Quantum key distribution network security routing and resource allocation method and related equipment
Patent Information
- Application Number
- CN202410115121.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2044-01-26
AI Technical Summary
[0002]相关的QKDN在受攻击时分配资源和路径的方案往往是集中在如何检测量子密钥分发网络中的DoS攻击等问题,缺乏从量子网络通信层面来缓解DoS攻击带来的影响
[0039] As can be seen from the above, the quantum key distribution network security routing and resource allocation method and related equipment provided in this application determine the attacked links based on the link information of each link in the quantum key distribution network. It comprehensively considers the quantum channel and classical channel in the quantum key distribution network, and combines the security level of the service. It executes high-security services through the shortest hop path, and considers the attack status of the shortest hop path. When all links of the shortest hop path are attacked, the execution of the service is abandoned.
Smart Images

Figure CN117914485B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this application relate to the technical field of communication, and in particular to a quantum key distribution network security routing and resource allocation method and related equipment. Background Technology
[0002] Related solutions for allocating resources and paths when QKDN is attacked often focus on how to detect DoS attacks in quantum key distribution networks, lacking solutions to mitigate the impact of DoS attacks from the quantum network communication level.
[0003] Meanwhile, the common approach to dealing with DoS attacks in QKDN is to select an alternative path, without considering the attacker's DoS attacks on multiple links and then on trusted nodes. Even if an alternative path is selected, it will not significantly improve network performance.
[0004] Therefore, in scenarios where links in a quantum key distribution network (QKDN) are subjected to DoS attacks, the reasonable allocation of routing and resources at the network communication layer is a problem that must be solved to ensure and improve the performance of QKDN under DoS attacks. Summary of the Invention
[0005] In view of this, the purpose of this application is to propose a network security routing and resource allocation method and related equipment for quantum key distribution.
[0006] To achieve the above objectives, this application provides a network security routing and resource allocation method for quantum key distribution, including:
[0007] In response to a service being added to a preset waiting queue, it is determined whether the service is being added for the first time. If it is determined that the service is being added again, the service in the waiting queue is moved to the head of the queue.
[0008] The link information between trusted nodes of a preset quantum channel is determined. Based on the link information, the attacked links are identified. The security level of the service at the top of the queue is determined. In response to determining that the service at the top of the queue is at the preset first security level, the path with the shortest hop count is determined as the target path. It is then determined whether all links of the target path have been attacked. In response to determining that all links have been attacked, the service at the top of the queue is added to the waiting queue. In response to determining that there are unattacked links, time slot resources and wavelength resources that meet preset freshness requirements are allocated to the target path, and the service at the top of the queue is executed.
[0009] In response to determining that the service at the top of the queue is at a preset second security level, multiple candidate paths with the shortest hop counts are identified. It is then determined whether a candidate path from all candidate paths can be identified where all links are unaffected. If such a path is identified, it is used as the target path. Time slot resources and wavelength resources are allocated to the target path, and the service at the top of the queue is executed. If no path can be identified, the service at the top of the queue is encrypted using a classic key. The first security level is higher than the second security level.
[0010] Furthermore, before determining the link information between trusted nodes in the preset quantum channel, the process also includes:
[0011] In response to receiving a preset service termination notification signal, the link information between the trusted nodes of the quantum channel is determined;
[0012] In response to determining that no service termination notification signal has been received, the system continues to receive notification signals.
[0013] Furthermore, the link information includes the key rate and the quantum error rate;
[0014] Furthermore, based on the link information of each link, the attacked links are identified, including:
[0015] For each link, if the key rate is less than a preset first threshold and / or the quantum error rate is greater than a preset second threshold, then the link is determined to be under attack.
[0016] Furthermore, after identifying the attacked links based on the link information of each link, the process also includes:
[0017] Update the attacked links to a preset set of attacked links;
[0018] Update the replenishment cycle of quantum keys in the preset key pool, and update the capacity threshold of the key pool, whereby the capacity threshold represents the maximum capacity of quantum keys in the key pool.
