A method and apparatus for determining a key supplement critical point, a terminal and a medium
By calculating the average key consumption and replenishment bandwidth to determine the key threshold and dynamically adjusting the key replenishment critical point, the problem of unreasonable and untimely key replenishment in quantum secure networks is solved, thus improving the stability and efficiency of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MATRICTIME DIGITAL TECH CO LTD
- Filing Date
- 2023-12-27
- Publication Date
- 2026-07-21
AI Technical Summary
In existing quantum-safe networks, the key replenishment process suffers from problems such as excessive bandwidth consumption, untimely timing, inefficiency, unevenness, and lack of timeliness, which affect the normal application of quantum-safe terminals and system stability.
By determining the average key consumption traffic and key replenishment bandwidth, calculating the key threshold, and dynamically adjusting the key replenishment critical point, the timing of key replenishment can be reasonably arranged to ensure that the key replenishment process does not occupy application bandwidth and replenishes keys in a timely manner.
It improves the efficiency and flexibility of key replenishment, ensures the normal application of quantum-safe terminals and system stability, and avoids the risks of bandwidth interference and key depletion.
Smart Images

Figure CN117640088B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of information security and quantum encryption technology, and in particular to a method, apparatus, terminal and medium for determining key supplementation critical points. Background Technology
[0002] Current quantum-safe networks can distribute keys to quantum-secure terminals through a key center. In this method, when a quantum-secure terminal detects that its remaining key quantity has reached a preset key replenishment threshold, it can send a replenishment request to the access base station it connects to. Upon receiving the request, the access base station selects a key center according to network policy and requests the key center to allocate a replenishment key, an encryption key, and a key index for the replenishment key. After allocation, the key center sends the encryption key and key index to the access base station, which then sends the encryption key, key index, and key center information to the quantum-secure terminal via quantum encryption. Based on the key center information, the quantum-secure terminal requests to download the encrypted replenishment key from the key center. The key center can then encrypt and distribute the replenishment key to the quantum-secure terminal, thus achieving quantum-encrypted communication between the quantum-secure terminal and the key center.
[0003] The following problems are frequently encountered in the above key distribution methods:
[0004] 1. Inappropriate key replenishment: The process of replenishing the key consumes a large amount of bandwidth of the quantum-safe terminal, affecting the normal application of the quantum-safe terminal by users.
[0005] 2. Inappropriate Key Supplementation: When a user needs key traffic to use an application on a quantum-secure terminal, the key supplementation process competes with that application for bandwidth.
[0006] 3. Inefficient distribution: There may be instances where the bandwidth of quantum-safe terminals is not effectively utilized when it is idle.
[0007] 4. Uneven distribution: The key replenishment request is only initiated when the key reaches the preset key replenishment threshold, resulting in concentrated bandwidth usage.
[0008] 5. Delayed distribution: There may be a situation where the keys in the quantum-safe terminal are exhausted, but subsequent keys have not yet been replenished.
[0009] Given the aforementioned problems, determining the key replenishment threshold becomes particularly important, as it directly affects the stability, security, and efficiency of quantum-safe networks. Therefore, determining a reasonable key replenishment threshold is crucial for ensuring the smooth distribution of scientific keys. Summary of the Invention
[0010] This application provides a method, apparatus, terminal, and medium for determining key replenishment thresholds, thereby ensuring scientific key distribution.
[0011] Firstly, this application provides a method for determining a key replenishment threshold, the method comprising:
[0012] Based on the obtained average key consumption traffic, the target average key consumption traffic is determined, and based on the obtained key replenishment bandwidth, the target key replenishment bandwidth is determined; wherein, the average key consumption traffic is the average key consumption per preset unit of time, and the key replenishment bandwidth is the bandwidth used to replenish the key;
[0013] The product of the average traffic consumption of the target key and the pre-configured key pool capacity is determined, and the quotient of the product and the supplementary bandwidth of the target key is determined as the key threshold.
[0014] Based on the key threshold, a key replenishment threshold is determined, and a supplementary key is determined when the keys in the key pool reach the key replenishment threshold.
