Attack Detection and Mitigation Method and Related Devices Based on Quantum Key Distribution Network

By obtaining the status information of links and key pools in the quantum key distribution network, detecting attacks and querying alternate paths, the problem of network vulnerability is solved and the security of data transmission is improved.

CN116346322BActive Publication Date: 2025-05-27BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310116021.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-08
Publication Date
2025-05-27
Estimated Expiration
2043-02-08

AI Technical Summary

Technical Problem

Due to the characteristics of key resource constraints and open links, the quantum key distribution network is vulnerable to attacks, affecting the security of data transmission.

Method used

By obtaining the status information of the link and key pool in the quantum key distribution network, we can determine whether the data transmission path is attacked. If it is attacked, query the backup path to determine whether the link and key pool of the backup path meet the preset conditions. If it is satisfied, the backup path is used as the target path for data transmission.

Benefits of technology

It realizes detection and mitigation of whether the quantum key distribution network is attacked, improves the network's security protection capabilities, and ensures the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346322B_ABST
    Figure CN116346322B_ABST
Patent Text Reader

Abstract

The present disclosure provides an attack detection and mitigation method and related devices based on a quantum key distribution network, where the quantum key distribution network includes: a link and a key pool; the method includes: obtaining status information of the link and the key pool in the quantum key distribution network; performing judgment processing on the target status information of the target link and the target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network is attacked; in response to determining that the quantum key distribution network is attacked, querying for an alternative path in the quantum key distribution network; performing judgment processing on the alternative link and the alternative key pool corresponding to the alternative path to determine that the alternative link and the alternative key pool meet preset conditions, and using the alternative path as the target path for data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and in particular, to an attack detection and mitigation method and related devices based on a quantum key distribution network. Background Art

[0002] With the development of quantum key distribution networks, interconnection and interoperability have been achieved between different domains of quantum key distribution networks. However, due to the constraint of key resources and the characteristic of link openness of quantum key distribution networks in different domains, they are vulnerable to attacks, which affects the security of data transmission in quantum key distribution networks.

[0003] In view of this, how to detect and mitigate whether a quantum key distribution network has been attacked and improve the security protection ability of the quantum key distribution network has become an urgent problem to be solved. Summary of the Invention

[0004] In view of this, an object of the present disclosure is to propose an attack detection and mitigation method and related devices based on a quantum key distribution network to solve or partially solve the above technical problems.

[0005] Based on the above object, a first aspect of the present disclosure proposes an attack detection and mitigation method based on a quantum key distribution network, including:

[0006] Obtaining status information of links and key pools in the quantum key distribution network;

[0007] Judging and processing the target status information of the target link and the target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network has been attacked;

[0008] In response to determining that the quantum key distribution network has been attacked, querying for an alternative path in the quantum key distribution network;

[0009] Judging and processing the alternative link and the alternative key pool corresponding to the alternative path to determine that the alternative link and the alternative key pool meet preset conditions, and using the alternative path as the target path for data transmission.

[0010] Based on the same inventive concept, a second aspect of the present disclosure proposes an attack detection and mitigation device based on a quantum key distribution network, including:

[0011] An obtaining module, configured to obtain status information of links and key pools in the quantum key distribution network;

[0012] A judging module, configured to judge and process the target status information of the target link and the target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network has been attacked;

[0013] A query module, configured to query an alternate path in the quantum key distribution network in response to determining that the quantum key distribution network is under attack;

[0014] An update module, configured to perform a judgment process on an alternate link and an alternate key pool corresponding to the alternate path, determine that the alternate link and the alternate key pool meet preset conditions, and use the alternate path as the target path for data transmission.

[0015] Based on the same inventive concept, a third aspect of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable by the processor, where the processor implements the method as described above when executing the computer program.

[0016] Based on the same inventive concept, a fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method as described above.

[0017] As can be seen from the above, the present disclosure provides an attack detection and mitigation method and related devices based on a quantum key distribution network. Obtain the status information of links and key pools in the quantum key distribution network; perform a judgment process on the target status information of the target link and the target key pool corresponding to the target path for data transmission to determine whether the quantum key distribution network is under attack; in response to determining that the quantum key distribution network is under attack, query an alternate path in the quantum key distribution network; perform a judgment process on the alternate link and the alternate key pool corresponding to the alternate path, determine that the alternate link and the alternate key pool meet preset conditions, and use the alternate path as the target path for data transmission. Realize the detection of whether the quantum key distribution network is under attack and the mitigation of the attack, improve the security protection ability of the quantum key distribution network, and ensure the security of data transmission in the quantum key distribution network. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following description are only embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a flowchart of the attack detection and mitigation method based on the quantum key distribution network according to an embodiment of the present disclosure;

[0020] Figure 2AIt is a network topology diagram in the scenario of interconnection of quantum key distribution networks according to an embodiment of the present disclosure;

[0021] Figure 2B It is a flowchart of DDoS attack detection and mitigation for a quantum key distribution network according to an embodiment of the present disclosure;

[0022] Figure 2C It is a network topology diagram of key pool abstraction according to an embodiment of the present disclosure;

[0023] Figure 2D It is a flowchart of monitoring quantum network performance indicators according to an embodiment of the present disclosure;

[0024] Figure 2E It is a flowchart of performance indicator judgment according to an embodiment of the present disclosure;

[0025] Figure 2F It is a flowchart of standby path selection and judgment according to an embodiment of the present disclosure;

[0026] Figure 2G It is a flowchart of online key retransmission according to an embodiment of the present disclosure;

[0027] Figure 2H It is a flowchart of network resource update according to an embodiment of the present disclosure;

[0028] Figure 3 It is a schematic structural diagram of an attack detection and mitigation device based on a quantum key distribution network according to an embodiment of the present disclosure;

[0029] Figure 4 It is a schematic structural diagram of an electronic device according to an embodiment of the present disclosure. Specific Embodiments

[0030] To make the objectives, technical solutions and advantages of the present disclosure more clear and understandable, the present disclosure will be further described in detail below with reference to specific embodiments and the accompanying drawings.

