Relay method and device for centralized quantum network key resource management

By selecting key relay nodes through graph theory modeling and uploading only a portion of the key XOR value, the problem of key waste in centralized quantum networks is solved, resource management is optimized, and latency is reduced.

CN118921168BActive Publication Date: 2025-12-16CHINA TELECOM QUANTUM TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411153359.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2025-12-16
Estimated Expiration
2044-08-21

AI Technical Summary

Technical Problem

The problem of wasted XOR values ​​in centralized quantum networks has not been effectively solved, leading to resource waste and user experience latency.

Method used

An undirected topology graph is constructed using graph theory modeling. Key relay nodes are selected based on the degree of the nodes. A subset of nodes are selected to form a relay routing path through key relay. Only the XOR value of the key nodes is uploaded, while other nodes wait for scheduling, thus reducing the waste of key resources.

Benefits of technology

While taking into account both system performance and user experience, it reduces the waste of centralized routing key resources and decreases the latency of user request key system response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118921168B_ABST
    Figure CN118921168B_ABST
Patent Text Reader

Abstract

The application discloses a relay method and device for centralized quantum network key resource management, and the method comprises the following steps: establishing a non-directional topological graph of a quantum network based on local relay node information of the quantum network, wherein the nodes of the non-directional topological graph are local relay nodes, the edges are the association relationships between the local relay nodes, and the degree of the node is the number of edges having the association relationship with the current node; and three types of centralized quantum network topological models, namely, I-type topological model, II-type topological model and III-type topological model, are proposed around key consumption; the I-type structure adopts non-collision node upload key XOR value, the II-type structure adopts a tolerance mechanism and allows the key XOR value of part of the uploaded nodes, and the III-type structure adopts a shortest path mechanism to select a key relay route for the system; and the application avoids the XOR value strategy of uploading all the nodes by selecting the XOR value strategy of the key nodes, so that the time delay of the system response to the user request key is sacrificed to reduce the waste of the centralized routing key resources.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security application products, and particularly relates to a relay method and device for centralized quantum network key resource management. BACKGROUND

[0002] In recent years, the state has vigorously developed quantum information technology, and quantum technology is a strong security base for information technology. Researchers and engineering and technical personnel respond to the call of the state and actively invest in the development of quantum network-related technologies and product landing. Quantum network construction has become an urgent task for the construction of new-generation networks.

[0003] In the standard "YD / T-4301 Quantum Communication Network Architecture", the architecture of the quantum network is carefully classified. The quantum network architecture can be divided into two categories according to the control mode, namely distributed and centralized. Although the standardized network architecture makes a reasonable division and design of the network layer, in actual application, different control modes determine that the control layer will adopt different key management methods. The distributed can use the key relay method to complete the key transfer, and the centralized uses the XOR value of the uploaded key to realize the key transfer of the quantum key distribution network controller (QKDNC). However, different control modes have different disadvantages. After the user applies for the key resource of the distributed quantum network, the QKDNC calculates the routing and completes the key relay through the generated key, but this key relay method has the disadvantage that the distributed quantum network will have time overhead due to the generation of the key and the calculation of the relay routing, which will cause a certain time delay in the intuitive experience of the user. The centralized quantum network uploads the XOR value of the local key management center (KM) in real time, and once the key is used, the key XOR value associated with it will be discarded, which will cause waste.

[0004] In the related art, the patent application document with the publication number CN116366237A proposes a centralized quantum key relay management method. The scheme proposes that the key relay management system stores the key XOR data of the relay node, the relay node no longer stores the key XOR data, and the key relay management system responds to the key relay request to parse the terminal node information and the key quantity demand information from the key relay request, queries the topology path containing the node corresponding to the terminal node information in the key topology, selects the target topology path from the multiple topology paths, the key quantity of each sub-topology path meets the key quantity demand information, obtains the key XOR data associated with the terminal node in the topology path as the target key XOR data, performs XOR operation on the target key XOR data associated with the terminal node information, and sends the XOR operation result to the corresponding terminal node. Therefore, the optimization target of the centralized quantum network strategy proposed by the scheme is to find the best path that meets the key quantity demand for the user, and the essence is to meet the key quantity demand of the user; in addition, the key topology constructed in the scheme is to find the next hop high-quality node resource with the edge information of the topology, and in the process of finding the next hop, the key quantity of the target node is constrained as a limit condition, so the key topology has a certain directionality, which is a directed topology graph.

[0005] In the quantum network virtualization architecture method proposed in the patent application document with the publication number CN110677241A, a combination problem is used to describe the actual problem, and C(n, 2) is used to calculate the combination number of nodes to list the routing state of virtual nodes, where n represents the node number value of the virtual node. In the document "Research on Routing and Resource Allocation Technology of Quantum Key Distribution Network Based on Partially Trusted Relay", Zou Xingyu, Master's Thesis", a cooperative routing ILP model of the QKD network based on partially trusted relay is proposed, and the optimization key waste problem is the key consumption of the encryption service and the key consumption of the encryption service key.