[0019] Furthermore, each of the time slots contains multiple quantum keys;
[0020] Furthermore, time slot resources and wavelength resources that meet preset freshness requirements are allocated to the target path, including:
[0021] Determine the freshness of each preset time slot, and identify candidate time slots whose freshness meets the freshness requirements;
[0022] In response to determining that the number of candidate time slots meets a preset time slot number threshold, candidate time slots are allocated to the target path;
[0023] And allocate preset wavelength resources for the target path.
[0024] Furthermore, it is determined whether a candidate path from all candidate paths can be identified where all links are unaffected by attacks, including:
[0025] Among all candidate paths, starting with the candidate path with the fewest hops, determine whether all links of that candidate path have not been attacked.
[0026] In response to the determination that all links of the candidate path have not been attacked, the candidate path is determined as the target path;
[0027] In response to the determination that there is an attacked link in the candidate path, the system determines whether all links in the next candidate path are unattacked, in ascending order of hop count.
[0028] If, after traversing all candidate paths, it is determined that each candidate path has links that have been attacked, then it is determined that no candidate path can be determined where none of the links have been attacked.
[0029] Furthermore, time slot resources and wavelength resources are allocated to the target path, including:
[0030] Determine whether the wavelength and time slot resources of the target path are sufficient;
[0031] In response to the determination that wavelength resources are sufficient and time slot resources are sufficient, wavelength resources are allocated to the target path, and the time slot with the lowest freshness is allocated to the target path.
[0032] Based on the same inventive concept, this application also provides a quantum key distribution network security routing and resource allocation device, including: a service sorting module, a first service execution module, and a second service execution module;
[0033] The service sorting module is configured to, in response to a service being added to a preset waiting queue, determine whether the service is being added for the first time, and in response to determining that the service is being added again, move the service in the waiting queue to the head of the queue.
[0034] The first service execution module is configured to: determine the link information of the links between trusted nodes of a preset quantum channel; determine the attacked links based on the link information of each link; determine the security level of the service at the top of the queue; in response to determining that the service at the top of the queue is at a preset first security level, determine the path with the shortest hop count as the target path; determine whether all links of the target path have been attacked; in response to determining that all links have been attacked, add the service at the top of the queue to the waiting queue; in response to determining that there are unattacked links, allocate time slot resources and wavelength resources that meet preset freshness requirements to the target path, and execute the service at the top of the queue.
[0035] The second service execution module is configured to, in response to determining that the service at the top of the queue is at a preset second security level, identify multiple candidate paths with the shortest hop count, determine whether a candidate path from all candidate paths can be identified where all links are not under attack, and in response to identifying such a candidate path, use the identified candidate path as the target path, allocate time slot resources and wavelength resources to the target path, and execute the service at the top of the queue; and in response to not identifying such a candidate path, encrypt the service at the top of the queue using a classic key, wherein the first security level is higher than the second security level.
[0036] Based on the same inventive concept, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the quantum key distribution network security routing and resource allocation method as described in any of the above claims.
[0037] Based on the same inventive concept, this application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions for causing the computer to execute the above-described quantum key distribution network security routing and resource allocation method.
[0038] Based on the same concept, corresponding to any of the above embodiments, this application also provides a computer program product, including computer program instructions, which, when executed on a computer, cause the computer to perform the quantum key distribution network security routing and resource allocation method as described in any of the preceding claims.
[0039] As can be seen from the above, the quantum key distribution network security routing and resource allocation method and related equipment provided in this application determine the attacked links based on the link information of each link in the quantum key distribution network. It comprehensively considers the quantum channel and classical channel in the quantum key distribution network, and combines the security level of the service. It executes high-security services through the shortest hop path, and considers the attack status of the shortest hop path. When all links of the shortest hop path are attacked, the execution of the service is abandoned.
