A quantum-secure communication system and its method for establishing an encrypted tunnel

By pre-creating multiple processes and threads on the CPU of the Quantum Security Gateway, multi-process and multi-thread concurrency is achieved, the problem of excessive CPU usage when multiple service terminals in the quantum security communication system are solved, and the efficiency and reliability of establishing an encrypted tunnel are improved.

CN118972055BActive Publication Date: 2025-05-30FANERJIA INTELLIGENT ELECTRIC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411293711.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-14
Publication Date
2025-05-30
Estimated Expiration
2044-09-14

AI Technical Summary

Technical Problem

When the quantum security communication system applies to establish encrypted tunnels at the same time when multiple service terminals apply to establish encrypted tunnels, the CPU usage rate of the quantum security gateway is too high, resulting in the inability to quickly establish multiple encrypted tunnels. As the number of quantum security gateways increases, the network and security protection configurations are complex, affecting reliability.

Method used

Each CPU of the Quantum Security Gateway pre-creates multiple processes for establishing an encrypted tunnel, and each process pre-creates multiple threads for performing the task of establishing an encrypted tunnel, thereby realizing multi-process and multi-thread concurrency, improving the efficiency and reliability of establishing an encrypted tunnel.

Benefits of technology

Through multi-process and multi-thread concurrency, the quantum security gateway can handle the applications of multiple service terminals at the same time, realize load balancing, improve the efficiency and reliability of establishing encrypted tunnels, and avoid performance degradation caused by excessive CPU usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972055B_ABST
    Figure CN118972055B_ABST
Patent Text Reader

Abstract

The present application proposes a quantum-secure communication system and a method for establishing an encrypted tunnel. The quantum-secure communication system includes a quantum-secure gateway, a service terminal, and a key management platform. The quantum-secure gateway includes multiple CPUs. Each CPU pre-creates multiple processes, and each process pre-creates multiple threads. When multiple service terminals simultaneously apply to establish an encrypted tunnel, the task of establishing the encrypted tunnel is sequentially assigned to the CPU with the lowest current load in the order of application, and is executed by the idle thread of the process with the lowest current load in this CPU. The quantum-secure gateway negotiates and establishes an encrypted channel with the corresponding service terminal, and establishes the tunnel mode of the encrypted channel based on the quantum key distributed by the key management platform. In the present application, the quantum-secure gateway includes multiple processes and multiple threads for creating encrypted tunnels, and can "concurrently" establish encrypted tunnels with multiple service terminals based on multi-process and multi-thread, so as to improve the efficiency and reliability of establishing encrypted tunnels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and particularly relates to a quantum-secure communication system and a method for establishing an encrypted tunnel thereof. Background Art

[0002] A quantum-secure communication system generally includes a quantum-secure gateway, service terminals, and a key management platform. During the secure communication process of the quantum-secure communication system, the quantum-secure gateway needs to negotiate with the service terminals to establish an encrypted channel, and at the same time apply for quantum keys from the key management platform and call the tunnel mode of the quantum keys to establish the encrypted channel. It can be seen that the process of establishing an encrypted tunnel in the quantum-secure communication system is relatively complex. When multiple service terminals apply to establish encrypted tunnels simultaneously, after the quantum-secure gateway completes one encrypted tunnel establishment task, it then processes the application of the next service terminal and executes a new encrypted tunnel establishment task, that is, multiple encrypted tunnel establishment tasks are "serialized" in the quantum-secure gateway, which easily leads to an excessive CPU usage rate of the quantum-secure gateway, thus making it impossible to quickly establish multiple encrypted tunnels.

