Cross-domain quantum key distribution method of optical transport network, OTN device and system

By negotiating cross-domain quantum key distribution between OTN devices and a quantum cryptography service platform, the key distribution problem of OTN transmission networks in cross-domain scenarios is solved, realizing secure and efficient quantum key distribution and encryption/decryption, which is suitable for complex networking environments.

CN119011141BActive Publication Date: 2026-07-24CHINA TELECOM QUANTUM TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM QUANTUM TECH CO LTD
Filing Date
2024-08-28
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing technologies, OTN transmission networks lack an effective quantum key distribution mechanism in cross-domain scenarios and face key security risks. In particular, existing key distribution modes are not applicable and lack security protection in OTN cross-metropolitan area networking and wide area networking environments.

Method used

Cross-domain quantum key distribution is achieved by sending cross-domain session key application information to the quantum cryptography service platform through the OTN device, generating and forwarding KeyBlock to the peer OTN device, using a pre-set quantum key as the user's master key to encrypt the working key, and combining it with the national cryptographic SM4 algorithm for data encryption and decryption. The quantum key distribution network is used to implement symmetric key pool caching to avoid direct connection to the quantum cryptography service platform.

Benefits of technology

It realizes the negotiation and distribution of cross-domain quantum keys in OTN transport networks, solves the cross-domain key distribution problem, improves the security and integrity of keys, reduces the difficulty of system modification, is suitable for complex networking environments, and remains secure in quantum computing environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011141B_ABST
    Figure CN119011141B_ABST
Patent Text Reader

Abstract

The application discloses a cross-domain quantum key distribution method of an optical transport network, an OTN device and a system. The method comprises the following steps: sending cross-domain session key application information to a corresponding first quantum cryptography service platform; receiving session key information returned by the first quantum cryptography service platform, wherein the session key information comprises a working key KeyValue and a cross-platform key request field, the cross-platform key request field comprises a working key identifier KeyID, a key identifier key_tag and a cross-platform session key application value Keyblock; and delivering the cross-platform key request field to a peer OTN device through an overhead byte of an ODUk, so that the peer OTN device requests a corresponding second quantum cryptography service platform to acquire the working key KeyValue based on the cross-platform key request field. The application realizes cross-domain distribution of quantum keys of an OTN transmission network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, specifically to a cross-domain quantum key distribution method, OTN device, and system for optical transport networks. Background Technology

[0002] In recent years, with the rapid development of informatization and digitalization, optical transport networks (OTNs) have become a crucial part of information infrastructure due to their high bandwidth, high transmission rate, and low loss characteristics. Information infrastructure serves vital systems closely related to national welfare and people's livelihoods, such as finance, energy, transportation, water supply, healthcare, and emergency services. Ensuring the security of information infrastructure has become a rigid requirement for the development of informatization. As optical transport networks continue to develop and become more widespread, and with the constantly evolving and deepening types of information security risks, most existing optical transport networks operate in a "data-naked" state, with only a few using public-key cryptography for key distribution. However, with the rapid development of computing power, represented by quantum computing, unprecedented challenges have been brought to the traditionally widely used public-key cryptography system for information security. Cryptographic technology, as the most critical line of defense for information security, urgently requires new technological means to improve the security level of existing optical transport networks.

[0003] In related technologies, the quantum key distribution scheme proposed in the invention patent application document with publication number CN108667526A involves generating a quantum key through negotiation by a quantum key distribution (QKD) terminal and storing it in the key storage unit of the corresponding node. After multiple services are multiplexed and mapped into the optical path data unit ODUk, the quantum key is directly obtained through the key storage unit to encrypt the optical path data unit ODUk. This scheme focuses on data encryption and decryption based on quantum keys for multiple service types, but does not directly describe the specific implementation method of obtaining the quantum key.

[0004] The invention patent application document with publication number CN111224772A describes a method for distributing and managing symmetric encryption keys in an OTN transmission system. By using the encryption end and decryption end to apply for keys from the key management end, this scheme focuses on the symmetric key management method in a multi-level cross-domain environment. It is a further integration and application of quantum key distribution and OTN transmission system, but does not directly describe the specific implementation method.

[0005] The drawbacks of the key distribution modes proposed by the aforementioned technologies are:

[0006] (1) In terms of key distribution mode, the key distribution mode proposed by the above-mentioned related technologies is not suitable for the complex networking environment of OTN transmission network, especially in cross-domain scenarios such as OTN cross-metropolitan area networking and wide area networking, there is a lack of a mechanism and method to support cross-domain quantum key distribution.

