A key distribution network routing method based on trusted relay
Patent Information
- Application Number
- CN202210780003.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-04
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2042-07-04
AI Technical Summary
[0006]目前的密钥分发网络是完全基于QKD技术和可信中继技术组成的大规模、多点对多点的网络,但是由于QKD技术基于光子,都是在固定节点服务,无法适应于移动网络
Smart Images

Figure CN117394989B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum secure communication, and in particular to a routing method for key distribution networks based on trusted relays. Background Technology
[0002] Quantum key distribution (QKD) utilizes quantum systems to prepare, transmit, receive, and purify information to obtain a secure symmetric key that is physically impossible to steal. This process ensures that the keys obtained by both communicating parties are completely identical, and no third party can obtain any information about the key. In a quantum key distribution system, the sender needs to transmit quantum light and synchronization light to the receiver, and both parties need to exchange data for key negotiation.
[0003] However, key distribution methods based on physical signals are all limited by distance. For example, the attenuation of quantum channels increases exponentially with distance, while conventional optical fibers typically attenuate by half every 10-15 kilometers. Quantum key distribution, using extremely weak light at the single-photon level, must operate within a finite key generation distance (attenuation) to ensure a good signal-to-noise ratio and thus obtain secure codes. Currently, the typical secure key generation distance for product-level systems is about 100 kilometers, and the furthest distance in laboratories is about 400 kilometers. Wireless channel key generation is also constrained by distance.
[0004] Therefore, when the distance between the communicating parties exceeds the effective and secure coding distance, relaying is an important means of extending the distance. Currently, trusted relays are a practical solution for long-distance quantum key distribution, for example... Figure 1 As shown.
[0005] Currently, QKD network routing generally references the TCP / IP protocol of IP networks, modifying it based on the OSPF technology concept. It employs a hierarchical, domain-based approach to interconnect nodes, automatically building its own routing table based on specific routing information exchanged between nodes, and automatically adjusting in real-time according to changes in links and nodes. When a node or link in the network fails, or when other available routes exist, the optimal route can be dynamically selected to continue communication, similar to dynamic routing. This scheme, based on mature routing technologies from classic networks, has been widely adopted by many research institutions. For example, the SECOQC network released in Europe uses the OSPF protocol for key relay path selection, including network routing domain division, routing information exchange between nodes, and routing algorithms. Domestic research groups have also designed algorithms for the key relay process, incorporating link key resources as an important parameter into the routing algorithm within the OSPF protocol. For example, each relay link is assigned a weight, and the path with the lowest weight is selected as the final path in each dynamic route generation. The weight of a link is related to factors such as the key generation rate, key storage, and load. The higher the generation rate, the more keys are stored, and the lower the load, the lower the link weight value. Since the link weight also changes, each node needs to periodically send the weight values of all the links it connects to to surrounding nodes or to the control node.
[0006] Current key distribution networks are large-scale, multi-point-to-multi-point networks based entirely on QKD technology and trusted relay technology. However, since QKD technology is based on photons and serves only fixed nodes, it cannot be adapted to mobile networks. Summary of the Invention
[0007] To address the aforementioned problems in the existing technology, this invention discloses a key distribution network routing method based on trusted relays. By leveraging a specific key distribution network and addressing, network access configuration, and route generation steps, it makes the joining, configuration, and route generation of mobile nodes possible and easy to implement, thereby enabling the application of wireless key distribution in mobile scenarios and the rapid expansion of key distribution networks.
[0008] This invention relates to a routing method for a key distribution network based on trusted relays, wherein the key distribution network includes one or more autonomous system networks;
[0009] The autonomous system network has multiple nodes, which are mobile nodes and / or fixed nodes, and includes a key production module and a key exchange module.
[0010] The key generation module is used to provide point-to-point keys for the key exchange module;
[0011] The autonomous system network is equipped with a regional routing key exchange module KEM2-IR and a border routing key exchange module KEM2-ASBR. The regional routing key exchange module KEM2-IR is used to generate routes between nodes within the autonomous system network, and the border routing key exchange module KEM2-ASBR is used to generate routes between different autonomous systems networks.
