A one-time-one-pad high-speed secure optical communication method based on space division multiplexing technology

By transmitting and logically XORing true random keys through multiple spatial channels of space-division multiplexing optical fibers, the problem of high-speed true random key security distribution is solved, and the absolute security of one-time confidential communication is achieved. It is suitable for military communications and government agency scenarios with high security requirements.

CN118984226BActive Publication Date: 2025-09-12GUANGDONG UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411053792.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-02
Publication Date
2025-09-12
Estimated Expiration
2044-08-02

AI Technical Summary

Technical Problem

Existing technologies make it difficult to achieve high-speed true random key security distribution that matches modern communication rates on classical fiber optic channels, resulting in traditional encryption algorithms being insufficiently secure in the face of quantum computing threats and unable to achieve absolutely secure one-time, one-pad confidential communication.

Method used

By utilizing multiple spatial transmission channels of space-division multiplexing optical fibers, the true random keys generated by both communicating parties are encrypted and transmitted in different spatial channels, and a logical XOR operation is performed at the receiving end to generate a consistent true random encryption key, thereby achieving secure distribution of true random keys that match the communication rate. Ultimately, one-time confidential communication is achieved through XOR encryption of the true random encryption key stream and plaintext data.

Benefits of technology

It achieves secure distribution of true random keys that matches modern communication rates on classic fiber channels, enhances the security and anti-attack capabilities of communication networks, and ensures the absolutely secure transmission of plaintext data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118984226B_ABST
    Figure CN118984226B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of secure optical fiber communication technology and relates to a novel one-time pad high-speed secure optical communication system and method, comprising a true random number generator, an electrical domain encryption and decryption module, an optical domain encryption and decryption module, and a logical exclusive-OR module, thereby solving the one-time pad secure communication technology problem in the background art. The present invention generates different true random key sequences using an independent true random number generator module at the transmitting and receiving ends of both parties in legitimate communication, performs electrical and optical domain scrambling encryption, and obtains an encrypted true random key. With the help of multiple spatial transmission channels of space-division multiplexing optical fiber, the true random keys generated by both parties in communication are encrypted and transmitted in different spatial channels, and each party performs a logical exclusive-OR with its own key to generate a consistent true random encryption key, thereby achieving secure distribution of true random keys that match the communication rate. Finally, one-time pad high-speed secure communication is achieved by exclusive-OR encryption of the true random encryption key stream with plaintext data. Compared with traditional stream encryption based on pseudo-random number generators, the present invention can provide a one-time pad high-speed secure optical communication solution based on secure distribution of true random keys that is compatible with classical channels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of optical communication technology, and more particularly to a one-time, one-pad, high-speed, secure optical communication method based on space division multiplexing technology. Background Art

[0002] With the rapid development of next-generation information technologies such as big data, cloud computing, and the Internet of Things, the demand for massive data transmission is creating a capacity crisis for traditional fiber-optic communication networks. Communication technologies based on novel spatial division multiplexing (SDM) optical fibers promise to exponentially increase the capacity of existing single-mode, single-core optical fibers, offering a key solution to this future capacity crisis. However, while high-speed fiber-optic communication networks enable the interconnection of massive amounts of data, they also pose significant challenges to network security. Ensuring confidential data transmission within these networks is becoming increasingly pressing.

[0003] Traditional secure communication technologies primarily rely on encryption algorithms such as the Data Encryption Standard (DES) and the Advanced Encryption Standard (AES) to ensure confidential data transmission. Their security relies heavily on computational complexity and the attacker's computing power. While cracking these algorithms with current computing resources takes longer than the required secrecy of the key, theoretically, a brute-force attack can break secure communication systems based on computational complexity. Furthermore, with the advancement of ultra-large-scale parallel computing, particularly quantum computing, the data confidentiality provided by traditional encryption algorithms is facing threats.

[0004] In 1917, AT&T's Vernam proposed a one-time pad secure communication scheme, which was later proven absolutely secure by Shannon from an information theory perspective. One-time pad secure communication achieves absolute security by XOR-encrypting plaintext data with a key of equal length. The key to its confidentiality lies in the fact that the encryption key is completely random, used only once and then discarded, and can never be used again in part or in whole. The key must be securely shared between legitimate communicating parties. Without the decryption key, an attacker, even with powerful computing resources, can obtain no information about the plaintext except the length of the ciphertext, thus theoretically guaranteeing the absolute security of the plaintext data. However, despite the theoretical absolute security of the one-time pad, the practical and secure distribution of the truly random key is extremely difficult, severely limiting its practical application.

