A quantum secure network key distribution flow control method and device
Patent Information
- Application Number
- CN202311791520.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-25
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-12-25
AI Technical Summary
[0004]1、分发不均衡:由于某些受钥方获取密钥速度较快,而其他受钥方却较慢,从而导致密钥分发不均衡
[0020]1. Because the target distribution bandwidth is determined based on the recipient's instantaneous distribution bandwidth and the sender's available bandwidth, the sender can monitor network bandwidth usage in real time. This real-time capability helps the sender adjust its distribution strategy promptly to adapt to changes in network load. Furthermore, the sender adjusts bandwidth based on the recipient's instantaneous distribution bandwidth, meaning it adjusts bandwidth based on real-time data. This gives the key distribution system a degree of adaptability, enabling it to adapt to changes in the network environment and ensuring stable key distribution services for the recipient under various conditions.
Smart Images

Figure CN117792627B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of information security and quantum encryption technology, and in particular to a quantum-secure network key distribution flow control method and apparatus. Background Technology
[0002] Current quantum-secure networks can distribute keys to key recipients via a key issuer. In this method, when the key recipient discovers that the remaining key quantity has reached a preset key replenishment threshold, it can send a replenishment request to the access base station it is connected to. Upon receiving the replenishment request, the access base station selects a key issuer according to network policy and requests that the key issuer allocate a replenishment key, an encryption key, and a key index for the replenishment key. After the key issuer completes the allocation, it sends the encryption key and key index to the access base station, which then sends the encryption key, key index, and key issuer information to the key recipient via quantum encryption. Based on the key issuer information, the key recipient requests to download the encrypted replenishment key from the key issuer. The key issuer can then use this encrypted key to encrypt and distribute the replenishment key to the key recipient, thus achieving quantum-encrypted communication between the key recipient and the key issuer.
[0003] In the aforementioned key distribution method, distributing the key from the key sender to the key receiver is the core step in ensuring quantum-secure communication. However, during this process, due to differences in distribution speed and uneven requests among key receivers, the key sender may face a series of problems, including:
[0004] 1. Uneven distribution: Because some key recipients obtain keys faster than others, the distribution of keys is uneven.
[0005] 2. Unfair distribution: The key recipient who requests a supplementary key first occupies a large amount of the key sender's bandwidth, causing key recipients who request a supplementary key later to have to wait in line.
[0006] 3. Improper distribution: The process of supplementing the key consumes a large amount of the key recipient's bandwidth, affecting the normal application of the key recipient by users.
[0007] 4. Inefficient distribution: The bandwidth of the key recipient may be idle and not effectively utilized.
[0008] In conclusion, the importance of flow control by the key issuer in key distribution lies not only in ensuring the effective distribution of scientific keys, but also in the stability, performance, and user experience of the entire quantum secure network. Therefore, how the key issuer implements flow control in key distribution is crucial to guaranteeing the distribution of scientific keys. Summary of the Invention
[0009] This application provides a quantum-safe network key distribution flow control method and apparatus to achieve efficient and stable key distribution to the key recipient, and to avoid key distribution affecting the normal use of applications on the key recipient.
[0010] In a first aspect, this application provides a flow control method for key distribution in a quantum-safe network, the method comprising:
[0011] Obtain the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender;
[0012] The target distribution bandwidth for the key recipient is determined based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0013] Secondly, this application provides a quantum-secure network key distribution flow control device, the device comprising:
[0014] The acquisition unit is used to acquire the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender.
[0015] The processing unit is configured to determine the target distribution bandwidth for the key recipient in this instance based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0016] Thirdly, this application also provides a key issuer, which includes at least a processor and a memory, wherein the processor is used to execute a computer program stored in the memory to implement the steps of the quantum secure network key distribution flow control method as described in the first aspect above.
[0017] Fourthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the quantum-safe network key distribution flow control method described in the first aspect above.
[0018] Fifthly, this application also provides a computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform the steps of the quantum secure network key distribution flow control method described in the first aspect above.
[0019] The beneficial effects of this application are as follows:
[0020] 1. Because the target distribution bandwidth is determined based on the recipient's instantaneous distribution bandwidth and the sender's available bandwidth, the sender can monitor network bandwidth usage in real time. This real-time capability helps the sender adjust its distribution strategy promptly to adapt to changes in network load. Furthermore, the sender adjusts bandwidth based on the recipient's instantaneous distribution bandwidth, meaning it adjusts bandwidth based on real-time data. This gives the key distribution system a degree of adaptability, enabling it to adapt to changes in the network environment and ensuring stable key distribution services for the recipient under various conditions.
[0021] 2. By acquiring the bandwidth of the key recipient and the key sender, the excessive use of the key recipient's network resources during the key distribution process can be avoided, preventing network congestion during key transmission that could affect the normal use of applications on the key recipient, and ensuring the performance of the key recipient and the reliability of key distribution.