[0006] In addition, the related technologies listed above cannot solve the waste problem of the key XOR value of the centralized network. SUMMARY

[0007] The present application aims to solve the waste problem of the key XOR value of the centralized network.

[0008] The present application solves the above technical problems by the following technical means:

[0009] On the one hand, a relay method for centralized quantum network key resource management is proposed, which comprises:

[0010] establishing an undirected topological graph of the quantum network based on information of the local relay nodes of the quantum network, wherein nodes of the undirected topological graph are the local relay nodes, edges of the undirected topological graph are association relationships between the local relay nodes, and a degree of a node is a number of edges having an association relationship with the current node;

[0011] when the undirected topological graph is of type I topology, selecting a node having a degree of 2 from the local relay nodes as a first key relay node based on the degrees of the nodes, and screening part of the nodes from the remaining local relay nodes to form a relay routing path with the first key relay node in a key relay manner;

[0012] when the undirected topological graph is of type II topology, selecting a node having a degree of 3 from the local relay nodes as a second key relay node based on the degrees of the nodes, and screening part of the nodes from the remaining local relay nodes to form a relay routing path with the second key relay node in a key relay manner;

[0013] when the undirected topological graph is of type III topology, screening part of the nodes from all the local relay nodes to perform distributed routing in a key relay manner;

[0014] wherein, in the type I topology, the minimum degree of the nodes is 2 except for the nodes having a degree of 1; in the type II topology, the minimum degree of the nodes is 3 except for the nodes having a degree of 1; and in the type III topology, the minimum degree of the nodes is greater than 3 except for the nodes having a degree of 1.

[0015] Further, the KM device and the QKD device form the local relay nodes, the edges between the nodes are matching relationships between the QKD devices to represent a pair of nodes for key distribution, and a value of an edge is a key negotiation value generated between a QKD device and an adjacent QKD device.

[0016] Further, the screening of part of the nodes from the remaining local relay nodes to form a relay routing path with the first key relay node in a key relay manner comprises:

[0017] finding part of the nodes that can form a minimum path with the first key relay node from the remaining local relay nodes as a screening condition according to the shortest distance between the nodes.

[0018] Further, the screening of part of the nodes from the remaining local relay nodes to form a relay routing path with the second key relay node in a key relay manner as a screening condition according to the shortest distance between the nodes comprises:

[0019] finding part of the nodes that can form a minimum path with the second key relay node from the remaining local relay nodes as a screening condition according to the shortest distance between the nodes.

[0020] Further, when the undirected topology graph is type III topology, the method comprises:

[0021] The part of the local relay nodes are selected for performing the distributed routing according to the shortest distance.

[0022] Further, the method further comprises:

[0023] Receiving the key XOR value of the edge on which the two nodes associated with the first key relay node are located uploaded by the first key relay node or receiving the key XOR value of the edge on which the two nodes associated with the second key relay node are located uploaded by the second key relay node;

[0024] Performing the distributed routing on the relay routing path.

[0025] Further, the degree of the key relay node is determined according to the following objective function:

[0026]

[0027] In the formula, d i represents the degree of the i-th local relay node, and N represents the total number of the local relay nodes.

[0028] In a second aspect, the application further provides a relay device for centralized quantum network key resource management, and the system comprises:

[0029] A topology graph construction module is configured to establish an undirected topology graph of a quantum network based on local relay node information of the quantum network, wherein the nodes of the undirected topology graph are the local relay nodes, the edges of the undirected topology graph are the association relationships between the local relay nodes, and the degree of a node is the number of edges having an association relationship with the current node.

[0030] A first path identification module is configured to, when the undirected topology graph is type I topology, select a node having a degree of 2 as a first key relay node from the local relay nodes based on the degree of the node, and select part of the local relay nodes from the remaining local relay nodes to form a relay routing path together with the first key relay node in a key relay manner.

[0031] A second path identification module is configured to, when the undirected topology graph is type II topology, select a node having a degree of 3 as a second key relay node from the local relay nodes based on the degree of the node, and select part of the local relay nodes from the remaining local relay nodes to form a relay routing path together with the second key relay node in a key relay manner.

[0032] A third path identification module is configured to, when the undirected topology graph is a III-type topology, select part of nodes from all local relay nodes by using a key relay mode to perform distributed routing;

[0033] In the I-type topology, the minimum degree of the nodes is 2 except for the nodes with a degree of 1; in the II-type topology, the minimum degree of the nodes is 3 except for the nodes with a degree of 1; and in the III-type topology, the minimum degree of the nodes is greater than 3 except for the nodes with a degree of 1.

