Security detection and defense method in quantum key distribution network and related equipment

By employing a distributed control architecture and traffic identification module in the quantum key distribution network, burst traffic is identified and diverted, solving the problem of centralized controllers being vulnerable to denial-of-service attacks. This enables secure detection and defense of the network, improving its stability and security.

CN116318871BActive Publication Date: 2026-03-31BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-01
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing technologies lack effective detection and defense against denial-of-service attacks in quantum key distribution networks, especially in distributed control architectures where centralized controllers are vulnerable to attacks that could lead to network collapse. Furthermore, traditional IP network defense solutions are not suitable for QKD networks.

Method used

A distributed control network architecture is adopted to identify sudden traffic by monitoring traffic information, determine whether it is attack traffic, and transfer high load from a single controller to multiple controllers. Combined with the collaborative work of the key management layer and the control layer, a distributed network architecture is built to defend against denial-of-service attacks.

Benefits of technology

This technology enables balanced processing and differentiation of burst traffic in quantum key distribution networks, reducing the computational burden on the controller, preventing controller crashes, and improving network security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318871B_ABST
    Figure CN116318871B_ABST
Patent Text Reader

Abstract

The present disclosure provides a security detection and defense method in a quantum key distribution network and related equipment. The method acquires a pre-constructed distributed control network architecture for a target quantum key distribution network; monitors traffic information in the control network architecture and identifies whether there is burst traffic in the traffic information; if there is burst traffic, determines whether the burst traffic is attack traffic; in response to determining that the burst traffic is attack traffic, discarding the traffic; if it is determined that the burst traffic is not attack traffic, determining whether the burst traffic is processed by a single network controller; if it is determined that the burst traffic is processed by a single network controller, transferring the burst traffic from the single network controller to multiple network controllers in the distributed control layer. The present scheme can balance, distinguish and process burst traffic in the quantum key distribution network, which is conducive to protecting the network controller from denial of service attacks and improving the security of the quantum key distribution network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network communication technology, and in particular to a security detection and defense method and related equipment in a quantum key distribution network. Background Technology

[0002] Existing technologies using SDN controllers tend to use a single controller to control the entire network. However, research on the feasibility of SDN deployment shows that the physical centralization of the control plane in a single controller is subject to several limitations in terms of scalability, availability, and reliability. When network traffic is high, resource storage and computing bottlenecks are likely to occur. Furthermore, research indicates that centralized controllers are vulnerable to DoS (denial of Service) attacks, resulting in single points of failure and affecting normal network functions.

[0003] Unlike traditional IP networks, quantum key distribution (QKD) networks transmit encryption key resources. In traditional networks, switches act only as relays when transmitting data packets, requiring no additional resources. However, to ensure key confidentiality, QKD networks require multiple key managers (KMs) to continuously XOR, decrypt, and encrypt the key resources end-to-end. This couples routing and key pool resources during key distribution. Furthermore, most existing technologies focus on detecting and defending against denial-of-service (DoS) attacks in SDN-controlled IP networks, with limited research on DoS attacks occurring on southbound interface links in QKD networks. Due to the differences in networking and transmission resources between IP networks and QKD networks, traditional solutions for defending against DoS attacks are not applicable to QKD networks.

[0004] Therefore, the inventors have developed and improved the detection and defense against denial-of-service attacks in distributed control quantum key distribution networks. Summary of the Invention

[0005] In view of this, the purpose of this disclosure is to propose a security detection and defense method and related equipment in a quantum key distribution network that can distinguish between normal burst traffic and abnormal attack traffic when a sudden surge in traffic occurs in the network, and transfer the high load from a single victim controller to multiple controllers, thereby reducing the computing pressure on the controllers and preventing controller crashes.

[0006] To achieve the above objectives, this application, in its first aspect, provides a security detection and defense method in a quantum key distribution network, comprising:

[0007] Obtain a pre-constructed distributed control network architecture for a target quantum key distribution network; wherein the control network architecture includes a distributed control layer and a key management layer, and the control layer receives and processes network information sent by the distributed control layer;

[0008] Monitor traffic information in the control network architecture and identify whether there is sudden traffic in the traffic information;

[0009] If the sudden traffic occurs, determine whether the sudden traffic is attack traffic;

[0010] In response to determining that the burst traffic is attack traffic, the traffic is discarded; or, in response to determining that the burst traffic is not attack traffic, it is determined whether the burst traffic is processed by a single network controller in the distributed control layer.

[0011] When it is determined that the burst traffic is being processed by a single network controller, the burst traffic is transferred from the single network controller to multiple network controllers in the distributed control layer.

[0012] In some optional embodiments, the control network architecture further includes an application layer and a key distribution layer, including:

[0013] The key distribution layer is used to generate keys and store them in the key management layer;

[0014] In response to the key management layer receiving the key request information from the application layer, it sends a key relay request information to the distributed control layer.

[0015] The distributed control layer extracts the required key from the key management layer based on the relay request information, and the relay route allocates the key.

[0016] Based on the application layer, key distribution layer, distributed control layer, and key management layer, the distributed network architecture is constructed.