[0015] Secondly, this application also provides a device for determining a key replenishment critical point, the device comprising:
[0016] The acquisition unit is used to determine the target key consumption average traffic based on the acquired key consumption average traffic, and to determine the target key supplementation bandwidth based on the acquired key supplementation bandwidth; wherein, the key consumption average traffic is the average key consumption per preset unit of time, and the key supplementation bandwidth is the bandwidth used to supplement the key;
[0017] The processing unit is configured to determine the product of the average traffic consumed by the target key and the pre-configured key pool capacity, and to determine the quotient of the product and the target key supplementation bandwidth as a key threshold; based on the key threshold, to determine a key supplementation critical point, and to determine a supplementary key when the keys in the key pool reach the key supplementation critical point.
[0018] Thirdly, this application also provides a quantum-safe terminal, which includes at least a processor and a memory. The processor is used to execute a computer program stored in the memory to implement the steps of the key supplementation critical point determination method described in the first aspect above.
[0019] Fourthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method for determining the key supplementation critical point as described in the first aspect above.
[0020] Fifthly, this application also provides a computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform the steps of the key supplementation critical point determination method described in the first aspect above.
[0021] The beneficial effects of this application are as follows:
[0022] 1. The key replenishment threshold is determined based on the average key consumption rate and the key replenishment bandwidth. Based on this average key consumption rate, future application key requirements can be accurately predicted. Therefore, the key replenishment threshold can be adjusted based on this average key consumption rate, i.e., the timing of key replenishment, to adapt to changes in actual communication needs and improve key replenishment efficiency. Based on this key replenishment bandwidth, quantum-safe terminals can configure network resources more flexibly, and the key replenishment process will not consume the bandwidth required by applications on the quantum-safe terminal, ensuring that key replenishment does not cause excessive interference to applications on the quantum-safe terminal, improving the performance of the quantum-safe terminal, and enabling effective use of the idle bandwidth for key replenishment.
[0023] 2. By determining the product of the average traffic consumption of the target key and the pre-configured key pool capacity, and using the quotient of this product and the target key replenishment bandwidth as the key threshold, it is possible to effectively ensure that the keys in the key pool within the quantum-safe terminal are replenished before they are exhausted, thus ensuring that the quantum-safe terminal can replenish keys in a timely manner and guaranteeing the stability of the quantum-safe system. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 A schematic diagram illustrating the process of determining a key supplementation critical point provided in an embodiment of this application;
[0026] Figure 2 A schematic diagram illustrating the specific key supplementation critical point determination process provided in this application embodiment;
[0027] Figure 3 A schematic diagram of a key supplementation critical point determination device provided in this application;
[0028] Figure 4 This is a schematic diagram of the structure of a quantum-safe terminal provided in an embodiment of this application. Detailed Implementation
[0029] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0030] In order to determine a reasonable key replenishment threshold and achieve scientific key replenishment, this application provides a method, apparatus, terminal and medium for determining the key replenishment threshold.
[0031] Example 1:
[0032] Figure 1 A schematic diagram illustrating the process of determining a key supplementation critical point provided in this application embodiment, the process including:
[0033] S101: Based on the obtained average key consumption traffic, determine the target average key consumption traffic, and based on the obtained key replenishment bandwidth, determine the target key replenishment bandwidth; wherein, the average key consumption traffic is the average key consumption per preset unit of time, and the key replenishment bandwidth is the bandwidth used to replenish the key.
[0034] In one possible application scenario, the quantum-safe terminal stores a key that can be used for quantum encryption / decryption, quantum hash verification, etc. To ensure the security of quantum-safe communication, the key stored in the quantum-safe terminal is only used once and discarded after use, resulting in a decreasing number of unused keys in the quantum-safe terminal. Therefore, the quantum-safe terminal needs to replenish keys in a timely manner to ensure the stable operation and security of the entire quantum-safe system. To effectively manage key replenishment, this application provides a method for determining the key replenishment critical point. This method is applied to a quantum-safe terminal, which can be a quantum-safe user-end device, such as a global quantum-safe device or an isolation zone device, or a quantum-safe non-user-end device, such as an application server or a security server. The aim is to achieve dynamic management of key replenishment timing by reasonably estimating the key replenishment critical point, thereby improving the security and efficiency of the quantum-safe system.