[0034] In a third aspect, the application further provides a quantum key distribution network controller, which comprises a memory and a processor; the processor runs a program corresponding to executable program code stored in the memory, so as to implement the relay method for centralized quantum network key resource management.

[0035] In a fourth aspect, the application further provides a computer readable storage medium, which stores a computer program; when the computer program is executed by a processor, the relay method for centralized quantum network key resource management is implemented.

[0036] The application has the following advantages:

[0037] (1) The application models the topology structure of the centralized quantum network by using the graph theory modeling method, and represents the degree of the nodes as the number of edges having a correlation with the current node; under the condition that the topology of the centralized quantum network is established, the network is invariable, and the degree of the nodes is invariable; the degree of the nodes is used to represent the tolerable degree of key loss; in order to balance the system and the user experience, a compromise is made between the user and the system; in each resource management period, the key relay nodes are selected from the local relay nodes based on the degree of the nodes; the degree of the key relay nodes represents the tolerable degree of key loss, that is, only the XOR value of the key of part of the local relay nodes is uploaded, so that the XOR value strategy of the key of the selected key nodes is used to avoid the XOR value strategy of the key of all the nodes, a little time delay of the system response to the user request for the key is sacrificed, and the waste of the key resources of the centralized routing is reduced.

[0038] Additional aspects and advantages of the application will be made apparent by the following description. BRIEF DESCRIPTION OF DRAWINGS

[0039] Figure 1 is a centralized quantum network key XOR uploading schematic diagram in an embodiment of the application;

[0040] Figure 2 is a centralized quantum network KM undirected graph in an embodiment of the application;

[0041] Figure 3 is a flowchart of a relay method of centralized quantum network key resource management according to an embodiment of the present application;

[0042] Figure 4 is a schematic diagram of uploading XOR values of nodes in a type I centralized quantum network topology according to an embodiment of the present application;

[0043] Figure 5 is a schematic diagram of uploading XOR values of nodes in a type II centralized quantum network topology according to an embodiment of the present application;

[0044] Figure 6 is a schematic diagram of uploading XOR values of nodes in a type III centralized quantum network topology according to an embodiment of the present application;

[0045] Figure 7 is a flowchart of a quantum network key resource optimization management strategy according to an embodiment of the present application;

[0046] Figure 8 is a structural schematic diagram of a relay device of centralized quantum network key resource management according to an embodiment of the present application;

[0047] Figure 9 is a structural schematic diagram of a quantum key distribution network controller according to an embodiment of the present application. DETAILED DESCRIPTION

[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in a clear and complete manner with reference to the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0049] As shown in Figure 1 , a centralized quantum network key XOR uploading schematic diagram is described, a network node receiving quantum keys from only one QKD device is regarded as a user node, and other network nodes are regarded as local relay nodes. The local relay nodes and the user nodes can both connect a user service system and provide quantum key services externally, but only the local relay nodes upload quantum keys generated by different links after XOR operation. The local KM node, also referred to as a local KM node, needs to generate XOR values of two sides of the node in real time and upload to the centralized KM in the QKDNC, and the key management requested by the user is completed in the manner of centralized calculation of XOR values by the QKDNC. Figure 1When a user at the central end sends a key request to the centralized quantum network, the centralized quantum network collects the XOR values ​​of keys from different KM nodes in real time, uploads them to the QKDNC, and performs the XOR operation to directly fulfill the key request from the user at the other end.

[0050] like Figure 2 As shown in the diagram, the points where QKD devices and KM devices are located are abstracted as relay nodes. The relationships between KM nodes are represented by edges in an undirected graph. Each edge represents the key generation between QKD devices within the same node. The degree of a node indicates its matching relationship with its neighboring nodes; a higher degree indicates that the node has generated keys with more QKD nodes. Figure 1 The key XOR value is generated by XORing the keys generated between two adjacent nodes of a node. The higher the node's degree, the more XOR value sequences are generated. The degree of a node is d. i 'i' represents the node index, and the associated edges are their degree values. For example, if node 2 is associated with 3 edges, then the degree of node 2 is represented as 'd'. i =3. The higher the degree, the more the XOR values ​​of the keys of each pair of nodes satisfy the combination formula. For example, the XOR value of the key generated by node 2 based on the associated edge is:

[0051]

[0052] Using a centralized key management approach, the XOR value of the key is uploaded to QKDNC by each node. Assuming there are N nodes in total, the number of XOR values ​​uploaded by N nodes to QKDNC is:

[0053]