[0040] Furthermore, for services that are not at a high security level, the system determines whether to use quantum keys or classical keys to encrypt the service by judging whether there is a path where all links are unattacked. When choosing to encrypt the service with quantum keys, the system uses the time slot with the lowest freshness to execute the encryption, thus fully considering the utilization of time slots and the avoidance of attacks. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 This is a flowchart illustrating the quantum key distribution network security routing and resource allocation method according to an embodiment of this application;
[0043] Figure 2 This is an execution logic diagram of the quantum key distribution network security routing and resource allocation method according to an embodiment of this application;
[0044] Figure 3 This is a schematic diagram of the structure of the quantum key distribution network security routing and resource allocation device according to an embodiment of this application;
[0045] Figure 4 This is a schematic diagram of the electronic device structure according to an embodiment of this application. Detailed Implementation
[0046] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.
[0047] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0048] As described in the background section, the existing network security routing and resource allocation methods for quantum key distribution are still insufficient to meet the actual needs of countering attacks in quantum communication.
[0049] In the process of developing this application, the applicant discovered that the main problem with the relevant quantum key distribution network security routing and resource allocation methods is that their solutions often focus on how to detect DoS attacks in quantum key distribution networks, and lack a way to mitigate the impact of DoS attacks from the quantum network communication level.
[0050] Meanwhile, the common approach to dealing with DoS attacks in QKDN is to select an alternative path, without considering the attacker's DoS attacks on multiple links and then on trusted nodes. Even if an alternative path is selected, it will not significantly improve network performance.
[0051] Therefore, in scenarios where links in a quantum key distribution network (QKDN) are subjected to DoS attacks, the reasonable allocation of routing and resources at the network communication layer is a problem that must be solved to ensure and improve the performance of QKDN under DoS attacks.
[0052] Based on this, one or more embodiments of this application provide a method for network security routing and resource allocation for quantum key distribution.
[0053] In the embodiments of this application, a control platform and a QKDN (Quantum Key Distribution Network) are preset, which can generate time slots, i.e. quantum keys and classical keys; wherein, the QKDN includes multiple quantum trusted relay nodes (hereinafter referred to as nodes or trusted nodes).
[0054] Furthermore, the control platform can acquire relevant information about each node and each link, and allocate key resources and wavelength resources to each link.
[0055] Furthermore, the control platform can also receive service requests from external sources, and form a waiting queue of the received services, and execute each service in sequence according to the order in which they are in the waiting queue.
[0056] In this embodiment, each trusted node in QKDN is susceptible to external attacks, such as DoS attacks (denial of service attacks).
[0057] The embodiments of this application are described in detail below with reference to the accompanying drawings.
[0058] refer to Figure 1 An embodiment of the quantum key distribution network security routing and resource allocation method of this application includes the following steps:
[0059] Step S101: In response to a service being added to the preset waiting queue, determine whether the service is being added for the first time. If it is determined that the service is being added again, move the service in the waiting queue to the first position of the queue.
[0060] In the embodiments of this application, when a service is added to the waiting queue of the control platform, the order of the newly added service in the waiting queue can be adjusted by determining whether the service is being added to the waiting queue for the first time.
[0061] Specifically, such as Figure 2 As shown, after executing step S201 and determining that the service has been added to the waiting queue, step S202 is further executed to determine whether it is a service that has been added again.
[0062] If it is determined that the service is not being added to the waiting queue for the first time, that is, if the determination result of step S202 is yes, then step S203 is further executed to move the service to the head of the queue.
[0063] Specifically, when it is determined that a service added to the waiting queue has been added to the waiting queue before and is being added to the waiting queue again, the order of the service in the waiting queue is adjusted to the first position in the queue, and further step S204, receiving a notification signal, is executed.
[0064] Furthermore, when it is determined that the service is being added to the waiting queue for the first time, that is, when the result of step S202 is negative, the order of the services in the waiting queue is not adjusted, and step S204 is executed directly.