[0005] Existing solutions primarily employ a compromise approach, using stream encryption techniques to simulate and approximate one-time pad secure communication. A seed key is passed through a pseudo-random number generator to generate a key stream, which serves as the encryption key. This key stream is then bitwise XORed with the plaintext data to generate the encrypted ciphertext, thereby achieving secure transmission. The main problem with this approach is that the key stream is not truly random and cannot meet the requirements for absolutely secure one-time pad secure communication. One-time pad secure communication based on quantum key distribution (QKD) has also been proposed and extensively researched in recent years. Quantum key distribution utilizes the principle of single-photon non-cloning to ensure absolute key security. However, it still faces challenges such as difficulty in single-photon amplification, low key rate, and incomplete compatibility with high-speed classical communication systems, making it difficult to achieve one-time pad high-speed secure communication (OFC (2005): OWI3.). In addition, a technique for generating true random numbers based on chaotic synchronization and performing one-time pad encryption and decryption on plaintext data has also been proposed (Journal of Lightwave Technology, 34.22 (2016): 5325-5331). However, due to the bandwidth limitations of chaotic lasers, the rate of true random number generation is limited by the relaxation oscillation frequency of semiconductor lasers, making it difficult to achieve one-time pad encryption and decryption at gigabit or even higher communication rates. Therefore, how to achieve high-speed true random key secure distribution over classical fiber channels that matches modern communication rates, and thus achieve one-time pad secure communication based on Shannon information theory, remains an unresolved problem.

[0006] The present invention utilizes space-division multiplexing optical fiber channels to achieve secure distribution of high-speed true random keys and one-time pad confidential communication, which can greatly enhance the security of data in communication networks and the system's anti-attack capabilities. In scenarios with extremely high security requirements, such as military communications and government agencies, it can ensure the absolute security of confidential data, which is of great significance to network security. Summary of the Invention

[0007] In order to overcome the defects of traditional methods, the present invention provides a one-time pad high-speed secure optical communication method based on space-division multiplexing technology, which solves the problem of secure distribution of high-speed true random keys and is applied to the secure distribution of keys and the secure transmission of plaintext data during one-time pad secure communication. With the help of multiple spatial transmission channels of space-division multiplexing optical fibers, the true random keys generated by each communicating party are encrypted and transmitted in different spatial channels, and each party performs a logical XOR on the received true random key with its own key to generate a consistent true random encryption key, thereby achieving secure distribution of true random keys that match the communication rate, and finally achieving one-time pad secure communication through XOR encryption of the true random encryption key stream and plaintext data. The purpose of the present invention is to construct a method for secure distribution of true random keys and a high-speed one-time pad secure communication system that are compatible with classical channels.

[0008] The system of the present invention is suitable for application scenarios with high requirements for secure communication between large enterprise data centers, government dedicated lines, and military communication nodes, and involves confidential communication technologies such as true random key encryption and space division multiplexing encrypted transmission.

[0009] To achieve the above object, the present invention provides a one-time-one-pad high-speed secure optical communication method based on space division multiplexing technology, comprising:

[0010] A one-time pad secure optical communication system comprises party A, a space-division multiplexing optical fiber transmission link unit, and party B. Party A and party B respectively comprise a party A true random key generation and encryption unit (1), a party B true random key decryption unit (2), a party B true random key generation and encryption unit (3), a party A true random key decryption unit (4), an optical fiber transmission link unit (5), a party A one-time pad encryption and decryption unit (6), a party A transmission unit (7), a party B transmission unit (8), and a party B one-time pad encryption and decryption unit (9). Wherein, the Party A true random key generation and encryption unit (1) and the Party A true random key decryption unit (4) provide an encryption key for the Party A one-time pad encryption and decryption unit (6), the Party A one-time pad encryption and decryption unit (6) provides the Party A transmission unit (7) with the encrypted plaintext data to be sent by Party A, and the Party A transmission unit (7) provides the Party A one-time pad encryption and decryption unit (6) with the Party B encrypted plaintext data to be decrypted; the Party B true random key generation and encryption unit (3) and the Party B true random key decryption unit (2) provide an encryption key for the Party B one-time pad encryption and decryption unit (9), the Party B one-time pad encryption and decryption unit (9) provides the Party B transmission unit (8) with the Party B encrypted plaintext data to be sent by Party B, and the Party B transmission unit (8) provides the Party B one-time pad encryption and decryption unit (9) with the Party A encrypted plaintext data to be decrypted;

[0011] Furthermore, in the preferred technical solution provided by the present invention, Party A and Party B are both parties in legal communication.

[0012] Furthermore, in the preferred technical solution provided by the present invention, the true random key generation and encryption unit (1) of party A comprises: a true random key generation unit (101), a true random key electrical domain encryption unit (102), a true random key sending unit (103), and a true random key optical domain encryption unit (104); wherein the output end of the true random key generation unit (101) is connected to the input end of the true random key electrical domain encryption unit (102), the output end of the true random key electrical domain encryption unit (102) is connected to the input end of the true random key sending unit (103), and the output end of the true random key sending unit (103) is connected to the input end of the true random key optical domain encryption unit (104). The true random key generation unit (101) is used to generate a true random key K A, characterized in that the statistical characteristics of the key do not have periodicity; the true random key electric domain encryption unit (102) is used to encrypt the true random key K generated by the true random key generation unit (101) A The invention relates to a method for performing scrambling operations such as scrambling and replacing to realize electrical domain encryption. The true random key sending unit (103) is used to modulate the true random key encrypted by the true random key electrical domain encryption unit and send it in the optical domain. The true random key optical domain encryption unit (104) is used to perform optical domain scrambling encryption on the true random electrical domain encryption key modulated onto the optical carrier.