[0012] The routing method includes a location query step and a route generation step, wherein:
[0013] The location query step is used by the calling user to query the current network address of the called user;
[0014] The route generation step is used to generate a route from the calling user to the called user based on the current network address of the called user.
[0015] In the route generation step, when the calling user and the called user belong to the same autonomous system network, the area routing key exchange module KEM2-IR within the autonomous system network generates a route from the calling user to the called user.
[0016] When the calling user and the called user do not belong to the same Autonomous System Network (ASN), the boundary routing key exchange module KEM2-ASBR of the ASN to which the calling user belongs determines the first exit boundary node of the ASN to which the calling user belongs and the second exit boundary node of the ASN to which the called user belongs, and generates a cross-domain route from the first exit boundary node to the second exit boundary node; the area routing key exchange module KEM2-IR of the ASN to which the calling user belongs generates a route from the calling user to the first exit boundary node; and the area routing key exchange module KEM2-IR of the ASN to which the called user belongs generates a route from the second exit boundary node to the called user.
[0017] Furthermore, the key generation module of the mobile node includes a WCKG component, and the key generation module of the fixed node includes a QKD component.
[0018] Furthermore, the autonomous system network is also equipped with a relay key exchange module KEM1 and a user key exchange module KEM3;
[0019] The relay-type key exchange module KEM1 is only used for key exchange between adjacent nodes;
[0020] The user-defined key exchange module KEM3 is deployed within the terminal node for unidirectional routing.
[0021] Furthermore, the autonomous system network is equipped with a local location query server (HLR) and a visitor location query server (VLR).
[0022] The routing method further includes a user registration step, which includes a sub-step of registering user data with the local location lookup server (HLR) of the user's home autonomous system after the user registers, and a sub-step of registering user data with the visitor location lookup server (VLR) of the local autonomous system after the user moves to another autonomous system, wherein the visitor location lookup server (VLR) informs the user of the new network address of the user's home autonomous system's HLR based on the user data.
[0023] Furthermore, the user data includes a local username and a network address, wherein the local username contains the domain name information of the autonomous system network to which the user belongs;
[0024] The fixed node has a unique fixed network address, and the mobile node has a temporary network address.
[0025] Preferably, the fixed network address includes a country name, operator name, regional network name, and node name, and the temporary network address includes a country name, operator name, regional network name, and temporary network code.
[0026] Furthermore, the routing method of the present invention may further include a network access configuration step, wherein:
[0027] When a new node is added to an autonomous system network, a point-to-point bidirectional key pool is established between the key exchange module of the new node and the key exchange modules of the adjacent nodes.
[0028] When a new autonomous system network (ASN) is added to the key distribution network, a point-to-point bidirectional key pool is established between the boundary routing key exchange module (KEM2-ASBR) of the new ASN and the boundary routing key exchange module (KEM2-ASBR) of the adjacent ASN.
[0029] Furthermore, the route generation step includes sub-steps such as key exchange modules exchanging link status with each other or centrally reporting route status, generating network topology information, and generating a routing control table based on the network topology information.
[0030] Preferably, in the route generation step, the weight of each link is dynamically calculated based on the network topology information, and the link used for the key is selected based on the weight.
[0031] The weight is related to the key generation rate, key storage, and load of the link. Attached Figure Description
[0032] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0033] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 This illustrates a trusted relay process in the prior art;
[0035] Figure 2 An example of a key distribution network based on trusted relays according to the present invention is illustrated schematically;
[0036] Figure 3 An example of a fixed network address according to the present invention is shown;
[0037] Figure 4 An example of a temporary network address according to the present invention is shown;
[0038] Figure 5 An example of the addressing procedure according to the present invention is shown;
[0039] Figure 6 The link construction process of adjacent autonomous system networks according to the present invention is illustrated;
[0040] Figure 7 The network topology generation process of the distributed link-state routing protocol of the present invention is illustrated.
[0041] Figure 8 The network topology generation process of the centralized link-state routing protocol of the present invention is illustrated.