[0054] like Figure 4 The diagram shown illustrates a centralized quantum network key relay strategy. Figure 4 The nodes and edges mentioned in the text are still in accordance with Figure 1 The graph described is abstracted as an undirected topological graph. Figure 4 The nodes and edges of the undirected graph are arranged according to... Figure 2 Definition. For Figure 4 The diagram shows an undirected graph with N nodes. Assume that due to the centralized and continuous uploading of XOR values, the key is discarded after each XOR value is used. For example, node 2 has three XOR values ​​for its key: K... 12 +K 25 K 12 +K 23 K 23 +K 25 Assume K 12 +K 25 If the key XOR value is used, then K 12The associated edge combination and K 25 The other XOR values of node 2 are discarded, and L is defined as the lost key, d i >1, and the lost key of node 2 is L:

[0055]

[0056] Therefore, the key consumption of the whole key of the N-node centralized key is L:

[0057]

[0058] In order to reduce the key loss of the centralized quantum network, an optimization objective is established to describe the key consumption of the centralized quantum network as follows:

[0059]

[0060] According to the above optimization objective, the network can adopt a key relay mode to avoid minimizing the above loss. It is assumed that the N nodes in the centralized network only participate in strategy making, and all nodes wait to be scheduled. When the distributed routing is performed, the key consumption is 0. However, this mode will cause the user to have time overhead for waiting for the key relay strategy making and the key XOR value generation. Therefore, this mode is not desirable.

[0061] In order to balance the system and user experience, the embodiment makes a compromise between the system optimization objective and the time overhead of the user waiting. That is, in each resource management period, only part of the local relay nodes upload the key XOR value to the quantum centralized network QKDNC, and the remaining local relay nodes do not upload. In this case, an approximation optimization objective is adopted to establish a strategy for scheduling nodes, and the XOR value strategy of the key node selected by the strategy avoids the XOR value strategy of all nodes. In this way, the time delay of the system response to the user request for keys is sacrificed to reduce the problem of waste of centralized routing key resources. Therefore, as shown in Figure 3 Fig. 1, an embodiment of the present application proposes a relay method for centralized quantum network key resource management, which is applied to a quantum key distribution network controller. The method comprises the following steps:

[0062] S10, a directed topology graph of a quantum network is established based on local relay node information of the quantum network. The nodes of the directed topology graph are local relay nodes, the edges of the directed topology graph are the association relationships between the local relay nodes, and the degree of the node is the number of edges having an association relationship with the current node.

[0063] In particular, the embodiment depicts the quantum centralized network topology as an undirected graph, wherein the quantum centralized network key network undirected topology graph is denoted as C(V, E), the nodes v i are KM nodes, v i ∈ V, wherein the KM device and the QKD device jointly constitute a relay node of the centralized quantum network, the edges e i,j between the nodes of the undirected topology graph are matches between QKD devices and QKD devices, indicating that there is an association relationship between the nodes of a pair of nodes i, j for key distribution, and the value of the edge is the key generated between the QKD device and the QKD device, i.e., the value of the edge is the value of the key negotiation between the node i and the node j, denoted as k ij The degree of the node is used to depict the association relationship between the node and the neighbor node, and the value of the degree of the node is the number of associated edges, wherein d i denotes the degree of the i-th node.

[0064] Further, the key waste problem of the centralized quantum network is analyzed by using the graph theory modeling method, and three types of centralized quantum network topology models are proposed around the key consumption, which are type I, type II, and type III topology networks; in the type I topology, the degree of the node is at least 2 except for the node with a degree of 1; in the type II topology, the degree of the node is at least 3 except for the node with a degree of 1; and in the type III topology, the minimum value of the degree of the node is greater than 3 except for the node with a degree of 1.

[0065] S20, when the undirected topology graph is a type I topology, a node with a degree of 2 is selected as a first key relay node from the local relay nodes based on the degree of the node, and part of the nodes are screened out from the remaining local relay nodes in a key relay manner to form a relay routing path with the first key relay node;

[0066] S30, when the undirected topology graph is a type II topology, a node with a degree of 3 is selected as a second key relay node from the local relay nodes based on the degree of the node, and part of the nodes are screened out from the remaining local relay nodes in a key relay manner to form a relay routing path with the second key relay node;

[0067] S40, when the undirected topology graph is a type II topology, part of the nodes are screened out from all the local relay nodes in a key relay manner for performing distributed routing.

[0068] It should be noted that the number of the keys XOR values that can be generated by the node according to the combination problem is The greater the degree of the node, the higher the correlation degree of the node with its periphery, and thus the degree of the node can be used to represent the tolerance degree of key loss, and the degree of each relay node can be used to select a key relay node to directly upload the key XOR value, that is, only part of the local relay nodes are scheduled to upload the key XOR value, so that the XOR value strategy of the key node selected by the strategy avoids the XOR value strategy of all nodes.

[0069] Specifically, the key XOR value is uploaded by the key node in the I-type network topology and the II-type network topology, and the system considers that the uploaded part of the XOR value is tolerable, and the key consumption L=0 only occurs in the III-type network topology, which is considered as a special case in which the XOR value cannot be uploaded in the present case.