[0065] Step S102: Determine the link information between trusted nodes in the preset quantum communication network, identify the attacked links based on the link information, determine the security level of the service at the top of the queue, and in response to determining that the service at the top of the queue is at the preset first security level, determine the path with the shortest hop count as the target path, and determine whether all links of the target path have been attacked. In response to determining that all links have been attacked, add the service at the top of the queue to the waiting queue. In response to determining that there are unattacked links, allocate time slot resources and wavelength resources that meet the preset freshness requirements to the target path, and execute the service at the top of the queue.
[0066] In the embodiments of this application, based on the service at the top of the queue determined in the aforementioned steps, the attacked link is determined by determining the information of each link, and the target path, time slot resources and wavelength resources are allocated to the service according to the security level of the service at the top of the queue, so as to execute the service.
[0067] Before identifying the attacked link, step S204 can be further executed based on step S202 or step S203, thereby enabling the control platform to receive real-time notification signals regarding the QKDN.
[0068] Specifically, the notification signal may include a service completion notification signal, which is used to notify the control platform that the previous service has ended.
[0069] Based on the notification signal received in step S204, it can be further determined whether the current QKDN meets the execution conditions for executing the service at the head of the current queue, and the service is executed when the conditions are met.
[0070] Specifically, step S205 is executed to determine whether a service termination notification signal has been received.
[0071] Furthermore, when a service termination notification is received, i.e., the judgment result of step S205 is yes, it is considered that the previous service has ended, QKDN meets the execution conditions, and further executes step S206 to obtain link information.
[0072] Furthermore, if no service termination notification is received, that is, if the judgment result of step S205 is negative, it is considered that the previous service has not ended, QKDN does not meet the execution conditions, and the process returns to step S204.
[0073] Furthermore, during step S206, the control platform can traverse each node in the QKDN topology network and the links between each node to monitor the link information of each link in the QKDN in real time.
[0074] The link information may include the link's SKR (key rate) and QBER (quantum bit error rate).
[0075] In this embodiment, based on the link information of each link in the QKDN determined in the aforementioned steps, the links in the QKDN that are under DoS attack can be further identified, and the target path can be determined based on the links under DoS attack, and resource allocation can be performed.
[0076] like Figure 2 As shown, based on step S206, step S207 can be further executed to determine whether a link has been attacked.
[0077] Specifically, a first threshold for determining SKR and a second threshold for determining QBER can be preset.
[0078] Based on this, for each link in the QKDN, the SKR of the link can be compared with the first threshold, and the QBER of the link can be compared with the second threshold.
[0079] Furthermore, if the SKR of the link is greater than or equal to the first threshold and the QBER is less than or equal to the second threshold, then the link is considered to be under DoS attack but not under DoS attack.
[0080] Furthermore, if the SKR of the link is less than the first threshold and / or the QBER is greater than the second threshold, then the link is considered to be under a DoS attack.
[0081] Based on this, if it is determined that any link in the QKDN is under a DoS attack, the execution result of step S207 is yes, and step S208 is further executed to update the set of attacked links, the key pool replenishment period, and the key pool capacity threshold; if it is determined that no link in the QKDN is under a DoS attack, the execution result of step S208 is no, and step S209 is further executed to determine whether the service is at a high security level.
[0082] Specifically, the set of attacked links can be pre-set, and the quantum key replenishment period and quantum key capacity threshold can be pre-set for the quantum key key pool. The key pool generates quantum keys according to the replenishment period and ensures that the number of generated quantum keys does not exceed the capacity threshold.
[0083] Based on this, when it is determined that there is an attacked link in the QKDN, the attacked link can be recorded in the attacked link set to update the attacked link set, and the current replenishment cycle and capacity threshold of the key pool can be updated. After the update, step S209 is executed.
[0084] Specifically, the replenishment cycle can be adjusted to be shorter and the capacity threshold can be adjusted to be larger to increase the number of quantum keys in the key pool.
[0085] Furthermore, if it is determined that there are no attacked links in the QKDN, then the attacked link set, replenishment cycle and capacity threshold can be skipped and step S208 can be skipped and step S209 can be executed directly.