[0022] 3. By comparing the minimum instantaneous distribution bandwidth of the key recipient with the minimum available bandwidth of the key sender, the key sender can determine a suitable target distribution bandwidth. This helps to balance bandwidth utilization between the key sender and the key recipient, and improve the efficiency of key distribution.
[0023] 4. Different key recipients have different instantaneous distribution bandwidths, which means that the target distribution bandwidth determined for different key recipients is also different. This is beneficial for providing a suitable target distribution bandwidth for each key recipient based on their performance, thereby meeting the needs of different key recipients, ensuring that the key distribution of different key recipients is balanced, and avoiding unfair distribution problems caused by performance differences between different key recipients. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 A schematic diagram of a flow control process for key distribution in a quantum-safe network is provided as an embodiment of this application;
[0026] Figure 2 A schematic diagram illustrating the flow control process for key distribution in a quantum-secure network, provided for embodiments of this application;
[0027] Figure 3 A schematic diagram of a quantum-safe network key distribution flow control device provided in this application;
[0028] Figure 4 This is a schematic diagram of the structure of a key issuer provided in an embodiment of this application. Detailed Implementation
[0029] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0030] In order to achieve efficient and stable key distribution to the key recipient, and to avoid key distribution affecting the normal use of applications on the key recipient, this application provides a quantum-safe network key distribution flow control method and apparatus.
[0031] Example 1:
[0032] Figure 1 This application provides a schematic diagram of a flow control process for key distribution in a quantum-safe network, which includes:
[0033] S101: Obtain the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender.
[0034] The quantum-safe network key distribution flow control method provided in this application is applied to the key issuer, which can generate and distribute keys for at least one key recipient. Considering that when the key issuer actually distributes keys to each key recipient, some recipients may acquire keys faster than others, leading to uneven key distribution; or, key recipients requesting supplementary keys first may consume a large amount of the key issuer's bandwidth, causing subsequent requesters to queue; or, the process of supplementing keys may consume a large amount of the key recipient's bandwidth, affecting the normal application use of that key recipient, etc., the key issuer cannot efficiently and stably distribute keys to each key recipient. Therefore, the key issuer can dynamically adjust the bandwidth for key distribution to each key recipient based on their network conditions to ensure efficient and stable key distribution and avoid key distribution affecting the normal use of applications on the key recipients. For example, for a given key recipient, the key issuer can obtain the recipient's instantaneous distribution bandwidth and the issuer's current available bandwidth. This instantaneous distribution bandwidth and the issuer's available bandwidth are then processed to determine the target distribution bandwidth for distributing keys to the recipient. The instantaneous distribution bandwidth refers to the bandwidth the recipient uses to replenish keys at a given moment; it reflects the recipient's real-time key replenishment capability at that instant, corresponding to the network's instantaneous demand. The instantaneous distribution bandwidth obtained for the recipient typically changes over time. Available bandwidth refers to the bandwidth that the key issuer can utilize to distribute keys to the recipient. Determining this available bandwidth requires consideration of network resource limitations and other possible contention.
[0035] The instantaneous distribution bandwidth of the key recipient in this instance can be reported by the key recipient, for example, when the key recipient requests to download the key from the key issuer, or it can be determined by the key issuer based on the data reported by the key recipient to determine the instantaneous distribution bandwidth, for example, when the key recipient requests to download the key from the key issuer periodically. No specific limitation is made here.
[0036] In one possible implementation, the instantaneous distribution bandwidth is determined by the difference between the maximum bandwidth of the key recipient in this instance and the ciphertext traffic of the key recipient in this instance; wherein, the maximum bandwidth is the maximum bandwidth of the key recipient during the communication process after power-on.
[0037] When a key recipient conducts quantum encrypted communication based on an existing key (pre-set or previously supplemented key), it continuously learns its maximum bandwidth and ciphertext traffic during this communication process. The maximum bandwidth includes the bandwidth required for ciphertext transmission and the bandwidth required for key relay. This maximum bandwidth reveals the key recipient's network bandwidth capability. Since the key recipient's network bandwidth capability is determined by the network line, service provider, and the key recipient's terminal, its actual communication capability is determined by the combination of these three factors. By analyzing the ciphertext traffic, future application key requirements can be predicted more accurately, allowing the key recipient to configure network resources more flexibly. This ensures that key supplementation does not excessively interfere with applications on the key recipient's network, improving performance. The ciphertext traffic acquired by the key recipient typically changes over time. Based on the difference between the key recipient's current maximum bandwidth and current ciphertext traffic, the instantaneous distribution bandwidth can be determined, thus determining the key recipient's current key acquisition efficiency.
[0038] In one example, the instantaneous average bandwidth distribution can be determined by the following formula:
[0039] B s =TB max -Q s
[0040] Among them, B s The instantaneous distribution bandwidth, in TB. max Q represents the maximum bandwidth in this operation. s This represents the encrypted traffic volume.