[0070] As a further preferred technical solution, in step S20, part of the nodes are selected from the remaining local relay nodes to form a relay routing path with the first key relay node in a key relay manner, comprising:

[0071] According to the shortest node distance as the screening condition, part of the nodes are searched from the remaining local relay nodes to form a minimum path with the first key relay node.

[0072] Specifically, in the I-type topology, the non-conflict nodes upload the key XOR value, the relay nodes with a degree of 2 are found as key intermediate nodes, and the key XOR values on the edges of the two relay nodes associated with each key relay node are uploaded to the centralized quantum network in real time. The remaining relay nodes are used as scheduling nodes and do not upload the key value, but wait for the QKDNC to find the minimum path according to the shortest node distance as the screening condition to wait for scheduling.

[0073] As a further preferred technical solution, in step S30, part of the nodes are selected from the remaining local relay nodes to form a routing path with the second key relay node in a node distance shortest manner, comprising:

[0074] According to the shortest node distance as the screening condition, part of the nodes are searched from the remaining local relay nodes to form a minimum path with the second key relay node.

[0075] Specifically, in the II-type structure, the tolerance mechanism is adopted, and the key XOR value of part of the nodes is allowed to be uploaded, that is, the relay nodes with a degree of 3 are defined as tolerable nodes, and the key XOR values on the edges of the two nodes associated with each tolerable node are calculated and uploaded to the centralized quantum network in real time. The remaining relay nodes are used as scheduling nodes and do not upload the key value, but wait for the QKDNC to find the minimum path according to the shortest node distance as the screening condition to wait for scheduling.

[0076] As a further preferred technical solution, step S40: when the undirected topology graph is a Type III topology, a subset of nodes are selected from all local relay nodes using a key relay method to perform distributed routing, including:

[0077] Select a subset of nodes from all local relay nodes to perform distributed routing, based on the shortest node distance as the filtering criterion.

[0078] Specifically, the Type III structure uses the shortest path mechanism to select key relay routes for the system. The Type III structure is a star network with high correlation between nodes. In this case, uploading the XOR value of a node key will result in a large amount of key waste. Therefore, the optimal strategy is for all relay nodes to wait for QKDNC to find the shortest path based on the shortest node distance and wait for scheduling. The nodes that are scheduled in real time complete the route calculation in a distributed routing manner.

[0079] Specifically, by Figure 2 and Figure 4 Analysis reveals that, given the established centralized quantum network topology, the network remains constant, as does the degree of each node. Nodes with a degree greater than 2 will incur key consumption. Therefore, the strategy only allows nodes with a degree of 2 in the centralized network to upload the XOR value of their keys; other nodes are not uploaded. Node 1 will not incur key consumption. i =2 indicates that node i has two neighboring nodes and there are two associations between these three nodes. A node degree of 2 means there will be no conflict. Nodes with a degree greater than 2 are considered to have a key XOR value conflict, and are defined as conflicting nodes. Figure 4 In a type I topology, a node with a degree of 2 is... Figure 4 The diagram shows nodes 3, 4, and 5. The XOR value of the generated key is: K for node 3. 23 +K 34 Node 4 is K 34 +K 46 Node 5 is K 25 +K 56 For the remaining local relay nodes excluding the critical relay nodes, the shortest distance priority is used to form a key route before scheduling. That is, QKDNC waits for the remaining relay nodes to select some nodes to participate in the distributed routing calculation key relay route at both ends based on the shortest node distance as the filtering condition.

[0080] like Figure 4 As shown, assuming the user initiator is node 1 and the receiver is node 8, and assuming the route calculated by the controller QKDNC is 1-2-5-6-8, the 2-5-6 segment is the relay route information calculated by the centralized policy, and the XOR value uploaded by the key relay node 5 is K. 25+K 56 , XOR value K 25 +K 56 is pre-computed and exists in the controller. After determining the complete key relay routing path information 1-2-5-6-8, K 25 +K 56 will be disassembled XOR value to get the key K 25 , K 56 , and the controller schedules the QKD device where node 1-node 2 to generate the key negotiation value K 12 , and the QKD device where node 6-node 8 to generate the key negotiation value K 68 , and K 12 and K 68 are securely transmitted to the controller QKDNC, and the controller QKDNC calculates the distributed routing according to the key K 12 , K 25 , K 56 , K 68 to perform key relay. This embodiment sacrifices a little time delay of the system response to the user's request key by pre-computing and pre-existing in the controller part of the pre-prepared key K 25 and K 56 , to reduce the waste of key resources of centralized routing.