[0086] Furthermore, each service is pre-set with a security level identifier. When executing step S209, the security level of the service can be determined by querying the security level identifier of the service at the top of the queue.
[0087] The security level can include a first security level and a second security level, with the first security level being higher than the second security level.
[0088] Furthermore, when the security level of the service is the first security level, that is, the execution result of step S209 is yes, then step S210 can be further executed to determine the shortest hop path as the target path.
[0089] Specifically, the Dijkstra algorithm is used to determine the path with the shortest number of hops among all possible paths for executing the service, and this path is then used as the target path.
[0090] Based on this, step S211 can be further executed to determine whether all links on the target path have been attacked.
[0091] Specifically, it can be determined from the updated set of attacked links whether each link on the target path has been attacked. When each link on the target path has been attacked, that is, when the result of step S211 is yes, it is considered that there is a high risk that the resources required for the target path to execute the service are insufficient, and step S215 is further executed to add the service to the waiting queue.
[0092] Furthermore, if there are unattacked links on the target path, that is, if the result of step S211 is negative, then step S212 can be further executed to determine whether there are enough time slots that meet the freshness requirements.
[0093] Specifically, a freshness can be preset for a time slot. This freshness represents the difference between the service arrival time and the quantum key generation time. The larger the difference, the lower the freshness of the time slot; the smaller the difference, the higher the freshness of the time slot. In this embodiment, the quantum key is represented by a time slot, and each time slot contains multiple quantum keys.
[0094] Furthermore, a freshness requirement is pre-set for the freshness of time slots. After determining the freshness of each time slot, the freshness of each time slot is compared with the freshness requirement, and time slots with a freshness greater than or equal to the freshness requirement are determined to meet the freshness requirement.
[0095] Furthermore, a time slot quantity threshold can be preset for time slots to determine whether the number of time slots that meet the freshness requirements is greater than or equal to the time slot quantity threshold.
[0096] Furthermore, if the number of time slots that meet the freshness requirement is less than the time slot number threshold, that is, if the execution result of step S212 is negative, then the time slot resources are considered insufficient, and step S214 is further executed to determine that the time slot allocation connection is blocked, and step S215 is further executed to add the service to the waiting queue.
[0097] Furthermore, when the number of time slots that meet the freshness requirement is greater than or equal to the threshold number of time slots, that is, when the execution result of step S212 is yes, it is considered that the time slot resources are sufficient, and step S213 is further executed to allocate time slots that meet the freshness requirement to the target path.
[0098] Specifically, the time slots that meet the freshness requirements can be allocated to each trusted node in the target path. After allocating time slots to the target path, step S225 is further executed to determine whether the wavelength resources of the service using quantum keys are sufficient.
[0099] Furthermore, if wavelength resources are sufficient, step S216 can be performed to execute the service using quantum keys.
[0100] Specifically, the service at the head of the queue can be executed according to the allocated target path, time slot resources (i.e., quantum key resources) and wavelength resources.
[0101] Furthermore, if wavelength resources are insufficient, then step S224 is executed to determine that the wavelength allocation connection is blocked, and step S215 is executed to add the service to the waiting queue.
[0102] Step S103: In response to determining that the service at the top of the queue is at a preset second security level, multiple candidate paths with the shortest hop counts are identified. It is then determined whether a candidate path from all candidate paths can be identified where all links are unaffected. If such a path is identified, the identified candidate path is used as the target path. Time slot resources and wavelength resources are allocated to the target path, and the service at the top of the queue is executed. If such a path cannot be identified, the service at the top of the queue is encrypted using a classic key. The first security level is higher than the second security level.
[0103] In the embodiments of this application, based on the above-mentioned determination of the security level of the service at the head of the queue, when the security level of the service is level two, it can be determined whether to use the path in the QKDN to execute the service or to use the classic key to execute the service, depending on the attack situation of the link.
[0104] Specifically, when the security level of the service is the second security level, it is considered that its security level is lower than the first security level and does not belong to the high security level. That is, if the execution result of step S209 is negative, then step S217 can be further executed to determine the K shortest paths.