[0035] When a quantum-safe terminal replenishes its keys, the applications running on that terminal still need to function normally. However, the key replenishment process may consume a significant amount of bandwidth on the quantum-safe terminal, affecting the normal operation of applications and leading to unreasonable and untimely key replenishment. Therefore, in this application, the quantum-safe terminal can collect key consumption data within a preset duration, determine the average key consumption within each preset unit of time (denoted as average key consumption flow for ease of description), and more accurately predict future application key requirements based on this average key consumption flow. Furthermore, it can adjust the key replenishment threshold based on this average key consumption flow, i.e., adjust the timing of key replenishment to adapt to changes in actual communication needs and improve key replenishment efficiency. The preset duration is greater than or equal to the preset unit of time, which can be seconds or minutes, without specific limitations. For example, the quantum-safe terminal can monitor the total key consumption within the preset duration through an installed encryption system. Then, the quantum-safe terminal converts the preset duration into a target duration of the same unit of time, and divides the total consumption by the target duration to obtain the average key consumption flow.
[0036] For example, if the preset duration is t minutes and the preset unit duration is 1 second, the target duration converted to the same unit duration is t*60 seconds. If the total key consumption within the preset duration is C(t), then the average key consumption rate Q is... avg It can be determined using the following formula:
[0037] Q avg = C(t) / (t*60) seconds
[0038] In one example, after determining the average key consumption flow based on the above embodiments, the average key consumption flow can be determined as the target average key consumption flow, and then the key replenishment threshold can be determined based on the target average key consumption flow.
[0039] In another example, considering the potential surge in application traffic in practical applications, this application increases the average key consumption traffic to a certain extent. The target average key consumption traffic is then determined based on this increased average key consumption traffic. This allows the quantum-safe terminal to better adapt to such sudden increases in demand, ensuring that key replenishment does not affect the normal operation of the quantum-safe terminal and improving the robustness of key replenishment.
[0040] In one possible implementation, the average key consumption is increased to a certain extent, and the target average key consumption is determined based on the increased average key consumption, including the following methods:
[0041] Method 1: The target key consumption average traffic is determined by summing the average traffic consumption of the key with any value in a pre-configured upward adjustment range; wherein, all values in the upward adjustment range are greater than 0 and less than 1.
[0042] In this application, an upward adjustment range can be pre-configured, where all values are greater than 0 and less than 1. For example, the upward adjustment range can be (0, 1), (0.1, 0.9), or (0.2, 0.5), etc. The specific setting of this upward adjustment range can be flexibly configured according to actual needs, and no specific limitation is made here. After determining the average key consumption flow based on the above embodiments, any value can be randomly selected from the pre-configured upward adjustment range, and then the sum of this value and the average key consumption flow is determined as the target average key consumption flow.
[0043] Method 2: If the average key consumption is not an integer, then the value of the average key consumption rounded up is determined as the target average key consumption.
[0044] In this application, the average key consumption may not be an integer. Therefore, the average key consumption can be rounded up to determine the target average key consumption.
[0045] Considering that the key replenishment process consumes a significant amount of bandwidth, which can affect the normal operation of applications on the quantum-safe terminal, and that there may be situations where the bandwidth of the quantum-safe terminal is idle and not effectively utilized, this application proposes that the quantum-safe terminal can also determine a key replenishment threshold based on the key replenishment bandwidth. This allows the quantum-safe terminal to configure network resources more flexibly, ensuring that key replenishment does not cause excessive interference to applications on the quantum-safe terminal, thereby improving the performance of the quantum-safe terminal. For example, the quantum-safe terminal can obtain ciphertext traffic within a preset duration through an installed encryption system, then determine the ciphertext traffic within a preset unit duration (denoted as the ciphertext traffic bandwidth) based on the ciphertext traffic. The key replenishment bandwidth is then determined based on the difference between the preset maximum bandwidth and the ciphertext traffic bandwidth.