[0081] As shown in Figure 5 , to supplement Figure 4 a special case of a centralized quantum network key relay strategy diagram, assuming that the centralized quantum network only exists for the special case of nodes of 3 and above, define Figure 5 the topology shown in II type topology. As shown in Figure 5 , the degree of N nodes is at least 1, and the others are all node degrees of 2 or more. In this case, the minimum node degree of the system is 3, and it is node 2, node 3, and node 7. Then the XOR value can be calculated for these three nodes and uploaded to QKDNC, and it can be considered that the loss brought by uploading the key XOR value of the node with a degree of 3 can be tolerated.

[0082] In addition, in addition to the node with a degree of 1, the network structure with a minimum node degree of 4 or 5 or 6, etc. is defined as III type structure, which will no longer be relaxed (as shown in Figure 6 ). This network actually conforms to the star structure, and each node is associated with many other nodes. If the key XOR value of any node is uploaded, it will bring more loss to the cryptographic system. In this case, it can be considered not to upload the XOR value but to use the key relay method to select the node participating in the distributed routing calculation each time.

[0083] Specifically, as shown in Figure 7As shown, in order to better illustrate the method of policy execution, the method of policy execution is described as a whole as follows:

[0084] (1) Undirected graph establishment, according to the network topology output is the centralized quantum network undirected graph;

[0085] (2) Calculate the node degree, calculate the node degree of each node according to the centralized quantum network undirected graph, and need to be sorted;

[0086] (3) Confirm the centralized quantum network topology model, judge the topology structure is I, II, III type structure;

[0087] (4) Identify nodes, if I, II type, I type identifies all nodes with degree 2; II type identifies all nodes with degree 3, if not, go to step (7);

[0088] (5) Upload key XOR value, calculate the key XOR value of the edge where the identified node is located and upload it to QKDNC;

[0089] (6) Key calculation, the remaining nodes participate in key routing selection, select relay routing for the remaining nodes according to the minimum path, and combine the above steps to provide QKDNC calculation;

[0090] (7) According to the minimum path, select the relay routing for the remaining nodes, and provide the QKDNC calculation for the scheduled nodes.

[0091] It should be noted that the embodiment adopts the graph theory modeling method to analyze the key waste problem of the centralized quantum network, and proposes three types of centralized quantum network topology models for the key consumption, which are I, II and III type topology structures. And for the three types of network topology structures, the key relay strategy is proposed, the I type structure uploads the key XOR value of the non conflict node, the II type structure adopts the tolerance mechanism, allows to upload the key XOR value of part of the nodes, and the III type structure adopts the shortest path mechanism to select the key relay routing for the system. Compared with the traditional centralized quantum network key management method, the embodiment analyzes the key waste problem of the centralized quantum network, describes the key waste problem into a mathematical graph theory problem, and describes the mathematical problem of key XOR value waste by using combination problem. And the key resource management of the centralized quantum network is optimized, considering the user experience and the key management complexity of the system, a compromise is made between the user and the system, and three key management strategies for different network topologies are proposed.

[0092] In addition, for the local relay node in Figure 4 to Figure 6 , the process of uploading the key XOR value is as follows:

[0093] sending quantum network local relay node information to a quantum key distribution network controller for the quantum key distribution network controller to establish an undirected topology graph of a quantum network, nodes of the undirected topology graph being local relay nodes, edges of the undirected topology graph being association relationships between the local relay nodes, and a degree of a node being a number of edges having an association relationship with the current node;

[0094] receiving a key relay node identifier issued by the quantum key distribution network controller and determining whether the local relay node corresponding to the identifier is itself;

[0095] if yes, uploading a key XOR value of an associated edge to the QKDNC;

[0096] if no, waiting for a call from the quantum key distribution network controller.

[0097] In addition, as Figure 8 shown, another embodiment of the present application proposes a relay device for centralized quantum network key resource management, the system comprising:

[0098] a topology graph construction module 10 for establishing an undirected topology graph of a quantum network based on quantum network local relay node information, nodes of the undirected topology graph being local relay nodes, edges of the undirected topology graph being association relationships between the local relay nodes, and a degree of a node being a number of edges having an association relationship with the current node;

[0099] a first path identification module 20 for, when the undirected topology graph is an I-type topology, selecting a node having a degree of 2 from the local relay nodes as a first key relay node based on the degree of the node, and screening part of the nodes from the remaining local relay nodes to form a relay routing path with the first key relay node in a key relay manner;

[0100] a second path identification module 30 for, when the undirected topology graph is a II-type topology, selecting a node having a degree of 3 from the local relay nodes as a second key relay node based on the degree of the node, and screening part of the nodes from the remaining local relay nodes to form a relay routing path with the second key relay node in a key relay manner;

[0101] a third path identification module 40 for, when the undirected topology graph is a III-type topology, screening part of the nodes from all the local relay nodes to perform distributed routing in a key relay manner;

[0102] wherein, in the I-type topology, the degree of a node is at least 2 except for a node having a degree of 1; in the II-type topology, the degree of a node is at least 3 except for a node having a degree of 1; and in the III-type topology, the minimum degree of a node is greater than 3 except for a node having a degree of 1.

