A method and apparatus for multi-protocol update of metropolitan quantum key distribution service
By setting up a key cache between the source and destination nodes of the metro QKD service and retrieving the key during protocol switching, the problem of temporary interruption of key negotiation was solved, enabling seamless switching between multiple protocols and immediate use, thus improving the service quality of the metro QKD service.
Patent Information
- Application Number
- CN202310281752.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-21
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-03-21
AI Technical Summary
Existing technologies cannot solve the limitation of real-time updates of multiple protocols caused by temporary interruptions in key negotiation, making it difficult to guarantee the service quality of metropolitan area QKD services.
A key cache is set up between the source and destination nodes of the metropolitan QKD service. The key is initially reserved and retrieved from the cache when the protocol is switched to compensate for the interruption caused by initialization and delay the dismantling of the protocol to ensure seamless switching.
It enables seamless switching between multiple protocols without the awareness of key negotiation interruptions, improving the update efficiency and service quality of metro QKD services.
Smart Images

Figure CN116506518B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a multi-protocol update method and apparatus, particularly a multi-protocol update method and apparatus for metropolitan quantum key distribution services. Background Technology
[0002] Quantum Key Distribution (QKD) networks can provide user networks with theoretically "unconditionally secure" quantum keys, thereby ensuring the security of user networks. The QKD protocol is the cornerstone of building QKD networks. Existing QKD metropolitan area networks (MANs) are typically built based on a single QKD protocol. However, with the development and advancement of various QKD protocols, especially the development of multi-protocol QKD transceivers, the reliance on a single protocol in QKD MANs makes it difficult to improve the practical security of QKD services. This has led to the emergence of a new type of QKD MAN: the multi-protocol QKD MAN.
[0003] In multi-protocol QKD metropolitan area networks (MANs), metropolitan QKD services can improve security by updating and switching the QKD protocols between their source and destination nodes. However, each QKD protocol update requires transceiver initialization and channel calibration, causing a temporary interruption in the key negotiation process and making it difficult to guarantee the quality of service (QoS) of metropolitan QKD services. Existing technologies cannot solve the problem of the limitations imposed by temporary interruptions in key negotiation on real-time updates of multi-protocol services. Summary of the Invention
[0004] Purpose of the invention: The purpose of this invention is to provide a multi-protocol update method and apparatus for metropolitan quantum key distribution services that allows for on-demand multi-protocol switching and seamless key negotiation interruption.
[0005] Technical solution: The multi-protocol update method for metropolitan quantum key distribution service described in this invention allows source and destination nodes of the metropolitan QKD service to switch between all available protocols for protocol updates, and each available protocol has a corresponding key buffer.
[0006] The key buffer corresponding to each of the available protocols is initially set to store the initial reserved key. When the available protocol is first connected between the source and destination nodes of the metropolitan QKD service, the initial reserved key is extracted from the corresponding key buffer to compensate for the amount of key interrupted due to the initialization of the available protocol, and the protocol update is completed.
[0007] Each time the available protocol needs to be dismantled between the source and destination nodes of the metropolitan QKD service, the key generated in the first time period is injected into the corresponding key buffer. When the available protocol reconnects to the source and destination nodes of the metropolitan QKD service, the key is extracted from the corresponding key buffer to compensate for the amount of key that was temporarily interrupted by the key negotiation during the initialization of the available protocol, thus completing this protocol update.
[0008] Each time the protocol is updated, an available fiber optic channel is reselected to connect the available protocol to the source and destination nodes of the metropolitan area QKD service;
[0009] The first time period is not shorter than the initialization time of the available protocol.
[0010] Furthermore, the number of initial reserved keys stored in the key buffer corresponding to each available protocol is not less than the initialization time of the available protocol multiplied by the quantum key generation rate supported by the available protocol.
[0011] Furthermore, all available protocols between the source and destination nodes of the metropolitan area QKD service are QKD protocols, and all available protocols are selected based on the fiber optic link length and the number of intermediate nodes between the source and destination nodes of the metropolitan area QKD service.