[0046] In another example, obtaining the key supplemental bandwidth includes:
[0047] Obtain the maximum bandwidth and encrypted traffic bandwidth of the network interface;
[0048] The difference between the maximum quantum-safe bandwidth and the ciphertext flow bandwidth is determined as the key supplement bandwidth.
[0049] In this application, the quantum-secure terminal can also collect the maximum bandwidth monitored by the network interface card (referred to as the maximum bandwidth monitored by the network port) and the ciphertext traffic monitored by the encryption system installed on the quantum-secure terminal within a preset duration. Then, the quantum-secure terminal converts the preset duration into a target duration of the same unit as the preset duration, and divides the ciphertext traffic by the target duration to obtain the ciphertext traffic bandwidth. The quantum-secure terminal subtracts the maximum bandwidth monitored by the network port from the ciphertext traffic bandwidth to obtain a bandwidth difference value. This difference value represents the remaining bandwidth of the network under the current conditions, i.e., the bandwidth not occupied by ciphertext traffic. This remaining bandwidth is the bandwidth that can be used for key replenishment without affecting the normal use of the application.
[0050] For example, if the preset duration is t minutes and the preset unit duration is 1 second, the target duration converted to the same unit duration is t*60 seconds. If the encrypted traffic within the preset duration is Q(t), then the encrypted traffic bandwidth K avg It can be determined using the following formula:
[0051]
[0052] In one example, after determining the key supplementation bandwidth based on the above embodiments, the key supplementation bandwidth can be determined as the target key supplementation bandwidth, and then the key supplementation threshold can be determined based on the target key supplementation bandwidth.
[0053] In another example, considering the potential surge in application traffic in practical applications, this application reduces the ciphertext traffic bandwidth to a certain extent. The target key replenishment bandwidth is then determined based on this reduced bandwidth. This allows the quantum-safe terminal to better adapt to such sudden increases in demand, ensuring that the bandwidth used for key replenishment does not consume the bandwidth required for application use. In other words, key replenishment does not affect the normal operation of the quantum-safe terminal, thus improving the robustness of key replenishment in this quantum-safe terminal.
[0054] In one possible implementation, the ciphertext traffic bandwidth is reduced to a certain extent, and the target key supplementary bandwidth is determined based on the reduced ciphertext traffic bandwidth in the following ways:
[0055] Method A: Determine the target key supplement bandwidth by the difference between the key supplement bandwidth and any value in a pre-configured downward adjustment range; wherein, all values in the downward adjustment range are greater than 0 and less than the key supplement bandwidth.
[0056] In this application, a downward adjustment range can be pre-configured, where all values within this range are greater than 0 and less than the currently determined key supplement bandwidth. For example, the upward adjustment range can be (0, key supplement bandwidth), (0.1, key supplement bandwidth), or (0.5, key supplement bandwidth), etc. The specific setting of this downward adjustment range can be flexibly configured according to actual needs, and no specific limitation is made here. After determining the key supplement bandwidth based on the above embodiments, any value can be randomly selected from the pre-configured downward adjustment range, and the difference between the key supplement bandwidth and the selected value is determined as the target key supplement bandwidth.
[0057] Method B involves rounding up the ciphertext traffic bandwidth to reduce the bandwidth by adjusting the key.
[0058] Since the more bandwidth the application requires, the less bandwidth is needed for key supplementation, this application allows for an upward adjustment of the ciphertext traffic bandwidth after it has been obtained. For example, the ciphertext traffic bandwidth can be increased using a method similar to the key consumption average traffic increase method described in the previous embodiment. Conversely, the key supplementation bandwidth, determined by the difference between the maximum network interface monitoring bandwidth and the ciphertext traffic bandwidth, can be reduced to a certain extent if the ciphertext traffic bandwidth increases while the maximum network interface monitoring bandwidth remains unchanged.