[0003] To improve the efficiency of establishing encrypted tunnels in the quantum-secure communication system, some quantum-secure communication systems are provided with multiple quantum-secure gateways to increase the number of service terminals that can be accessed and the speed of establishing encrypted tunnels. However, with the increase in the number of quantum-secure gateways, the network and security protection configurations among the quantum-secure gateways, service terminals, and key management platforms become more and more complex, affecting the reliability of establishing encrypted tunnels. Summary of the Invention

[0004] This application is precisely proposed based on the above-mentioned needs of the prior art. The technical problem to be solved by this application is to provide a quantum-secure communication system and a method for establishing an encrypted tunnel thereof. Each CPU of the quantum-secure gateway pre-creates multiple processes for establishing encrypted tunnels, and each process pre-creates multiple threads for executing encrypted tunnel establishment tasks, so that the quantum-secure gateway can "concurrently" establish encrypted tunnels with multiple service terminals based on multi-process and multi-thread, thereby improving the efficiency and reliability of establishing encrypted tunnels.

[0005] To solve the above problems, this application provides the following technical solutions.

[0006] The present application proposes a method for establishing an encrypted tunnel in a quantum-secure communication system. The quantum-secure communication system includes a quantum-secure gateway, service terminals, and a key management platform. The quantum-secure gateway includes multiple CPUs. The method for establishing an encrypted tunnel in the quantum-secure communication system includes: creating processes and threads: Each CPU pre-creates multiple processes for establishing encrypted tunnels, and each process pre-creates multiple threads for executing the tasks of establishing encrypted tunnels; task allocation: When multiple service terminals simultaneously apply to the quantum-secure gateway to establish encrypted tunnels, the tasks of establishing encrypted tunnels are sequentially allocated to the CPU with the lowest current load in the order of application, and are executed by the idle threads of the process with the lowest current load in this CPU; establishing an encrypted channel: The threads assigned tasks start to execute, and the quantum-secure gateway negotiates and establishes an encrypted channel with the corresponding service terminal; applying for quantum keys: The quantum-secure gateway and the corresponding service terminal respectively apply to the key management platform for quantum keys, so that the key management platform generates and distributes quantum keys; establishing an encrypted tunnel: The quantum-secure gateway and the corresponding service terminal receive the quantum keys and call the quantum keys as session keys to establish the tunnel mode of the encrypted channel.

[0007] Further, the quantum-secure gateway pre-creates a process pool and a thread pool to control the number of processes in each CPU and the number of threads in each process.

[0008] Further, the CPU with the lowest load is the CPU with the largest number of idle processes, and the process with the lowest load is the process with the largest number of idle threads.

[0009] Further, all processes are preset with default serial numbers of different sizes. When a service terminal applies to establish an encrypted tunnel, if there are multiple CPUs with the lowest current load and there are multiple processes with the lowest current load among the multiple CPUs with the lowest current load, then the task of establishing the encrypted tunnel is allocated to the process with the smallest default serial number among the multiple processes with the lowest current load, and is executed by the idle threads of this process.

[0010] Further, all threads are preset with default serial numbers of different sizes. When a service terminal applies to establish an encrypted tunnel, if there are multiple CPUs with the lowest current load and there are multiple processes with the lowest current load among the multiple CPUs with the lowest current load, then the task of establishing the encrypted tunnel is allocated to the idle thread with the smallest default serial number among the multiple processes with the lowest current load.

[0011] Further, the method for establishing an encrypted tunnel in the quantum-secure communication system further includes: presetting a timeout response time: the quantum-secure gateway presets the time allowed for a thread to be in an unresponsive state; counting the unresponsive time: when the thread enters an unresponsive state during the task of establishing an encrypted tunnel, the time of this unresponsive state is counted in real time; determining whether there is an unresponsive timeout: determining whether the unresponsive time is greater than or equal to the preset timeout response time; handling unresponsive timeout: if the unresponsive time is greater than or equal to the preset timeout response time, the thread stops executing the current task of establishing an encrypted tunnel and sends an alarm message; handling non-timeout unresponsiveness: if the unresponsive time is less than the preset timeout response time, the thread continues to execute the current task of establishing an encrypted tunnel, counts the time of entering the unresponsive state this time in real time, and re-determines whether the unresponsive time is greater than or equal to the preset timeout response time.