[0031] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meanings understood by those of ordinary skill in the field to which the present disclosure belongs. The "first", "second" and similar terms used in the embodiments of the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right" are only used to represent relative positional relationships. When the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0032] As described above, how to detect whether a quantum key distribution network is under attack and mitigate the attack to improve the security protection ability of the quantum key distribution network has become an important research issue.

[0033] The following are the explanations of the terms involved in the present disclosure:

[0034] QKDN: A quantum key distribution network (Quantum Key Distribution Network, abbreviated as QKDN) is a network for data transmission based on quantum key distribution. Among them, quantum key distribution uses the characteristics of quantum mechanics to ensure communication security. It enables both parties of communication to generate and share a random and secure key to encrypt and decrypt messages.

[0035] DDoS: A distributed denial of service attack (Distributed denial of service attack, abbreviated as DDoS) refers to multiple attackers at different locations launching attacks on one or several targets simultaneously, or one attacker controlling multiple machines at different locations and using these machines to simultaneously attack the victim.

[0036] Based on the above description, as Figure 1 shown, the attack detection and mitigation method based on a quantum key distribution network proposed in this embodiment, the quantum key distribution network includes: a link and a key pool; the method includes:

[0037] Step 101, obtain the status information of the link and the key pool in the quantum key distribution network.

[0038] Specifically, when implemented, the quantum key distribution network includes a link and a key pool, and the status information of the link and the key pool is obtained.

[0039] Step 102: Determine and process the target status information of the target link and the target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network is under attack.

[0040] In specific implementation, the quantum key distribution network further includes nodes. Determine the target path of data transmission according to the source node and the target node of data transmission, and determine the corresponding target link and target key pool according to the target path. Obtain the target status information of the target link and the target key pool, and perform a comparison and judgment process on the target status information and the corresponding preset threshold to determine whether the quantum key distribution network is under attack. Among them, the target link is the inter-domain quantum link in the target path; the target key pool is the inter-domain quantum key pool in the target path.

[0041] Step 103: In response to determining that the quantum key distribution network is under attack, query for an alternative path in the quantum key distribution network.

[0042] In specific implementation, when it is determined that the inter-domain quantum link of the quantum key distribution network is under attack, query for an alternative path according to the source node and the target node of data transmission.

[0043] Step 104: Perform a judgment process on the alternative link and the alternative key pool corresponding to the alternative path to determine that the alternative link and the alternative key pool meet the preset conditions, and use the alternative path as the target path for data transmission.

[0044] In specific implementation, obtain the alternative status information of the alternative link and the alternative key pool corresponding to the alternative path, and perform a comparison and judgment process on the alternative status information and the corresponding preset threshold. When it is determined that the alternative link and the alternative key pool of the alternative path meet the preset conditions, use the alternative path as the target path for data transmission. Among them, the alternative link is the inter-domain quantum link in the alternative path; the alternative key pool is the inter-domain quantum key pool in the alternative path.

[0045] In the above embodiment, determine the target path for data transmission in the quantum key distribution network, perform a judgment process on the inter-domain quantum link and the inter-domain quantum key pool in the target path to determine whether the target path is under attack, and realize the detection of whether the quantum key distribution network is under attack. When it is detected that the quantum key distribution network is under attack, query for an alternative path and judge the alternative path. When the alternative path meets the preset conditions, use the alternative path as the target path for data transmission, thereby mitigating the attack. Improve the security protection ability of the quantum key distribution network and ensure the security of data transmission in the quantum key distribution network.

[0046] In some embodiments, the quantum key distribution network further includes: nodes; the nodes include quantum nodes and gateway nodes; the links include intra-domain quantum links and inter-domain quantum links; the key pools include intra-domain quantum key pools and inter-domain quantum key pools.

[0047] Step 101 includes:

[0048] Step 1011, traverse the nodes in the quantum key distribution network to obtain the first physical positions of the quantum nodes and the gateway nodes.

[0049] In specific implementation, the nodes in the quantum key distribution network include quantum nodes and gateway nodes. Traverse each node in the quantum key distribution network to obtain and record the first physical positions of the quantum nodes and the gateway nodes.

[0050] Step 1012, traverse the links in the quantum key distribution network to obtain the second physical positions of the intra-domain quantum links and the inter-domain quantum links.

[0051] In specific implementation, the links in the quantum key distribution network include intra-domain quantum links and inter-domain quantum links. Traverse each link in the quantum key distribution network to obtain and record the second physical positions of the intra-domain quantum links and the inter-domain quantum links.

[0052] Step 1013, obtain the intra-domain quantum key pool and the inter-domain quantum key pool in the key pool.

[0053] In specific implementation, the key pools in the quantum key distribution network include intra-domain quantum key pools and inter-domain quantum key pools. Traverse each quantum key pool in the quantum key distribution network to obtain and record the intra-domain quantum key pool and the inter-domain quantum key pool.

[0054] Step 1014, query the inter-domain quantum key pool in the quantum key distribution network to obtain the key balance and key replenishment rate of the inter-domain quantum key pool.

[0055] In specific implementation, traverse each inter-domain quantum key pool in the quantum key distribution network to obtain and record the key balance and key replenishment rate of each inter-domain quantum key pool.

[0056] Step 1015, query the inter-domain quantum links in the quantum key distribution network to obtain the key rate and quantum bit error rate of the inter-domain quantum links.

[0057] In specific implementation, traverse each inter-domain quantum link in the quantum key distribution network to obtain and record the key rate and quantum bit error rate of each inter-domain quantum link.