[0059] For example, after obtaining the encrypted traffic bandwidth, if the encrypted traffic bandwidth is not an integer, the quantum secure terminal rounds the encrypted traffic bandwidth up. Then, it determines the key supplement bandwidth by taking the difference between the maximum bandwidth monitored by the network port and the adjusted encrypted traffic bandwidth, i.e., it determines the adjusted key supplement bandwidth. The quantum secure terminal can then determine this key supplement bandwidth as the target key supplement bandwidth.
[0060] S102: Determine the product of the average traffic consumed by the target key and the pre-configured key pool capacity, and determine the key threshold based on the quotient of the product and the supplementary bandwidth of the target key.
[0061] Once the average flow rate of the target key is determined based on the above embodiments, the quantum secure terminal can obtain the product of the average flow rate of the target key and the pre-configured key pool capacity, and then determine the quotient of the product and the target key supplementary bandwidth, and determine the determined quotient as the key threshold.
[0062] In one example, the key threshold can be determined by the following formula:
[0063] Z m =Q max *Q / K
[0064] Among them, Z m Characterizing the key threshold, Qmax Q represents the pre-configured key pool capacity, Q represents the average traffic consumed by the target key, and K represents the target key supplemental bandwidth.
[0065] For example, this key threshold determination method can be derived using the following formula:
[0066] Assume the key pool capacity of the quantum-safe terminal is Q. max The initial key threshold is Q1, meaning that key replenishment occurs when the remaining key quantity reaches Q1, and the key replenishment bandwidth is K. avg The average flow rate consumed by the ciphertext is Q. avg .
[0067] Initial key replenishment: Δ1 = Q max -Q1;
[0068] After replenishing Δ1, the quantum-safe terminal suffers further losses: Δ2 = Δ1 / K avg *Q avg ;
[0069] After replenishing Δ2, the quantum-safe terminal suffers further losses: Δ3 = Δ2 / K avg *Q avg ; ......
[0071] Following this logic, after replenishing Δ(n-1), the quantum-safe terminal suffers a loss: Δn = Δ(n-1) / K avg *Q avg ;
[0072] In the above scenario, for key replenishment to support key consumption by a quantum-safe terminal, the following two conditions must be met:
[0073] Condition 1: Δ1>Δ2>Δ3>……>Δn, where Δn is a positive number approaching 0;
[0074] Condition 2: Δ1+Δ2+Δ3+……+Δn max ;
[0075] K can be derived from condition 1. avg Q avg And combining the above expressions for Δ1 to Δn, condition 2 can be expressed as:
[0076] Q max -Q1+Δ1 / K avg *Q avg +Δ2 / K avg *Q avg +…+Δ(n-1) / K avg *Q avg max
[0077] => Δ1 / K avg *Q avg +Δ2 / K avg *Q avg +…+Δ(n-1) / K avg *Q avg <Q1
[0078] => Δ1 + Δ2 + ... + Δ(n-1) <Q1*K avg / Q avg
[0079] => Δ1 + Δ2 + ... + Δ(n-1) + Δn <Q1*K avg / Q avg +Δn
[0080] According to the inequality principle, if Q1*K avg / Q avg +Δn max Then it must exist that: Δ1 + Δ2 + Δ3 + ... + Δn max Furthermore, if Q1*K avg / Q avg +Δn max Then it must exist that: Q1*K avg / Q avg max Since Δn is a positive number approaching 0, Q1 can be derived. max *Q avg / K avg .
[0081] At the same time, according to condition 1: K avg Q avg It can also be seen that Q avg / 1<1, that is, Q max Q1 also aligns with business logic.
[0082] Therefore, it can be deduced that when the key is just exhausted, Q... max *Q avg / K avg =Q1 is the critical replenishment point.
[0083] The average key consumption Q was calculated based on the communication status of the quantum-secure terminal. avg and key supplement bandwidth K avg Then the key threshold can be calculated. Let's assume the key threshold is Z. m The formula for determining the key threshold is:
[0084] Z m =Q max *Q avg / K avg
[0085] S103: Based on the key threshold, determine the key replenishment threshold, and when the keys in the key pool reach the key replenishment threshold, determine the replenishment key.