[0012] Further, the encrypted channel is an IPSec VPN.

[0013] This application also proposes a quantum-secure communication system, and the quantum-secure communication system uses the above method to establish an encrypted tunnel.

[0014] Further, in the quantum-secure communication system, the number of quantum-secure gateways is multiple, and at least one of the quantum-secure gateways serves as a standby quantum-secure gateway.

[0015] The beneficial effects of this application include:

[0016] (1) Each CPU of the quantum-secure gateway pre-creates multiple processes for establishing encrypted tunnels, and each process pre-creates multiple threads for executing the tasks of establishing encrypted tunnels. When multiple service terminals simultaneously apply to the key management platform to establish encrypted tunnels, the quantum-secure gateway can "concurrently" establish encrypted tunnels with multiple service terminals based on multi-process and multi-threading, that is, the quantum-secure gateway can process all the applications of the service terminals at the same time, and execute some or all of the tasks of establishing encrypted tunnels according to the number of idle threads currently available. Thus, the time for processing applications is saved between multiple executions of the task of establishing encrypted tunnels, and the tasks assigned to different CPUs can be executed simultaneously, achieving parallel execution to a certain extent, and improving the efficiency and reliability of establishing encrypted tunnels.

[0017] (2) The tasks of establishing encrypted tunnels are sequentially assigned to the CPU with the lowest current load in the order of application, and are executed by the idle threads of the process with the lowest current load in this CPU, thereby reasonably distributing the tasks of establishing encrypted tunnels, achieving load balancing among the CPUs in the quantum-secure gateway, avoiding the situation where the speed of establishing encrypted tunnels decreases due to too high a usage rate of a certain CPU, and further improving the efficiency and reliability of establishing encrypted tunnels.

[0018] (3) By pre - creating a process pool and a thread pool, the quantum - secure gateway can control the number of processes and threads, and recycle idle processes and threads. When there is no task of establishing an encryption tunnel in a certain process or thread, the quantum - secure gateway does not need to destroy and end the process or thread. Instead, it uses the process pool or thread pool to recycle relevant resources, enabling the process or thread to be used again to execute the task of establishing an encryption tunnel, thus saving the time required for creating and destroying processes and threads, and further improving the efficiency of establishing encryption tunnels.

[0019] (4) Each process and / or thread of each quantum - secure gateway can have different default sequence numbers. When "there are multiple CPUs with the lowest current load, and there are multiple processes with the lowest current load among the multiple CPUs with the lowest current load", the processes and / or threads with smaller default sequence numbers still have a higher task - allocation priority, causing the corresponding CPUs to be more frequently assigned the task of establishing an encryption tunnel, while other CPUs are more idle, so that the utilization rates of different CPUs are different, avoiding multiple CPUs with similar utilization rates from failing simultaneously and resulting in communication failures, and further improving the reliability of establishing encryption tunnels.

[0020] (5) The processes and / or threads of multiple quantum - secure gateways can also have different default sequence numbers. When multiple quantum - secure gateways simultaneously access a certain number of service terminals, some of the quantum - secure gateways can be more frequently assigned the task of processing the establishment of encryption tunnels, while some other quantum - secure gateways are more idle, so that the utilization rates of different quantum - secure gateways are different, avoiding multiple quantum - secure gateways from failing simultaneously and resulting in communication failures, and further improving the reliability of establishing encryption tunnels.