[0058] Step 1016: Use the key surplus and key replenishment rate of the inter-domain quantum key pool, as well as the key rate and quantum bit error rate of the inter-domain quantum link, as the status information.

[0059] In specific implementation, the status information includes: the key surplus and key replenishment rate of the inter-domain quantum key pool, as well as the key rate and quantum bit error rate of the inter-domain quantum link.

[0060] In the above solution, obtain the key surplus and key replenishment rate of the inter-domain quantum key pool, as well as the key rate and quantum bit error rate of the inter-domain quantum link, and use them as the status information, so that it is possible to accurately determine whether the inter-domain quantum link is under attack by judging the status information.

[0061] In some embodiments, Step 102 includes:

[0062] Step 1021: Obtain the attribute information of data transmission.

[0063] In specific implementation, when a data transmission request is received, obtain the attribute information of data transmission. Among them, the attribute information includes at least one of the following: the source node, the destination node, the data transmission start time, the data transmission duration, and the quantum key rate required per unit time.

[0064] Step 1022: Calculate the shortest path of data transmission according to the attribute information, and use the link corresponding to the shortest path as the target link.

[0065] In specific implementation, determine the shortest path of data transmission according to the source node and destination node in the attribute information, and record the number of hops of the shortest path. Use the link corresponding to the shortest path as the target link, and determine the inter-domain quantum link in the target link as the target inter-domain quantum link.

[0066] Step 1023: Traverse the target inter-domain quantum key pool corresponding to the target inter-domain quantum link in the target link, and obtain the current key surplus in the target inter-domain quantum key pool.

[0067] In specific implementation, traverse the target inter-domain quantum key pool corresponding to the target inter-domain quantum link, and obtain the current key surplus in the target inter-domain quantum key pool. Among them, the current key surplus is the key surplus at the current moment.

[0068] Step 1024: Compare and judge the current key surplus with a preset key surplus threshold.

[0069] In specific implementation, the current key margin is compared with a preset key margin threshold to determine whether the target inter-domain quantum link through which the data is transmitted in the target path of the quantum key distribution network is attacked. Wherein, the key margin threshold is the minimum key margin threshold.

[0070] Step 1025, in response to determining that the current key margin is less than or equal to the key margin threshold, obtain the target key rate and the target quantum bit error rate of the target inter-domain quantum link, and perform judgment processing on the target key rate and the target quantum bit error rate to determine whether the quantum key distribution network is attacked.

[0071] In specific implementation, when the current key margin is less than or equal to the key margin threshold, perform judgment processing on the target key rate and the target quantum bit error rate of the target inter-domain quantum link to determine whether the target inter-domain quantum link through which the data is transmitted in the target path of the quantum key distribution network is attacked.

[0072] Step 1026, in response to determining that the current key margin is greater than the key margin threshold, update the status information of the quantum key distribution network.

[0073] In specific implementation, when the current key margin is greater than the key margin threshold, it is determined that the target inter-domain quantum link through which the data is transmitted in the target path of the quantum key distribution network is not attacked, and the status information of the quantum key distribution network is updated.

[0074] In the above solution, after performing judgment processing on the current key margin in the target inter-domain quantum key pool, judgment processing is performed on the target key rate and the target quantum bit error rate of the target inter-domain quantum link. By performing judgment processing on the target inter-domain quantum key pool and the target inter-domain quantum link respectively, the accuracy of detecting whether the target inter-domain quantum link is attacked can be improved.

[0075] In some embodiments, step 1023 includes:

[0076] Step 1023A, obtain the current key replenishment rate and the current key consumption rate in the target inter-domain quantum key pool.

[0077] Step 1023B, perform arithmetic processing on the current key replenishment rate and the current key consumption rate to obtain the current key margin.

[0078]

[0079] Wherein, v g (τ) is the current key replenishment rate, v cLet (τ) be the current key consumption rate, and Q t be the current key balance in the target inter-domain quantum key pool at time t.

[0080] In specific implementation, the current key balance is obtained by performing arithmetic operations on the current key replenishment rate and the current key consumption rate in the target inter-domain quantum key pool. Additionally, the current key balance in the target inter-domain quantum key pool can also be directly obtained.

[0081] In the above solution, the current key balance can be obtained in two ways: through arithmetic operations or direct acquisition, making the obtained current key balance more accurate.

[0082] In some embodiments, step 1025 includes:

[0083] Step 1025A, comparing and determining the target key rate with a preset key rate threshold, and comparing and determining the target quantum bit error rate with a preset quantum bit error rate threshold.

[0084] In specific implementation, the target status information of the target inter-domain quantum link in the target path is judged and processed. The specific process is: comparing and determining the target key rate with a preset key rate threshold, and comparing and determining the target quantum bit error rate with a preset quantum bit error rate threshold.

[0085] Wherein, the target key rate is the key rate of the target inter-domain quantum link at any time t within time t i and the target quantum bit error rate is the quantum bit error rate of the target inter-domain quantum link at any time t within time t i . The key rate threshold is the minimum key rate threshold, and the quantum bit error rate threshold is the maximum quantum bit error rate threshold.

[0086] Step 1025B, in response to determining that the target key rate is less than or equal to the key rate threshold and the target quantum bit error rate is greater than or equal to the quantum bit error rate threshold, determining that the target inter-domain quantum link in the quantum key distribution network is under attack.

[0087] In specific implementation, when the target key rate is less than or equal to the key rate threshold and the target quantum bit error rate is greater than or equal to the quantum bit error rate threshold, the target inter-domain quantum link in the target path of the quantum key distribution network is under attack. After determining the attack, query the backup path and judge the backup path to mitigate the attack on the quantum key distribution network.