[0086] After determining the key threshold based on the above embodiments, the quantum-secure terminal can determine the key replenishment threshold based on the key threshold. Subsequently, the quantum-secure terminal can determine whether the keys in the current key pool have reached the key replenishment threshold, thereby determining whether key replenishment is needed. When the quantum-secure terminal determines that the keys in the current key pool have reached the key replenishment threshold, it determines the key to replenish; when the quantum-secure terminal determines that the keys in the current key pool have not reached the key replenishment threshold, it continues to monitor whether the keys in the key pool have reached the key replenishment threshold.
[0087] In one example, the quantum-safe terminal can directly determine the key threshold as the key replenishment critical point.
[0088] In another example, the quantum-secure terminal can also increase the key threshold to a certain extent, and determine the increased key threshold as the key replenishment threshold, thereby achieving early and gradual key replenishment. For example, the key threshold rounded up can be used as the key replenishment threshold.
[0089] In one example, the quantum-safe terminal is also configured with update conditions, which can be preset periods, preset time points, received update control commands, etc. Once the quantum-safe terminal determines a key replenishment threshold, it can redetermine the threshold according to the preset update conditions and guide key replenishment based on this newly determined threshold. This involves updating the previously determined threshold, thereby enabling real-time dynamic adjustment of the key replenishment threshold based on the quantum-safe terminal's bandwidth utilization. Consequently, the key replenishment process based on this threshold does not interfere with the normal operation of applications on the quantum-safe terminal.
[0090] The beneficial effects of this application are as follows:
[0091] 1. The key replenishment threshold is determined based on the average key consumption rate and the key replenishment bandwidth. Based on this average key consumption rate, future application key requirements can be accurately predicted. Therefore, the key replenishment threshold can be adjusted based on this average key consumption rate, i.e., the timing of key replenishment, to adapt to changes in actual communication needs and improve key replenishment efficiency. Based on this key replenishment bandwidth, quantum-safe terminals can configure network resources more flexibly, and the key replenishment process will not consume the bandwidth required by applications on the quantum-safe terminal, ensuring that key replenishment does not cause excessive interference to applications on the quantum-safe terminal, improving the performance of the quantum-safe terminal, and enabling effective use of the idle bandwidth for key replenishment.
[0092] 2. By determining the product of the average traffic consumption of the target key and the pre-configured key pool capacity, and using the quotient of this product and the target key replenishment bandwidth as the key threshold, it is possible to effectively ensure that the keys in the key pool within the quantum-safe terminal are replenished before they are exhausted, thus ensuring that the quantum-safe terminal can replenish keys in a timely manner and guaranteeing the stability of the quantum-safe system.
[0093] Example 2:
[0094] The method for determining the key supplementation critical point provided in this application is illustrated below through specific embodiments. Figure 2 A schematic diagram illustrating the specific key supplementation critical point determination process provided in this application embodiment is shown. The process includes:
[0095] S201: Acquiring the key consumes average traffic.
[0096] S202: If the average key consumption is not an integer, then the value of the average key consumption rounded up is determined as the target average key consumption.
[0097] S203: Obtain the maximum bandwidth of the network port monitoring and the bandwidth of encrypted traffic.
[0098] S204: If the ciphertext traffic bandwidth is not an integer, then round up the ciphertext traffic bandwidth.
[0099] S205: The difference between the maximum bandwidth of the network port monitoring and the bandwidth of the encrypted traffic is determined as the key supplement bandwidth.
[0100] S206: Determine the supplementary bandwidth of this key as the target supplementary bandwidth.
[0101] It should be noted that the execution order between S201~S202 and S203~S206 can be either S201~S202 executed first and then S203~S206 executed, or S203~S206 executed first and then S201~S202 executed, or S201~S202 and S203~S206 executed simultaneously. No specific restrictions are imposed here.