[0103] The embodiment adopts a graph theory modeling manner to model the topology structure of the centralized quantum network, represents the degree of the node as the number of edges having an association relationship with the current node, and uses the degree of the node to represent the tolerable degree of key loss. In order to balance the system and user experience, a compromise is made between the user and the system. In each resource management period, the key relay node is selected from the local relay node based on the degree of the node. The degree of the key relay node represents the tolerable degree of key loss, that is, only the XOR value of the key of the partial local relay node is uploaded, so that the XOR value strategy of the key of the selected key node is used to avoid the XOR value strategy of the key of all nodes. The time delay of the system response to the user request key is sacrificed to reduce the problem of waste of key resources of the centralized routing.

[0104] As a further preferred technical solution, the KM device and the QKD device constitute the local relay node, and the value of the edge in the undirected topology graph is a key negotiation value generated between the QKD device and the adjacent QKD device.

[0105] As a further preferred technical solution, the first path identification module 20 is specifically configured to find part of the nodes that can form the minimum path with the first key relay node from the remaining local relay nodes according to the node distance shortest as a screening condition.

[0106] As a further preferred technical solution, the second path identification module 30 finds part of the nodes that can form the minimum path with the second key relay node from the remaining local relay nodes according to the node distance shortest as a screening condition.

[0107] As a further preferred technical solution, the third path identification module 40 is specifically configured to screen part of the nodes from all the local relay nodes according to the node distance shortest as a screening condition for executing the distributed routing.

[0108] As a further preferred technical solution, the degree of the key node is determined according to the following target function:

[0109]

[0110] In the formula, d i represents the degree of the i-th local relay node, and N represents the total number of the local relay nodes.

[0111] It should be noted that other embodiments of the relay device for key resource management of the centralized quantum network or the implementation method of the relay device can refer to the above-mentioned method embodiments, which will not be repeated here.

[0112] In addition, the device as described above can be implemented in the form of a computer program, which can run on a computer device as shown in the figure. Figure 9 .Figure 9 is a structural schematic block diagram of a computer device provided by an embodiment of the present application. The computer device can be a server.

[0113] The computer device includes a processor, a memory and a network interface connected through a system bus, wherein the memory can include a non-volatile storage medium and an internal memory.

[0114] The non-volatile storage medium can store an operating system and a computer program. The computer program includes program instructions which, when executed, can cause the processor to perform any one of the relay methods for centralized quantum network key resource management.

[0115] The processor is configured to provide computing and control capabilities to support the operation of the entire computer device.

[0116] The internal memory provides an environment for the operation of the computer program in the non-volatile storage medium, which, when executed by the processor, can cause the processor to perform any one of the relay methods for centralized quantum network key resource management.

[0117] The network interface is configured to perform network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that Figure 9 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0118] In addition, the present embodiment also proposes a computer readable storage medium, which stores a computer program, and the computer program includes program instructions. The processor executes the program instructions to implement the relay method for centralized quantum network key resource management provided by the above-mentioned embodiments of the present application.

[0119] It is to be appreciated that the above description and the examples that follow are intended to be illustrative only and that changes can be made to the description, either functionally or chronologically, as well as changes being made concerning which elements of the description and / or examples are employed per se, all without departing from the spirit and scope of the application. It should be further appreciated that the logic and / or steps represented in the flow diagrams and / or otherwise described herein, for example, can be considered as a sequence of executable instructions executed by a logic processor, such as a processing system, including a processor, or other logic processor-based system, or in conjunction with such an instruction execution system. In this regard, the "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer readable medium can comprise any one of the following: an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer readable medium include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disc read-only memory (CDROM). In addition, the computer readable medium can even be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, for example via optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and then stored in a computer memory.

[0120] It should be understood that aspects of the application can be implemented in hardware, software, firmware or combinations thereof. In the above embodiments, various steps or methods can be implemented in software or firmware that is stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any of the following technologies, or combinations thereof, can be used with the necessary logic gates and circuitry supporting logic functions for the data signals: discrete logic circuitry having logic gates for implementing logic functions upon data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and so forth.

[0121] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Also, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in an appropriate manner.

[0122] Furthermore, the terms "first", "second", etc. are used only for descriptive purposes and do not connote or imply relative importance or a quantity of the indicated technical features. Thus, a feature defined with "first", "second", etc. can include at least one of the features implicitly or explicitly. In the description of the present application, the meaning of "a plurality" is at least two, for example, two, three, etc., unless otherwise specifically defined.

[0123] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary and are not to be construed as limiting the present application, and that changes, modifications, substitutions and variations can be made by those skilled in the art without departing from the scope of the present application.