[0013] Furthermore, in the preferred technical solution provided by the present invention, the true random key decryption unit (2) of party B comprises: a true random key optical domain decryption unit (201), a true random key receiving unit (202), a true random key demodulation unit (203), and a true random key electrical domain decryption unit (204); wherein the output end of the true random key optical domain decryption unit (201) is connected to the input end of the true random key receiving unit (202), the output end of the true random key receiving unit (202) is connected to the input end of the true random key demodulation unit (203), and the output end of the true random key demodulation unit (203) is connected to the input end of the true random key electrical domain decryption unit (204). The true random key optical domain decryption unit (201) of party B is used to perform optical domain decryption on the true random key encrypted by the true random key optical domain encryption unit of party A. The true random key receiving unit (202) of party B is used to perform photoelectric detection and reception on the decrypted true random key and convert it into an electrical signal. The B-party true random key demodulation unit (203) is used to demodulate the decrypted true random key electrical signal; the B-party true random key electrical domain decryption unit (204) is used to perform electrical domain descrambling on the demodulated true random key electrical signal to restore the original true random key K sent by the A-party. A .

[0014] Furthermore, in the preferred technical solution provided by the present invention, the true random key generation and encryption unit (3) of party B includes: a true random key generation unit (301), a true random key electrical domain encryption unit (302), a true random key sending unit (303), and a true random key optical domain encryption unit (304); wherein the output end of the true random key generation unit (301) is connected to the input end of the true random key electrical domain encryption unit (302), the output end of the true random key electrical domain encryption unit (302) is connected to the input end of the true random key sending unit (303), and the output end of the true random key sending unit (303) is connected to the input end of the true random key optical domain encryption unit (304). The true random key generation unit (301) is used to generate a true random key K B, characterized in that the statistical characteristics of the key do not have periodicity; the true random key electronic domain encryption unit (302) is used to encrypt the true random key K generated by the true random key generation unit B The invention relates to a method for performing scrambling operations such as scrambling and replacing to realize electrical domain encryption. The true random key sending unit (303) is used to modulate the true random key encrypted by the true random key electrical domain encryption unit and send it in the optical domain. The true random key optical domain encryption unit (304) is used to perform optical domain scrambling encryption on the true random electrical domain encryption key modulated onto the optical carrier.

[0015] Furthermore, in the preferred technical solution provided by the present invention, the Party A true random key decryption unit (4) includes: a true random key optical domain decryption unit (401), a true random key receiving unit (402), a true random key demodulation unit (403), and a true random key electrical domain decryption unit (404); wherein the output end of the true random key optical domain decryption unit (401) is connected to the input end of the true random key receiving unit (402), the output end of the true random key receiving unit (402) is connected to the input end of the true random key demodulation unit (403), and the output end of the true random key demodulation unit (403) is connected to the input end of the true random key electrical domain decryption unit (404). The Party A true random key optical domain decryption unit (401) is used to perform optical domain decryption on the true random key encrypted by the Party B true random key optical domain encryption unit. The Party A true random key receiving unit (402) is used to perform photoelectric detection and reception on the decrypted true random key and convert it into an electrical signal. The A-party true random key demodulation unit (403) is used to demodulate the decrypted true random key electrical signal; the A-party true random key electrical domain decryption unit (404) is used to perform electrical domain descrambling on the demodulated true random key electrical signal to recover the original true random key K sent by the B-party. B .

[0016] Furthermore, in the preferred technical solution provided by the present invention, the space-division multiplexing optical fiber transmission link unit (5) includes: a space-division multiplexing fan-in fan-out unit (501), a space-division multiplexing transmission optical fiber (502), and a space-division multiplexing fan-in fan-out unit (503); wherein the space-division multiplexing fan-in fan-out units (501) and (503) are connected to the generation and encryption units (1) and (3) of the true random key of Party A and Party B, the decryption units (2) and (4) of the true random key, the one-time pad encryption and decryption units (6) and (9), and the transmission units (7) and (8). The space-division multiplexing optical fiber transmission link unit (5) is used for bidirectional transmission of the true random key encryption signals of Party A and Party B, as well as the confidential data signals of Party A and Party B. The space-division multiplexing optical fiber transmission link unit (5) can be a space-division multiplexing multi-core optical fiber, a few-mode optical fiber, a multi-core few-mode optical fiber, etc.