[0042] Figure 9 A flowchart illustrating an example of a routing method according to the present invention is shown. Detailed Implementation
[0043] In the following description, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example in order to fully convey the spirit of the invention to those skilled in the art. Therefore, the invention is not limited to the embodiments disclosed herein.
[0044] Figure 2 A key distribution network based on trusted relay according to the present invention is illustrated schematically.
[0045] like Figure 2As shown, a key distribution network may include one or more Autonomous Systems (AS), each with multiple nodes and responsible for routing between nodes within its own AS.
[0046] In this invention, the nodes used for the key distribution network may include mobile nodes in addition to fixed nodes, in order to meet the needs of mobile applications.
[0047] A node may include a key production module and a key exchange module (KEM).
[0048] The key production module can include any physically secure key production device to provide point-to-point keys to the key exchange module.
[0049] For example, a key generation module for mobile nodes may include a WCKG (Wireless Channel Key Generation) component; a key generation module for fixed nodes may include a QKD component.
[0050] The key exchange module receives keys from adjacent nodes and performs (XOR) relay to achieve end-to-end key distribution. In this invention, the key exchange module can perform functions such as node location lookup and route generation.
[0051] In addition, a User Service Module (USM) can be set up in the terminal node to connect with user applications and provide functions such as key services and user registration.
[0052] In this invention, the key exchange module for the node may include the following types:
[0053] (1) The relay-type key exchange module KEM1 is only used for key exchange between adjacent nodes and does not have routing function. The shared key used between adjacent nodes does not need to be stored for a long time.
[0054] (2) The area routing key exchange module KEM2-IR is responsible for generating routes between nodes within the same autonomous system network. The protocol used within the AS can be called the Interior Gateway Protocol (IGP).
[0055] (3) The boundary routing key exchange module KEM2-ASBR is typically deployed at the boundary nodes of an autonomous system network (AS) and is responsible for generating routes (cross-domain routes) between different ASs. The protocol between ASs can be called the Exterior Gateway Protocol (EGP).
[0056] (4) User-type key exchange module KEM3, which is usually deployed at the terminal node of the network, is responsible for one-way routing of user applications and providing services to USM.
[0057] By constructing a key distribution network in the form of interconnected autonomous systems (AS), a regional routing key exchange module KEM2-IR is set up within the AS to manage the routing within the region, and a boundary routing key exchange module KEM2-ASBR is set up at the AS boundary to handle the routing between different ASs. This allows keys to be easily relayed within and across domains, which makes the expansion of the key distribution network more convenient.
[0058] See also Figure 2 In the example shown, the key distribution network includes 8 nodes, of which: nodes 1-4 and nodes 5-8 belong to different autonomous systems networks, nodes 1 and 8 are terminal nodes, node 1 is a mobile node, nodes 4 and 5 are border nodes, and nodes 2-8 are fixed nodes.
[0059] In the first autonomous system network containing nodes 1-4, terminal node 1 is equipped with a key production module based on WCKG components, a user-type key exchange module KEM3, and a user service module USM. Node 2 is equipped with a key production module based on WCKG components (for pairing with node 1), a key production module based on QKD components (for pairing with node 3), and a regional routing key exchange module KEM2-IR. Node 3 is equipped with two key production modules based on QKD components (for pairing with nodes 2 and 4 respectively) and a relay key exchange module KEM1. Border node 4 is equipped with a key production module based on QKD components, a regional routing key exchange module KEM2-IR, and a border routing key exchange module KEM2-ASBR.
[0060] In the second autonomous system network containing nodes 5-8, terminal node 8 is equipped with a key production module based on QKD components, a user routing key exchange module KEM3, and a user service module USM. Node 7 is equipped with a key production module based on QKD components and a regional routing key exchange module KEM2-IR. Node 6 is equipped with a key production module based on QKD components and a relay key exchange module KEM1. Border node 5 is equipped with a key production module based on QKD components, a regional routing key exchange module KEM2-IR, and a border routing key exchange module KEM2-ASBR.