[0017] In some optional embodiments, monitoring traffic in the control network architecture and identifying any surges in traffic within the distributed control layer includes:

[0018] Set the prediction threshold range for the network controller's traffic in the distributed control layer;

[0019] When traffic passing through the network controller in the distributed control layer is detected to exceed the predicted threshold range, it is determined that there is a burst of traffic in the distributed control layer.

[0020] In some optional embodiments, setting the prediction threshold range for the traffic situation of the network controller in the distributed control layer includes:

[0021] Set a threshold margin for the prediction threshold; wherein the threshold margin is used to reduce the frequent determination of sudden traffic caused by normal fluctuations between the predicted value and the actual value collected during the monitoring process.

[0022] Set the prediction threshold for the number of relay requests in the current and previous time periods, and then sum the two values ​​with weights.

[0023] Set the correction bias for the prediction threshold.

[0024] In some optional embodiments, determining whether the burst traffic is attack traffic includes:

[0025] In response to the key manager of the key management layer receiving a first key request sent by the source encryption application to the network controller;

[0026] In response to the key manager of the key management layer receiving a second key request sent by the target encryption application corresponding to the burst traffic to the network controller;

[0027] By comparing the first key request and the second key request, in response to the two key requests matching each other, the burst traffic is determined to be secure traffic; when the two key requests do not match, the burst traffic is determined to be attack traffic.

[0028] In some optional embodiments, the step of discarding the traffic in response to determining that the burst traffic is attack traffic includes:

[0029] In response to determining that the burst traffic is attack traffic, the network controller sends a storage instruction to the key managers corresponding to the source encryption application and the destination encryption application;

[0030] In response to determining whether the network controller receives a key request that corresponds to the storage instruction;

[0031] When the key request corresponds to the storage instruction, it is determined to be normal burst traffic; when the instruction does not correspond, the traffic containing the key request is discarded.

[0032] In some optional embodiments, the step of transferring the burst traffic from a single network controller to other network controllers in the key management layer when the burst traffic is triggered by a single network controller includes:

[0033] Build a key pool between every two adjacent nodes in the network architecture;

[0034] In response to the fact that the key that would normally need to be issued by the source node is issued by a node adjacent to the source node, the burst traffic is transferred from the single network controller that triggered the burst traffic to the adjacent network controller.

[0035] In a second aspect, based on the same inventive concept, a security detection and defense device for a quantum key distribution network is also disclosed, comprising:

[0036] A network architecture acquisition module is used to acquire a pre-constructed distributed control network architecture for a target quantum key distribution network; wherein, the control network architecture includes a distributed control layer and a key management layer; the traffic information of the key management layer is transmitted to the distributed control layer;

[0037] A burst traffic identification module is used to monitor traffic information in the control network architecture and identify whether burst traffic exists in the traffic information;

[0038] The determination module is used to determine whether the burst traffic is attack traffic; and in response to determining that the burst traffic is attack traffic, to discard the traffic; or, in response to determining that the burst traffic is not attack traffic, to determine whether the burst traffic is processed by a single network controller in the distributed control layer.

[0039] The burst traffic transfer module is used to transfer the burst traffic from the single network controller to multiple network controllers in the distributed control layer when it is determined that the burst traffic is being processed by a single network controller.

[0040] In a third aspect, based on the same inventive concept, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor executes the program to implement the method described in any of the above solutions.

[0041] In a fourth aspect, a non-transitory computer-readable storage medium is also disclosed, the non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method described in any one of the above schemes.

[0042] As described above, the security detection and defense methods, devices, electronic equipment, and storage media in the quantum key distribution network provided in this disclosure, when a controller identifies a large amount of traffic through a burst traffic identification module, queries all key managers adjacent to the key manager that sent the key relay request, filters out key managers that do not belong to the controller, sends a control message to the key manager that sent the burst traffic, forwards its request to a key manager that is not under its control, and deletes the request message from the key manager that sent the burst traffic. This solution achieves the balancing, differentiation, and processing of burst traffic in the quantum key distribution network, which helps protect the network controller from denial-of-service attacks and improves the security of the quantum key distribution network. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 This is a flowchart of a security detection and defense method according to an embodiment of the present disclosure;

[0045] Figure 2 This is a schematic diagram of the structural framework of the control network architecture according to an embodiment of the present disclosure;

[0046] Figure 3 This is a node network topology diagram of the control network architecture according to an embodiment of the present disclosure;

[0047] Figure 4 This is a schematic diagram of the structure of the security detection and defense device according to an embodiment of the present disclosure;

[0048] Figure 5 This is a flowchart illustrating the overall network workflow of an embodiment of this disclosure;

[0049] Figure 6 This is a schematic diagram of an electronic device that is an exemplary embodiment of the present disclosure. Detailed Implementation

[0050] To make the objectives, technical solutions, and advantages of this disclosure clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.

[0051] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0052] Before describing in detail the security detection and defense methods, devices, electronic devices and storage media in the quantum key distribution network of integrated circuits provided in this application, the application scenarios and inventive concepts of this application are first described.