Claims

1. A relay method for centralized quantum network key resource management, characterized in that, The method includes: An undirected topology graph of a quantum network is established based on the local relay node information of the quantum network. The nodes of the undirected topology graph are local relay nodes, the edges of the undirected topology graph are the association relationships between local relay nodes, and the degree of a node is the number of edges that are associated with the current node. KM devices and QKD devices constitute the local relay nodes, and the edges between nodes are the matching relationships between QKD devices to represent a pair of nodes for key distribution. When the undirected topology is of type I, a node with a degree of 2 is selected from the local relay nodes based on the degree of the node as the first key relay node. The key XOR value of the edge where the two associated nodes are located is uploaded by the first key relay node. Then, some nodes are selected from the remaining local relay nodes in the key relay mode to form a relay routing path with the first key relay node. When the undirected topology is a Type II topology, a node with a degree of 3 is selected from the local relay nodes based on the degree of the node as the second key relay node. The key XOR value of the edge where the two associated nodes are located is uploaded by the second key relay node. Then, some nodes are selected from the remaining local relay nodes in the key relay mode to form a relay routing path with the second key relay node. When the undirected topology is a Type III topology, a key relay method is used to select some nodes from all local relay nodes for distributed routing. In Type I topology, the minimum degree of a node is 2, except for nodes with a degree of 1; in Type II topology, the minimum degree of a node is 3, except for nodes with a degree of 1; and in Type III topology, the minimum degree of a node is greater than 3, except for nodes with a degree of 1.

2. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, The edge value is the key negotiation value generated between the QKD device and its neighboring QKD devices.

3. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, The step of selecting a subset of nodes from the remaining local relay nodes using a key relay method to form a relay routing path with the first key relay node includes: Based on the shortest node distance as the filtering criterion, find the nodes from the remaining local relay nodes that can form the shortest path with the first key relay node.

4. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, The step of selecting a subset of nodes from the remaining local relay nodes and forming a routing path with the second key relay node based on the shortest node distance includes: Based on the shortest node distance as the filtering criterion, find the nodes from the remaining local relay nodes that can form the shortest path with the second key relay node.

5. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, When the undirected topology is a Type III topology, a subset of nodes is selected from all local relay nodes using a key relay method to perform distributed routing, including: Select a subset of nodes from all local relay nodes to perform distributed routing, based on the shortest node distance as the filtering criterion.

6. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, The method further includes: Distributed routing is performed on the relay routing path.

7. The relay method for centralized quantum network key resource management as described in claim 1, characterized in that, The degree of the key relay node is determined according to the following objective function: In the formula, d i Let N represent the degree of the i-th local relay node, and N represent the total number of local relay nodes.

8. A relay device for centralized quantum network key resource management, characterized in that, The system includes: The topology graph construction module is used to build an undirected topology graph of the quantum network based on the local relay node information of the quantum network. The nodes of the undirected topology graph are local relay nodes, the edges of the undirected topology graph are the association relationships between local relay nodes, and the degree of a node is the number of edges that are associated with the current node. KM devices and QKD devices constitute the local relay nodes, and the edges between nodes are the matching relationships between QKD devices to represent a pair of nodes for key distribution. The first path identification module is used to select a node with a degree of 2 from the local relay nodes as the first key relay node based on the degree of the node when the undirected topology graph is of type I. It also receives the key XOR value of the edge where the two associated nodes are located uploaded by the first key relay node, and selects some nodes from the remaining local relay nodes in a key relay manner to form a relay routing path with the first key relay node. The second path identification module is used to select a node with a degree of 3 from the local relay nodes as the second key relay node based on the degree of the node when the undirected topology graph is a type II topology, and to receive the key XOR value of the edge where the two associated nodes are located uploaded by the second key relay node, and to filter out some nodes from the remaining local relay nodes in a key relay manner to form a relay routing path with the second key relay node. The third path identification module is used to select a portion of the nodes from all local relay nodes for distributed routing when the undirected topology graph is a Type III topology, using a key relay method. In Type I topology, the minimum degree of a node is 2, except for nodes with a degree of 1; in Type II topology, the minimum degree of a node is 3, except for nodes with a degree of 1; and in Type III topology, the minimum degree of a node is greater than 3, except for nodes with a degree of 1.

9. A quantum key distribution network controller, characterized in that, The device includes a memory and a processor; wherein the processor runs a program corresponding to the executable program code stored in the memory to implement the relay method for centralized quantum network key resource management as described in any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the relay method for centralized quantum network key resource management as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Quantum network virtualization architecture method and device

    CN110677241A

  • Centralized quantum key relay management and control method, system and relay node

    CN116366237A

  • Quantum key relay method and apparatus based on centralized management and control network

    CN108023725A

  • Quantum key relay method

    CN109995515A