[0041] Taking the instantaneous distribution bandwidth reported by the key recipient to the key issuer as an example, the key recipient can monitor its bandwidth since the current power-on (including the bandwidth required for ciphertext transmission and the bandwidth required for key relay) through the network interface. It can then determine the maximum bandwidth from the monitored bandwidth and monitor the current ciphertext traffic through the same network interface. After obtaining its maximum bandwidth and ciphertext traffic, the key recipient can determine the difference between the maximum bandwidth and the ciphertext traffic, using this difference as its instantaneous distribution bandwidth, and then report this instantaneous distribution bandwidth to the key issuer.
[0042] Taking the example of the key issuer determining the instantaneous distribution bandwidth based on the data reported by the key recipient for determining the instantaneous distribution bandwidth, after the key recipient obtains the maximum bandwidth and the encrypted traffic of the key recipient based on the above embodiment, it can report the maximum bandwidth and the encrypted traffic of the key recipient to the key issuer. After receiving the maximum bandwidth and the encrypted traffic of the key recipient, the key issuer can determine the difference between the maximum bandwidth and the encrypted traffic, and use the determined difference as the instantaneous distribution bandwidth of the key recipient.
[0043] For example, the key recipient can report its maximum bandwidth, average key consumption traffic, and ciphertext traffic to the key issuer. If the key issuer has triple information including the maximum bandwidth, average key consumption traffic, and ciphertext traffic, it can determine the average distribution bandwidth and instantaneous distribution bandwidth of the key recipient based on the received maximum bandwidth, average key consumption traffic, and ciphertext traffic, using the method described in the above embodiments.
[0044] It should be noted that because communication traffic is not constant, the maximum bandwidth must not be less than the encrypted traffic.
[0045] In one possible implementation, the available bandwidth is determined by the quotient of the key issuer's planned bandwidth and the actual number of key recipients downloading concurrently.
[0046] For the key issuer, the planned bandwidth during construction is known to be W. max The maximum number of key recipients that can be downloaded concurrently is N. m Then the planned theoretical bandwidth B of the key sender is a key receiver. m =W max / N max The actual number of key recipients downloading concurrently is N, which is less than N0. max If so, then the available bandwidth of the key recipient can actually be planned to be B. 可用 =W max / N.
[0047] It should be noted that when planning the network for the key issuer, the average key consumption traffic of different key recipients needs to be comprehensively considered to plan the theoretical bandwidth, ensuring that the theoretical bandwidth is greater than the average key consumption traffic of different key recipients. Here, the average key consumption traffic is the average key consumption per preset unit of time by the key recipient.
[0048] In one possible implementation, for a higher-priority key recipient, such as a VIP key recipient, the available bandwidth of that key recipient can be B. vip B vip A pre-planned fixed available bandwidth, greater than the available bandwidth of the lower-priority key recipient, is used to ensure that the available bandwidth for the higher-priority key recipient to download the key from the key issuer is stable.
[0049] S102: Determine the target distribution bandwidth for the key recipient this time based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0050] After obtaining the instantaneous distribution bandwidth and available bandwidth based on the above embodiments, the key issuer can process the instantaneous distribution bandwidth and available bandwidth accordingly to determine the target distribution bandwidth for distributing the key to the key recipient. For example, the target distribution bandwidth can be determined based on the relationship between the instantaneous distribution bandwidth and available bandwidth, thereby enabling the key issuer to fully consider the performance of the key recipient and dynamically adjust the target distribution bandwidth when distributing the key to the key recipient, thus responding to network changes.
[0051] In one example, the key issuer can compare the available bandwidth with the instantaneous distribution bandwidth to determine their relative strengths. If the available bandwidth is greater than the instantaneous distribution bandwidth, it means the key issuer's distribution capacity fully meets the key recipient's needs. The key issuer only needs to consider the key recipient's network conditions, and can then determine the target distribution bandwidth based on the key recipient's instantaneous distribution bandwidth. If the available bandwidth is less than the instantaneous distribution bandwidth, it means the key issuer's distribution capacity cannot fully meet the key recipient's needs. In this case, the key issuer can determine the target distribution bandwidth based on the key recipient's available bandwidth. In other words, the target distribution bandwidth for the key recipient is determined based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0052] For example, if the available bandwidth is greater than the instantaneous distribution bandwidth, it means that the key recipient is currently in an idle state. In this case, the key sender can determine the instantaneous distribution bandwidth as the target distribution bandwidth, that is, use a smaller bandwidth to distribute the key, thereby making use of the idle time of this quantum-safe state to distribute the key as quickly as possible.