[0012] Furthermore, based on the multi-protocol update requirements between the source and destination nodes of the metropolitan QKD service and the priority of the available protocols, the available protocol that satisfies the multi-protocol update requirements and has the highest priority is selected as the available protocol for this update access between the source and destination nodes of the metropolitan QKD service.
[0013] Furthermore, the method for setting the priority of the available protocol includes: setting the priority according to the initialization time of the available protocol, or setting the priority according to the quantum key generation rate of the available protocol.
[0014] Furthermore, each time the protocol is updated, after the first time period, the available protocols that need to be removed from the source and destination nodes of the metropolitan QKD service will be removed.
[0015] The multi-protocol update device for metropolitan quantum key distribution (QKD) services of the present invention enables source and destination nodes of the metropolitan QKD service to switch between all available protocols for protocol updates. The device includes:
[0016] A key buffer setting unit is used to set a corresponding key buffer for each available protocol; each time an available protocol needs to be removed from the source and destination nodes of the metropolitan QKD service, the key generated within a first time period is injected into the corresponding key buffer; the first time period is not shorter than the initialization time of the available protocol;
[0017] A reserved key setting unit is used to initially set the key buffer corresponding to each of the available protocols to store an initial reserved key;
[0018] The protocol configuration unit is used to reselect an available optical fiber channel to access the available protocol between the source and destination nodes of the metropolitan QKD service during each protocol update.
[0019] The key extraction unit is used to extract the key from the key buffer during protocol updates to compensate for the temporary interruption of key negotiation caused by the initialization of the available protocol.
[0020] When an available protocol is first connected between the source and destination nodes of the metropolitan QKD service, the key extraction unit extracts the initial reserved key from the key cache corresponding to the available protocol; when the available protocol is connected between the source and destination nodes of the metropolitan QKD service again, the key extraction unit extracts the key from the key cache corresponding to the available protocol.
[0021] Furthermore, in the reserved key setting unit, the key quantity of the initial reserved key is not less than the initialization time of the available protocol × the quantum key generation rate supported by the available protocol.
[0022] The electronic device of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the multi-protocol update method for the metropolitan quantum key distribution service.
[0023] The computer-readable storage medium of the present invention stores a computer program, which, when executed by a processor, implements the multi-protocol update method for the metropolitan quantum key distribution service.
[0024] Beneficial effects: Compared with the prior art, the advantages of this invention are as follows: Key buffers are set up for different QKD protocols between source and destination nodes of metropolitan QKD services. When a protocol is dismantled, the key generated during the delayed dismantling period is injected into the key buffer. When a new protocol is accessed, the key in the key buffer corresponding to the new protocol is called in real time to compensate for the key generated during the period when key negotiation is temporarily interrupted due to the initialization of the new protocol. This achieves seamless switching of multiple protocols without the awareness of key negotiation interruption, providing metropolitan QKD services with seamless switching and on-demand capability, avoiding temporary interruption of key negotiation caused by multiple protocol updates, improving the efficiency of multi-protocol updates in metropolitan QKD services, and improving the service quality of metropolitan QKD services. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the metropolitan area QKD service of the present invention.
[0026] Figure 2 This is a flowchart of the multi-protocol update method of the present invention.
[0027] Figure 3 This is a schematic diagram of the metropolitan area QKD service in an embodiment of the present invention.
[0028] Figure 4 This is a structural diagram of the multi-protocol update device of the present invention. Detailed Implementation
[0029] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0030] The terms used in this invention are explained below:
[0031] (1) Multiprotocol
[0032] All protocols used in this invention are QKD protocols, and no other network protocols are involved. Table 1 summarizes some classic QKD protocols: BB84 (Bennett-Brassard-1984), E91 (Ekert-91), BBM92 (Bennett-Brassard-Mermin-1992), GG02 (Grosshans-Grangier-2002), DPS (Differential-Phase-Shift), COW (Coherent-One-Way), Measurement-Device-Independent (MDI), and Twin-Field (TF). These protocols lay the foundation for building high-performance multi-protocol QKD metropolitan area networks. Furthermore, the multi-protocol protocols mentioned in this invention are not limited to the classic protocols listed in Table 1.