[0017] Furthermore, in the preferred technical solution provided by the present invention, the one-time pad encryption and decryption unit (6) of Party A comprises: a true random key logic exclusive OR unit (601), a confidential data logic exclusive OR unit (602), and a confidential data unit (603); wherein the two input ends of the true random key logic exclusive OR unit (601) are respectively connected to the output ends of the true random key generation unit (101) and the true random key electric domain decryption unit (404), the output end of the true random key logic exclusive OR unit (601) is connected to the input end of the confidential data logic exclusive OR unit (602), and the other input and output ends of the confidential data logic exclusive OR unit (602) are respectively connected to the input and output ends of the confidential data unit (603) and the Party A transmission unit (701). The one-time pad encryption and decryption unit (6) is used to generate a true random key K that is consistent with that of Party A and Party B for encrypting confidential data. C The true random key logical exclusive OR unit (601) is used to receive the original true random key K generated by the true random key generating unit (101) of party A. A The true random key K sent by Party B and received by Party A's true random key electronic domain decryption unit (404) B , and perform a logical XOR operation to generate the encryption and decryption true random key K that is ultimately used to encrypt Party A’s plaintext data and decrypt Party B’s ciphertext data C The confidential data logical exclusive OR unit (602) is used to receive the true random encryption key of the true random key logical exclusive OR unit (601) and the plain text data in the confidential data unit (603), perform a logical exclusive OR operation on them, and generate encrypted data to be sent to party B; and is also used to receive the ciphertext data of party B output by the party A transmission unit (7), perform a logical exclusive OR operation on the ciphertext data of party B with the true random decryption key generated by the true random key logical exclusive OR unit (601), generate the decrypted plain text data sent by party B, and store it in the confidential data unit (603); the true random encryption key and the true random decryption key are the same;

[0018] Furthermore, in the preferred technical solution provided by the present invention, the input and output ends of the Party A transmission unit (7) are connected to the Party A one-time pad encryption unit (6) and the optical fiber transmission link unit (5), and are used to receive the Party A ciphertext encrypted with the true random key generated by the Party A one-time pad encryption unit (6) and send it to Party B, and to receive the Party B ciphertext encrypted with the true random key sent by Party B and send it to the Party A one-time pad decryption unit (6);

[0019] Furthermore, in the preferred technical solution provided by the present invention, the input and output ends of the Party B transmission unit (8) are connected to the Party B one-time pad encryption unit (9) and the optical fiber transmission link unit (5), and are used to receive the Party A ciphertext encrypted with the true random key sent by Party A to the Party B one-time pad decryption unit (9), and to receive the Party B ciphertext encrypted with the true random key generated by the Party B one-time pad encryption unit (9) to Party A;

[0020] Furthermore, in the preferred technical solution provided by the present invention, the one-time pad encryption and decryption unit (9) of Party B comprises: a true random key logic exclusive OR unit (901), a confidential data logic exclusive OR unit (902), and a confidential data unit (903); wherein, the two input ends of the true random key logic exclusive OR unit (901) are respectively connected to the output ends of the true random key generation unit (301) and the true random key electric domain decryption unit (204), the output end of the true random key logic exclusive OR unit (901) is connected to the input end of the confidential data logic exclusive OR unit (902), and the other input and output ends of the confidential data logic exclusive OR unit (902) are respectively connected to the input and output ends of the confidential data unit (903) and the Party B transmission unit (801). The one-time pad encryption and decryption unit (9) is used to generate a true random key K that is consistent with that of Party A and Party B for encrypting confidential data. C The true random key logical exclusive OR unit (901) is used to receive the original true random key K generated by the true random key generating unit (301) of the party B. B The true random key K sent by party A is received by party B's true random key electronic domain decryption unit (204) A , and perform a logical XOR operation to generate the encryption and decryption true random key K that is ultimately used to encrypt Party B’s plaintext data and decrypt Party A’s ciphertext data C The confidential data logical exclusive OR unit (902) is used to receive the true random encryption key of the true random key logical exclusive OR unit (901) and the plain text data in the confidential data unit (903), perform a logical exclusive OR operation on them, and generate encrypted data to be sent to Party A; and is also used to receive the ciphertext data of Party A output by the Party B transmission unit (8), perform a logical exclusive OR operation on the ciphertext data of Party A and the true random decryption key generated by the true random key logical exclusive OR unit (901), generate the decrypted plain text data sent by Party A, and store it in the confidential data unit (903); the true random encryption key and the true random decryption key are the same;

[0021] Furthermore, in the preferred technical solution provided by the present invention, the A party true random key generation and encryption unit (1) and the B party true random key generation and encryption unit (3) respectively send the encrypted true random key to the B party true random key decryption unit (2) and the A party true random key decryption unit (4) through different channels of the space division multiplexing optical fiber link unit (5);