[0021] (6) By presetting a timeout response time, the thread can stop executing the current task and send an alarm message when there is no response after the timeout. During this period, since the thread is occupied, other tasks of establishing encryption tunnels will skip this thread and be assigned to other threads, thus avoiding communication congestion caused by abnormal threads and further improving the efficiency and reliability of establishing encryption tunnels. Description of the Drawings

[0022] To more clearly illustrate the technical solutions in the specific embodiments of the present application, the following will briefly introduce the drawings required for the description of the specific embodiments. Obviously, the following - described drawings are only some specific embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0023] Figure 1 It is a system schematic diagram of the quantum - secure communication system in the specific embodiments of the present application;

[0024] Figure 2 It is a schematic flow diagram of the method for establishing an encrypted tunnel in the quantum secure communication system in the specific implementation manner of this application;

[0025] Figure 3 It is a schematic flow diagram of the method for establishing an encrypted tunnel when the thread has a preset default serial number in the specific implementation manner of this application;

[0026] Figure 4 It is a schematic flow diagram of the method for establishing an encrypted tunnel when the thread is unresponsive in the specific implementation manner of this application. Specific implementation manner

[0027] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with the accompanying drawings in this application. Obviously, the described implementation manners are only part of the implementation manners of this application, rather than all of them. Based on the implementation manners in this application, all other implementation manners obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application.

[0028] This specific implementation manner is described by taking power communication as an example.

[0029] As Figure 1 shown, the quantum secure communication system provided by this application includes a quantum secure gateway 1000, a service terminal 2000, and a key management platform 3000.

[0030] The types of the service terminal 2000 include power station terminals, feeder terminals, etc., which are responsible for collecting service data such as fault inspection and monitoring, and also have functions such as key application, key reception situation monitoring, data encryption and decryption, etc.

[0031] The quantum secure gateway 1000 is installed in the data center, and the quantum secure gateway 1000 is connected to the service terminal 2000 through the external network. As the entry device for external network data, the quantum secure gateway 1000 needs to negotiate and establish an encrypted tunnel with the service terminal 2000. After the service terminal 2000 encrypts the service data by invoking the session key, the encrypted service data is transmitted to the quantum secure gateway 1000 through the encrypted tunnel, and the quantum secure gateway 1000 can decrypt the encrypted service data by invoking the corresponding session key.

[0032] The key management platform 3000 is installed in the data center and is used for generating and distributing quantum keys. The service terminal 2000 and the quantum secure gateway 1000 respectively send applications to the key management platform 3000. When both the service terminal 2000 and the quantum secure gateway 1000 receive the quantum keys, the two use the quantum keys as session keys to encrypt and decrypt the service data.

[0033] There are multiple business terminals 2000, and the number of quantum security gateways 1000 is not less than one. For example, the number of business terminals 2000 can be three thousand, and the number of quantum security gateways 1000 can be two. The two quantum security gateways 1000 can be respectively connected to a certain number of business terminals 2000, or the two quantum security gateways 1000 can also work in a hot standby mode. One of them is the primary quantum security gateway, and the other is the standby quantum security gateway. When the network between the business terminal 2000 and the quantum security gateway 1000 is interrupted, once the network resumes, the three thousand business terminals 2000 will quickly connect to the primary quantum security gateway. The primary quantum security gateway needs to quickly establish an encrypted channel with the three thousand business terminals 2000, and at the same time, apply for quantum keys from the key management platform 3000 and call the tunnel mode of the quantum key to establish an encrypted channel; when the primary quantum security gateway fails, the three thousand business terminals 2000 quickly connect to the standby quantum security gateway, and it is also necessary for the standby quantum security gateway to quickly establish an encrypted tunnel with the three thousand business terminals 2000.

[0034] In order to enable the quantum security gateway 1000 to efficiently and reliably establish an encrypted tunnel with multiple business terminals 2000, in this specific embodiment, the quantum security gateway 1000 includes multiple CPUs 1100. Each CPU 1100 pre-creates multiple processes 1110 for establishing encrypted tunnels, and each process 1110 pre-creates multiple threads 1111 for executing the tasks of establishing encrypted tunnels, so that the quantum security gateway 1000 can "concurrently" establish encrypted tunnels with multiple business terminals 2000 based on multiple processes 1110 and multiple threads 1111, improving the efficiency and reliability of establishing encrypted tunnels.

