Quantum key distribution network based on inter-network interfacing and inter-network interfacing method thereof
By using a "north-south" network interconnection scheme, QKR devices are used to achieve quantum key relay between operators at the interconnection node, which solves the data security and network reliability problems between operators in the existing technology and realizes independent and secure quantum key distribution network interconnection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CAS QUANTUM NETWORK CO LTD
- Filing Date
- 2023-04-04
- Publication Date
- 2026-05-29
Smart Images

Figure CN116366246B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum key distribution technology, and in particular to a quantum key distribution network based on inter-network interconnection and its inter-network interconnection method. Background Technology
[0002] like Figure 1 As shown, existing quantum key distribution (QKD) networks mainly include components such as QKD devices, KM devices, and QKDN controllers.
[0003] In a QKD network, QKD devices primarily execute the QKD protocol to generate QKD keys. The specific implementation structure of QKD devices in the network may differ depending on the QKD protocol used. For example, for QKD protocols based on a "preparation-measurement" scheme, the QKD device includes both a transmitter and a receiver; for QKD protocols based on a measurement-assisted scheme (such as MDI-QKD and TF-QKD), the QKD device only acts as the transmitter, and the receiver is handled by intermediate nodes in the QKD link; in entanglement-based QKD protocols, the QKD device only acts as the receiver, and the transmitter that generates the entangled quantum signal is handled by intermediate nodes in the QKD link.
[0004] The KM device is responsible for receiving and managing the quantum keys generated by the QKD device, relaying the quantum keys, and providing them to cryptographic applications. Generally, a KM device includes functional modules such as a Key Management Agent (KMA), a Key Provider Agent (KSA), and a KM control unit.
[0005] KMA can include the following sub-functional modules:
[0006] ①Key storage function: used to receive keys from QKD devices, synchronize, authenticate, adjust length (combine or split) and format, and store processed keys and metadata (such as key ID, key length, key type and generation time);
[0007] ② Key relay function: Used to relay keys via communication links between KMAs to achieve end-to-end key distribution in QKDN. Key relay can employ encryption methods with Information Theory Security (ITS), such as the One-Time Password (OTP) scheme.
[0008] ③Key lifecycle management function: It is responsible for the key lifecycle management in the KM device, including the entire process from receiving the key from the KM device to delivering it to the application for use; it can also perform destruction or archiving operations on the key according to specific key management policies, such as after the key is used or when the validity period expires.
[0009] KSA may include the following sub-functional modules:
[0010] ①Key provision function: The KSAs at both ends of the communication use the communication link between the KSAs to synchronize and authenticate the key pairs shared by both parties, and provide the keys to the cryptographic application as needed;
[0011] ②Key Combination Function: Used to combine the key generated by the QKD device with the key generated by other key exchange methods (such as PQC) to obtain multiple security protections.
[0012] The KM control unit is responsible for connecting the KM device with network elements such as the QKD device, QKDN controller, and QKDN manager.
[0013] QKDN is responsible for controlling various resources of its affiliated QKD network to ensure the secure, stable, efficient, and robust operation of the QKD network. It may include the following functional modules:
[0014] ① Session control function: Used to support KMA to implement session process control for key relay, and also supports KSA to implement session process control for providing keys for various cryptographic applications;
[0015] ② Routing control function: Provides appropriate key relay routes between KM devices, and performs rerouting selection of key relays based on the fault, performance and / or availability status of the quantum layer and / or key management layer to ensure the continuity of key relay and key provision;
[0016] ③ Configuration control function: responsible for acquiring the configuration and status information of QKD devices and QKD links, KM devices and KM links, and responding to and processing the received fault warnings and diagnostic results, and adaptively reconfiguring QKD links and KM links;
[0017] ④ Policy control function: Responsible for controlling QKDN network resources based on specific Quality of Service (QoS) management and charging policies;
[0018] ⑤ Access control function: responsible for implementing identity authentication, permission management and access control for QKD network users.