[0053] Quantum key distribution (QKD) utilizes the properties of quantum mechanics to ensure communication security. It enables both communicating parties to generate and share a random, secure key to encrypt and decrypt messages. QKD's security is guaranteed by fundamental laws of quantum mechanics, including the measurement collapse theory, the Heisenberg uncertainty principle, and the no-cloning theorem, theoretically offering the advantage of "unconditional security." However, in practical networking, insecurity in other network structures may prevent the entire system from achieving absolute security.

[0054] This invention relates to the fields of quantum key distribution technology and SDN control technology. The problem to be solved is how to reduce the controller paralysis caused by DoS attacks on the SDN controller by malicious traffic and ensure the availability of the link between the key manager and the southbound interface of the SDN controller.

[0055] Existing research on QKD networks primarily focuses on attacks involving a pair of quantum transceiver nodes, with DoS attacks occurring on a single link between the two nodes. However, in practical applications, deploying highly secure, large-scale, long-distance quantum key distribution networks necessitates multiple quantum nodes and multiple links in a QKD network. DoS attacks in such multi-node networks are far more destructive. Furthermore, in QKD networks incorporating SDN controllers, DoS attacks can occur not only on the data links transmitting keys but also on the north-south links connecting the control and data layers. This invention aims to propose a method for detecting and defending against DoS attacks in distributed control quantum key distribution networks.

[0056] QKD stands for Quantum Key Distribution, SDN controller is a software-defined network controller, and DoS attack is a denial-of-service attack.

[0057] The inventors considered that existing technologies tend to use a single controller to control the entire network when using SDN controllers. However, studies on the feasibility of SDN deployment have shown that the physical centralization of the control plane in a single controller is subject to several limitations in terms of scalability, availability, and reliability. When network traffic is high, resource storage and computing bottlenecks are likely to occur. Furthermore, studies have shown that centralized controllers are vulnerable to denial-of-service (DoS) attacks, resulting in single points of failure and affecting the normal functioning of the network.

[0058] Unlike traditional IP networks, QKD networks transmit encryption key resources. In traditional networks, switches act only as relays when transmitting data packets, requiring no additional resources. However, to ensure key confidentiality, QKD networks require multiple key managers (KMs) to continuously XOR, decrypt, and encrypt the key resources end-to-end. This couples routing and key pool resources during key distribution. Furthermore, most existing technologies focus on DoS attack detection and defense in SDN-controlled IP networks, with limited research on DoS attacks occurring on southbound interface links in QKD networks. Due to the differences in networking and transmission resources between IP and QKD networks, traditional DoS attack defense schemes are not applicable to QKD networks.

[0059] Therefore, embodiments of the present invention provide a security detection and defense method in a quantum key distribution network.

[0060] First, the relevant technologies and scenarios applied in the embodiments of the present invention will be described and introduced;

[0061] (1) SDN-based quantum key distribution network:

[0062] Traditional QKD focuses solely on point-to-point connections at the physical layer, utilizing varying wavelengths or time slices based on the specific needs of point-to-point QKD. However, QKD networks require a unified control plane to globally allocate different resources for ease of operation. Software-defined networking (SDN) is widely used by dividing the network into data and control planes and supporting programmable functions. In recent years, research has focused on SDN-based QKD networks, enabling unified interaction between network devices and protocols.

[0063] The SDN-supported QKD network architecture consists of an application layer, a control layer, a key management layer, and a QKD layer. The application layer sits on top of the SDN-supported QKD network architecture. Unlike traditional optical networks, the application layer includes two main services: key configuration services and security management services. The controller allows abstraction of network resources, such as QKD optical path construction and routing for key generation within the QKD layer via the northbound interface. The control layer manages QKD resources in the QKD layer, provides services to multiple applications in the application layer, and receives resource allocation and policy information from the key distribution layer. The key management layer manages keys generated in the QKD layer and provides them to cryptographic applications in the application layer of the user network. Keys can be shared between any designated QKD nodes via a key management relay. QKD resources in the QKD layer include WDM links and QKD nodes, which can be used to perform point-to-point and end-to-end quantum key distribution processes, respectively.

[0064] (2) Quantum key trusted relay technology:

[0065] Quantum key distribution (QKD) follows a one-time pad encryption method to provide absolutely secure keys for user services in the application layer, ensuring data security in optical networks and extending the physical range of QKD networks. Key generation for remote node pairs is also accomplished through key distribution and key relay using multiple point-to-point QKD systems. At each node, the main process involves encryption-decryption-re-encryption. If a key needs to be transmitted from node A to node D at the current moment, the initial key is encrypted using a different key at node B, adjacent to node A. The encrypted key is then transmitted to node C, adjacent to node B. At node C, the key is decrypted using the same key as the one used to encrypt at node B, yielding the initial key. This encryption-decryption process is repeated until the initial key is transmitted from node A to node D.