[0035] It should be noted that since the quantum security gateway 1000 includes various hardware configurations, the number of CPUs 1100, processes 1110, and threads 1111 in different quantum security gateways 1000 also varies, and adaptive adjustments need to be made according to the quantity and performance of the specific hardware.

[0036] As Figure 2 shown, the method for establishing an encrypted tunnel in the quantum secure communication system includes:

[0037] S11: Each CPU 1100 pre-creates multiple processes 1110 for establishing encrypted tunnels, and each process 1110 pre-creates multiple threads 1111 for executing the tasks of establishing encrypted tunnels.

[0038] S12: When multiple service terminals 2000 simultaneously apply to the quantum security gateway 1000 to establish an encrypted tunnel, the task of establishing the encrypted tunnel is sequentially assigned to the CPU 1100 with the lowest current load according to the application order, and is executed by the idle thread 1111 of the process 1110 with the lowest current load in this CPU 1100.

[0039] S13: The thread 1111 assigned the task starts to execute, and the quantum security gateway 1000 negotiates with the corresponding service terminal 2000 to establish an IPSec VPN.

[0040] S14: The quantum security gateway 1000 and the corresponding service terminal 2000 respectively apply to the key management platform 3000 for quantum keys, enabling the key management platform 3000 to generate and distribute quantum keys.

[0041] S15: The quantum security gateway 1000 and the corresponding service terminal 2000 receive the quantum keys and call the quantum keys as session keys to establish the tunnel mode of the IPSec VPN.

[0042] By pre-creating multiple processes 1110 and multiple threads 1111, the quantum security gateway 1000 can execute multiple tasks of establishing encrypted tunnels "concurrently", that is, the quantum security gateway 1000 can process the applications of all service terminals 2000 simultaneously, and execute some or all of the tasks of establishing encrypted tunnels according to the number of current idle threads 1111, thus saving the time for processing applications between multiple executions of the task of establishing encrypted tunnels, and the tasks assigned to different CPUs 1100 can be executed simultaneously, achieving parallel execution to a certain extent and improving the efficiency and reliability of establishing encrypted tunnels.

[0043] In addition, the task of establishing the encrypted tunnel is sequentially assigned to the CPU 1100 with the lowest current load according to the application order, and is executed by the idle thread 1111 of the process 1110 with the lowest current load in this CPU 1100, thereby reasonably distributing the task of establishing the encrypted tunnel, achieving load balancing of each CPU 1100 in the quantum security gateway 1000, avoiding the reduction in the speed of establishing the encrypted tunnel due to too high a usage rate of a certain CPU, and further improving the efficiency and reliability of establishing the encrypted tunnel.

[0044] In this specific embodiment, the CPU 1100 with the lowest load refers to the CPU 1100 that contains the largest number of idle processes 1110, and the process 1110 with the lowest load refers to the process 1110 that contains the largest number of idle threads 1111. In some other embodiments, the number of processes 1110 contained in different CPUs 1100 of the quantum security gateway 1000 is equal, and the number of threads 1111 contained in different processes 1110 is also equal. The CPU 1100 with the lowest load can refer to the CPU 1100 with the fewest occupied processes 1110, and the process 1110 with the lowest load can refer to the process 1110 with the fewest occupied threads 1111.

[0045] In this specific embodiment, the number of processes 1110 and threads 1111 is controlled by pre-creating a process pool and a thread pool. Specifically, the process pool and the thread pool are pre-created by the operating system of the quantum security gateway 1000. The process pool and the thread pool can perform default configurations on the number and running environment of processes 1110 and threads 1111, so that when the quantum security gateway 1000 starts, multiple processes 1110 are automatically created for each CPU 1100, and multiple threads 1111 are automatically created for each process 1110. After the processes 1110 and threads 1111 execute and end, their used resources are cleared, so as to recycle and reuse the processes 1110 and threads 1111.