[0053] The beneficial effects of this application are as follows:
[0054] 1. Because the target distribution bandwidth is determined based on the recipient's instantaneous distribution bandwidth and the sender's available bandwidth, the sender can monitor network bandwidth usage in real time. This real-time capability helps the sender adjust its distribution strategy promptly to adapt to changes in network load. Furthermore, the sender adjusts bandwidth based on the recipient's instantaneous distribution bandwidth, meaning it adjusts bandwidth based on real-time data. This gives the key distribution system a degree of adaptability, enabling it to adapt to changes in the network environment and ensuring stable key distribution services for the recipient under various conditions.
[0055] 2. By acquiring the bandwidth of the key recipient and the key sender, the excessive use of the key recipient's network resources during the key distribution process can be avoided, preventing network congestion during key transmission that could affect the normal use of applications on the key recipient, and ensuring the performance of the key recipient and the reliability of key distribution.
[0056] 3. By comparing the minimum instantaneous distribution bandwidth of the key recipient with the minimum available bandwidth of the key sender, the key sender can determine a suitable target distribution bandwidth. This helps to balance bandwidth utilization between the key sender and the key recipient, and improve the efficiency of key distribution.
[0057] 4. Different key recipients have different instantaneous distribution bandwidths, which means that the target distribution bandwidth determined for different key recipients is also different. This is beneficial for providing a suitable target distribution bandwidth for each key recipient based on their performance, thereby meeting the needs of different key recipients, ensuring that the key distribution of different key recipients is balanced, and avoiding unfair distribution problems caused by performance differences between different key recipients.
[0058] Example 2:
[0059] To achieve efficient and stable key distribution to the key recipient, based on the above embodiments, in this application, after obtaining the available bandwidth and before determining the target distribution bandwidth for the key recipient based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth, the method further includes:
[0060] Obtain the average distribution bandwidth of the key recipient this time;
[0061] If the average distribution bandwidth is greater than the available bandwidth, then the expansion factor of the available bandwidth is determined, and the available bandwidth is expanded based on the expansion factor, so that the available bandwidth is updated based on the expanded available bandwidth; wherein the expanded available bandwidth is greater than the average distribution bandwidth.
[0062] In some potential application scenarios, the bandwidth pre-planned for the key issuer might be unreasonable, resulting in the key issuer's distribution capacity failing to meet actual application needs. Therefore, in this application, the key issuer can obtain the average distribution bandwidth of the key recipient for this current application. This average distribution bandwidth refers to the average bandwidth used by the key recipient to supplement keys over a certain period, reflecting the long-term distribution trend on the key recipient and serving as a comprehensive assessment of the key issuer's distribution efficiency. If the key issuer's planning is reasonable, its available bandwidth will generally be greater than the average distribution bandwidth of all key recipients, meaning the key issuer's distribution capacity can basically meet the key recipients' distribution needs. If the key issuer's planning is unreasonable, its available bandwidth may be less than the average distribution bandwidth of a particular key recipient, meaning the key issuer's distribution capacity cannot meet the current distribution needs of the key recipient. By using this average distribution bandwidth, the reasonableness of the key issuer's planning can be determined, thereby determining whether emergency measures should be taken to manage the key issuer's available bandwidth to ensure that the key issuer can stably and efficiently distribute keys to the key recipients.
[0063] It should be noted that the average distribution bandwidth of the key recipient will generally change over time.
[0064] In one possible implementation, the average distribution bandwidth is determined by the difference between the maximum bandwidth and the average key consumption traffic of the key recipient in this instance; wherein the average key consumption traffic is the average key consumption per preset unit of time.
[0065] In this application, the key recipient learns not only its maximum bandwidth but also its average key consumption rate. This average key consumption rate can be used to predict the amount of user communication data, thereby estimating the terminal key consumption rate and the timing control factors for key replenishment. Furthermore, the key recipient's average key consumption rate typically changes over time.
[0066] In one example, the average distribution bandwidth can be determined by the following formula:
[0067] B avg =TB max -TQ avg
[0068] Among them, B avg The average distribution bandwidth, in TB, represents this operation. max TQ represents the maximum bandwidth in this test. avg This represents the average key consumption rate for this operation.
[0069] Taking the average distribution bandwidth of the key recipient as reported by the key recipient to the key issuer as an example, the key recipient can monitor the bandwidth of the key recipient since the current power-on through the network interface (including the bandwidth required for encrypted transmission and the bandwidth required for key relay), and then determine the maximum bandwidth from the monitored bandwidth. In addition, the key recipient can monitor the total key consumption of the key recipient since the current power-on through the key recipient's encryption system. Then, the key recipient obtains the runtime of this power-on and converts it into a target duration with the same unit as the preset unit duration. The total consumption is divided by the target duration to obtain the average key consumption traffic.