[0061] According to the present invention, a local location query server (HLR) and a visitor location query server (VLR) can also be set up in an autonomous system network.
[0062] The Home Location Query Server (HLR) is used to register user data within the home autonomous system (AAS) and provide a query service for that data. For example, after a user registers, the corresponding key exchange module registers the user data with the HLR in the home AAS.
[0063] In this invention, user data may include (but is not limited to) information such as local username, network address, operator, node type (mobile node / fixed node) and user type (local user, roaming user).
[0064] For ease of addressing, the username can include the domain name information of the autonomous system network to which it belongs, such as "shanghai.qtict.cn" or "wuhan.unicom.cn".
[0065] Fixed nodes are assigned unique fixed network addresses to indicate their location within their home autonomous system (AS / RS). As a preferred example, such as... Figure 3 As shown, a fixed network address can contain information such as country name (e.g., cn), operator name (e.g., qtict), regional network name (e.g., shanghai), and node name (e.g., zhangdong), for example, "zhangdong.shanghai.qtict.cn" and "shangdi.beijing.qtict.cn".
[0066] Due to the mobility of mobile nodes, they will be assigned temporary network addresses. As a preferred example, such as... Figure 4 As shown, a temporary network address can contain information such as country name, operator name, regional network name, and temporary network code (e.g., temp66), such as "temp1.shanghai.qtict.cn" and "temp66.beijing.qtict.cn".
[0067]
[0068] Table 1 (Example of user data in HLR)
[0069] When a user moves to another autonomous system network, the key exchange module associated with the user needs to register the user's data with the local autonomous system network's VLR; and the local autonomous system network's VLR also needs to send a message to the user's home network's HLR based on the user data (such as domain name information contained in the username) to inform the HLR that the user has moved to a new network address.
[0070]
[0071]
[0072] Table 2 (Example of User Data in VLR)
[0073] With the help of HLR and VLR, when user A needs to call user B, user A's key exchange module can easily obtain user B's home autonomous system network from user B's username. By querying the HLR of user B's home autonomous system network, the HLR can obtain user B's current network address based on its stored record data.
[0074] For example Figure 5 As shown, when user A (whose home autonomous system is shanghai.qtict.cn) calls user B (whose home autonomous system is chengdu.Unicom.cn), user A learns about user B's home autonomous system chengdu.Unicom.cn from user B's username (e.g., Bob@chengdu.Unicom.cn). Therefore, user A can query user B's current network address from the HLR of the autonomous system with the domain name chengdu.Unicom.cn. The HLR of the autonomous system chengdu.Unicom.cn reports that user B has moved to the autonomous system beijing.Telecom.cn, and the current network address is temp100.beijing.Telecom.cn. Therefore, once user A knows user B's current network address, user A can begin generating a key route for user B.
[0075] As mentioned above, in the key distribution network of the present invention, the network access configuration of nodes and the network access configuration of autonomous systems (AS) can be easily implemented.
[0076] When adding a new node to an autonomous system network (ASN), a point-to-point bidirectional key pool needs to be established between the key exchange module of the new node and the key exchange modules of neighboring nodes for key relay transmission. The bidirectional key pool can be configured statically or automatically by discovering neighboring nodes and configuring it automatically.
[0077] Specifically, after configuring a network address for a new node (key exchange module), the new node's key exchange module can broadcast messages to neighboring nodes. Upon receiving the message, neighboring nodes can automatically establish a bidirectional key pool with the new node's key exchange module. For example, nodes a and b need to establish "a to b" and "b to a" bidirectional key pools. The key is uniquely identified by its network address, key pool name, and key pool offset. Therefore, during a call, the calling party determines the identifier of the currently used key, and the called party retrieves and uses the corresponding key according to the key identifier provided by the calling party, thus automatically preventing errors caused by key synchronization issues.
[0078] In a bidirectional key pool, the number of keys in the two key pools can be different. For example, the write speed and remaining key quantity of the "a to b" and "b to a" key pools are independent of each other. The key pool in the corresponding direction is consumed according to different encryption services or key relay directions.