[0033] Table 1 Classic QKD Protocol
[0034]
[0035]
[0036] The source and destination node configurations for metropolitan area QKD services corresponding to different QKD protocols can be divided into three categories: source node (send) → destination node (receive), source node (receive) ← untrusted relay (send) → destination node (receive), and source node (send) → untrusted relay (receive) ← destination node (send) (the roles of source and destination nodes can be interchanged). Therefore, the first type of configuration typically involves two nodes actually participating in the creation of the QKD service, while the latter two types typically involve three nodes. This invention does not consider the case where the untrusted relay is placed at the source or destination node.
[0037] (2) Metropolitan Area QKD Business
[0038] like Figure 1The diagram illustrates a typical metropolitan area QKD service. Metropolitan area QKD service is a QKD service within a metropolitan area network (MAN), created by connecting source and destination QKD nodes via a QKD link. Since the distance between source and destination nodes in a metropolitan area network is typically within 100km, the creation of QKD services can be independent of trusted relays. Therefore, the metropolitan area QKD service mentioned in this invention is also a QKD service without trusted relays. The QKD link is usually a fiber optic link.
[0039] QKD services can be created between adjacent QKD nodes (e.g., Figure 1 In the context of QKD services 1), it is also possible to create them between non-adjacent QKD nodes (such as...). Figure 1 QKD service 2). When a QKD service is created between adjacent QKD nodes, the available QKD protocols are mainly those in the "source node (sender) → destination node (receiver)" pattern shown in Table 1. When a QKD service is created between non-adjacent QKD nodes, the intermediate nodes between the non-adjacent source and destination nodes (such as...) Figure 1 The nodes (B) traversed by the QKD service 2 can perform bypass (BB84, GG02, COW protocol, etc.) or untrusted relay functions (MDI, TF protocol, etc.) depending on the protocol used by the QKD service. After a traditional metropolitan area QKD service is created, even if the connection between the source and destination nodes is dynamically reconstructed, the QKD protocol used by the QKD service will not change. This results in the actual security of the QKD service being heavily dependent on the protocol used. Dynamically updating and switching the QKD protocol between the source and destination nodes helps avoid a single protocol directly impacting the actual security of the QKD service.
[0040] like Figure 2 As shown, the multi-protocol update method for the metropolitan area quantum key distribution service includes the following steps:
[0041] Step 1: Business Information Inquiry
[0042] Step 1.1: Query the real-time topology information of the metropolitan area network, including topology structure, node information, link information, etc.
[0043] Step 1.2: Query the source and destination nodes of each metropolitan area QKD service and the path between the source and destination nodes.
[0044] Step 1.3: Query the available protocols for each metropolitan area QKD service. Available protocols include BB84, COW, GG02, MDI, TF, etc. The availability of a protocol depends on the fiber link length (loss) between the source and destination nodes and the number of intermediate nodes. For example, when there are no intermediate nodes between the source and destination nodes, QKD protocols such as MDI and TF based on untrusted relays are unavailable.
[0045] Step 1.4: Query the quantum key generation rate supported by the available protocols for each metropolitan area QKD service. The quantum key generation rate is related to the fiber optic link length (loss) between the source and destination nodes.
[0046] Step 1.5: Query the available protocol initialization time between source and destination nodes of each metropolitan QKD service. The initialization time is related to the protocol type and fiber link length, etc.
[0047] Step 2: Initial parameter settings
[0048] Step 2.1: Set up a key buffer for each available protocol between the source and destination nodes of the metropolitan QKD service. The key buffer stores the amount of keys used to compensate for the temporary interruption of key negotiation caused by the initialization of the corresponding QKD protocol. Given the differences in the actual security of different QKD protocols, a key buffer is set up for each QKD protocol of each metropolitan QKD service.
[0049] Step 2.2: Set the initial reserved key for each key buffer between the source and destination nodes of the metropolitan QKD service. The initial reserved key is used for the first update of the corresponding available protocol. The initial reserved key amount can be set to no less than the initialization time of the available protocol × the quantum key generation rate supported by the available protocol. Therefore, the initial reserved key amount of the key buffer corresponding to different available protocols may be different.
[0050] Step 2.3: Set the delay teardown time for each available protocol between the source and destination nodes of the metropolitan QKD service. The amount of keys generated during the delay teardown time is injected into the key buffer corresponding to the available protocol for subsequent updates. The delay teardown time can be set to be no less than the initialization time of the available protocol.