[0070] Assuming the startup duration is T minutes, the preset unit duration is 1 second, and the target duration converted to the same unit duration is T*60 seconds, and the total key consumption within the startup duration is C(T), then the average key consumption rate is TQ. avg It can be determined using the following formula:
[0071] TQ avg = C(T) / (T*60) seconds
[0072] After obtaining the maximum bandwidth and the average key consumption traffic of the current time based on the above embodiments, the key recipient can determine the difference between the maximum bandwidth and the average key consumption traffic, take the determined difference as the average distribution bandwidth of the current time, and report the average distribution bandwidth to the key issuer.
[0073] Taking the example of the key issuer determining the average distribution bandwidth based on the data reported by the key recipient for determining the average distribution bandwidth, after the key recipient obtains the maximum bandwidth and the average key consumption traffic of the key recipient based on the above embodiment, it can report the maximum bandwidth and the average key consumption traffic of the key recipient to the key issuer. After receiving the maximum bandwidth and the average key consumption traffic of the key recipient, the key issuer can determine the difference between the maximum bandwidth and the average key consumption traffic, and use the determined difference as the average distribution bandwidth of the key recipient for this time.
[0074] Based on the above embodiments, after obtaining the average distribution bandwidth of the key recipient, the key issuer can compare the available bandwidth with the average distribution bandwidth to determine whether the key issuer's plan is reasonable. If the available bandwidth is not less than the average distribution bandwidth, it indicates that the key issuer's plan is reasonable, and the target distribution bandwidth corresponding to the key recipient is determined based on the method in the above embodiments. If the available bandwidth is less than the average distribution bandwidth, it indicates that the key issuer's plan is unreasonable, and contingency measures are taken to process the key issuer's available bandwidth to ensure that the key issuer can stably and efficiently distribute keys to the key recipient.
[0075] For example, when the available bandwidth is less than the average distribution bandwidth, in order to obtain keys from the key issuer in a timely manner, the key recipient can expand the key downloaded from the key issuer, thereby logically expanding the distribution bandwidth of the key issuer. The key issuer, when the available bandwidth determined based on the above embodiments is less than the average distribution bandwidth of the key recipient, can determine the expansion factor of the available bandwidth, expand the determined available bandwidth based on the expansion factor, and then, based on the relationship between the expanded available bandwidth and the instantaneous distribution bandwidth, use the method in the above embodiments to determine the target distribution bandwidth for the key issuer to distribute the key to the key recipient. In other words, the original available bandwidth is updated based on the expanded available bandwidth.
[0076] The expansion factor can be a pre-configured static value or a dynamically determined value. For example, if the expansion factor is determined dynamically, it can be based on the quotient of the average distribution bandwidth and the available bandwidth. For instance, the determined quotient can be directly used as the expansion factor, or the determined quotient can be adjusted upwards, and the adjusted quotient can be used as the expansion factor. For example, if the determined quotient is 2.3, 2.3 can be rounded up to obtain 3, and 3 can be used as the expansion factor. As another example, if the determined quotient is 2.3, 2.3 can be rounded up and then further amplified, and the amplified value can be used as the expansion factor. This can be achieved by multiplying a coefficient greater than 1 with the rounded quotient, or by adding any value greater than 0 to the rounded quotient.
[0077] Once the key issuer determines the expansion factor of the available bandwidth, it can notify the key recipient of the expansion factor so that the key recipient can expand the key distributed by the key issuer based on the expansion factor.
[0078] Based on the above embodiments, the key sender obtains the instantaneous distribution bandwidth and average distribution bandwidth of the key recipient, as well as the available bandwidth of the key sender, in the following situations:
[0079] Scenario 1: Available bandwidth > Instantaneous distribution bandwidth > Average distribution bandwidth.
[0080] In this scenario, if the recipient is currently in an idle state, the sender will determine the instantaneous distribution bandwidth as the target distribution bandwidth and execute S207.
[0081] Scenario 2: Available bandwidth > Average distribution bandwidth > Instantaneous distribution bandwidth.
[0082] In this second scenario, if the application on the recipient is currently using the recipient's bandwidth, the key issuer will determine the instantaneous distribution bandwidth as the target distribution bandwidth, that is, use a smaller bandwidth to distribute the key, thereby distributing the key to the recipient without affecting the normal use of the application on the recipient.
[0083] Scenario 3: Instantaneous distribution bandwidth > Available bandwidth > Average distribution bandwidth.
[0084] In this third scenario, the recipient of the key is currently in an idle state, but the distribution capacity of the sender of the key cannot fully meet the recipient's needs. In this case, the sender of the key determines the available bandwidth as the target distribution bandwidth, thereby utilizing the idle time of the quantum-safe state to distribute the key as quickly as possible.
[0085] Case 4: Average distribution bandwidth > available bandwidth (including instantaneous distribution bandwidth > average distribution bandwidth > available bandwidth, or average distribution bandwidth > instantaneous distribution bandwidth > available bandwidth, or average distribution bandwidth > available bandwidth > instantaneous distribution bandwidth).