[0105] Specifically, the preset KSP algorithm (multiple shortest path algorithm) is used to determine the top few shortest paths from multiple paths that can perform the service, and these are used as candidate paths.
[0106] Among the candidate paths, the number of hops can be the same or different.
[0107] Based on this, step S218 can be further executed to determine whether there is a path where all links are unaffected by attacks.
[0108] Specifically, among all candidate paths, the candidate path with the fewest hops is selected first. If all links of the candidate path are not attacked, it can be identified as the target path.
[0109] Furthermore, if the candidate path with the fewest hops has an attacked link, then the next candidate path is determined in ascending order of hop count to see if all links are unattacked.
[0110] Furthermore, when the first candidate path is identified where all links are under attack, that candidate path is then designated as the target path.
[0111] Furthermore, after judging each candidate path, if each candidate path has an attacked link, it is considered that all candidate paths face a significant risk of insufficient resources, and further step S221 is executed to calculate the required key for the service, so as to select the classic key to execute the service.
[0112] In other embodiments, when each candidate path has an attacked link, a new round of judgment can be started again from the candidate path with the fewest hops, until after a preset number of rounds, if a candidate path with no attacked links is still not determined, then step S221 is executed to ensure that possible errors may occur during a single round of judgment.
[0113] Furthermore, based on step S218, once the target path is determined, that is, if the execution result of step S218 is yes, then step S219 is executed to determine whether the time slot is sufficient.
[0114] Specifically, in this step, based on the time slot quantity threshold, it can be determined whether there are enough time slots. If there are not enough time slots, that is, if the execution result of step S219 is negative, then step S214 is further executed to abandon the execution of the service.
[0115] In another embodiment, a wavelength threshold can be preset. When determining whether a time slot is sufficient, the wavelength is also determined. If the wavelength is insufficient, step S224 can be further executed to determine that the wavelength allocation connection is blocked, and step S215 can be further executed to abandon the execution of the service.
[0116] Furthermore, if there are sufficient time slots, that is, if the result of step S219 is yes, then step S220 is executed to allocate the time slot with the lowest freshness to the target path.
[0117] Specifically, the lower the freshness of a time slot, the longer it is considered to survive in the key pool. Based on this, time slots can be selected in order of freshness from low to high and allocated to each trusted node in the target path.
[0118] Based on this, step S225 can be further executed to determine whether the wavelength resources of the quantum key are sufficient.
[0119] Furthermore, if wavelength resources are sufficient, step S216 can be performed to execute the service using quantum keys.
[0120] Specifically, the service at the head of the queue can be executed according to the allocated target path, time slot resources (i.e., quantum key resources) and wavelength resources.
[0121] Furthermore, if wavelength resources are insufficient, then step S224 is executed to determine that the wavelength allocation connection is blocked, and step S215 is executed to add the service to the waiting queue.
[0122] In this embodiment, when performing step S221, the AES algorithm (symmetric block cipher algorithm) can be used to calculate the key required for the business at the head of the queue.
[0123] Further, the target path for executing the service is determined, and step S222 is executed to determine whether the wavelength resources of the service using the classic key are sufficient.
[0124] Based on this, when wavelength resources are sufficient, that is, when the judgment result of step S222 is yes, then step S223 is further executed to perform the service using the classic key and to use the key calculated above to encrypt the service transmission process.
[0125] Furthermore, when wavelength resources are insufficient, that is, when the judgment result of step S222 is negative, step S224 is further executed to abandon the execution of the service.
[0126] As can be seen, the quantum key distribution network security routing and resource allocation method of the embodiments of this application determines the attacked link based on the link information of each link in the quantum key distribution network, comprehensively considers the quantum key and classical key in the quantum key distribution network, and combines the security level of the service. The high-security-level service is executed through the shortest hop path, and the attack status of the shortest hop path is considered. When all links of the shortest hop path are attacked, the execution of the service is abandoned.