[0051] Step 3: Real-time updates via multiple protocols
[0052] Step 3.1: Set the priority of multi-protocol updates between source and destination nodes of metropolitan QKD service. The priority determines the order of multi-protocol updates. The priority setting is determined by the network operator. It can be set from shortest to longest initialization time, or from highest to lowest quantum key generation rate.
[0053] Step 3.2: Query the multi-protocol update requirements for each metropolitan area QKD service, such as no update, or after the update, whether the quantum key generation rate can be reduced / cannot be reduced, or after the update, the actual security of the protocol can be improved (QKD protocols based on untrusted relays such as MDI and TF can improve actual security to a certain extent compared with protocols such as BB84, COW, and GG02).
[0054] Step 3.3: Query the available protocols used in real time for each metropolitan area QKD service. In this protocol update, the available protocols that need to be removed are called the original protocols, and the available protocols that need to be accessed are called the new protocols.
[0055] Step 3.4: Based on the multi-protocol update requirements, select the available protocols that can be selected for this update of each metropolitan area QKD service. These are called available update protocols. There may be multiple available update protocols selected in this step.
[0056] Step 3.5: Select the available update protocol with the highest priority among the source and destination nodes of each metropolitan QKD service as the new protocol based on the multi-protocol update priority.
[0057] Step 3.6: Set the delayed teardown time point for the original protocol of each metropolitan area QKD service. For QKD services that do not update the protocol, there is no need to tear down the original protocol. For QKD services that are to be updated, the delayed teardown time point of the original protocol should be set no earlier than: the current time + the initialization time of the original protocol.
[0058] Step 3.7: Select available fiber optic channels to configure the transceiver connection corresponding to the new protocol between the source and destination nodes of each metropolitan QKD service. The fiber optic channels of the original QKD service protocol are still occupied due to the delayed teardown, and will be unoccupied at the delayed teardown time. Therefore, it is necessary to select new available fiber optic channels to connect the QKD transceivers corresponding to the new protocol.
[0059] Step 3.8: Extract the key from the key buffer to compensate for the temporary interruption of key negotiation caused by the initialization of the new protocol for each metropolitan QKD service. This step is performed simultaneously with Step 3.7. The purpose is to call the key from the new protocol buffer in real time while performing multi-protocol updates, thereby achieving seamless switching of multi-protocols without the awareness of key negotiation interruption.
[0060] Step 3.9: Update the status of the metropolitan area QKD service.
[0061] like Figure 3 The diagram shown is a specific illustration of the metropolitan area QKD service in this experiment. The following uses this metropolitan area QKD service as an example to verify the method described in this invention.
[0062] (1) Business Information Inquiry
[0063] By querying the real-time topology information of the metropolitan area network, you can obtain specific information about the four QKD nodes and the QKD links between them.
[0064] The query retrieves the source and destination nodes and the paths between them for each metropolitan area QKD service, as follows:
[0065] Service 1: AB; Service 2: AD; Service 3: AB (bypass / untrusted trunk) - C; Service 4: BC; Service 5: BC (bypass / untrusted trunk) - D; Service 6: CD;
[0066] Queries the available protocols for each metropolitan area QKD service (Service 1 / 2 / 4 / 6: BB84, COW, GG02; Service 3 / 5: BB84, COW, GG02, MDI, TF);
[0067] The available protocols supporting quantum key generation rates for each metropolitan area QKD service are as follows:
[0068] BB84 supports 30kbps (100km) / 80kbps (60km) / 100kbps (50km), COW supports 20kbps (100km) / 65kbps (60km) / 90kbps (50km), GG02 supports 10kbps (100km) / 95kbps (60km) / 120kbps (50km), MDI supports 60kbps (100km), and TF supports 100kbps (100km).