[0022] Compared with the existing technology, the beneficial effect of the technical solution of the present invention is that the true random keys generated by the communicating parties are encrypted and transmitted in different spatial channels through multiple spatial transmission channels of spatially divided optical fibers, and each party performs a logical XOR on the received true random key of the other party with its own key to generate a consistent true random encryption key, thereby realizing the secure distribution of true random keys that match the communication rate, and finally realizing one-time high-speed confidential communication through the logical XOR encryption of the true random encryption key stream and the plaintext data. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 The present invention is a schematic structural diagram of an embodiment of a one-time pad high-speed secure optical communication method based on space division multiplexing technology. In the figure, 1. A party's true random key generation and encryption unit: true random key generation unit (101), true random key electrical domain encryption unit (102), true random key sending unit (103), true random key optical domain encryption unit (104); 2. B party's true random key decryption unit: true random key optical domain decryption unit (201), true random key receiving unit (202), true random key demodulation unit (203), true random key electrical domain decryption unit (204); 3. B party's true random key generation and encryption unit: true random key generation unit (301), true random key electrical domain encryption unit (302), true random key sending unit (303), true random key optical domain encryption unit (304); 4. A party's true random key decryption unit: true random key optical domain decryption unit (201), true random key receiving unit (202), true random key demodulation unit (203), true random key electrical domain decryption unit (204); Machine key optical domain decryption unit (401), true random key receiving unit (402), true random key demodulation unit (403), true random key electrical domain decryption unit (404); 5. Space division multiplexing optical fiber transmission link unit: space division multiplexing fan-in fan-out unit (501), space division multiplexing transmission optical fiber (502), space division multiplexing fan-in fan-out unit (503); 6. Party A one-time pad encryption and decryption unit: true random key logical exclusive OR unit (601), confidential data logical exclusive OR unit (602), confidential data unit (603); 7. Party A transmission unit; 8. Party B transmission unit; 9. Party B one-time pad encryption and decryption unit: true random key logical exclusive OR unit (901), confidential data logical exclusive OR unit (902), confidential data unit (903);

[0024] Figure 2The figure is a flow chart of an embodiment of a one-time pad secure communication method based on space-division multiplexing optical fiber according to the present invention.

[0025] Figure 3 Schematic diagram of an embodiment of true random key encryption and decryption of the present invention. DETAILED DESCRIPTION

[0026] The accompanying drawings are for illustrative purposes only and are not to be construed as limiting this patent;

[0027] In order to better illustrate this embodiment, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product size;

[0028] It is understandable to those skilled in the art that some well-known structures and descriptions thereof may be omitted in the drawings.

[0029] The technical solution of the present invention is further described below with reference to the accompanying drawings and embodiments.

[0030] This embodiment provides a one-time pad secure communication system based on space division multiplexing optical fiber. Figure 1 As shown, it includes a true random key generation and encryption unit (1) for communication party A, a true random key decryption unit (2) for communication party B, a true random key generation and encryption unit (3) for party B, a true random key decryption unit (4) for party A, a space division multiplexing optical fiber transmission link unit (5), a one-time pad encryption and decryption unit (6) for party A, a transmission unit (7) for party A, a transmission unit (8) for party B, and a one-time pad encryption and decryption unit (9) for party B. Wherein, the Party A true random key generation and encryption unit (1) and the Party A true random key decryption unit (4) provide an encryption key for the Party A one-time pad encryption and decryption unit (6), the Party A one-time pad encryption and decryption unit (6) provides the Party A transmission unit (7) with the encrypted plaintext data to be sent by Party A, and the Party A transmission unit (7) provides the Party A one-time pad encryption and decryption unit (6) with the Party B encrypted plaintext data to be decrypted; the Party B true random key generation and encryption unit (3) and the Party B true random key decryption unit (2) provide an encryption key for the Party B one-time pad encryption and decryption unit (9), the Party B one-time pad encryption and decryption unit (9) provides the Party B transmission unit (8) with the Party B encrypted plaintext data to be sent by Party B, and the Party B transmission unit (8) provides the Party B one-time pad encryption and decryption unit (9) with the Party A encrypted plaintext data to be decrypted;

[0031] The true random key generation and encryption unit (1) of Party A in this embodiment comprises: a true random key generation unit (101), a true random key electrical domain encryption unit (102), a true random key sending unit (103), and a true random key optical domain encryption unit (104); wherein the output end of the true random key generation unit (101) is connected to the input end of the true random key electrical domain encryption unit (102), the output end of the true random key electrical domain encryption unit (102) is connected to the input end of the true random key sending unit (103), and the output end of the true random key sending unit (103) is connected to the input end of the true random key optical domain encryption unit (104). The true random key generation unit (101) is used to generate a true random key K A , characterized in that the statistical characteristics of the key do not have periodicity; the true random key electric domain encryption unit (102) is used to encrypt the true random key K generated by the true random key generation unit (101) A The invention relates to a method for performing scrambling operations such as scrambling and replacing to realize electrical domain encryption. The true random key sending unit (103) is used to modulate the true random key encrypted by the true random key electrical domain encryption unit and send it in the optical domain. The true random key optical domain encryption unit (104) is used to perform optical domain scrambling encryption on the true random electrical domain encryption key modulated onto the optical carrier.