[0127] Furthermore, for services that are not at a high security level, the system determines whether to use quantum signals or classical keys to encrypt the service by judging whether there is a path where all links are unaffected. When selecting a quantum channel to execute the service, the time slot with the lowest freshness is used, fully considering the utilization of time slots and the avoidance of attacks.
[0128] It should be noted that the method of the embodiments of this application can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of the embodiments of this application, and the multiple devices will interact with each other to complete the method described.
[0129] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0130] Based on the same inventive concept, and corresponding to the methods of any of the above embodiments, embodiments of this application also provide a quantum key distribution network security routing and resource allocation device.
[0131] refer to Figure 3 The quantum key distribution network security routing and resource allocation device includes: a service sorting module 301, a first service execution module 302, and a second service execution module 303;
[0132] The service sorting module 301 is configured to, in response to a service being added to a preset waiting queue, determine whether the service is being added for the first time, and in response to determining that the service is being added again, move the service in the waiting queue to the first position in the queue.
[0133] The first service execution module 302 is configured to: determine the link information of the links between trusted nodes of the preset quantum channel; determine the attacked links based on the link information of each link; determine the security level of the service at the top of the queue; in response to determining that the service at the top of the queue is at the preset first security level, determine the path with the shortest number of hops as the target path; and determine whether all links of the target path have been attacked. In response to determining that all links have been attacked, add the service at the top of the queue to the waiting queue; in response to determining that there are unattacked links, allocate time slot resources and wavelength resources that meet the preset freshness requirements to the target path, and execute the service at the top of the queue.
[0134] The second service execution module 303 is configured to, in response to determining that the service at the head of the queue is at a preset second security level, identify multiple candidate paths with the shortest hop count, determine whether a candidate path from all candidate paths can be identified where all links are not under attack, and in response to identifying such a candidate path, use the identified candidate path as the target path, allocate time slot resources and wavelength resources to the target path, and execute the service at the head of the queue; in response to not identifying such a candidate path, encrypt the service at the head of the queue using a classic key, wherein the first security level is higher than the second security level.
[0135] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing the embodiments of this application, the functions of each module can be implemented in one or more software and / or hardware.
[0136] The apparatus described above is used to implement the corresponding quantum key distribution network security routing and resource allocation method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0137] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, embodiments of this application also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the quantum key distribution network security routing and resource allocation method as described in any of the above embodiments.
[0138] Figure 4 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0139] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0140] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this application are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0141] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.
[0142] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0143] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0144] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this application, and not necessarily all the components shown in the figures.
[0145] The apparatus described above is used to implement the corresponding quantum key distribution network security routing and resource allocation method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0146] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the quantum key distribution network security routing and resource allocation method as described in any of the above embodiments.
[0147] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0148] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the quantum key distribution network security routing and resource allocation method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0149] Based on the same concept, corresponding to the methods of any of the above embodiments, this application also provides a computer program product, including computer program instructions, which, when run on a computer, cause the computer to execute the quantum key distribution network security routing and resource allocation method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0150] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in detail for the sake of brevity.
[0151] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0152] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0153] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.
Claims
1. A network security routing and resource allocation method for quantum key distribution, characterized in that, include: In response to a service being added to a preset waiting queue, it is determined whether the service is being added for the first time. If it is determined that the service is being added again, the service in the waiting queue is moved to the head of the queue. The link information between trusted nodes of a preset quantum channel is determined. Based on the link information, the attacked links are identified. The security level of the service at the top of the queue is determined. In response to determining that the service at the top of the queue is at the preset first security level, the path with the shortest hop count is determined as the target path. It is then determined whether all links of the target path have been attacked. In response to determining that all links have been attacked, the service at the top of the queue is added to the waiting queue. In response to determining that there are unattacked links, time slot resources and wavelength resources that meet preset freshness requirements are allocated to the target path, and the service at the top of the queue is executed. In response to determining that the service at the top of the queue is at a preset second security level, multiple candidate paths with the shortest hop counts are identified. It is then determined whether a candidate path from all candidate paths can be identified where all links are unaffected. If such a path is identified, it is used as the target path. Time slot resources and wavelength resources are allocated to the target path, and the service at the top of the queue is executed. If no path can be identified, the service at the top of the queue is encrypted using a classic key. The first security level is higher than the second security level.