[0069] The available protocol initialization times between the source and destination nodes of each metropolitan area QKD service are as follows:
[0070] Service 1: 10min (BB84), 8min (COW), 12min (GG02); Service 2: 12min (BB84), 10min (COW), 14min (GG02); Service 3: 20min (BB84), 16min (COW), 24min (GG02), 30min (MDI), 40min (TF); Service 4: 10min (BB84), 8min (COW), 12min (GG02); Service 5: 20min (BB84), 16min (COW), 24min (GG02), 30min (MDI), 40min (TF); Service 6: 10min (BB84), 8min (COW), 12min (GG02).
[0071] (2) Initial parameter settings
[0072] Set up a QKD protocol key cache area between each metropolitan area QKD service source and destination node;
[0073] Configure the initial reserved key for the QKD protocol key buffer between each metropolitan area QKD service source and destination node. The initial reserved key amounts are as follows:
[0074] Service 1: 60 Mbit (BB84), 43.2 Mbit (COW), 86.4 Mbit (GG02); Service 2: 57.6 Mbit (BB84), 39 Mbit (COW), 79.8 Mbit (GG02); Service 3: 36 Mbit (BB84), 19.2 Mbit (COW), 14.4 Mbit (GG02), 108 Mbit (MDI), 240 Mbit (TF); Service 4: 60 Mbit (BB84), 43.2 Mbit (COW), 86.4 Mbit (GG02); Service 5: 36 Mbit (BB84), 19.2 Mbit (COW), 14.4 Mbit (GG02), 108 Mbit (MDI), 240 Mbit (TF); Service 6: 60 Mbit (BB84), 43.2 Mbit (COW), 86.4 Mbit (GG02);
[0075] Set the delay time for tearing down the QKD protocol between each metropolitan QKD service source and destination node. This time is set to be the same as the initialization time of the available protocol between each metropolitan QKD service source and destination node.
[0076] (3) Real-time updates via multiple protocols
[0077] Configure the multi-protocol update priority between source and destination nodes of each metropolitan area QKD service, with the priority set from high to low based on the initialization time from shortest to longest:
[0078] Service 1: COW, BB84, GG02; Service 2: COW, BB84, GG02; Service 3: COW, BB84, GG02, MDI, TF; Service 4: COW, BB84, GG02; Service 5: COW, BB84, GG02, MDI, TF; Service 6: COW, BB84, GG02;
[0079] The multi-protocol update requirements for each metropolitan area QKD service are as follows:
[0080] Service 1: No update; Service 2: Update allows for a decrease in quantum key generation rate; Service 3: Update improves protocol security; Service 4: Update does not allow for a decrease in quantum key generation rate; Service 5: No update; Service 6: No update;
[0081] The original protocols for each metropolitan area QKD service are as follows:
[0082] Service 1: BB84; Service 2: GG02; Service 3: BB84; Service 4: COW; Service 5: MDI; Service 6: GG02;
[0083] Based on multi-protocol update requirements, the available update protocols for each metropolitan area QKD service are selected as follows:
[0084] Business 2: COW, BB84; Business 3: MDI, TF; Business 4: BB84, GG02;
[0085] Based on multi-protocol update priority, the highest priority available update protocol between the source and destination nodes of each metropolitan area QKD service is selected as the new protocol, namely:
[0086] Business 2: COW; Business 3: MDI; Business 4: BB84;
[0087] Set the delayed teardown time points for the original protocol of each metropolitan area QKD service, as follows:
[0088] Service 2: GG02 delayed by 14 minutes; Service 3: BB84 delayed by 20 minutes; Service 4: COW delayed by 8 minutes;
[0089] Select available fiber optic channels to configure the transceiver connection corresponding to the new protocol between the source and destination nodes of each metropolitan QKD service, and extract the key from the key buffer to compensate for the temporary interruption of key negotiation caused by the initialization of the new protocol for each metropolitan QKD service.
[0090] Finally, complete the real-time updates of multiple protocols and update the status of the metropolitan area QKD service.
[0091] like Figure 4 As shown, the multi-protocol update device for metropolitan quantum key distribution services according to the present invention includes a global control module, a service information query module, an initial parameter setting module, and a multi-protocol real-time update module. The global control module is responsible for controlling the operation of the entire device and is connected to the service information query module, the initial parameter setting module, and the multi-protocol real-time update module.
[0092] The business information query module is used to query detailed information about metropolitan area QKD services, specifically including topology query unit, node path query unit, protocol query unit, key query unit, and time query unit.