[0102] S207: Determine the product of the average traffic consumed by the target key and the pre-configured key pool capacity, and determine the quotient of the product and the target key supplementary bandwidth as the key threshold.
[0103] S208: Determine the key threshold as the key replenishment critical point.
[0104] S209: Determine whether the preset update conditions are met. If yes, execute S201; otherwise, execute S209.
[0105] Example 3:
[0106] Based on the same inventive concept, this application also provides a device for determining the key replenishment critical point. Figure 3 A schematic diagram of a key supplementation critical point determination device provided in this application is provided. The device includes:
[0107] The acquisition unit 31 is used to determine the target key consumption average traffic based on the acquired key consumption average traffic, and to determine the target key supplement bandwidth based on the acquired key supplement bandwidth; wherein, the key consumption average traffic is the average key consumption per preset unit of time, and the key supplement bandwidth is the bandwidth used to supplement the key;
[0108] Processing unit 32 is configured to determine the product of the average traffic consumed by the target key and the pre-configured key pool capacity, and to determine the quotient of the product and the target key supplementation bandwidth as a key threshold; based on the key threshold, to determine a key supplementation critical point, and to determine a supplementary key when the keys in the key pool reach the key supplementation critical point.
[0109] It should be noted that the principle of the key supplementation critical point determination device provided in this embodiment to solve the technical problem is the same as the principle of the technical problem to solve the technical problem in the above method embodiment, and the repeated parts will not be described again.
[0110] Example 4:
[0111] Based on the above embodiments, this application also provides a quantum-safe terminal. Figure 4 This is a schematic diagram of the structure of a quantum-safe terminal provided in an embodiment of this application, as shown below. Figure 4As shown, it includes: processor 41, communication interface 42, memory 43 and communication bus 44, wherein processor 41, communication interface 42 and memory 43 communicate with each other through communication bus 44.
[0112] The memory 43 stores a computer program, which, when executed by the processor 41, causes the processor 41 to perform the following steps:
[0113] Based on the obtained average key consumption traffic, the target average key consumption traffic is determined, and based on the obtained key replenishment bandwidth, the target key replenishment bandwidth is determined; wherein, the average key consumption traffic is the average key consumption per preset unit of time, and the key replenishment bandwidth is the bandwidth used to replenish the key;
[0114] The product of the average traffic consumption of the target key and the pre-configured key pool capacity is determined, and the quotient of the product and the supplementary bandwidth of the target key is determined as the key threshold.
[0115] Based on the key threshold, a key replenishment threshold is determined, and a supplementary key is determined when the keys in the key pool reach the key replenishment threshold.
[0116] Since the principle of solving the problem by the above-mentioned quantum secure terminal is similar to the method for determining the key supplementation critical point, the implementation of the above-mentioned quantum secure terminal can be found in the embodiments of the method, and repeated details will not be repeated.
[0117] Example 5:
[0118] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program executable by a processor. When the program runs on the processor, it causes the processor to perform the following steps:
[0119] Based on the obtained average key consumption traffic, the target average key consumption traffic is determined, and based on the obtained key replenishment bandwidth, the target key replenishment bandwidth is determined; wherein, the average key consumption traffic is the average key consumption per preset unit of time, and the key replenishment bandwidth is the bandwidth used to replenish the key;
[0120] The product of the average traffic consumption of the target key and the pre-configured key pool capacity is determined, and the quotient of the product and the supplementary bandwidth of the target key is determined as the key threshold.
[0121] Based on the key threshold, a key replenishment threshold is determined, and a supplementary key is determined when the keys in the key pool reach the key replenishment threshold.
[0122] Since the principle of the computer-readable storage medium in solving the problem is similar to the method for determining the key supplementation critical point, the implementation of the computer-readable storage medium can be found in the embodiments of the method, and repeated details will not be repeated.