[0046] Since creating processes 1110 and threads 1111 takes time, and destroying processes 1110 and threads 1111 also takes time, by pre-creating a process pool and a thread pool, the quantum security gateway 1000 can control the number of processes 1110 and threads 1111, and recycle and reuse the idle processes 1110 and threads 1111. When there is no task of establishing an encryption tunnel in a certain process 1110 or thread 1111, the quantum security gateway 1000 does not need to destroy and end the process 1110 or thread 1111, but uses the process pool or the thread pool to recycle the relevant resources, so that the process 1110 or thread 1111 can be used again to execute the task of establishing an encryption tunnel, thus saving the time required for creating and destroying processes 1110 and threads 1111, and further improving the efficiency of establishing an encryption tunnel.

[0047] When the service terminal 2000 applies to establish an encryption tunnel, if there are multiple CPUs 1100 with the lowest current load, and there are multiple processes 1110 with the lowest current load among the multiple CPUs 1100 with the lowest current load, that is, the CPUs 1100 with the lowest current load are not unique, and there are at least two different CPUs 1100 that simultaneously have processes 1110 with the lowest current load. At this time, there are multiple CPUs 1100 with the highest task allocation priority, and the task of establishing an encryption tunnel is usually randomly assigned to one of the CPUs 1100.

[0048] In this specific embodiment, the quantum security gateway 1000 sorts all the processes 1110 and / or threads 1111 it creates in advance, that is, each process 1110 and / or thread 1111 has a default serial number of different sizes. When there are multiple CPUs 1100 with the lowest current load, and there are multiple processes 1110 with the lowest current load among the multiple CPUs 1100 with the lowest current load, an encrypted tunnel task is established and assigned to the process 1110 with the smallest default serial number among the multiple processes 1110 with the lowest current load, and is executed by the idle thread 1111 of this process 1110; or, an encrypted tunnel task is established and assigned to the idle thread 1111 with the smallest default serial number among the multiple processes 1110 with the lowest current load.

[0049] As Figure 3 shown, taking the thread 1111 having a preset default serial number as an example, the method for establishing an encrypted tunnel in the quantum secure communication system includes:

[0050] S21: Each CPU 1100 creates multiple processes 1110 for establishing an encrypted tunnel in advance, and each process 1110 creates multiple threads 1111 for executing the encrypted tunnel establishment task in advance, and all threads 1111 have preset default serial numbers of different sizes.

[0051] S22: The service terminal 2000 applies to the quantum security gateway 1000 to establish an encrypted tunnel.

[0052] S23: Determine whether "there are multiple CPUs 1100 with the lowest current load, and there are multiple processes with the lowest current load among the multiple CPUs 1100 with the lowest current load".

[0053] S24: If "there are multiple CPUs 1100 with the lowest current load, and there are multiple processes with the lowest current load among the multiple CPUs 1100 with the lowest current load", then the encrypted tunnel establishment task is assigned to the idle thread 1111 with the smallest default serial number among the processes 1110 with the lowest current load for execution.

[0054] S25: If "there are not multiple CPUs 1100 with the lowest current load, or there are no multiple processes 1110 with the lowest current load among the multiple CPUs 1100 with the lowest current load", then the encrypted tunnel establishment task is assigned to the CPU 1100 with the lowest current load, and is executed by the idle thread 1111 of the process 1110 with the lowest current load in this CPU 1100.

[0055] S26: The thread 1111 assigned the task starts to execute, and the quantum security gateway 1000 negotiates with the corresponding service terminal 2000 and establishes an IPSec VPN.

[0056] S27: The quantum security gateway 1000 and the corresponding service terminal 2000 respectively apply to the key management platform 3000 for quantum keys, enabling the key management platform 3000 to generate and distribute quantum keys.