[0088] Step 1025C, in response to determining that the target key rate is greater than the key rate threshold and the target quantum bit error rate is less than the quantum bit error rate threshold, update the status information of the quantum key distribution network.

[0089] In specific implementation, when the target key rate is greater than the key rate threshold and the target quantum bit error rate is less than the quantum bit error rate threshold, it indicates that the target inter-domain quantum link of the target path in the quantum key distribution network is not under attack. After determining that there is no attack, update the status information of the quantum key distribution network.

[0090] In the above solution, after judging the status information of the target inter-domain quantum key pool in the target path, further judge the status information of the target inter-domain quantum link in the target path, and then determine whether the target inter-domain quantum link is under attack, so as to make the attack detection more accurate and avoid misjudgment.

[0091] In some embodiments, step 104 includes:

[0092] Step 1041, judge whether there is a standby inter-domain quantum link in the standby path.

[0093] In specific implementation, after determining that the target inter-domain quantum link in the target path is under attack, find a standby path between the source node and the destination node, and judge whether there is a standby inter-domain quantum link in the standby path between the source node and the destination node. Wherein, the standby path is another path other than the target path.

[0094] Step 1042, in response to determining that there is no such standby inter-domain quantum link in the standby path, perform key retransmission on the quantum key distribution network.

[0095] In specific implementation, when there is no standby inter-domain quantum link between the source node and the destination node, re-distribute the keys in the quantum key distribution network.

[0096] Step 1043, in response to determining that there is such a standby inter-domain quantum link in the standby path, perform judgment processing on the standby inter-domain quantum link, determine that the standby inter-domain quantum link meets the preset conditions, and use the standby path as the target path for data transmission.

[0097] In specific implementation, when there is a standby inter-domain quantum link between the source node and the destination node, the standby inter-domain quantum key pool and the standby inter-domain quantum link in the standby path are judged and processed. When the standby inter-domain quantum key pool and the standby inter-domain quantum link meet the preset conditions, the standby path is used as the target path for data transmission. Among them, the judgment process of the standby path is the same as the judgment process of the target path described above.

[0098] In the above solution, by querying the standby path between the source node and the destination node and judging the standby path as the target path for data transmission, the attack on the target inter-domain quantum link can be relieved in time. By judging the standby path, it is ensured that the standby path meets the preset conditions, avoiding the situation that the standby path is attacked or cannot perform data transmission.

[0099] In some embodiments, step 1043 includes:

[0100] Step 10431, traverse the standby inter-domain quantum key pool corresponding to the standby inter-domain quantum link, and obtain the remaining standby keys in the standby inter-domain quantum key pool.

[0101] In specific implementation, obtain the standby key replenishment rate and the standby key consumption rate in the standby inter-domain quantum key pool. Perform arithmetic processing on the standby key replenishment rate and the standby key consumption rate to obtain the remaining standby keys,

[0102] Q′ t =∫ 0 t v′ g (τ)dτ-∫ 0 t v′ c (τ)dτ

[0103] Wherein, v g ′(τ) is the standby key replenishment rate, v c ′(τ) is the standby key consumption rate, Q t ′ is the remaining standby keys in the standby inter-domain quantum key pool at time t.

[0104] Step 10432, compare and judge the remaining standby keys with a preset key remaining threshold.

[0105] In specific implementation, compare and judge the remaining standby keys with a preset key remaining threshold, and further determine whether the standby inter-domain quantum link through which the data is transmitted in the standby path of the quantum key distribution network is attacked. Among them, the key remaining threshold is the minimum key remaining threshold.

[0106] Step 10433, in response to determining that the spare key margin is greater than the key margin threshold, use the spare path as the target path for data transmission, and update the status information of the quantum key distribution network.

[0107] In specific implementation, when the spare key margin is greater than the key margin threshold, it is determined that the spare inter-domain quantum link through which the spare path in the quantum key distribution network is transmitted is not attacked. Use the spare path as the target path for data transmission, and update the status information of the quantum key distribution network. By replacing the attacked target path with an un-attacked spare path, the attack on the quantum key distribution network can be alleviated.

[0108] Step 10434, in response to determining that the spare key margin is less than or equal to the key margin threshold, obtain the spare key rate and the spare quantum bit error rate of the spare inter-domain quantum link, and perform judgment processing on the spare key rate and the spare quantum bit error rate.

[0109] In specific implementation, when the spare key margin is less than or equal to the key margin threshold, it is determined that the spare inter-domain quantum link through which the spare path in the quantum key distribution network is transmitted is attacked. Further judgment processing is performed on the spare key rate and the spare quantum bit error rate of the spare inter-domain quantum link. The specific judgment process is as follows:

[0110] Step 10434A, determine that the spare key rate is greater than the key rate threshold and the spare quantum bit error rate is less than the quantum bit error rate threshold, and re-query the spare paths in the quantum key distribution network.

[0111] In specific implementation, when the spare key rate is greater than the key rate threshold and the spare quantum bit error rate is less than the quantum bit error rate threshold, re-query the spare paths in the quantum key distribution network.

[0112] Step 10434B, determine that the spare key rate is less than or equal to the key rate threshold and the spare quantum bit error rate is greater than or equal to the quantum bit error rate threshold, and perform key retransmission on the quantum key distribution network.

[0113] In specific implementation, when the spare key rate is less than or equal to the key rate threshold and the spare quantum bit error rate is greater than or equal to the quantum bit error rate threshold, no re-distribution is performed on the quantum key distribution network.

[0114] In the above solution, by replacing the attacked target path with an un-attacked spare path, the attack on the quantum key distribution network can be alleviated.