[0019] In practical applications, quantum key distribution networks from different domains often need to be interconnected to achieve a wider-area quantum key distribution network structure. Currently, quantum key distribution networks from different domains often adopt an "east-west" interconnection scheme.
[0020] Figure 2 The diagram illustrates an existing "east-west" network interconnection scheme, in which operator 1 has quantum key distribution network A and quantum key distribution network C, while operator 2 has quantum key distribution network B. Networks A and C need to be interconnected through network B.
[0021] According to the "east-west" inter-network connection scheme, in order to achieve the connection between networks A and C through network B, a pair of QKD devices needs to be added between networks A and B, and between networks B and C, respectively, to provide symmetric keys between the connection KM devices of networks A and B, and between the connection KM devices of networks B and C.
[0022] Furthermore, classic data links need to be added between the KM devices connecting networks A and B, and between the KM devices connecting networks B and C, to allow key relay between networks A and B, and between networks B and C.
[0023] In addition, classic data links need to be added between the QKDN controllers of networks A, B, and C to allow the generation and computation of key relay routes for different QKD networks. Furthermore, classic data links need to be added between the QKDN controller of network B and the KM devices of networks A and C, or between the QKDN controllers of networks A and C and the KM device of network B, along with boundary KM devices that allow control of different QKD networks.
[0024] However, this "east-west" inter-network connection scheme has at least the following risks:
[0025] (1) The QKDN service flows of Operator 1 and Operator 2 are interconnected: The QKDN controllers of Operator 1 and Operator 2 contain sensitive data such as network topology and network key quantity. This data is internal operator business data and should not be shared with each other. However, with this scheme, the information of QKDNs of different networks is mutually known.
[0026] (2) The key relay service flow of KM devices is interoperable: the key of operator 1 needs to be relayed through the network of operator 2, and the key data is also sensitive data and should not be shared. However, with this scheme, the relay keys of KM devices in different networks need to be interoperable. At the same time, since it is a traversal connection, if there is a problem with the QKD network of operator 2, it will cause the key relay service of operator 1 to be interrupted.
[0027] (3) The network boundaries of QKD networks of different operators are blurred, and business data can penetrate each other, which is not conducive to the delineation of security boundaries and management boundaries. At the same time, it is difficult to define the evaluation boundaries when conducting QKD network security level protection evaluation and cryptographic evaluation. Summary of the Invention
[0028] To address the aforementioned problems in existing technologies, this invention discloses a quantum key distribution network based on inter-network interconnection and its inter-network interconnection method. It employs a "north-south" network interconnection scheme, requiring only the establishment of a data interface between the QKR device and the KM device at the interconnection node to provide symmetric keys. This allows direct key relay between two quantum key distribution networks (belonging to the same operator) that need to be interconnected, without needing to transmit business data through the interconnection quantum key distribution network (which may belong to another operator). This ensures operator data security and reliable network operation. Furthermore, the interconnection mode is simple and the boundaries are clear, facilitating separate upgrades, compliance testing, and cryptographic evaluations for each network.
[0029] Specifically, the first aspect of the present invention relates to an inter-network connection method for quantum key distribution networks, used to connect a first quantum key distribution network and a third quantum key distribution network via a second quantum key distribution network, comprising the following steps:
[0030] A first boundary KM device is configured within the first quantum key distribution network, and a pair of QKD devices are configured between the first boundary KM device and its adjacent KM devices.
[0031] Configure a second boundary KM device within the third quantum key distribution network, and configure a pair of QKD devices between the second boundary KM device and its adjacent KM devices;
[0032] In a second quantum key distribution network, a first QKR device and a second QKR device are configured to obtain symmetric keys from the KM devices of the second quantum key distribution network and output them to the first boundary KM device and the second boundary KM device, respectively; and,
[0033] A classical data link is established between the first boundary KM device and the second boundary KM device to allow quantum key relay between the first quantum key distribution network and the third quantum key distribution network using symmetric keys.