[0057] S28: The quantum security gateway 1000 and the corresponding service terminal 2000 receive the quantum keys and call the quantum keys as session keys to establish the tunnel mode of IPSec VPN.

[0058] The difference from the above "random allocation" is that in this specific embodiment, each process 1110 and / or thread 1111 of the quantum security gateway 1000 has a default serial number of different sizes. Therefore, when "there are multiple CPUs 1100 with the lowest current load, and there are multiple processes 1110 with the lowest current load among the multiple CPUs 1100 with the lowest current load", the processes 1110 and / or threads 1111 with smaller default serial numbers still have a higher task allocation priority, enabling the corresponding CPUs 1100 to be more frequently allocated the task of establishing an encrypted tunnel, while other CPUs 1100 are more idle, so that the usage rates of different CPUs 1100 are different, to avoid multiple CPUs 1100 with similar usage rates failing simultaneously and resulting in inability to communicate, and further improving the reliability of establishing an encrypted tunnel.

[0059] In addition, when the number of quantum security gateways 1000 is multiple, all processes 1110 / or threads 1111 of the multiple quantum security gateways 1000 can also be sorted, that is, each process 1110 and / or thread 1111 of the multiple quantum security gateways 1000 has a default serial number of different sizes. In this way, when multiple quantum security gateways 1000 are simultaneously connected to a certain number of service terminals 2000, some of the quantum security gateways 1000 can be more frequently allocated the task of processing and establishing an encrypted tunnel, while some other quantum security gateways 1000 are more idle, so that the usage rates of different quantum security gateways 1000 are different, to avoid multiple quantum security gateways 1000 with similar usage rates failing simultaneously and resulting in inability to communicate, and further improving the reliability of establishing an encrypted tunnel.

[0060] When the thread 1111 executes the task of establishing an encrypted tunnel, it may enter an unresponsive state, resulting in the service terminal 2000 being unable to communicate due to the timeout of the response time for establishing the encrypted tunnel.

[0061] In this specific embodiment, the quantum security gateway 1000 can preset a timeout response time and statistically count the time in the unresponsive state in real time. If thread 1111 times out without response, the current task of establishing an encrypted tunnel is stopped and an alarm message is sent; if thread 1111 does not reach the timeout response time, the current task of establishing an encrypted tunnel continues to be executed, and at the same time, the time in the unresponsive state this time is continuously counted until thread 1111 times out without response and stops executing the current task.

[0062] As Figure 4 shown, when thread 1111 is unresponsive, the method for establishing an encrypted tunnel in the quantum secure communication system includes:

[0063] S31: Preset the time allowed for thread 1111 to be in the unresponsive state.

[0064] S32: When thread 1111 enters the unresponsive state while executing the task of establishing an encrypted tunnel, statistically count the time in this unresponsive state in real time.

[0065] S33: Determine whether the unresponsive time is greater than or equal to the preset timeout response time.

[0066] S34: If the unresponsive time is greater than or equal to the preset timeout response time, thread 1111 stops executing the current task of establishing an encrypted tunnel and sends an alarm message.

[0067] S35: If the unresponsive time is less than the preset timeout response time, thread 1111 continues to execute the current task of establishing an encrypted tunnel, statistically count the time in the unresponsive state this time, and re-determine whether the unresponsive time is greater than or equal to the preset timeout response time.

[0068] By presetting the timeout response time, thread 1111 can stop executing the current task of establishing an encrypted tunnel and send an alarm message when it times out without response. During this period, since thread 1111 is in an occupied state, other tasks of establishing an encrypted tunnel will skip this thread 1111 and be assigned to other threads 1111, thus avoiding communication congestion caused by abnormal thread 1111 and further improving the efficiency and reliability of establishing an encrypted tunnel.