[0115] In the above embodiments, a target path for data transmission in the quantum key distribution network is determined, and the inter-domain quantum links and inter-domain quantum key pools in the target path are judged and processed to determine whether the target path is under attack, so as to detect whether the quantum key distribution network is under attack. When it is detected that the quantum key distribution network is under attack, a backup path is queried and judged. When the backup path meets the preset conditions, the backup path is used as the target path for data transmission, thereby mitigating the attack. The security protection ability of the quantum key distribution network is improved, and the security of data transmission in the quantum key distribution network is ensured.

[0116] It should be noted that the embodiments of the present disclosure can be further described in the following manner:

[0117] As Figure 2A shown, Figure 2A is a network topology diagram in the scenario of interconnection of quantum key distribution networks. The quantum key distribution network includes: nodes, links, and key pools. Among them, the nodes include gateway nodes and quantum nodes, the links include intra-domain quantum links and inter-domain quantum links, and the key pools include intra-domain quantum key pools and inter-domain quantum key pools. As Figure 2A shown, QKDN A and QKDN B are quantum key distribution network A and quantum key distribution network B respectively, which are two quantum key distribution networks. Gateway A Node1 and Gateway B Node1 are gateway node A and gateway node B respectively, which are two gateway nodes. QKDN A Node1, QKDN A Node2, QKDN A Node3, and QKDN A Node4 are quantum nodes in quantum key distribution network A; QKDN B Node1, QKDN B Node2, QKDN B Node3, and QKDN B Node4 are quantum nodes in quantum key distribution network B.

[0118] As Figure 2B shown, Figure 2B is a flowchart for DDoS attack detection and mitigation of the quantum key distribution network. Step 201, monitoring of network performance metrics. Step 202, judging whether each performance metric meets the threshold. Step 203, selection and judgment of inter-domain backup paths. Step 204, online key retransmission. Step 205, network resource update.

[0119] As Figure 2C shown, Figure 2CNetwork topology diagram for key pool abstraction. A1 - A2, A1 - A4, A4 - A3, A2 - A4, A2 - A3, A2 - GA1, and A3 - GA1 are the key pools of quantum key distribution network A; B1 - B2, B1 - B4, B4 - B3, B2 - B4, B2 - B3, B2 - GB1, and B3 - GB1 are the key pools of quantum key distribution network B.

[0120] As Figure 2D shown, Figure 2D is the flowchart for monitoring quantum network performance metrics. Step 201 specifically includes:

[0121] Step 2011: Traverse each node in the quantum key distribution network topology, and respectively record the quantum nodes {A1, A2, A3, A4, B1, B2, B3, B4} and gateway nodes {GA1, GB1} in the network topology.

[0122] Step 2012: Traverse each link in the quantum key distribution network topology, and respectively record the intra - domain quantum links {l A1-A2 , l A1-A4 , l A4-A3 , l A3-GA1 , l A2-GA1 , l B1-B2 , l B1-B4 , l B4-B3 , l B3-GB1 , l B2-GB1} and the inter - domain quantum link {l BA1-GB1}.

[0123] Step 2013: Traverse each quantum key pool in the quantum key distribution network topology, and respectively record the intra - domain quantum key pools {A1 - A2, A1 - A4, A4 - A3, A2 - A4, A2 - A3, A2 - GA1, A3 - GA1, B1 - B2, B1 - B4, B4 - B3, B2 - B4, B2 - B3, B2 - GB1, B3 - GB1}, the inter - domain quantum key pool {GA1 - GB1}. The specific key pool representations and abstraction forms are as Figure 2C shown.

[0124] Step 2014: Traverse each inter - domain quantum key pool {GA1 - GB1} in the quantum key distribution network topology, obtain and record the key balance of each inter - domain quantum key pool and the key replenishment rate of each quantum key pool. The specific obtained values are shown in Table 1. Among them, Table 1 is the key pool status table.

[0125] Table 1 Key Pool Status Table

[0126]

[0127]

[0128] In step 2015, traverse each inter-domain quantum link in the quantum key distribution network topology, obtain and record the QBER and SKR values of each inter-domain quantum link. The specific obtained values are shown in Table 1.

[0129] As Figure 2E shown, Figure 2E is the flowchart for performance index judgment. Step 202 specifically includes:

[0130] In step 2021, parse the service attributes. Assume that the source and destination nodes s r , d r of the service are A1 and B1 respectively, the service start time T s is 10 s, the service duration T h is 30 s, and the service end time T end is 40 s.

[0131] In step 2022, calculate the shortest path {l A1-GA1 , l GA1-GB1 , l GB1-B1} under the service physical topology.

[0132] In step 2023, according to the shortest path links {l A1-GA1 , l GA1-GB1 , l GB1-B1} under the physical topology, traverse the inter-domain quantum key pool GA1-GB1 in the shortest path, and obtain the current key resources and status in the inter-domain key pool, that is: the key balance and the key pool key replenishment rate, etc. in each inter-domain key pool at the current moment. The key pool status is as Figure 2E shown, where it is assumed that the minimum balance threshold Q min of the key pool is 90 unit, the minimum threshold SKR min of the key rate is 0.08 kbit / s, and the maximum threshold QBER max of the quantum bit error rate is 4.2%.

[0133] In step 2024, judge whether the key balance Q GA1-GB1 in the inter-domain key pool at the current moment is greater than the minimum balance threshold Q min of 90 unit, that is: judge whether Q GA1-GB1 = 100 unit > Q min = 90 unit, and execute step 2025 according to the judgment result.

[0134] In step 2025, judge whether the quantum bit error rate QBER i in the inter-domain quantum link at any moment t GA1-GB1 within the time t is less than the maximum threshold QBER max= 4.2%, and at the same time determine that at any moment t within time t i the key rate SKR in the inter-domain quantum link GA1-Gb1 is greater than the minimum key rate threshold SKR min = 0.08 kbit / s, that is: determine QBER ti < QBER max ∪SKR ti > SKR min , according to the judgment result, that is: QBER GA1-Gb1 = 5.8% > QBER max = 4.2% ∪SKR GA1-GB1 = 0.03 < SKR min = 0.08, execute step 2026.