[0086] In scenario four, the key issuer's planning is flawed, requiring a logical expansion of its available bandwidth, and the key recipient needs to expand the key obtained from the key issuer. Based on this, the key issuer obtains the expansion factor of the available bandwidth, expands the available bandwidth accordingly, and then determines the target distribution bandwidth based on the minimum of the instantaneous distribution bandwidth and the expanded available bandwidth. Simultaneously, the key issuer also notifies the key recipient of this expansion factor.
[0087] Example 3:
[0088] To fully utilize the idle bandwidth of the key recipient, based on the above embodiments, in this application, determining the target distribution bandwidth of the key recipient based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth includes:
[0089] If the maximum bandwidth of the key recipient is less than the available bandwidth, the minimum value is amplified based on a pre-configured amplification factor; wherein, the maximum bandwidth is the maximum bandwidth of the key recipient during communication after this power-on, and the amplification factor is greater than 1;
[0090] The amplified value is determined as the target distribution bandwidth.
[0091] Since the maximum bandwidth of the key recipient is derived from the recipient's detection value, rather than a measured value actively released by the recipient, this maximum bandwidth may differ from the recipient's actual maximum bandwidth. This could result in situations where the recipient's idle bandwidth and the key sender's distribution capacity are not fully utilized. Therefore, in this application, the key sender can obtain the recipient's maximum bandwidth and determine whether the available bandwidth is greater than the maximum bandwidth. If the available bandwidth is greater than the maximum bandwidth, it indicates that the key sender's distribution capacity is not fully utilized, and the recipient's idle bandwidth is also not fully utilized. In this case, after determining the minimum value based on the above embodiment, the key sender can amplify the minimum value based on a pre-configured amplification factor, and then determine the target distribution bandwidth based on the amplified value to distribute the key to the recipient based on the target distribution bandwidth. If the available bandwidth is not greater than the maximum bandwidth, it indicates that the key sender's distribution capacity has been fully utilized. In this case, the key sender determines the determined minimum value as the target distribution bandwidth and distributes the key to the recipient based on the target distribution bandwidth.
[0092] It should be noted that this amplification factor is greater than 1. When setting this amplification factor, different values can be set based on different scenarios. If you want to utilize the recipient's idle bandwidth as much as possible, you can set the amplification factor higher. If you want to avoid excessive target distribution bandwidth, which could affect the normal use of the recipient's application, you can set the amplification factor lower. Ideally, this amplification factor should not be set too high or too low. In specific implementation, it can be flexibly set according to actual needs, and no specific limitations are made.
[0093] During a key distribution round, the key recipient can periodically report the maximum bandwidth to the key issuer, so that the key issuer can adjust the target distribution bandwidth in a timely manner based on the latest reported maximum bandwidth.
[0094] In one possible implementation, before obtaining the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender, the method further includes:
[0095] If the previously determined minimum value is stored in the current key distribution process, and the previously determined minimum value is amplified based on the amplification factor, then the maximum bandwidth of the key recipient in this round is obtained.
[0096] It is determined that the current maximum bandwidth is greater than the previously saved maximum bandwidth.
[0097] After the key issuer amplifies the minimum value based on the above embodiment, if the target distribution bandwidth is determined based on the amplified value and the key is distributed to the key recipient based on the target distribution bandwidth, the maximum bandwidth of the key recipient will increase, resulting in changes to both the instantaneous distribution bandwidth and the average distribution bandwidth of the key recipient. Since both the instantaneous and average distribution bandwidths of the key recipient change, the key issuer can redetermine the available bandwidth based on the changed average distribution bandwidth, and redetermine the minimum value based on the redetermined available bandwidth and the changed instantaneous distribution bandwidth. Then, based on whether the available bandwidth is greater than the changed maximum bandwidth, it can determine whether the redetermined minimum value needs to be amplified. For example, before obtaining the instantaneous distribution bandwidth and the available bandwidth of the key recipient in this round of key distribution, the key issuer can determine whether the previously determined minimum value is stored in this round of key distribution. If the key issuer determines that the previously determined minimum value is not stored in this round of key distribution, it indicates that the key issuer is determining the target distribution bandwidth corresponding to the key recipient for the first time, and then determines the target distribution bandwidth corresponding to the key recipient based on the method in the above embodiment. If the key issuer determines that the previously determined minimum value is stored in the current key distribution process, it means that the key issuer has not determined the target distribution bandwidth corresponding to the key recipient for the first time. Then, it is determined whether the previously determined minimum value has been amplified based on the amplification factor.
[0098] If it is determined that the previously determined minimum value was not amplified based on the amplification factor, then the target distribution bandwidth corresponding to the key recipient this time is determined based on the method in the above embodiments. If it is determined that the previously determined minimum value was amplified based on the amplification factor, then the maximum bandwidth of the key recipient this time is obtained, and the maximum bandwidth this time is compared with the saved maximum bandwidth of the previous time.