[0079] Furthermore, fixed key pools can be established between fixed nodes with fixed network addresses, and temporary key pools can be established between mobile nodes with temporary network addresses and fixed nodes or between mobile nodes. The temporary key pool can be deregistered after the link is disconnected.
[0080] When a new Autonomous System (AS) joins a quantum key distribution network (QSDN), a point-to-point key pool needs to be established between the key exchange module (KEM2-ASBR) of the new AS and the key exchange modules (KEM2-ASBR) of neighboring ASs for cross-domain key relay transmission. The bidirectional key pool can be configured statically or automatically by discovering neighboring ASs and configuring it automatically.
[0081] Specifically, the KEM2-ASBR (Kingdom Access Module for Key Exchange) can contain fixed network addresses of two or more Autonomous Systems (AS). Therefore, after a new AS joins the quantum key distribution network, its KEM2-ASBR can query all other KEM2-ASBRs within each AS. Since each AS's KEM2-IR (Kingdom Access Module for Key Exchange) knows the internal routing topology of that AS, it is easy to connect other KEM2-ASBRs within the AS to the newly joined KEM2-ASBR, for example... Figure 6 As shown.
[0082] After the border routing key exchange module KEM2-ASBR in the new AS establishes a connection with the border routing key exchange module KEM2-ASBR in other ASs, it can send messages to the border routing key exchange module KEM2-ASBR. Upon receiving the message, the adjacent border routing key exchange module KEM2-ASBR can automatically build a bidirectional key pool with the new AS's border routing key exchange module KEM2-ASBR.
[0083] After describing the key distribution network structure of the present invention, the route generation process based on this key distribution network will be explained below.
[0084] In this invention, a link-state routing protocol is used to generate routes, namely: key exchange modules exchange link states (distributed) or centrally report routing states (centralized) to generate network topology information, and finally generate a routing control table based on the network topology information.
[0085] Figure 7 The network topology generation process of the distributed link-state routing protocol of the present invention is illustrated.
[0086] As shown in the diagram, after node C joins the network, it periodically sends Hello data packets to surrounding nodes to confirm the location of the key exchange modules of neighboring nodes. Then, it broadcasts its connection status to surrounding connected nodes, with neighboring nodes D, E, etc., relaying the broadcast until the entire network has a grasp of the network topology. Preferably, to save on the overhead of classic networks, if the network topology remains unchanged, node C may broadcast its connection status again after a long period of time (or may not need to).
[0087] When node C does not receive a proper response to the Hello data packet it sends, node C immediately updates the connection state and broadcasts the message.
[0088] Figure 8 The network topology generation process of the centralized link-state routing protocol of the present invention is illustrated.
[0089] As shown in the diagram, after node C joins the network, it periodically sends Hello packets to surrounding nodes to confirm the location of the key exchange modules of neighboring nodes. Then, it reports the connection status to the centralized routing controller (CRM), which then manages the network topology.
[0090] In this system, each link in the network is assigned a weight, and each dynamic route generation can select the final path based on the weight (e.g., selecting the path with the lowest weight). The weight is related to factors such as the link's key generation rate, key storage, and load. For example, the higher the generation rate, the more key storage, and the lower the load, the smaller the link weight value.
[0091] Since the weights of the links also change, similar to the network topology, each node also needs to periodically send the weight values of all the links it connects to to surrounding nodes or to the CRM.
[0092] The following example illustrates how to implement routing based on weights. Assume that on link i, the key generation rate is ai, the key inventory is bi, and the link weight W is the harmonic average of (ai × t + bi), where t is an adjustable cumulative time parameter, i.e.:
[0093]
[0094] Assuming t=10, the calculated weights W of the three feasible links "ACDEG", "ACDFG" and "ACDFHG" between nodes A and G are 2.225, 20.53 and 1.009, respectively. At this point, the link "ACDFHG" with the smallest weight (cost) can be selected as the relay route.