[0066] (3) DoS attack detection mechanism in SDN network:

[0067] One of the biggest security weaknesses of SDN is DoS / DDoS attacks (Denial of Service attacks). Compared to traditional scenarios, this attack is more severe in SDN due to its centralized logical control. Because of the storage capacity limitations of current switches, their flow tables cannot contain forwarding policies for all flows. Once a switch cannot find a matching rule for a new incoming packet, it stores the packet in its buffer and sends a query to the controller requesting the appropriate routing rule. This reactive caching mechanism makes switches and controllers vulnerable to DoS attacks. An attacker can overwhelm a switch with payload packets belonging to different flows. The switch's flow tables and buffers will quickly fill up, at which point new, legitimate incoming packets will be dropped. Simultaneously, the controller will exhaust its processing power to handle the large number of meaningless queries that could crash the entire network.

[0068] Research on DoS attacks over SDN in IP networks includes, but is not limited to, the following: Based on the limited and vulnerable nature of controllers in handling large volumes of malicious requests, a simple scheduling-based flow request isolation approach is used to improve the controller's processing capacity. Compared to a single request processing queue, the new scheme logically divides the controller into multiple queues, which can rationally utilize the controller's processing resources. The concept of "entropy" is introduced; entropy is related to randomness, and the higher the randomness, the higher the entropy. If one or more hosts begin receiving excessive incoming packets, randomness decreases, and entropy decreases. Once the entropy falls below a threshold, a DoS attack is detected, and in practice, this threshold can be adjusted based on the statistics of the entire network to ensure proper operation in constantly changing network environments.

[0069] This invention addresses the need for a system capable of distinguishing between normal burst traffic and abnormal attack traffic when sudden surges occur in the network. It also considers the ability to transfer high loads from a single affected controller to multiple controllers, reducing the computational burden on the controllers and preventing controller crashes. Specifically, this invention relates to a distributed SDN architecture in a QKD network, along with a burst traffic identification module, a burst traffic transfer module, and a processing module for determining whether a burst traffic event constitutes a DoS attack.

[0070] Combination Figure 1 As shown, a security detection and defense method in quantum key distribution networks is proposed, including the following steps:

[0071] S1: Obtain a pre-constructed distributed control network architecture for the target quantum key distribution network; wherein, the control network architecture includes an application layer, a distributed control layer, a key management layer, and a key distribution layer (QKD layer), and the control layer receives and processes network information sent by the distributed control layer;

[0072] In the following optional embodiments, step S1 further includes:

[0073] S101: The key distribution layer is used to generate keys and store them in the key management layer;

[0074] S102: In response to the key management layer receiving the key request information from the application layer, the key relay request information is sent to the distributed control layer;

[0075] S103: The distributed control layer extracts the required key from the key management layer based on the relay request information, and the relay route allocates the key;

[0076] S104: Based on the application layer, key distribution layer, distributed control layer, and key management layer, the distributed network architecture is constructed.

[0077] The structural framework of the control network architecture is as follows: Figure 2 As shown in the diagram, the application layer, distributed control layer, key management layer, and key distribution layer (QKD layer) are arranged in the hierarchy shown in the diagram.

[0078] In this example, the application layer is the user terminal that needs key resources and can send key requests to the key management layer. The key distribution layer (QKD layer) is used to generate keys, the key management layer is used to store the keys generated by the key distribution layer, and the distributed control layer is used to control the key distribution of the key management layer and collect relevant key information. The distributed control layer, key management layer and key distribution layer (QKD layer) transmit the required keys to the application layer.

[0079] It should be noted that the distributed control layer consists of several SDN controllers forming a planar structure. All controllers are of equal status, each connected via an east-west interface and communicating with the key manager via a south-west interface. The distributed SDN environment provides logically centralized control, meaning that all controllers not only possess information about the key managers they govern but also have access to the global network state.

[0080] Furthermore, before an SDN controller can build a global network state, it must first receive the local network state from each SDN controller. Additionally, any changes occurring within the scope of each controller's control must be shared with other controllers so they can update their global network state. Each controller has a data store to store and maintain the global network state, and all SDN controllers also have east-west API connections with other controllers, allowing each network controller to directly contact and notify other network controllers.

[0081] The key management layer consists of several key managers, each managed by a different SDN controller. Key relay requests are a crucial type of request that the SDN controller in a QKD network needs to handle.

[0082] Furthermore, when the key manager receives a key request from a user, it determines whether the request requires key relay. If so, it sends a key relay request to the controller that manages the key manager, and transmits it from bottom to top via the southbound interface link. The key relay request constitutes most of the information source between the controller and the key manager.

[0083] S2: Monitor the traffic information in the control network architecture and identify whether there is burst traffic in the traffic information;

[0084] In some optional embodiments, step S2 further includes the following steps:

[0085] S201: Set the prediction threshold range for the traffic status of the network controller in the distributed control layer;

[0086] S202: In response to detecting that the traffic passing through the network controller in the distributed control layer exceeds the predicted threshold range, it is determined that there is a burst of traffic in the distributed control layer.