[0093] The topology query unit is used to query real-time topology information of the metropolitan area network;
[0094] The node path query unit is used to query the source and destination nodes of each metropolitan area QKD service and the path between the source and destination nodes.
[0095] The protocol query unit is used to query the available protocols for each metropolitan area QKD service;
[0096] The key query unit is used to query the quantum key generation rate supported by the available protocols for each metropolitan area QKD service;
[0097] The time query unit is used to query the initialization time of the available protocols between the source and destination nodes of each metropolitan QKD service.
[0098] The initial parameter setting module is used to set various parameters before the first multi-protocol update, specifically including the key buffer setting unit, the reserved key setting unit, and the delay teardown time setting unit.
[0099] The key buffer setting unit is used to set the key buffer corresponding to each available protocol between the source and destination nodes of the metropolitan QKD service. Each time an available protocol needs to be removed from the source and destination nodes of the metropolitan QKD service, the key generated within the delay removal time will be injected into the corresponding key buffer.
[0100] The reserved key setting unit is used to initially set each key buffer to store an initial reserved key; the initial reserved key amount can be set to no less than the initialization time of the available protocol × the quantum key generation rate supported by the available protocol;
[0101] The delayed teardown time setting unit is used to set the delayed teardown time for each available protocol. The delayed teardown time can be set to be no less than the initialization time of the available protocol.
[0102] The multi-protocol real-time update module is used to complete the real-time update of multiple protocols for metropolitan area QKD services. Specifically, it includes a priority setting unit, an update requirement query unit, a protocol query unit, a protocol filtering unit, a protocol selection unit, a delay teardown setting unit, a protocol configuration unit, a key extraction unit, and an update unit.
[0103] The priority setting unit is used to set the priority of multi-protocol updates between source and destination nodes of metropolitan QKD services. The priority can be set from high to low based on the initialization time from shortest to longest, or from high to low based on the quantum key generation rate.
[0104] The update requirement query unit is used to query the multi-protocol update requirements for each metropolitan area QKD service;
[0105] The protocol query unit is used to query the QKD protocol (original protocol) used in real time for each metropolitan area QKD service;
[0106] The protocol filtering unit is used to filter the available update protocols that can be selected for each metro QKD service;
[0107] The protocol selection unit is used to select the highest priority available update protocol as the new protocol;
[0108] The delayed removal setting unit is used to set the delayed removal time point of the original protocol for each metropolitan area QKD service;
[0109] The protocol configuration unit is used to reselect an available optical fiber channel to access the available protocol between the source and destination nodes of the metropolitan QKD service during each protocol update, and to configure the transceiver connection corresponding to the new protocol between each source and destination node of the metropolitan QKD service.
[0110] The key extraction unit is used to extract keys from the key buffer to compensate for the temporary interruption of key negotiation caused by the initialization of a new protocol for each metropolitan QKD service. When an available protocol is first connected between the source and destination nodes of the metropolitan QKD service, the key extraction unit extracts the initial reserved key from the key buffer corresponding to the available protocol. When the available protocol is connected between the source and destination nodes of the metropolitan QKD service again, the key extraction unit extracts the key from the key buffer corresponding to the available protocol.
[0111] The update unit is used to update the status of metropolitan area QKD services.
[0112] The electronic device of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the multi-protocol update method for the metropolitan quantum key distribution service.
[0113] The computer-readable storage medium of the present invention stores a computer program, which, when executed by a processor, implements the multi-protocol update method for the metropolitan quantum key distribution service.
[0114] The computer-readable storage medium may include RAM, ROM, EEPROM, CD-ROM or other optical disc storage devices, magnetic disk storage devices or other magnetic storage devices, flash memory, or any other media that can be used to store desired program code in the form of instructions or data structures and is accessible by a computer.
[0115] The processor is used to execute a computer program stored in memory to implement the various steps in the methods described in the above embodiments.