[0095] Since the key generation rate ai and the key inventory bi change rapidly, broadcasting every weight change would incur significant overhead. Therefore, it is preferable to assign values to ai×t+bi within a certain range, such as 0 in the range of 0 to 0.001M, 1 in the range of 0.001M to 1M, and 10 in the range of 1M to 10M, thereby significantly reducing the number of broadcasts related to link state changes.
[0096] Although the routing method of the key distribution network based on trusted relay of the present invention has been described above, the following will still use... Figure 9 A flowchart illustrating an example of this routing method is provided to better understand it.
[0097] The routing method of the present invention may include a location query step and a route generation step.
[0098] The location lookup step is used by the calling user to find the current network address of the called user.
[0099] like Figure 9 As shown, when Alice, a user in home network A, calls Bob, a user in home network B, Alice queries Bob's HLR (i.e., the HLR of network B) for Bob's current network address and determines whether the call between Alice and Bob is cross-domain.
[0100] The route generation step is used to generate a route from the calling user to the called user based on the current network address of the called user.
[0101] like Figure 9 As shown, when the calling user (Alice) and the called user (Bob) belong to the same Autonomous System Network (ASN), the KEM2-IR regional routing key exchange module within the ASN generates a route from the calling user to the called user. Therefore, the key can be exchanged from Alice to Bob according to the generated route.
[0102] When the calling user and the called user do not belong to the same Autonomous System Network (ASN), the boundary routing key exchange module KEM2-ASBR of the ASN (Network A) of the calling user determines the first exit boundary node of the ASN (Network A) and the second exit boundary node of the ASN (Network B) of the called user, generating a cross-domain route from the first exit boundary node to the second exit boundary node. The area routing key exchange module KEM2-IR of the ASN of the calling user generates a route from the calling user to the first exit boundary node. Therefore, the key can be exchanged from KEM2-IR to the first exit boundary node, and then KEM2-ASBR exchanges the key to the second exit boundary node.
[0103] The KEM2-IR, a zone-routing key exchange module of the autonomous system network to which the called user belongs, generates a route from the second exit boundary node to the called user, so the key can be exchanged to user Bob by KEM2-IR.
[0104] Furthermore, the route generation step may also include sub-steps such as key exchange modules exchanging link status with each other or centrally reporting route status, generating network topology information, and generating a routing control table based on the network topology information.
[0105] Preferably, the route generation step can dynamically calculate the weight of each link based on the network topology information, and select the link to be used for the key based on the weight.
[0106] Furthermore, as mentioned above, to facilitate addressing, the routing method of the present invention may also include a user registration step, which includes a sub-step of registering user data with the local location lookup server (HLR) of the user's home autonomous system after user registration, and a sub-step of registering user data with the visitor location lookup server (VLR) of the local autonomous system after the user moves to another autonomous system, wherein the visitor location lookup server (VLR) informs the user of the new network address of the user's home autonomous system (HLR) based on the user data.
[0107] Furthermore, the routing method of the present invention may also include a network entry configuration step, wherein: when a new node is added to an autonomous system network, a point-to-point bidirectional key pool is constructed between the key exchange module of the new node and the key exchange module of the adjacent node; when a new autonomous system network is added to a key distribution network, a point-to-point bidirectional key pool is constructed between the boundary routing key exchange module KEM2-ASBR of the new autonomous system network and the boundary routing key exchange module KEM2-ASBR of the adjacent autonomous system network.
[0108] In summary, the routing method of this invention, by leveraging a specific key distribution network and addressing, network access configuration, and route generation steps, makes the joining, configuration, and route generation of mobile nodes possible and easy to implement. This allows for the application of wireless key distribution in mobile scenarios and the large-scale expansion of the key distribution network. Therefore, a quantum-secure service system oriented towards mobile applications and universal services can be constructed, providing quantum key services to important nodes in communication infrastructure, cloud server clusters, and mobile terminals such as computers and mobile phones. This can be applied to scenarios such as voice communication, video conferencing, and mobile payment, greatly expanding the application scope of key distribution networks based on trusted relays.