Claims
1. A method for determining a key replenishment critical point, characterized in that, The method includes: Based on the obtained average key consumption traffic, the target average key consumption traffic is determined, and based on the obtained key replenishment bandwidth, the target key replenishment bandwidth is determined; wherein, the average key consumption traffic is the average key consumption per preset unit of time, and the key replenishment bandwidth is the bandwidth used to replenish the key; The product of the average traffic consumption of the target key and the pre-configured key pool capacity is determined, and the quotient of the product and the supplementary bandwidth of the target key is determined as the key threshold. Based on the key threshold, a key replenishment threshold is determined, and when the keys in the key pool reach the key replenishment threshold, a supplementary key is determined. The step of determining the target key's average traffic consumption based on the acquired key's average traffic consumption includes: The target average key consumption is determined by summing the average key consumption with any value within a pre-configured upward adjustment range; wherein all values within the upward adjustment range are greater than 0 and less than 1; or If the average key consumption is not an integer, then the value of the average key consumption rounded up is determined as the target average key consumption. Obtaining the key supplemental bandwidth includes: Obtain the maximum bandwidth and encrypted traffic bandwidth of the network interface; The difference between the maximum bandwidth of the network port monitoring and the bandwidth of the ciphertext traffic is determined as the key supplement bandwidth; The step of determining the key replenishment threshold based on the key threshold includes: The value of the key threshold rounded up is determined as the key supplementation critical point.
2. The method as described in claim 1, characterized in that, After obtaining the ciphertext traffic bandwidth, before determining the difference between the maximum bandwidth monitored by the network interface and the ciphertext traffic bandwidth as the key supplement bandwidth, the method further includes: If the encrypted traffic bandwidth is not an integer, then the encrypted traffic bandwidth is rounded up.
3. The method as described in claim 1, characterized in that, The determination of the target key supplement bandwidth based on the acquired key supplement bandwidth includes: The target key supplement bandwidth is determined by the difference between the key supplement bandwidth and any value in a pre-configured downward adjustment range; wherein all values in the downward adjustment range are greater than 0 and less than the key supplement bandwidth.
4. The method as described in claim 1, characterized in that, The method further includes: According to preset update conditions, the key replenishment critical point is redefined and updated; the update conditions are a preset period, a preset time point, or the receipt of an update control command.
5. A device for determining a key supplementation critical point, characterized in that, The device includes: The acquisition unit is used to determine the target key consumption average traffic based on the acquired key consumption average traffic, and to determine the target key supplementation bandwidth based on the acquired key supplementation bandwidth; wherein, the key consumption average traffic is the average key consumption per preset unit of time, and the key supplementation bandwidth is the bandwidth used to supplement the key; The step of determining the target key consumption average based on the obtained key consumption average traffic includes: The target average key consumption is determined by summing the average key consumption with any value within a pre-configured upward adjustment range; wherein all values within the upward adjustment range are greater than 0 and less than 1; or If the average key consumption is not an integer, then the value of the average key consumption rounded up is determined as the target average key consumption. Obtaining the key supplemental bandwidth includes: Obtain the maximum bandwidth and encrypted traffic bandwidth of the network interface; The difference between the maximum bandwidth of the network port monitoring and the bandwidth of the ciphertext traffic is determined as the key supplement bandwidth; The determination of the target key supplement bandwidth based on the acquired key supplement bandwidth includes: The target key supplement bandwidth is determined by the difference between the key supplement bandwidth and any value in a pre-configured downward adjustment range; wherein, all values in the downward adjustment range are greater than 0 and less than the key supplement bandwidth. The processing unit is configured to determine the product of the average traffic consumption of the target key and the pre-configured key pool capacity, and to determine the quotient of the product and the target key supplementation bandwidth as a key threshold; based on the key threshold, to determine a key supplementation critical point, and to determine a supplementary key when the keys in the key pool reach the key supplementation critical point; The step of determining the key replenishment threshold based on the key threshold includes: The value of the key threshold rounded up is determined as the key supplementation critical point.
6. A quantum-safe terminal, characterized in that, The quantum-safe terminal includes at least a processor and a memory, wherein the processor is used to execute a computer program stored in the memory to implement the steps of the method for determining the key supplementation critical point as described in any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the method for determining the key supplementation critical point as described in any one of claims 1-4.