[0034] Furthermore, the first and third quantum key distribution networks belong to different operators than the second quantum key distribution network.
[0035] Furthermore, the first and second boundary KM devices can be controlled by at least one of the QKDN controllers in the first and third quantum key distribution networks.
[0036] Furthermore, a classical data link can be established between the QKDN controllers of the first and third quantum key distribution networks.
[0037] Furthermore, the QKR device can be configured to perform at least one of the following: key synchronization, secure key storage, KM device authentication, and heartbeat monitoring.
[0038] Furthermore, a QKR management device can be configured to manage the flow, rate, and pre-stored key quantity limits for key input and output of the QKR device.
[0039] A second aspect of the present invention relates to a quantum key distribution network based on inter-network interconnection, comprising a first quantum key distribution network, a second quantum key distribution network, and a third quantum key distribution network;
[0040] The first quantum key distribution network is configured with a first boundary KM device, and a pair of QKD devices are configured between the first boundary KM device and its adjacent KM device.
[0041] The third quantum key distribution network is configured with a second boundary KM device, and a pair of QKD devices are configured between the second boundary KM device and its adjacent KM device;
[0042] A second quantum key distribution network is configured with a first QKR device and a second QKR device. The first QKR device is configured to obtain a quantum key from a neighboring KM device within the second quantum key distribution network and output it to a first boundary KM device. The second QKR device is configured to obtain a quantum key from a neighboring KM device within the second quantum key distribution network and output it to a second boundary KM device, thereby distributing a symmetric key between the first and second boundary KM devices.
[0043] The first boundary KM device is connected to the second boundary KM device via a classic data link.
[0044] Furthermore, the first and third quantum key distribution networks belong to different operators than the second quantum key distribution network.
[0045] Furthermore, the QKDN controllers of the first and third quantum key distribution networks are connected via a classical data link.
[0046] Furthermore, the QKR device is configured to perform at least one of key synchronization, secure key storage, KM device authentication, and heartbeat monitoring; and / or may also include a QKR management device for managing the flow, rate, and pre-stored key quantity limits of the QKR device's key input and output. Attached Figure Description
[0047] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 A typical topology of a quantum key distribution network is schematically illustrated.
[0050] Figure 2 An example of an "east-west" inter-network connection scheme in the prior art is illustrated schematically;
[0051] Figure 3 An example of a quantum key distribution network based on inter-network interconnection according to the present invention is illustrated schematically. Detailed Implementation
[0052] In the following description, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example in order to fully convey the spirit of the invention to those skilled in the art. Therefore, the invention is not limited to the embodiments disclosed herein.
[0053] Figure 3 An example of a quantum key distribution network based on inter-network connection according to the present invention is shown, wherein two quantum key distribution networks (first quantum key distribution network A and third quantum key distribution network C) belonging to different domains in operator 1 need to be connected through the second quantum key distribution network B of another operator 2 to complete the required network formation.
[0054] like Figure 3 As shown, each quantum key distribution network A, B, and C includes a QKDN controller, a KM device, and a QKD device to implement the corresponding quantum key distribution function within the network.
[0055] Unlike the existing "east-west" network interconnection scheme, this invention will adopt a "north-south" network interconnection scheme, using the second quantum key distribution network B to achieve the interconnection of the first and third quantum key distribution networks A and C.
[0056] To better understand the "north-south" network connection scheme of the present invention, the following will be combined with Figure 3 The present invention provides a detailed description of the inter-network connection method for quantum key distribution networks.
[0057] See also Figure 3According to the present invention, when it is necessary to realize the connection between the first quantum key distribution network A and the third quantum key distribution network C through the second quantum key distribution network B, the first QKR device and the second QKR device can be configured in the second quantum key distribution network B.
[0058] The first QKR device and the second QKR device can be respectively set up in the docking nodes of the first quantum key distribution network A and the second quantum key distribution network B, and in the docking node of the third quantum key distribution network C and the second quantum key distribution network B. The first QKR device and the second QKR device can respectively (southbound) dock with the KM device within the second quantum key distribution network B to obtain quantum keys, thereby obtaining a shared quantum key through the second quantum key distribution network B for use as a symmetric key.