[0032] The true random key decryption unit (2) of party B in this embodiment comprises: a true random key optical domain decryption unit (201), a true random key receiving unit (202), a true random key demodulation unit (203), and a true random key electrical domain decryption unit (204); wherein the output end of the true random key optical domain decryption unit (201) is connected to the input end of the true random key receiving unit (202), the output end of the true random key receiving unit (202) is connected to the input end of the true random key demodulation unit (203), and the output end of the true random key demodulation unit (203) is connected to the input end of the true random key electrical domain decryption unit (204). The true random key optical domain decryption unit (201) of party B is used to perform optical domain decryption on the true random key encrypted by the true random key optical domain encryption unit of party A. The true random key receiving unit (202) of party B is used to perform photoelectric detection and reception on the decrypted true random key and convert it into an electrical signal. The B-party true random key demodulation unit (203) is used to demodulate the decrypted true random key electrical signal; the B-party true random key electrical domain decryption unit (204) is used to perform electrical domain descrambling on the demodulated true random key electrical signal to restore the original true random key K sent by the A-party. A .

[0033] The true random key generation and encryption unit (3) of party B in this embodiment includes: a true random key generation unit (301), a true random key electrical domain encryption unit (302), a true random key sending unit (303), and a true random key optical domain encryption unit (304); wherein the output end of the true random key generation unit (301) is connected to the input end of the true random key electrical domain encryption unit (302), the output end of the true random key electrical domain encryption unit (302) is connected to the input end of the true random key sending unit (303), and the output end of the true random key sending unit (303) is connected to the input end of the true random key optical domain encryption unit (304). The true random key generation unit (301) is used to generate a true random key K B , characterized in that the statistical characteristics of the key do not have periodicity; the true random key electronic domain encryption unit (302) is used to encrypt the true random key K generated by the true random key generation unit B The invention relates to a method for performing scrambling operations such as scrambling and replacing to realize electrical domain encryption. The true random key sending unit (303) is used to modulate the true random key encrypted by the true random key electrical domain encryption unit and send it in the optical domain. The true random key optical domain encryption unit (304) is used to perform optical domain scrambling encryption on the true random electrical domain encryption key modulated onto the optical carrier.

[0034] The true random key decryption unit (4) of Party A in this embodiment comprises: a true random key optical domain decryption unit (401), a true random key receiving unit (402), a true random key demodulation unit (403), and a true random key electrical domain decryption unit (404); wherein the output end of the true random key optical domain decryption unit (401) is connected to the input end of the true random key receiving unit (402), the output end of the true random key receiving unit (402) is connected to the input end of the true random key demodulation unit (403), and the output end of the true random key demodulation unit (403) is connected to the input end of the true random key electrical domain decryption unit (404). The true random key optical domain decryption unit (401) of Party A is used to perform optical domain decryption on the true random key encrypted by the true random key optical domain encryption unit of Party B. The true random key receiving unit (402) of Party A is used to perform photoelectric detection and reception on the decrypted true random key and convert it into an electrical signal. The A-party true random key demodulation unit (403) is used to demodulate the decrypted true random key electrical signal; the A-party true random key electrical domain decryption unit (404) is used to perform electrical domain descrambling on the demodulated true random key electrical signal to recover the original true random key K sent by the B-party. B .

[0035] The spatial division multiplexing optical fiber transmission link unit (5) of this embodiment includes: a spatial division multiplexing fan-in fan-out unit (501), a spatial division multiplexing transmission optical fiber (502), and a spatial division multiplexing fan-in fan-out unit (503); wherein the spatial division multiplexing fan-in fan-out units (501) and (503) are connected to the true random key generation and encryption units (1) and (3) of Party A and Party B, the true random key decryption units (2) and (4), the one-time pad encryption and decryption units (6) and (9), and the transmission units (7) and (8). The spatial division multiplexing optical fiber transmission link unit (5) is used for bidirectional transmission of the true random key encryption signals of Party A and Party B, as well as the confidential data signals of Party A and Party B. The spatial division multiplexing optical fiber transmission link unit (5) can be a spatial division multiplexing multi-core optical fiber, a few-mode optical fiber, a multi-core few-mode optical fiber, etc.