[0099] If the current maximum bandwidth is determined to be greater than the previous maximum bandwidth, it indicates that the recipient's idle bandwidth may still not be fully utilized. Therefore, based on the method described in the above embodiments, the minimum value corresponding to the recipient in this instance is determined, and this minimum value is amplified based on a pre-configured amplification factor. The amplified value is then determined as the target distribution bandwidth. If the current maximum bandwidth is determined not to be greater than the previous maximum bandwidth, it indicates that the recipient's idle bandwidth has been fully utilized. Therefore, the target distribution bandwidth for this instance is reverted to the previously determined minimum value, i.e., the previously determined minimum value is determined as the target distribution bandwidth for this instance.
[0100] This method allows for the continuous and dynamic adjustment of the target distribution bandwidth for the key sender to distribute the key to the key recipient, thereby fully utilizing the recipient's idle bandwidth and the sender's distribution capabilities.
[0101] Example 4:
[0102] The flow control method for key distribution in quantum secure networks provided in this application is illustrated below through specific embodiments. Figure 2 This application provides a specific flowchart illustrating flow control for key distribution in a quantum-secure network, which includes:
[0103] S201: The key sender receives the maximum bandwidth, average key consumption, and ciphertext traffic reported by the key receiver.
[0104] S202: The key issuer determines the average distribution bandwidth based on the difference between the maximum bandwidth and the average key consumption traffic, and determines the instantaneous distribution bandwidth based on the difference between the maximum bandwidth and the ciphertext traffic.
[0105] It should be noted that the maximum bandwidth is greater than the instantaneous distribution bandwidth, and the maximum bandwidth is greater than the average distribution bandwidth.
[0106] S203: The key issuer determines the available bandwidth based on the quotient of the key issuer's planned bandwidth and the actual number of key recipients downloading concurrently.
[0107] S204: The key issuer determines whether the average distribution bandwidth is greater than the available bandwidth. If yes, proceed to S205; otherwise, proceed to S206.
[0108] S205: The key issuer determines the expansion factor of the available bandwidth, expands the available bandwidth based on the expansion factor, and notifies the key recipient of the expansion factor, and executes S204.
[0109] The expansion factor can be determined by the quotient of the average distributed bandwidth and the available bandwidth.
[0110] S206: The key issuer determines the minimum of the instantaneous distribution bandwidth and the available bandwidth.
[0111] S207: The key issuer determines whether the available bandwidth is greater than the maximum bandwidth. If so, it executes S208; otherwise, it executes S209.
[0112] S208: The key issuer saves the minimum value and the maximum bandwidth of this operation, and amplifies the minimum value based on the pre-configured amplification factor to determine the target distribution bandwidth based on the amplified value. Based on the target distribution bandwidth, the key is distributed to the key recipient, and 210 is executed.
[0113] S209: The key issuer saves the minimum value and the maximum bandwidth of this operation, determines the target distribution bandwidth based on the minimum value, and distributes the key to the key recipient based on the target distribution bandwidth, and executes 210.
[0114] S210: Before completing the current round of key distribution to the key recipient, the key issuer receives again the maximum bandwidth, average key consumption traffic, and ciphertext traffic reported by the key recipient.
[0115] It should be noted that after the key issuer completes the distribution of the key to the key recipient in this round, it can delete the minimum value and maximum bandwidth that the key issuer saved during this round of key distribution.
[0116] S211: The key issuer determines whether to amplify the previously determined minimum value based on the pre-configured amplification factor. If so, execute S212; otherwise, execute S202.
[0117] S212: The key issuer determines whether the current maximum bandwidth is greater than the previously saved maximum bandwidth. If so, execute S202; otherwise, execute S213.
[0118] S213: Set the minimum value determined last time as the target distribution bandwidth for this time.
[0119] Using the above method, the key issuer can dynamically adjust the target distribution bandwidth based on the maximum bandwidth reported by the key recipient each time, the average key consumption traffic and ciphertext traffic, and the available bandwidth of the key issuer. This ensures full utilization of network resources, minimizes the impact on the normal use of applications on the key recipient, maximizes the use of the key recipient's idle bandwidth resources, and thus achieves the distribution of the key to the key recipient in the shortest possible time.
[0120] Example 5:
[0121] Based on the same inventive concept, this application also provides a quantum-secure network key distribution flow control device. Figure 3 This application provides a schematic diagram of a flow control device for key distribution in a quantum-secure network. The device includes:
[0122] The acquisition unit 31 is used to acquire the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender.
[0123] Processing unit 32 is used to determine the target distribution bandwidth of the key recipient for this time based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0124] It should be noted that the principle of the quantum secure network key distribution flow control device provided in this embodiment to solve the technical problem is the same as the principle of the method embodiment above, and the repeated parts will not be repeated.