[0087] Further, it may include:

[0088] S203: Set the threshold margin of the prediction threshold; wherein, the threshold margin is used to reduce the frequent determination of sudden traffic caused by normal fluctuations between the predicted value and the actual value collected during the monitoring process.

[0089] S204: Set the predicted threshold for the number of relay requests in the current and previous time periods, and sum the two values ​​with weights;

[0090] S205: Set the correction deviation for the prediction threshold.

[0091] In some embodiments, a threshold calculation and comparison method is used to identify whether there are sudden surges in traffic on a controller, and only single bursts of traffic originating from a single key manager KM1 are considered. The threshold setting has a significant impact on the detection results. If the threshold is too high, threatening traffic may be classified as normal traffic, thus rendering the detection ineffective; if the threshold is too low, normal traffic may be easily classified as abnormal, increasing the system's detection and processing overhead and potentially affecting requests from legitimate users. Furthermore, the threshold should change according to network traffic variations; it should be a dynamic value, as static thresholds are unsuitable for complex and ever-changing real-world environments.

[0092] It's important to note that the moving average method is a commonly used approach that uses a set of recent actual data to predict values ​​for one or more future periods. This method involves relatively little computation, and the moving average line can effectively reflect the trend and changes in a time series. However, it also has significant limitations. For example, calculating a moving average requires n past observations. When predicting a large number of values, a large amount of data must be stored, resulting in additional computational overhead and increasing the burden on the controller. Furthermore, in the moving average method, each of the n past observations has equal weight, while in reality, the most recent observations often contain more relevant information and therefore have a greater weight. This can negatively impact the accuracy of the predicted values.

[0093] Based on the problems of the moving average method, this solution adopts an exponentially weighted moving average method with a correction bias as the method for calculating the traffic threshold. The exponentially weighted moving average is an improvement on the moving average, calculating and smoothing the current value using the actual measured value and the predicted value at the current time. Compared with the moving average method, the exponentially weighted moving average can better reflect the changing trend of the time series and does not need to store all historical values, resulting in lower memory overhead, making it suitable as a method for controllers to detect traffic. The calculation method of the predicted threshold includes three multiplicative parts: threshold margin, current and previous time period relay request counts, and correction bias. The threshold margin is set to reduce frequent judgments of sudden traffic caused by normal fluctuations between the predicted and actual values; the current and previous time period relay request counts form the main part of the traffic prediction, and the two are in the form of a weighted sum; the correction bias ensures the relative accuracy of the predicted threshold in the early stages of network operation.

[0094] It's important to note that network traffic is often bursty; as the number of active users increases, traffic may suddenly surge. Traffic generated by legitimate users will be flagged as abnormal by this module. To ensure that legitimate user requests are not dropped, the next stage uses a DoS attack detection module to further determine which requests are flagged as abnormal.

[0095] S3: Determine whether the burst traffic is attack traffic;

[0096] In some optional embodiments, step S3 further includes:

[0097] S301: In response to the key manager of the key management layer receiving a first key request sent by the source encryption application to the network controller;

[0098] S302: In response to the key manager of the key management layer receiving a second key request sent to the network controller by the target encryption application corresponding to the burst traffic;

[0099] S303: Compare the first key request and the second key request, and in response to the situation where the two key requests match, determine that the burst traffic is secure traffic; when the two key requests do not match, determine that the burst traffic is attack traffic.

[0100] Based on the characteristics of key request transmission, when an encryption application needs a key for encryption, the source encryption application sends a key request to the KM (Knowledge Manager), and the KM provides the key to the source encryption application. Simultaneously, the target encryption application also sends a request containing key-related information (such as the required key ID) to the KM it is connected to. That is, both encryption applications send key request messages to their respective KMs to obtain the same symmetric key. However, DoS attacks aim to occupy and consume controller resources using useless requests; therefore, the spurious key request message stream generated by a DoS attack does not have a specific target encryption application. By detecting whether key requests appear in pairs, it is possible to determine whether a sudden traffic spike is a DoS attack.

[0101] The source encryption application key format is shown in Table 1 below:

[0102] Table 1

[0103]

[0104] The target encryption application key format is shown in Table 2 below:

[0105] Table 2

[0106]

[0107] In addition to modules such as key relay, key storage, and key lifecycle management, a key request storage unit needs to be added to the key manager. This unit is responsible for collecting key requests from source / destination cryptographic applications and storing the source / destination cryptographic application IDs in the key request messages. The storage space of this unit allows setting an upper limit on the number of stored IDs based on changes in network traffic.

[0108] S4: In response to determining that the burst traffic is attack traffic, discard the traffic; or, in response to determining that the burst traffic is not attack traffic, determine whether the burst traffic is processed by a single network controller in the distributed control layer.

[0109] In some optional embodiments, step S4 further includes:

[0110] S401: In response to determining that the burst traffic is attack traffic, the network controller sends a storage instruction to the key manager corresponding to the source encryption application and the destination encryption application;

[0111] S402: In response to determining whether the key request received by the network controller corresponds to the storage instruction;

[0112] S403: When the key request corresponds to the storage instruction, it is determined to be normal burst traffic; when the instruction does not correspond, the traffic containing the key request is discarded.

