signal secrecy processing in the DFMA-PON system, amplifies the influence of the optical noise in the system, and uses the influence of the noise formed by the redundant information on the source signal, making the illegal receiver more affected by the inherent noise of the optical device when it does not know the phase sequence satisfied by the receiver's matched filter and the starting interception position of the filtered signal, as well as the key sequence of the plaintext information and the signal basis mapping rule. The received constellation diagram is more easily affected by the noise, making it more difficult to recover the original signal, while ensuring the security of the plaintext and the DFMA system, and finally realizing the secure transmission technology applicable to the DFMA-PON system of the present invention.
[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the purpose and scope of the present technical solution, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A physical layer encryption method for a digital orthogonal filtering multiple access passive optical network, characterized in that At the transmitting end, in each sub-channel, the original data is first encoded and modulated, and then M-1 zeros are inserted between adjacent data samples to achieve M-fold upsampling of the modulated signal. Then, digital orthogonal shaping filtering is performed. Finally, after addition in the digital domain, the signal is output through a digital-to-analog converter, and the output signal is modulated onto an optical carrier by an electro-optic conversion unit for transmission. At the receiving end, inverse operations are performed, including performing corresponding digital orthogonal matched filtering on the received signal, taking one value from every M data samples for corresponding downsampling, and finally decoding and modulating. During the encoding modulation and decoding modulation processes, it is necessary to process the starting truncation position of the filtered output signal and the phase of the digital filter. Processing the starting truncation position of the filtered output signal specifically includes: setting the starting truncation position in advance in the shaping filter and the matched filter according to the truncation processing mechanism, and at the same time performing high-order mapping encryption processing on the original bit data and the digital filter using the Y-00 encryption protocol. Processing the phase of the digital filter, that is, the random phase of the digital filter satisfies: Among them, is the random phase corresponding to the I sub-band digital orthogonal shaping filter, is the random phase corresponding to the I sub-band digital orthogonal matched filter, is the random phase corresponding to the Q sub-band filter digital orthogonal shaping filter.
2. The physical layer encryption method according to claim 1, wherein The high-order mapping encryption processing based on the Y-00 encryption protocol specifically includes: using a linear shift register as the key expansion method in the Y-00 encryption, that is, equally dividing the generated long key stream and the original plaintext sequence into N groups, and generating ciphertext signals according to the encryption function of the following formula; then using the generated ciphertext signals as the transmitted data at the transmitting end of the DFMA-PON system for subsequent operations. Where D is the quaternary plaintext data, E is the generated ciphertext, Pol(B) takes different values according to the parity of the key base B. When the key base is odd, the value is 1, otherwise it is 0.
3. A physical layer encryption system applicable to the encryption method described in any one of claims 1 to 2, characterized in that, The system includes: an optical signal transmitting end, an optical fiber channel, and an optical receiving end. The optical signal transmitting end includes: a signal generation module, an upsampling module, a digital orthogonal shaping filter, a digital-to-analog converter, and a Mach-Zehnder modulator. The optical receiving end includes: a photodetector, an analog-to-digital converter, a digital orthogonal matched filter, a downsampling module, and receiving end signal processing. Among them, the digital orthogonal shaping filter pair and the digital orthogonal matched filter pair are orthogonal filter pairs constructed based on the Hilbert transform pair, including two types of digital filters, namely the in-phase filter and the quadrature filter.
Citation Information
Patent Citations
Encryption method for multiple access-passive optical networks
CN107360479A
TWDM-PON system physical layer security method based on MD5 verification and AES encryption
CN111786773A