[0036] The one-time pad encryption and decryption unit (6) of Party A in this embodiment includes: a true random key logic XOR unit (601), a confidential data logic XOR unit (602), and a confidential data unit (603); wherein, the two input ends of the true random key logic XOR unit (601) are respectively connected to the output ends of the true random key generation unit (101) and the true random key electric domain decryption unit (404), the output end of the true random key logic XOR unit (601) is connected to the input end of the confidential data logic XOR unit (602), and the other input and output ends of the confidential data logic XOR unit (602) are respectively connected to the input and output ends of the confidential data unit (603) and the Party A transmission unit (701). The one-time pad encryption and decryption unit (6) is used to generate a true random key K that is consistent with that of Party A and Party B for encrypting confidential data. C The true random key logical exclusive OR unit (601) is used to receive the original true random key K generated by the true random key generating unit (101) of party A. A The true random key K sent by Party B and received by Party A's true random key electronic domain decryption unit (404) B , and perform a logical XOR operation to generate the encryption and decryption true random key K that is ultimately used to encrypt Party A’s plaintext data and decrypt Party B’s ciphertext data C The confidential data logical exclusive OR unit (602) is used to receive the true random encryption key of the true random key logical exclusive OR unit (601) and the plain text data in the confidential data unit (603), perform a logical exclusive OR operation on them, and generate encrypted data to be sent to party B; and is also used to receive the ciphertext data of party B output by the party A transmission unit (7), perform a logical exclusive OR operation on the ciphertext data of party B with the true random decryption key generated by the true random key logical exclusive OR unit (601), generate the decrypted plain text data sent by party B, and store it in the confidential data unit (603); the true random encryption key and the true random decryption key are the same;

[0037] The input and output ends of the party A transmission unit (7) in this embodiment are connected to the party A one-time pad encryption unit (6) and the optical fiber transmission link unit (5), and are used to receive the true random key generated by the party A one-time pad encryption unit (6) to encrypt the party A ciphertext to party B, and to receive the party B ciphertext encrypted with the true random key sent by party B to the party A one-time pad decryption unit (6);

[0038] The input and output ends of the party B transmission unit (8) in this embodiment are connected to the party B one-time pad encryption unit (9) and the optical fiber transmission link unit (5), and are used to receive the party A ciphertext encrypted with the true random key sent by party A and send it to the party B one-time pad decryption unit (9), and to receive the party B ciphertext encrypted with the true random key generated by the party B one-time pad encryption unit (9) and send it to party A;

[0039] The one-time pad encryption and decryption unit (9) of Party B in this embodiment includes: a true random key logic exclusive OR unit (901), a confidential data logic exclusive OR unit (902), and a confidential data unit (903); wherein, the two input ends of the true random key logic exclusive OR unit (901) are respectively connected to the output ends of the true random key generation unit (301) and the true random key electric domain decryption unit (204), the output end of the true random key logic exclusive OR unit (901) is connected to the input end of the confidential data logic exclusive OR unit (902), and the other input and output ends of the confidential data logic exclusive OR unit (902) are respectively connected to the confidential data unit (903) and the input and output ends of the Party B transmission unit (801). The one-time pad encryption and decryption unit (9) is used to generate a true random key K that is consistent with that of Party A and Party B for encrypting confidential data. C The true random key logical exclusive OR unit (901) is used to receive the original true random key K generated by the true random key generating unit (301) of the party B. B The true random key K sent by party A is received by party B's true random key electronic domain decryption unit (204) A , and perform a logical XOR operation to generate the encryption and decryption true random key K that is ultimately used to encrypt Party B’s plaintext data and decrypt Party A’s ciphertext data C The confidential data logical exclusive OR unit (902) is used to receive the true random encryption key of the true random key logical exclusive OR unit (901) and the plain text data in the confidential data unit (903), perform a logical exclusive OR operation on them, and generate encrypted data to be sent to Party A; and is also used to receive the ciphertext data of Party A output by the Party B transmission unit (8), perform a logical exclusive OR operation on the ciphertext data of Party A and the true random decryption key generated by the true random key logical exclusive OR unit (901), generate the decrypted plain text data sent by Party A, and store it in the confidential data unit (903); the true random encryption key and the true random decryption key are the same;

[0040] The true random key generation unit can generate the true random key by sampling and quantizing based on a noise light source, a chaotic light source or quantum noise;

[0041] The encryption unit of the true random key can be implemented by P-box permutation, S-box nonlinear scrambling, etc.

[0042] The embodiment process of the one-time pad confidential communication method based on space division multiplexing optical fiber is as follows: Figure 2 As shown, the following steps are included:

[0043] S1: Both communicating parties independently configure a true random number generator that is unrelated to each other;

[0044] S2: The true random number generators configured by both communicating parties generate a true random key sequence with a length no less than the plaintext length;

[0045] S3: The communicating parties perform permutation and scrambling of their generated true random key sequences, encrypting them in the electrical domain, and modulating them onto the optical signal.

[0046] S4: The communicating parties encrypt the true random key sequences modulated onto the optical signal in the optical domain and scramble the true random key sequences encrypted in the electrical domain.

[0047] S5: The communicating parties send their respective optically encrypted true random key sequences through the optical sending unit into different channels of the spatial division multiplexing optical fiber to each other;

[0048] S6: The communicating parties decrypt the encrypted true random key sequence received from the other party, recover the other party's original true random key sequence, and perform an XOR operation with the self-generated true random key sequence to obtain the same symmetric encryption and decryption key;

[0049] S7: The communicating parties use the generated key to XOR encrypt the plaintext data and modulate it onto an optical signal for secure transmission via space-division multiplexing optical fiber.