[0113] When determining whether a sudden traffic surge is a DoS attack, the SDN controller sends a command to the relevant module of the source / destination KM to retrieve the stored ID. The KM then sends the stored relevant information to the controller, which performs ID comparison. If the same ID exists in the queue information, the request is determined to be a normal sudden flow; otherwise, the request is discarded. By detecting key requests, the accuracy of DoS abnormal traffic detection is improved.

[0114] S5: When it is determined that the burst traffic is being processed by a single network controller, the burst traffic is transferred from the single network controller to multiple network controllers in the distributed control layer.

[0115] In some optional embodiments, step S5 further includes:

[0116] S501: Construct a key pool between every two adjacent nodes in the network architecture;

[0117] S502: In response to the fact that the key that would normally need to be issued by the source node is issued by a node adjacent to the source node, the burst traffic is transferred from the single network controller that triggered the burst traffic to an adjacent network controller.

[0118] In the QKD network, since a key pool can be established between every two adjacent nodes, the key that would normally need to be issued by the source node can also be issued by a node adjacent to the source node. Therefore, burst traffic can be transferred from one controller to multiple controllers, reducing the load on a single controller without affecting normal key distribution. This module is designed to transfer burst traffic that is not a DoS attack.

[0119] When a controller identifies a large volume of traffic through its burst traffic identification module, it queries all key managers adjacent to the key manager that sent the upload key relay request. It then filters out key managers not belonging to its own controller, sends a control message to the key manager that sent the burst traffic, forwards its request to a key manager not under its control, and deletes the request message from the key manager that sent the burst traffic. Since the request processing capabilities of the controllers connected to each adjacent key manager may differ, the number of requests forwarded to them should be allocated proportionally.

[0120] The following embodiments are provided as specific examples to describe this solution:

[0121] like Figure 3 As shown, since this scheme focuses on link protection between the SDN controller and the key manager, only the control layer and key management layer are depicted in the topology diagram below. As shown, this network contains three controllers C1, C2, and C3 and 10 KM nodes, where C1 controls KM1, KM2, and KM3, denoted as C11.<KM1、KM2、KM3> Similarly, C2<KM8、KM9> C3<KM3、KM4、KM5、KM6、KM10> Each controller is connected via an east-west interface and can obtain a global network view; the KM node connection is shown in the figure, and there is a pair of quantum key pools between each adjacent node.

[0122] Assume that the three controllers measure the number of key relay requests they receive every time unit, and set the relevant parameters m=1.5 and T=3 for the prediction threshold in the burst traffic identification module. For controller C1, the number of key relay requests received in the first and second time units are 4 and 6 respectively, and in the third time unit, it receives 100 key relay requests reported from KM2.

[0123] The specific calculation formula for the prediction threshold proposed by the exponentially weighted moving average method with corrected bias in the burst traffic identification module is as follows:

[0124]

[0125]

[0126] In the formula, N(t) represents the number of key relay requests sent by KM1 to the controller at the current time, P(t-1) represents the predicted value of key relay requests in the previous time period, T represents the number of historical time periods, and θ represents the weight of the number of key relay requests at the current time. T and θ are inversely proportional. The smaller the value of T, the closer the value of θ is to 1, the higher the weight of the number of requests measured in the current time period, the lower the weight of the predicted value of the historical time period, and the stronger the time-relatedness. In the formula, 1-θ t To correct for the bias, the relative accuracy of the prediction threshold P(t) can be guaranteed when t is small, where m is the threshold margin. If N(t) > P(t), then the current controller receives a burst of traffic from KM1.

[0127] According to the prediction threshold calculation method of this module, we can obtain P(1) = 4.5, P(2) = 9, P(3) = 90. The flow rate in the first two time units is less than the prediction threshold. Since 100 > 90 in the third time unit, it indicates that there is a sudden flow at that moment.

[0128] To determine whether the sudden traffic surge is a DoS attack occurring between the SDN southbound interface and the KM, controller C1 will send instructions to both the controllers of KM2 and the destination node to retrieve the ID stored in the key request, based on the destination node information contained in the key request sent by KM2. (The destination node's controller then sends this instruction to the destination KM, which retrieves the instruction before sending it back to C1.) The IDs stored on both sides are compared. If no matching ID is found in the queue information, C1 will discard the request sent by KM2. If a matching ID is found, the next step of the sudden traffic comparison process will proceed.

[0129] The specific method for proportionally distributing traffic to adjacent SDN controllers in the burst traffic transfer module is as follows:

[0130]

[0131] Where Nr represents the total number of burst traffic, and n represents the number of controllers receiving the transferred traffic, Nr i This represents the number of traffic allocated to the i-th adjacent key manager, and af represents the current traffic capacity of each controller, and the required traffic volume. This ensures that the controller has sufficient computing power to receive traffic.