[0125] Example 6:
[0126] Based on the above embodiments, this application also provides a key issuer. Figure 4 This is a schematic diagram of the structure of a key issuer provided in an embodiment of this application, as shown below. Figure 4 As shown, it includes: processor 41, communication interface 42, memory 43 and communication bus 44, wherein processor 41, communication interface 42 and memory 43 communicate with each other through communication bus 44.
[0127] The memory 43 stores a computer program, which, when executed by the processor 41, causes the processor 41 to perform the following steps:
[0128] Obtain the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender;
[0129] The target distribution bandwidth for the key recipient is determined based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0130] Since the principle of the key issuer in solving the problem is similar to the flow control method for key distribution in quantum secure networks, the implementation of the key issuer can be found in the embodiments of the method, and the repeated parts will not be described again.
[0131] Example 7:
[0132] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program executable by a processor. When the program runs on the processor, it causes the processor to perform the following steps:
[0133] Obtain the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender;
[0134] The target distribution bandwidth for the key recipient is determined based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth.
[0135] Since the principle of the computer-readable storage medium in solving the problem is similar to the flow control method for key distribution in quantum secure networks, the implementation of the computer-readable storage medium can be found in the embodiments of the method, and repeated details will not be repeated.
Claims
1. A flow control method for key distribution in a quantum-safe network, characterized in that, The method includes: Obtain the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender; Obtain the average distribution bandwidth of the key recipient this time; If the average distribution bandwidth is greater than the available bandwidth, then the expansion factor of the available bandwidth is determined, and the available bandwidth is expanded based on the expansion factor, so that the available bandwidth is updated based on the expanded available bandwidth; wherein, the expanded available bandwidth is greater than the average distribution bandwidth; The target distribution bandwidth for the key recipient is determined based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth. Wherein, determining the expansion factor of the available bandwidth includes: Determine the quotient of the average distribution bandwidth and the available bandwidth; The expansion factor is determined based on the determined quotient; After determining the expansion factor of the available bandwidth, the method further includes: The expansion factor is communicated to the key recipient so that the key recipient can expand the key distributed by the key issuer based on the expansion factor.
2. The method as described in claim 1, characterized in that, The instantaneous distribution bandwidth is determined by the difference between the maximum bandwidth of the key recipient in this instance and the ciphertext traffic of the key recipient in this instance; wherein, the maximum bandwidth is the maximum bandwidth of the key recipient during the communication process after power-on in this instance; The available bandwidth is determined by the quotient of the key issuer's planned bandwidth and the actual number of key recipients downloading concurrently.
3. The method as described in claim 1, characterized in that, The average distribution bandwidth is determined by the difference between the maximum bandwidth and the average key consumption traffic of the key recipient in this instance; wherein, the average key consumption traffic is the average key consumption per preset unit of time.
4. The method as described in claim 1, characterized in that, Determining the target distribution bandwidth for the key recipient based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth includes: If the maximum bandwidth of the key recipient is less than the available bandwidth, the minimum value is amplified based on a pre-configured amplification factor; wherein, the maximum bandwidth is the maximum bandwidth of the key recipient during communication after this power-on, and the amplification factor is greater than 1; The amplified value is determined as the target distribution bandwidth.
5. The method as described in claim 4, characterized in that, Before obtaining the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender, the method further includes: If the previously determined minimum value is stored in the current key distribution process, and the previously determined minimum value is amplified based on the amplification factor, then the maximum bandwidth of the key recipient in this round is obtained. It is determined that the current maximum bandwidth is greater than the previously saved maximum bandwidth.
6. The method as described in claim 5, characterized in that, If it is determined that the current maximum bandwidth is not greater than the saved previous maximum bandwidth, the method further includes: The previously determined minimum value is set as the target distribution bandwidth for the key recipient in this instance.
7. A quantum-safe network key distribution flow control device, characterized in that, The device includes: The acquisition unit is used to acquire the instantaneous distribution bandwidth of the key recipient and the available bandwidth of the key sender; and to acquire the average distribution bandwidth of the key recipient. The processing unit is configured to: if the average distribution bandwidth is greater than the available bandwidth, determine an expansion factor of the available bandwidth, and expand the available bandwidth based on the expansion factor, so as to update the available bandwidth based on the expanded available bandwidth; notify the key recipient of the expansion factor, so that the key recipient expands the key distributed by the key issuer based on the expansion factor; wherein the expanded available bandwidth is greater than the average distribution bandwidth; and determine the target distribution bandwidth of the key recipient for this time based on the minimum value between the instantaneous distribution bandwidth and the available bandwidth. The processing unit is configured to determine the expansion factor of the available bandwidth by: determining the quotient of the average distribution bandwidth and the available bandwidth; and determining the expansion factor based on the determined quotient.
Citation Information
Patent Citations
Data transmission bandwidth adjustment method and device, electronic equipment and storage medium
CN114786268A
Dynamic service-oriented bandwidth and key distribution method and related device
CN116389947A