[0059] Furthermore, a first boundary KM device can be configured within the first quantum key distribution network A, and a pair of QKD devices can be configured between the first boundary KM device and its adjacent KM devices, thereby extending the QKD link of the first quantum key distribution network A to the docking node for the second quantum key distribution network B. Correspondingly, a second boundary KM device can also be configured within the third quantum key distribution network C, and a pair of QKD devices can be configured between the second boundary KM device and its adjacent KM devices, thereby extending the QKD link of the third quantum key distribution network C to the docking node for the second quantum key distribution network B.
[0060] At this point, at the corresponding docking node, the first QKR device (northbound) in the second quantum key distribution network B can dock with the first boundary KM device in the first quantum key distribution network A, so that the first boundary KM device can obtain quantum keys (e.g., symmetric keys) from the first QKR device. At the same time, the second QKR device (northbound) in the second quantum key distribution network B can dock with the second boundary KM device in the third quantum key distribution network C, so that the second boundary KM device can obtain quantum keys (e.g., symmetric keys) from the second QKR device.
[0061] Therefore, when the first and third quantum key distribution networks A and C, which need to be connected, obtain symmetric keys using corresponding QKR devices, a classical communication link can be established between the first boundary KM device of the first quantum key distribution network A and the second boundary KM device of the third quantum key distribution network C. This allows the first and third quantum key distribution networks, which belong to the same operator, to directly perform quantum key relay, without needing the key relay data to enter the second quantum key distribution network B, which belongs to another operator, for relay transmission.
[0062] In this invention, a classical data link can also be established between the QKDN controller of the first quantum key distribution network A and the QKDN controller of the third quantum key distribution network C, so as to allow the calculation and generation of key relay routes for different quantum key distribution networks.
[0063] Furthermore, classical data links can be established between the QKDN controllers of the first quantum key distribution network A and the third quantum key distribution network C and the corresponding boundary KM devices, so as to allow control of the boundary KM devices that control different quantum key distribution networks.
[0064] Based on the above configuration, in the quantum key distribution network that connects the first and third quantum key distribution networks A and C through the second quantum key distribution network B, there are only data interfaces between quantum key distribution networks A and C belonging to operator 1 and quantum key distribution network B belonging to operator 2, namely the QKD device and the boundary KM device. In terms of data interaction, operator 2's second quantum key distribution network only needs to provide symmetric keys to operator 1's first and third quantum key distribution networks through the above data interface. The business data streams of the quantum key distribution networks belonging to the two operators do not interact. For operator 2, it is equivalent to forming a virtual key leased line through operator 1's network, connecting quantum key distribution networks A and C, and realizing the connection between the two.
[0065] Furthermore, according to the present invention, in addition to the key input / output function of obtaining and outputting symmetric keys to the KM device, the QKR device may also include the following functions:
[0066] (1) Key synchronization capability, used to ensure the consistency of symmetric keys in input, output, storage and other stages.
[0067] (2) Key security storage capability, used to ensure the security of the symmetric key during its lifetime within the device.
[0068] (2) Security authentication function, used to authenticate KM devices.
[0069] (4) Heartbeat detection function, used to determine whether the KM device is online.
[0070] (5) Parameter configuration function, used for configuring and managing various basic parameters of the equipment.
[0071] Optionally, a QKR management device can also be configured to provide management functions such as traffic limits, rate limits, and pre-stored key limits for the deployed QKR devices.