[0109] Although the present invention has been described above with reference to the accompanying drawings and specific embodiments, those skilled in the art will readily recognize that the above embodiments are merely exemplary and used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A routing method for a key distribution network based on trusted relays, wherein the key distribution network includes one or more autonomous system networks; The autonomous system network has multiple nodes, which are mobile nodes and / or fixed nodes, and includes a key production module and a key exchange module. The key generation module is used to provide point-to-point keys for the key exchange module; The autonomous system network is equipped with a regional routing key exchange module KEM2-IR and a border routing key exchange module KEM2-ASBR. The regional routing key exchange module KEM2-IR is used to generate routes between nodes within the autonomous system network, and the border routing key exchange module KEM2-ASBR is used to generate routes between different autonomous systems networks. The routing method includes a location query step and a route generation step, wherein: The location query step is used by the calling user to query the current network address of the called user; The route generation step is used to generate a route from the calling user to the called user based on the current network address of the called user. In the route generation step, when the calling user and the called user belong to the same autonomous system network, the area routing key exchange module KEM2-IR within the autonomous system network generates a route from the calling user to the called user. When the calling user and the called user do not belong to the same Autonomous System Network (ASN), the boundary routing key exchange module KEM2-ASBR of the ASN to which the calling user belongs determines the first exit boundary node of the ASN to which the calling user belongs and the second exit boundary node of the ASN to which the called user belongs, and generates a cross-domain route from the first exit boundary node to the second exit boundary node; the area routing key exchange module KEM2-IR of the ASN to which the calling user belongs generates a route from the calling user to the first exit boundary node; the area routing key exchange module KEM2-IR of the ASN to which the called user belongs generates a route from the second exit boundary node to the called user. The autonomous system network is equipped with a local location query server (HLR) and a visitor location query server (VLR). The routing method further includes a user registration step, which includes a sub-step of registering user data with the local location lookup server (HLR) of the user's home autonomous system after the user registers, and a sub-step of registering user data with the visitor location lookup server (VLR) of the local autonomous system after the user moves to another autonomous system, wherein the visitor location lookup server (VLR) informs the user of the new network address of the user's home autonomous system's HLR based on the user data.
2. The routing method as described in claim 1, wherein, The key generation module of the mobile node includes a WCKG component, and the key generation module of the fixed node includes a QKD component.
3. The routing method as described in claim 1, wherein, The autonomous system network is also equipped with a relay key exchange module KEM1 and a user key exchange module KEM3. The relay-type key exchange module KEM1 is only used for key exchange between adjacent nodes; The user-defined key exchange module KEM3 is deployed within the terminal node for unidirectional routing.
4. The routing method as described in claim 1, wherein, The user data includes local usernames and network addresses; The local username includes the domain name information of the autonomous system network to which the user belongs; The fixed node has a unique fixed network address, and the mobile node has a temporary network address.
5. The routing method as described in claim 4, wherein, The fixed network address includes the country name, operator name, regional network name, and node name, while the temporary network address includes the country name, operator name, regional network name, and temporary network code.
6. The routing method as described in claim 1, further comprising a network access configuration step, wherein: When a new node is added to an autonomous system network, a point-to-point bidirectional key pool is established between the key exchange module of the new node and the key exchange modules of the adjacent nodes. When a new autonomous system network (ASN) is added to the key distribution network, a point-to-point bidirectional key pool is established between the boundary routing key exchange module (KEM2-ASBR) of the new ASN and the boundary routing key exchange module (KEM2-ASBR) of the adjacent ASN.
7. The routing method as described in claim 1, wherein, The route generation step includes sub-steps such as key exchange modules exchanging link status with each other or centrally reporting route status, generating network topology information, and generating a routing control table based on the network topology information.
8. The routing method as described in claim 7, wherein, In the route generation step, the weight of each link is dynamically calculated based on the network topology information, and the link used for the key is selected based on the weight.
9. The routing method as described in claim 8, wherein, The weights are related to the key generation rate, key storage, and load of the link.
Citation Information
Patent Citations
DASH-aware network application function (D-NAF)
CN104854835A
Wide-area quantum key distribution routing method and device based on SDN
CN112332984A