Claims
1. A multi-protocol update method for metropolitan quantum key distribution services, characterized in that, The source and destination nodes of the metropolitan QKD service switch between all available protocols to update the protocol, and each of the available protocols has a corresponding key cache area; The key buffer corresponding to each of the available protocols is initially set to store the initial reserved key. When the available protocol is first connected between the source and destination nodes of the metropolitan QKD service, the initial reserved key is extracted from the corresponding key buffer to compensate for the amount of key interrupted due to the initialization of the available protocol, and the protocol update is completed. Each time the available protocol needs to be dismantled between the source and destination nodes of the metropolitan QKD service, the key generated in the first time period is injected into the corresponding key buffer. When the available protocol reconnects to the source and destination nodes of the metropolitan QKD service, the key is extracted from the corresponding key buffer to compensate for the amount of key that was temporarily interrupted by the key negotiation during the initialization of the available protocol, thus completing this protocol update. Each time the protocol is updated, after the first time period, the available protocols that need to be removed from the source and destination nodes of the metropolitan QKD service will be removed. Each time the protocol is updated, an available fiber optic channel is reselected to connect the available protocol to the source and destination nodes of the metropolitan area QKD service; The first time period is not shorter than the initialization time of the available protocol.
2. The multi-protocol update method for metropolitan quantum key distribution service according to claim 1, characterized in that, The number of initial reserved keys stored in the key buffer corresponding to each available protocol shall not be less than the initialization time of the available protocol multiplied by the quantum key generation rate supported by the available protocol.
3. The multi-protocol update method for metropolitan quantum key distribution service according to claim 1, characterized in that, All available protocols between the source and destination nodes of the metropolitan area QKD service are QKD protocols. All available protocols are selected based on the fiber optic link length and the number of intermediate nodes between the source and destination nodes of the metropolitan area QKD service.
4. The multi-protocol update method for metropolitan quantum key distribution service according to claim 1, characterized in that, Based on the multi-protocol update requirements between the source and destination nodes of the metropolitan QKD service and the priority of the available protocols, the available protocol that meets the multi-protocol update requirements and has the highest priority is selected as the available protocol for this update access between the source and destination nodes of the metropolitan QKD service.
5. The multi-protocol update method for metropolitan quantum key distribution service according to claim 4, characterized in that, The methods for setting the priority of the available protocols include: setting the priority based on the initialization time of the available protocol, or setting the priority based on the quantum key generation rate of the available protocol.
6. A multi-protocol update device for metropolitan quantum key distribution services, characterized in that, The device for switching between all available protocols to update protocols in metropolitan area QKD service source and destination nodes includes: A key buffer setting unit is used to set a corresponding key buffer for each available protocol; each time an available protocol needs to be removed from the source and destination nodes of the metropolitan QKD service, the key generated within a first time period is injected into the corresponding key buffer; the first time period is not shorter than the initialization time of the available protocol; each time the protocol is updated, after the first time period, the available protocol that needs to be removed from the source and destination nodes of the metropolitan QKD service is removed. A reserved key setting unit is used to initially set the key buffer corresponding to each of the available protocols to store an initial reserved key; The protocol configuration unit is used to reselect an available optical fiber channel to access the available protocol between the source and destination nodes of the metropolitan QKD service during each protocol update. The key extraction unit is used to extract the key from the key buffer during protocol updates to compensate for the temporary interruption of key negotiation caused by the initialization of the available protocol. When an available protocol is first connected between the source and destination nodes of the metropolitan QKD service, the key extraction unit extracts the initial reserved key from the key cache corresponding to the available protocol; when the available protocol is connected between the source and destination nodes of the metropolitan QKD service again, the key extraction unit extracts the key from the key cache corresponding to the available protocol.
7. The multi-protocol update device for metropolitan quantum key distribution service according to claim 6, characterized in that, In the reserved key setting unit, the key quantity of the initial reserved key is not less than the initialization time of the available protocol × the quantum key generation rate supported by the available protocol.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is loaded into the processor, it implements the multi-protocol update method for metropolitan quantum key distribution service according to any one of claims 1-5.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the multi-protocol update method for metropolitan quantum key distribution service according to any one of claims 1-5.
Citation Information
Patent Citations
QKD network deployed in metropolitan area network and access network and key distribution method thereof
CN112073180A
QKD network, metropolitan area node and secret key distribution method between access networks
CN112073181A