[0132] In this example, C1 notifies the other controllers C2 and C3 of its sudden traffic spike, and searches for the key manager adjacent to KM2 based on the key management layer network topology. According to the network topology, KM1, KM4, and KM8 are adjacent to KM2. Because C1...<KM1、KM2、KM7> KM4 and KM8 are not in this set and are controlled by C3 and C2 respectively. C1 sends a forwarding control command to KM2 through the southbound interface, forwarding KM2's key relay request to KM4 and KM8 via the KM link. Currently, the ratio of traffic size that C1, C2, and C3 can handle is 1:5:4. Therefore, C1 instructs KM2 to send 50 requests to C2 and 40 requests to C3, and changes the source node of the key relay request from KM2 to KM4 and KM8; it retains 10 requests for itself.

[0133] The security detection and defense method in the quantum key distribution network provided in this embodiment mainly includes a QKD network distributed SDN architecture, and three parts: a burst traffic identification module, a burst traffic doS attack determination module, and a burst traffic transfer module. When a controller identifies a large amount of traffic through the burst traffic identification module, it queries all key managers adjacent to the key manager that sent the key relay request, filters out key managers that do not belong to the controller, sends a control message to the key manager that sent the burst traffic, forwards its request to a key manager not under its control, and deletes the request message from the key manager that sent the burst traffic. This achieves the balancing, differentiation, and processing of burst traffic in the QKD network, which helps protect the SDN controller from DoS attacks and improves the security of the QKD network.

[0134] In some embodiments, such as Figure 4 As shown, based on the same inventive concept, a security detection and defense device in a quantum key distribution network is also disclosed, comprising:

[0135] Network architecture acquisition module 1 is used to construct a distributed control network architecture; wherein, the control network architecture includes a distributed control layer and a key management layer;

[0136] Among them, such as Figure 5 As shown, the network architecture acquisition module is also used for,

[0137] In response to the key management layer receiving the key request information from the application layer, it sends a key relay request information to the distributed control layer.

[0138] Based on the key relay request information, the network controller of the distributed control layer constructs a global network state;

[0139] The key distribution layer allocates keys based on the global network state;

[0140] Based on the application layer, key distribution layer, distributed control layer, and key management layer, the distributed network architecture is constructed.

[0141] The burst traffic identification module 2 is used to monitor the traffic situation in the control network architecture and identify whether there is a surge in burst traffic in the distributed control layer;

[0142] The burst traffic identification module 2 is also used to set the prediction threshold range for the traffic status of the network controller in the distributed control layer.

[0143] When traffic passing through the network controller in the distributed control layer is detected to exceed the predicted threshold range, it is determined that there is a burst of traffic in the distributed control layer;

[0144] Furthermore, a threshold margin is set for the prediction threshold; wherein, the threshold margin is used to reduce the frequent determination of sudden traffic caused by normal fluctuations between the predicted value and the actual value collected during the monitoring process.

[0145] Set the prediction threshold for the number of relay requests in the current and previous time periods, and then sum the two values ​​with weights.

[0146] Set the correction bias for the prediction threshold.

[0147] The determination module 3 is used to determine whether the burst traffic is attack traffic; and in response to determining that the burst traffic is attack traffic, to discard the traffic; and when determining that the burst traffic is not attack traffic, to determine whether the burst traffic is triggered by a single network controller in the key management layer.

[0148] The determination module 3 is further configured to respond to the key manager of the key management layer receiving a first key request sent by the source encryption application to the network controller;

[0149] In response to the key manager of the key management layer receiving a second key request sent by the target encryption application corresponding to the burst traffic to the network controller;

[0150] In response to the comparison of the first key request and the second key request, if the two key requests match, the burst traffic is determined to be secure traffic; if the two key requests do not match, the burst traffic is determined to be attack traffic.

[0151] Furthermore, in response to determining that the burst traffic is attack traffic, the network controller sends a storage instruction to the key managers corresponding to the source encryption application and the destination encryption application;

[0152] In response to determining whether the network controller receives a key request that corresponds to the storage instruction;

[0153] When the key request corresponds to the storage instruction, it is determined to be normal burst traffic; when the instruction does not correspond, the traffic containing the key request is discarded.

[0154] The burst traffic transfer module 4 transfers the burst traffic from the single network controller to other network controllers in the key management layer when the burst traffic is triggered by a single network controller.

[0155] The burst traffic transfer module 4 is also used to build a key pool between every two adjacent nodes in the network architecture.

[0156] In response to the fact that the key that would normally need to be issued by the source node is issued by a node adjacent to the source node, the burst traffic is transferred from the single network controller that triggered the burst traffic to the adjacent network controller.

[0157] Based on the same inventive concept, corresponding to any of the above embodiments, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the intrinsically secure optical network service mapping method described in any of the above embodiments.

[0158] Figure 6 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.

[0159] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0160] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0161] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0162] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0163] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.

[0164] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0165] The electronic devices described above are used to implement the corresponding methods in any of the foregoing embodiments and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0166] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the intrinsically secure optical network service mapping method as described in any of the above embodiments.

[0167] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0168] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the intrinsically secure optical network service mapping method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0169] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in the details for the sake of brevity.