[0072] In summary, the "north-south" inter-network interconnection scheme of this invention allows the service data flows of quantum key distribution networks belonging to different operators to be independent, thereby ensuring operator data security. For example, the QKDN service flows of operator 1 and operator 2 are independent of each other, without needing to obtain critical information such as the other's network topology and key quantity; the service data flows of KM devices are also independent, and the key relay services of operators 1 and 2 are conducted independently, without relying on the other's network for key relay. Simultaneously, this invention can also ensure the reliable operation of the quantum key distribution network based on inter-network interconnection. For example, even if operator 2's quantum key distribution network B experiences a brief interruption, as long as the QKR devices in the interconnection nodes have a certain number of pre-stored symmetric keys, it will not affect operator 1's services. Furthermore, under this interconnection scheme, the inter-network interconnection mode is simple and the boundaries are clear; and there are only intra-site interfaces between QKR devices and KM devices, without interfaces between different sites, facilitating network isolation and enabling separate upgrades, compliance testing, and cryptographic evaluation for each network.
[0073] Although the present invention has been described above with reference to the accompanying drawings and specific embodiments, those skilled in the art will readily recognize that the above embodiments are merely exemplary and used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A method for interconnecting quantum key distribution networks, used to achieve interconnection between a first quantum key distribution network and a third quantum key distribution network via a second quantum key distribution network, comprising the following steps: A first boundary KM device is configured within the first quantum key distribution network, and a pair of QKD devices are configured between the first boundary KM device and its adjacent KM devices. Configure a second boundary KM device within the third quantum key distribution network, and configure a pair of QKD devices between the second boundary KM device and its adjacent KM devices; In the second quantum key distribution network, a first QKR device and a second QKR device are configured so that symmetric keys can be obtained from the KM devices of the second quantum key distribution network and output to the first boundary KM device and the second boundary KM device, respectively. as well as, A classical data link is established between the first boundary KM device and the second boundary KM device to allow quantum key relay between the first quantum key distribution network and the third quantum key distribution network using symmetric keys.
2. The network interconnection method as described in claim 1, wherein, The first and third quantum key distribution networks belong to different operators than the second quantum key distribution network.
3. The inter-network connection method as described in claim 2, wherein, The first and second boundary KM devices are controlled by at least one of the QKDN controllers in the first and third quantum key distribution networks.
4. The network interconnection method as described in claim 3, wherein, Establish a classical data link between the QKDN controllers of the first and third quantum key distribution networks.
5. The network interconnection method as described in claim 1, wherein, Configure the QKR device to achieve at least one of the following: key synchronization, secure key storage, KM device authentication, and heartbeat monitoring.
6. The network interconnection method as described in claim 1, wherein, It is also equipped with a QKR management device to manage the flow, rate, and pre-stored key quantity limits for key input and output of the QKR device.
7. A quantum key distribution network based on inter-network interconnection, comprising a first quantum key distribution network, a second quantum key distribution network, and a third quantum key distribution network; The first quantum key distribution network is configured with a first boundary KM device, and a pair of QKD devices are configured between the first boundary KM device and its adjacent KM device. The third quantum key distribution network is configured with a second boundary KM device, and a pair of QKD devices are configured between the second boundary KM device and its adjacent KM device; A second quantum key distribution network is configured with a first QKR device and a second QKR device. The first QKR device is configured to obtain a quantum key from a neighboring KM device within the second quantum key distribution network and output it to a first boundary KM device. The second QKR device is configured to obtain a quantum key from a neighboring KM device within the second quantum key distribution network and output it to a second boundary KM device, thereby distributing a symmetric key between the first and second boundary KM devices. The first boundary KM device is connected to the second boundary KM device via a classic data link.
8. The quantum key distribution network as described in claim 7, wherein, The first and third quantum key distribution networks belong to different operators than the second quantum key distribution network.
9. The quantum key distribution network as described in claim 7, wherein, The QKDN controllers of the first and third quantum key distribution networks are connected via a classical data link.
10. The quantum key distribution network as described in claim 7, wherein, The QKR device is configured to perform at least one of key synchronization, secure key storage, KM device authentication, and heartbeat monitoring; and / or includes a QKR management device for managing the flow, rate, and pre-stored key quantity limits of the QKR device for key input and output.