[0135] Step 2026: The inter-domain link l BA1-GB1 is under DDoS attack.

[0136] As Figure 2F shown, Figure 2F is the flowchart of standby path selection and judgment. Step 203 specifically includes:

[0137] Step 2031: Search for the inter-domain standby path between the gateway node pair BA1-GB1.

[0138] Step 2032: Judge whether there is a standby path between the gateway node pairs under the physical topology, that is: there is no standby path for BA1-GB1, execute step 204.

[0139] As Figure 2G shown, Figure 2G is the flowchart of key online retransmission. Step 204 specifically includes:

[0140] Step 2041: Re-distribute the keys for the gateway node pair BA1-GB1 of the inter-domain quantum link {l BA1-GB1} under DDoS attack.

[0141] As Figure 2H shown, Figure 2H is the flowchart of network resource update. Step 205 specifically includes:

[0142] Step 2051: Judge to traverse each intra-domain quantum key pool and each inter-domain quantum key pool in the network topology, and at the same time respectively obtain the key balances of each intra-domain and inter-domain quantum key pool.

[0143] Step 2052: Update the network resources, traverse the topology, and update the state information such as the key pool key resources, link quantum bit error rate, and key rate on each link, and the process ends.

[0144] In the above solution, the target path for data transmission in the quantum key distribution network is determined, and the inter-domain quantum links and inter-domain quantum key pools in the target path are judged and processed to determine whether the target path is under attack, so as to detect whether the quantum key distribution network is under attack. When it is detected that the quantum key distribution network is under attack, a backup path is queried and judged. When the backup path meets the preset conditions, the backup path is used as the target path for data transmission, thereby mitigating the attack. The security protection ability of the quantum key distribution network is improved, and the security of data transmission in the quantum key distribution network is ensured.

[0145] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this case of a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.

[0146] It should be noted that some embodiments of the present disclosure are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the above embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0147] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides an attack detection and mitigation device based on a quantum key distribution network.

[0148] Refer to Figure 3 , the attack detection and mitigation device based on a quantum key distribution network includes:

[0149] An acquisition module 301, configured to acquire the status information of the links and key pools in the quantum key distribution network.

[0150] A judgment module 302, configured to perform judgment and processing on the target status information of the target links and target key pools corresponding to the target path of data transmission to determine whether the quantum key distribution network is attacked.

[0151] A query module 303, configured to query the backup path in the quantum key distribution network in response to determining that the quantum key distribution network is attacked.

[0152] An update module 304, configured to perform judgment processing on a standby link and a standby key pool corresponding to the standby path, determine that the standby link and the standby key pool meet preset conditions, and use the standby path as the target path for data transmission.

[0153] In some embodiments, the quantum key distribution network further includes: nodes; the nodes include quantum nodes and gateway nodes; the links include intra-domain quantum links and inter-domain quantum links; the key pools include intra-domain quantum key pools and inter-domain quantum key pools.

[0154] The acquisition module 301 includes:

[0155] A first acquisition unit, configured to traverse the nodes in the quantum key distribution network to acquire the first physical positions of the quantum nodes and the gateway nodes.

[0156] A second acquisition unit, configured to traverse the links in the quantum key distribution network to acquire the second physical positions of the intra-domain quantum links and the inter-domain quantum links.

[0157] A third acquisition unit, configured to acquire the intra-domain quantum key pool and the inter-domain quantum key pool in the key pool.

[0158] A fourth acquisition unit, configured to query the inter-domain quantum key pool in the quantum key distribution network to acquire the key surplus and the key replenishment rate of the inter-domain quantum key pool.

[0159] A fifth acquisition unit, configured to query the inter-domain quantum links in the quantum key distribution network to acquire the key rate and the quantum bit error rate of the inter-domain quantum links.

[0160] A status information determination unit, configured to use the key surplus and the key replenishment rate of the inter-domain quantum key pool and the key rate and the quantum bit error rate of the inter-domain quantum links as the status information.

[0161] In some embodiments, the judgment module 302 includes:

[0162] An attribute information acquisition unit, configured to acquire the attribute information of data transmission.

[0163] A target link determination unit, configured to calculate the shortest path of data transmission according to the attribute information, and use the link corresponding to the shortest path as the target link.

[0164] A current key surplus acquisition unit, configured to traverse the target inter-domain quantum key pool corresponding to the target inter-domain quantum link existing in the target link to acquire the current key surplus in the target inter-domain quantum key pool.

[0165] The first comparison unit is configured to compare and determine the current key margin with a preset key margin threshold.

[0166] The attack determination unit is configured to, in response to determining that the current key margin is less than or equal to the key margin threshold, obtain the target key rate and the target quantum bit error rate of the target inter-domain quantum link, and perform judgment processing on the target key rate and the target quantum bit error rate to determine whether the quantum key distribution network is attacked.

[0167] The status information update unit is configured to, in response to determining that the current key margin is greater than the key margin threshold, update the status information of the quantum key distribution network.

[0168] In some embodiments, the current key margin acquisition unit includes:

[0169] The rate acquisition subunit is configured to acquire the current key replenishment rate and the current key consumption rate in the target inter-domain quantum key pool.

[0170] The operation subunit is configured to perform arithmetic processing on the current key replenishment rate and the current key consumption rate to obtain the current key margin.

[0171] Q t = ∫ 0 t v g (τ)dτ - ∫ 0 t v c (τ)dτ

[0172] where v g (τ) is the current key replenishment rate, v c (τ) is the current key consumption rate, and Q t is the current key margin in the target inter-domain quantum key pool at time t.