[0170] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of the implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0171] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0172] This disclosure is intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for security detection and defense in a quantum key distribution network, characterized in that, The method comprises: obtaining a pre-constructed distributed control network architecture for a target quantum key distribution network; wherein the control network architecture comprises a distributed control layer and a key management layer, and the control layer receives and processes network information sent by the distributed control layer; setting a threshold margin of the prediction threshold; wherein the threshold margin is used to reduce the frequent determination of burst traffic caused by normal jitter between the prediction value and the real value collected in the monitoring process; setting the relay request number of the prediction threshold in the current and last period, and weighted sum of both; setting the correction bias of the prediction threshold; in response to detecting that the traffic through the network controller in the distributed control layer exceeds the prediction threshold range, determining that there is burst traffic in the distributed control layer; wherein the calculation formula of the prediction threshold is: ; ; In the formula, N(t) represents the current time The number of key relay requests sent to the controller, P(t-1) represents the predicted value of the key relay request in the last time period, T represents the number of historical record periods, The weight of the number of key relay requests at the current time, The correction bias, m is the threshold margin; if the burst traffic exists, determining whether the burst traffic is attack traffic; in response to determining that the burst traffic is attack traffic, discarding the traffic; or, in response to determining that the burst traffic is not attack traffic, determining whether the burst traffic is processed by a single network controller in the distributed control layer; when it is determined that the burst traffic is processed by a single network controller, transferring the burst traffic from the single network controller to multiple network controllers in the distributed control layer.

2. The method of security detection and defense of claim 1, wherein, The control network architecture further comprises an application layer and a key distribution layer, and the method further comprises: The key distribution layer is configured to generate keys and store the keys to the key management layer; in response to the key management layer receiving key request information sent by the application layer, sending key relay request information to the distributed control layer; the distributed control layer extracts the required keys from the key management layer based on the relay request information, and distributes the keys by relay routing; Based on the application layer, the key distribution layer, the distributed control layer and the key management layer, the distributed control network architecture is constructed.

3. The method of security detection and defense of claim 1, wherein, The determination of whether the burst traffic is attack traffic comprises: in response to the key manager of the key management layer receiving a first key request sent by a source encryption application to a network controller; in response to the key manager of the key management layer receiving a second key request sent by a target encryption application corresponding to the burst traffic to a network controller; comparing the first key request and the second key request, in response to the two key requests matching each other, determining that the burst traffic is safe traffic; when the two key requests do not match, determining that the burst traffic is attack traffic.

4. The method of security detection and defense of claim 3, wherein, The response to determining that the burst traffic is attack traffic, discarding the traffic, comprises: in response to determining that the burst traffic is attack traffic, the network controller sends a storage instruction to the key manager corresponding to the source encryption application and the destination encryption application; in response to determining whether the key request received by the network controller corresponds to the storage instruction; if the key request corresponds to the storage instruction, it is determined to be normal burst traffic; if the instruction does not correspond, the traffic containing the key request is discarded.

5. The method of security detection and defense of claim 1, wherein, The response to determining that the burst traffic is processed by a single network controller, transferring the burst traffic from the single network controller to multiple network controllers in the distributed control layer, comprises: a pair of key pools is constructed between each two adjacent nodes in the network architecture; in response to the key originally required to be sent by the source node being sent by the adjacent node of the source node, the burst traffic is transferred from the single network controller triggering the burst traffic to the adjacent network controller.

6. A security detection and defense apparatus in a quantum key distribution network, characterized by: The method comprises: The network architecture obtaining module is configured to obtain a pre-constructed distributed control network architecture for a target quantum key distribution network; wherein the control network architecture comprises a distributed control layer and a key management layer, and the control layer receives and processes network information sent by the distributed control layer; The burst traffic identification module is configured to set a threshold margin of a prediction threshold; wherein the threshold margin is used to reduce frequent determination of burst traffic caused by normal jitter between a prediction value and an actual value collected in a monitoring process; set the prediction threshold to the number of relay requests in the current and previous time periods, and weighted sum of the two; set the correction bias of the prediction threshold; in response to detecting that the traffic through the network controller in the distributed control layer exceeds the prediction threshold range, determine that there is burst traffic in the distributed control layer; wherein the calculation formula of the prediction threshold is: ; ; wherein, N(t) represents the current time The number of key relay requests sent to the controller, P(t-1) represents the predicted value of the key relay request in the previous time period, T represents the number of historical record time periods, The weight of the number of key relay requests at the current time, The correction bias, m is the threshold margin; The determining module is configured to determine whether the burst traffic is attack traffic; and in response to determining that the burst traffic is attack traffic, discard the traffic; or in response to determining that the burst traffic is not attack traffic, determine whether the burst traffic is processed by a single network controller in the distributed control layer; The burst traffic transferring module is configured to, when it is determined that the burst traffic is processed by a single network controller, transfer the burst traffic from the single network controller to multiple network controllers in the distributed control layer. 7.An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable by the processor, the processor implementing the method of any one of claims 1 to 5 when executing the program. 8.A non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method of any one of claims 1 to 5.