[0050] S8: The receiver uses the consistent key to XOR decrypt the ciphertext data and complete the one-time confidential communication.

[0051] The terms used in the drawings to describe positional relationships are for illustrative purposes only and should not be construed as limiting this patent;

[0052] Obviously, the above embodiments of the present invention are merely examples for the purpose of clearly illustrating the present invention, and are not intended to limit the embodiments of the present invention. Those skilled in the art will appreciate that other variations or modifications can be made based on the above description. It is not necessary and impossible to enumerate all embodiments here. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the claims of the present invention.

Claims

1. A one-time, one-pad, high-speed, secure optical communication method based on space division multiplexing technology, characterized in that: include: The two communicating parties obtain their own true random keys through independent true random key generation units; The communicating parties encrypt the true random keys they obtain through the electrical and optical encryption units to obtain the encrypted true random keys. The encrypted true random key is connected to a spatial channel of a space-division multiplexing optical fiber and transmitted to the communication party; The communicating parties decrypt the encrypted true random key transmitted via the space-division multiplexing optical fiber link through the electrical domain and optical domain decryption units to obtain the decrypted true random key; The communicating parties perform a logical XOR operation on the decrypted true random key and the true random key generated by themselves to generate a consistent true random key for one-time pad encryption and decryption; The communicating parties use the final true random key to perform a one-time logical XOR encryption on the plaintext data to generate ciphertext data, and then transmit the ciphertext data through other channels of the space-division multiplexing optical fiber link; The receiver performs logical XOR decryption using the one-time pad true random key shared by the final draft to restore the original plaintext data, thus achieving one-time pad high-speed data confidential communication.

2. The one-time pad high-speed secure optical communication method according to claim 1, characterized in that: The true random key generating unit may be a quantum true random key generator or a chaotic true random key generator.

3. The one-time pad high-speed secure optical communication method according to claim 1, characterized in that: The electrical domain encryption unit is used to perform electrical domain replacement and scrambling operations on the true random key; the optical domain encryption unit is used to perform optical domain scrambling on the replaced and scrambled true random key to achieve scrambling encryption of the true random key in terms of intensity and phase.

4. The one-time pad high-speed secure optical communication method according to claim 1, wherein: The electrical domain decryption unit is used to perform electrical domain reversible replacement and reversible scrambling operations on the encrypted true random key; the optical domain decryption unit is used to perform optical domain descrambling on the encrypted true random key, eliminate the disturbance of the true random key in intensity and phase, and restore the original true random key.

5. The one-time pad high-speed secure optical communication method according to claim 1, characterized in that: The space division multiplexing optical fiber can be a multi-core optical fiber, a few-mode optical fiber, or a multi-core few-mode optical fiber.

6. A one-time-one-pad high-speed secure optical communication system based on space division multiplexing technology, characterized in that: include: A true random key generation unit, an electrical domain encryption unit, an optical domain encryption unit, a space-division multiplexing optical fiber link, an electrical domain decryption unit, an optical domain decryption unit, and a logical exclusive OR unit, wherein: The true random key generation unit is used for both communicating parties to independently generate their own true random keys; The electrical domain encryption unit is used to perform electrical domain encryption on the generated true random key; The optical domain encryption unit is used to perform optical domain encryption on the true random key encrypted in the electrical domain; The spatial division multiplexing optical fiber link is used to optically transmit the encrypted true random key signal generated by the optical domain encryption unit; The optical domain decryption unit is used to perform optical domain decryption on the encrypted true random key signal transmitted through the spatial division multiplexing optical fiber link; The electrical domain decryption unit is used to perform electrical domain decryption on the true random key decrypted in the optical domain to restore the original true random key; The logical XOR unit is used to perform a logical XOR on the received decryption true random key and the true random key generated by itself to generate a true random key that is ultimately used for one-time pad encryption and decryption; The one-time pad true random encryption and decryption key is used to perform one-time pad logical XOR encryption on plaintext data to be sent, or to perform one-time pad logical XOR decryption on received ciphertext data, thereby realizing high-speed confidential optical communication.

7. The one-time pad high-speed secure optical communication system according to claim 6, characterized in that: The electrical domain encryption unit may be an electrical domain P-box replacement unit or an electrical domain S-box nonlinear scrambling unit; the optical domain encryption unit may be an encryption unit based on dispersion or electro-optical phase feedback modulation.

8. The one-time pad high-speed secure optical communication system according to claim 6, characterized in that: The electrical domain decryption module may be an electrical domain P-box inverse permutation unit or an electrical domain S-box nonlinear inverse perturbation unit; the optical domain encryption unit may be a reversible decryption unit based on dispersion and electro-optical phase feedback modulation.

9. The one-time pad high-speed secure optical communication system according to claim 6, characterized in that: The true random keys independently generated and encrypted by the communicating parties are transmitted through different spatial channels of the space-division multiplexing optical fiber to prevent eavesdroppers from stealing the final one-time pad true random encryption and decryption keys through a single spatial channel.