[0173] In some embodiments, the attack determination unit includes:

[0174] The second comparison subunit is configured to compare and determine the target key rate with a preset key rate threshold, and compare and determine the target quantum bit error rate with a preset quantum bit error rate threshold.

[0175] An attack determination subunit, configured to determine that the target inter-domain quantum link in the quantum key distribution network is under attack in response to determining that the target key rate is less than or equal to the key rate threshold and the target qubit error rate is greater than or equal to the qubit error rate threshold.

[0176] A status information update subunit, configured to update the status information of the quantum key distribution network in response to determining that the target key rate is greater than the key rate threshold and the target qubit error rate is less than the qubit error rate threshold.

[0177] In some embodiments, the update module 304 includes:

[0178] A backup path determination unit, configured to determine whether there is a backup inter-domain quantum link in the backup path.

[0179] A key retransmission unit, configured to retransmit the key for the quantum key distribution network in response to determining that there is no backup inter-domain quantum link in the backup path.

[0180] A path update unit, configured to perform judgment processing on the backup inter-domain quantum link in response to determining that there is a backup inter-domain quantum link in the backup path, determine that the backup inter-domain quantum link meets the preset conditions, and use the backup path as the target path for data transmission.

[0181] In some embodiments, the path update unit includes:

[0182] A backup key margin acquisition subunit, configured to traverse the backup inter-domain quantum key pool corresponding to the backup inter-domain quantum link and acquire the backup key margin in the backup inter-domain quantum key pool.

[0183] A third comparison subunit, configured to compare and judge the backup key margin with a preset key margin threshold.

[0184] A path update subunit, configured to use the backup path as the target path for data transmission and update the status information of the quantum key distribution network in response to determining that the backup key margin is greater than the key margin threshold.

[0185] A fourth comparison subunit, configured to acquire the backup key rate and backup qubit error rate of the backup inter-domain quantum link and perform judgment processing on the backup key rate and the backup qubit error rate in response to determining that the backup key margin is less than or equal to the key margin threshold.

[0186] A standby path query subunit, configured to determine that the standby key rate is greater than a key rate threshold and the standby quantum bit error rate is less than a quantum bit error rate threshold, and re-query for a standby path in the quantum key distribution network.

[0187] A key retransmission subunit, configured to determine that the standby key rate is less than or equal to the key rate threshold and the standby quantum bit error rate is greater than or equal to the quantum bit error rate threshold, and perform key retransmission on the quantum key distribution network.

[0188] For convenience of description, when describing the above device, it is divided into various modules according to functions and described separately. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0189] The device in the above embodiment is used to implement the corresponding attack detection and mitigation method based on the quantum key distribution network in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0190] Based on the same inventive concept, corresponding to the method in any of the above embodiments, the present disclosure further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the attack detection and mitigation method based on the quantum key distribution network in any of the above embodiments.

[0191] Figure 4 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.

[0192] The processor 1010 may be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0193] The memory 1020 may be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and called and executed by the processor 1010.

[0194] The input / output interface 1030 is used to connect to the input / output module to implement information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0195] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module may implement communication through a wired method (such as USB (Universal Serial Bus), network cable, etc.) or through a wireless method (such as a mobile network, WIFI (Wireless Fidelity), Bluetooth, etc.).

[0196] The bus 1050 includes a path for transmitting information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0197] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solutions of the embodiments of this specification, and do not have to include all the components shown in the figure.

[0198] The electronic device in the above embodiment is used to implement the corresponding attack detection and mitigation method based on the quantum key distribution network in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0199] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the attack detection and mitigation method based on a quantum key distribution network as described in any of the above embodiments.

[0200] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0201] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the attack detection and mitigation method based on a quantum key distribution network as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0202] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples; under the concept of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present disclosure as described above, which are not provided in detail for the sake of brevity.

[0203] In addition, for simplicity of explanation and discussion, and so as not to make the embodiments of the present disclosure difficult to understand, well-known power / ground connections of integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present disclosure are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present disclosure may be practiced without these specific details or with variations of these specific details. Accordingly, these descriptions should be considered illustrative rather than restrictive.

[0204] Although the present disclosure has been described in connection with specific embodiments thereof, many alternatives, modifications, and variations thereof will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0205] Embodiments of the present disclosure are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Accordingly, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the embodiments of the present disclosure shall be included within the protection scope of the present disclosure.

Claims

1. An attack detection and mitigation method based on a quantum key distribution network, characterized in that, the quantum key distribution network includes: links and key pools; the method includes: Obtaining the status information of the links and key pools in the quantum key distribution network; Judging and processing the target status information of the target link and target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network is under attack; In response to determining that the quantum key distribution network is under attack, querying for alternative paths in the quantum key distribution network; Judging and processing the alternative link and alternative key pool corresponding to the alternative path to determine that the alternative link and the alternative key pool meet the preset conditions, and using the alternative path as the target path for data transmission; The judging and processing the target status information of the target link and target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network is under attack includes: Obtaining the attribute information of data transmission; Calculating the shortest path of data transmission according to the attribute information, and using the link corresponding to the shortest path as the target link; Traversing the target inter-domain quantum key pools corresponding to the target inter-domain quantum links existing in the target link, and obtaining the current key surplus in the target inter-domain quantum key pools; Comparing and judging the current key surplus with a preset key surplus threshold; In response to determining that the current key surplus is less than or equal to the key surplus threshold, obtaining the target key rate and target quantum bit error rate of the target inter-domain quantum link, and judging and processing the target key rate and the target quantum bit error rate to determine whether the quantum key distribution network is under attack; In response to determining that the current key surplus is greater than the key surplus threshold, updating the status information of the quantum key distribution network.