2. The method according to claim 1, characterized in that, Before determining the link information between trusted nodes of the preset quantum channel, the method further includes: In response to receiving a preset service termination notification signal, the link information between the trusted nodes of the quantum channel is determined; In response to determining that no service termination notification signal has been received, the system continues to receive notification signals.
3. The method according to claim 1, characterized in that, The link information includes the key rate and the quantum error rate; The process of determining the attacked links based on the link information of each link includes: For each link, if the key rate is less than a preset first threshold and / or the quantum error rate is greater than a preset second threshold, then the link is determined to be under attack.
4. The method according to claim 1, characterized in that, After determining the attacked links based on the link information of each link, the process further includes: Update the attacked links to a preset set of attacked links; Update the replenishment cycle of quantum keys in the preset key pool, and update the capacity threshold of the key pool, whereby the capacity threshold represents the maximum capacity of quantum keys in the key pool.
5. The method according to claim 1, characterized in that, Each of the time slots contains multiple quantum keys; The allocation of time slot resources and wavelength resources that meet preset freshness requirements for the target path includes: Determine the freshness of each preset time slot, and identify candidate time slots whose freshness meets the freshness requirements; In response to determining that the number of candidate time slots meets a preset time slot number threshold, candidate time slots are allocated to the target path; And allocate preset wavelength resources for the target path.
6. The method according to claim 1, characterized in that, The determination of whether a candidate path can be identified from all candidate paths where none of the links have been attacked includes: Among all candidate paths, starting with the candidate path with the fewest hops, determine whether all links of that candidate path have not been attacked. In response to the determination that all links of the candidate path have not been attacked, the candidate path is determined as the target path; In response to the determination that there is an attacked link in the candidate path, the system determines whether all links in the next candidate path are unattacked, in ascending order of hop count. If, after traversing all candidate paths, it is determined that each candidate path has links that have been attacked, then it is determined that no candidate path can be determined where none of the links have been attacked.
7. The method according to claim 1, characterized in that, The allocation of time slot resources and wavelength resources for the target path includes: Determine whether the wavelength and time slot resources of the target path are sufficient; In response to the determination that wavelength resources are sufficient and time slot resources are sufficient, wavelength resources are allocated to the target path, and the time slot with the lowest freshness is allocated to the target path.
8. A network security routing and resource allocation device for quantum key distribution, characterized in that, include: The module consists of a business sorting module, a first business execution module, and a second business execution module. The service sorting module is configured to, in response to a service being added to a preset waiting queue, determine whether the service is being added for the first time, and in response to determining that the service is being added again, move the service in the waiting queue to the head of the queue. The first service execution module is configured to: determine the link information of the links between trusted nodes of a preset quantum channel; determine the attacked links based on the link information of each link; determine the security level of the service at the top of the queue; in response to determining that the service at the top of the queue is at a preset first security level, determine the path with the shortest hop count as the target path; determine whether all links of the target path have been attacked; in response to determining that all links have been attacked, add the service at the top of the queue to the waiting queue; in response to determining that there are unattacked links, allocate time slot resources and wavelength resources that meet preset freshness requirements to the target path, and execute the service at the top of the queue. The second service execution module is configured to, in response to determining that the service at the top of the queue is at a preset second security level, identify multiple candidate paths with the shortest hop count, determine whether a candidate path from all candidate paths can be identified where all links are not under attack, and in response to identifying such a candidate path, use the identified candidate path as the target path, allocate time slot resources and wavelength resources to the target path, and execute the service at the top of the queue; and in response to not identifying such a candidate path, encrypt the service at the top of the queue using a classic key, wherein the first security level is higher than the second security level.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing the computer to perform the method according to any one of claims 1 to 7.