[0069] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for establishing an encrypted tunnel in a quantum secure communication system, characterized in that: The quantum secure communication system includes a quantum secure gateway, a service terminal, and a key management platform. The quantum secure gateway includes multiple CPUs. There are multiple service terminals, and the number of the service terminals is greater than the number of CPUs. The method for establishing an encrypted tunnel of a quantum secure communication system includes: Creating processes and threads: Each CPU pre-creates multiple processes for establishing encrypted tunnels, and each process pre-creates multiple threads for executing the task of establishing encrypted tunnels; Task allocation: When multiple business terminals apply to the quantum security gateway to establish encrypted tunnels at the same time, the task of establishing encrypted tunnels is allocated to the CPU with the smallest current load in the order of application, and is executed by the idle thread of the process with the smallest current load in the CPU; Among them, all processes have preset priorities, and the priorities are represented by default serial numbers of different preset sizes. When the business terminal applies to establish an encrypted tunnel, there are multiple CPUs with the smallest current loads, and there are multiple processes with the smallest current loads in the multiple CPUs with the smallest current loads, then the task of establishing the encrypted tunnel is assigned to the process with the smallest default serial number among the multiple processes with the smallest current loads, and is executed by the idle thread of the process; and / or, all threads have preset priorities, and the priorities are represented by default serial numbers of different preset sizes. When the business terminal applies to establish an encrypted tunnel, there are multiple CPUs with the smallest current loads, and there are multiple processes with the smallest current loads in the multiple CPUs with the smallest current loads, then the task of establishing the encrypted tunnel is assigned to the idle thread with the smallest default serial number among the multiple processes with the smallest current loads for execution; Establish an encrypted channel: The thread to which the task is assigned starts to execute, and the quantum security gateway negotiates with the corresponding business terminal and establishes an encrypted channel; Apply for quantum keys: The quantum security gateway and the corresponding business terminal apply for quantum keys from the key management platform respectively, so that the key management platform generates and distributes quantum keys; Establish an encrypted tunnel: The quantum security gateway and the corresponding business terminal receive the quantum key and call the quantum key as the session key to establish the tunnel mode of the encrypted channel.

2. The method for establishing an encrypted tunnel of a quantum secure communication system according to claim 1, characterized in that: The quantum security gateway creates process pools and thread pools in advance to control the number of processes in each CPU and the number of threads in each process.

3. The method for establishing an encrypted tunnel of a quantum secure communication system according to claim 2, characterized in that: The CPU with the smallest load is the CPU with the largest number of idle processes, and the process with the smallest load is the process with the largest number of idle threads.

4. The method for establishing an encrypted tunnel of a quantum secure communication system according to claim 1, characterized in that: Also includes: Preset timeout response time: The quantum security gateway presets the time that a thread is allowed to be in an unresponsive state; Statistics of unresponsive time: When a thread enters an unresponsive state while executing the task of establishing an encrypted tunnel, the duration of this unresponsive state is counted in real time; Timeout and no response: Determine whether the no response time is greater than or equal to the preset timeout response time; No response timeout processing: If the no response time is greater than or equal to the preset timeout response time, the thread stops executing the current encryption tunnel establishment task and sends an alarm message; No response but not timeout processing: If the no response time is less than the preset timeout response time, the thread continues to execute the current task of establishing an encrypted tunnel, counts the time of entering the no response state in real time, and re-determines whether the no response time is greater than or equal to the preset timeout response time.

5. The method for establishing an encrypted tunnel of a quantum secure communication system according to claim 1, characterized in that: The encryption channel is IPSec VPN.

6. A quantum secure communication system, characterized in that: A method for establishing an encrypted tunnel in a quantum secure communication system as described in any one of claims 1 to 5 is applied.

7. The quantum secure communication system according to claim 6, characterized in that: There are multiple quantum security gateways, at least one of which serves as a backup quantum security gateway.

Citation Information

Patent Citations

  • IPSec VPN method used for realizing quantum safety

    CN107453869A

  • Method and device for establishing multiple communication tunnels, medium and electronic equipment

    CN115834292A