2. The method according to claim 1, characterized in that, the quantum key distribution network further includes: nodes; the nodes include quantum nodes and gateway nodes; the links include intra-domain quantum links and inter-domain quantum links; the key pools include intra-domain quantum key pools and inter-domain quantum key pools; The obtaining the status information of the links and key pools in the quantum key distribution network includes: Traversing the nodes in the quantum key distribution network to obtain the first physical positions of the quantum nodes and the gateway nodes; Traversing the links in the quantum key distribution network to obtain the second physical positions of the intra-domain quantum links and the inter-domain quantum links; Obtaining the intra-domain quantum key pools and the inter-domain quantum key pools in the key pools; Querying the inter-domain quantum key pools in the quantum key distribution network to obtain the key surplus and key replenishment rate of the inter-domain quantum key pools; Querying the inter-domain quantum links in the quantum key distribution network to obtain the key rate and quantum bit error rate of the inter-domain quantum links; Using the key surplus and key replenishment rate of the inter-domain quantum key pools and the key rate and quantum bit error rate of the inter-domain quantum links as the status information.

3. The method according to claim 1, It is characterized in that obtaining the current key balance in the target inter-domain quantum key pool includes: obtaining the current key replenishment rate and the current key consumption rate in the target inter-domain quantum key pool; performing arithmetic processing on the current key replenishment rate and the current key consumption rate to obtain the current key balance, Among them, v g (τ) is the current key replenishment rate, v c (τ) is the current key consumption rate, Q t is the current key remainder in the target inter-domain quantum key pool at time t.

4. The method according to claim 1, It is characterized in that judging and processing the target key rate and the target quantum bit error rate to determine whether the quantum key distribution network is attacked, including: comparing and judging the target key rate with a preset key rate threshold, and comparing and judging the target quantum bit error rate with a preset quantum bit error rate threshold; in response to determining that the target key rate is less than or equal to the key rate threshold and the target quantum bit error rate is greater than or equal to the quantum bit error rate threshold, determining that the target inter-domain quantum link in the quantum key distribution network is attacked; in response to determining that the target key rate is greater than the key rate threshold and the target quantum bit error rate is less than the quantum bit error rate threshold, updating the state information of the quantum key distribution network.

5. The method according to claim 1, It is characterized in that judging and processing the standby link and the standby key pool corresponding to the standby path to determine that the standby link and the standby key pool meet the preset conditions, and using the standby path as the target path for data transmission, including: judging whether there is a standby inter-domain quantum link in the standby path; in response to determining that there is no standby inter-domain quantum link in the standby path, performing key retransmission on the quantum key distribution network; in response to determining that there is a standby inter-domain quantum link in the standby path, judging and processing the standby inter-domain quantum link to determine that the standby inter-domain quantum link meets the preset conditions, and using the standby path as the target path for data transmission.

6. The method according to claim 5, It is characterized in that judging and processing the standby inter-domain quantum link to determine that the standby inter-domain quantum link meets the preset conditions, and using the standby path as the target path for data transmission, including: traversing the standby inter-domain quantum key pool corresponding to the standby inter-domain quantum link to obtain the standby key balance in the standby inter-domain quantum key pool; comparing and judging the standby key balance with a preset key balance threshold; in response to determining that the standby key balance is greater than the key balance threshold, using the standby path as the target path for data transmission and updating the state information of the quantum key distribution network; in response to determining that the standby key balance is less than or equal to the key balance threshold, obtaining the standby key rate and the standby quantum bit error rate of the standby inter-domain quantum link, and judging and processing the standby key rate and the standby quantum bit error rate; Determine that the spare key rate is greater than the key rate threshold and the spare qubit error rate is less than the qubit error rate threshold, and re-query for spare paths in the quantum key distribution network; Determine that the spare key rate is less than or equal to the key rate threshold and the spare qubit error rate is greater than or equal to the qubit error rate threshold, and perform key retransmission on the quantum key distribution network.

7. An attack detection and mitigation device based on a quantum key distribution network, characterized in that the quantum key distribution network includes: links and a key pool; the device includes: an acquisition module configured to acquire status information of links and the key pool in the quantum key distribution network; a judgment module configured to perform judgment processing on the target status information of the target link and the target key pool corresponding to the target path of data transmission to determine whether the quantum key distribution network is under attack; a query module configured to, in response to determining that the quantum key distribution network is under attack, query for spare paths in the quantum key distribution network; an update module configured to perform judgment processing on the spare link and the spare key pool corresponding to the spare path to determine that the spare link and the spare key pool meet preset conditions, and use the spare path as the target path for data transmission; the judgment module includes: an attribute information acquisition unit configured to acquire attribute information of data transmission; a target link determination unit configured to calculate the shortest path of data transmission according to the attribute information and use the link corresponding to the shortest path as the target link; a current key margin acquisition unit configured to traverse the target inter-domain quantum key pool corresponding to the target inter-domain quantum link existing in the target link and acquire the current key margin in the target inter-domain quantum key pool; a first comparison unit configured to perform comparison and judgment on the current key margin and a preset key margin threshold; an attack determination unit configured to, in response to determining that the current key margin is less than or equal to the key margin threshold, acquire the target key rate and the target qubit error rate of the target inter-domain quantum link, and perform judgment processing on the target key rate and the target qubit error rate to determine whether the quantum key distribution network is under attack; a status information update unit configured to, in response to determining that the current key margin is greater than the key margin threshold, update the status information of the quantum key distribution network.

8. An electronic device, characterized in that it includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the method according to any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium, characterized in that the non-transitory computer-readable storage medium stores computer instructions for causing a computer to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Service protection method and system in quantum key distribution optical network

    CN109120333A

  • Quantum communication service station AKA key negotiation method and system based on asymmetric key pool pair and serial number

    CN110493177A