[0007] (2) In terms of key security, the key distribution mode proposed by the above-mentioned related technologies lacks security protection for key distribution and storage, and there are security risks such as key theft and tampering. Summary of the Invention

[0008] The technical problem to be solved by this invention is how to achieve cross-domain distribution of quantum keys in OTN transmission networks.

[0009] The present invention solves the above-mentioned technical problems through the following technical means: On one hand, this invention proposes a cross-domain quantum key distribution method for optical transport networks, applied to OTN devices, the method comprising: Send cross-domain session key request information to the corresponding first quantum cryptography service platform; The system receives session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag in the key filling process, and a cross-platform session key request value KeyBlock. The cross-platform key request field is transmitted to the peer OTN device via the overhead bytes of ODUk, so that the peer OTN device can request the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field.

[0010] Furthermore, the cross-domain session key request information includes session ID, key length, peer OTN device information, and plaintext service policy configuration information; The plaintext of the business policy configuration information includes a unique business policy identifier, a business policy validity period, a local OTN device identifier, an identifier of the first quantum cryptography service platform corresponding to the local OTN device, an identifier of the peer OTN device, and an identifier of the second quantum cryptography service platform corresponding to the peer OTN device.

[0011] Furthermore, before sending the cross-domain session key request information to the corresponding first quantum cryptography service platform, the method further includes: A communication network was established between the DCN network and the First Quantum business management platform; Receive the encrypted business policy configuration information and the hash value of the plaintext business policy configuration information sent by the first quantum business management platform; The encrypted business strategy configuration information is decrypted and the hash value is verified to obtain the plaintext business strategy configuration information.

[0012] Furthermore, the encrypted business strategy configuration information is obtained by encrypting the plaintext business strategy configuration information using the Chinese national cryptographic symmetric encryption algorithm CBC mode; The hash value of the plaintext of the business strategy configuration information is obtained by performing a hash operation on the plaintext of the business strategy configuration information using the national cryptographic hash algorithm SM3.

[0013] Furthermore, the first quantum cryptography service platform and the second quantum cryptography service platform pre-cache a symmetric key pool, which stores quantum keys distributed by the quantum key distribution network; The symmetric key pool in the first quantum cryptography service platform stores the identifier of the first quantum cryptography service platform and the key identifier key_tag; The symmetric key pool in the second quantum cryptography service platform stores the identifier of the second quantum cryptography service platform and the key identifier key_tag.

[0014] Furthermore, the KeyValue is a working key of the corresponding length obtained by the first quantum cryptography service platform or the second quantum cryptography service platform from its own cross-domain key pool based on the key length.

[0015] Furthermore, the OTN device has a pre-installed quantum key as a user master key, and applies for the working key from the first quantum cryptography service platform based on the user master key.

[0016] Furthermore, the working key included in the session key information is encrypted using the user's master key.

[0017] Furthermore, after both the local OTN device and the remote OTN device have obtained the working key, the method further includes: The payload data of ODUk is encrypted and decrypted based on the working key and the national cryptographic SM4 algorithm.

[0018] Secondly, the present invention provides an OTN device, the OTN device comprising: The session key request module is used to send cross-domain session key request information to the corresponding first quantum cryptography service platform; The session key information receiving module is used to receive session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag, and a cross-platform session key request value KeyBlock. The cross-domain forwarding module is used to transmit the cross-platform key request field to the peer OTN device through the overhead bytes of ODUk, so that the peer OTN device can request the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field.

[0019] Thirdly, the present invention proposes a cross-domain quantum key distribution system for optical transport networks, the system comprising a first OTN device, a second OTN device, a first quantum service management platform, a second quantum service management platform, a first quantum cryptography service platform, a second quantum cryptography service platform, and a quantum key distribution network; The first OTN device is connected to the first quantum service management platform and the first quantum cryptography service platform via the DCN network; the second OTN device is connected to the second quantum service management platform and the second quantum cryptography service platform via the DCN network; the first quantum cryptography service platform is connected to both the first quantum service management platform and the quantum key distribution network; the second quantum cryptography service platform is connected to both the second quantum service management platform and the quantum key distribution network. The first OTN device and the second OTN device are used to perform the cross-domain quantum key distribution method for optical transport networks as described above.

[0020] The advantages of this invention are: (1) In this invention, the OTN device, acting as the active end, sends cross-domain session key application information to its corresponding quantum cryptography service platform, generates and forwards KeyBlock to the OTN device, acting as the passive end, for the passive end OTN device to apply for cross-domain quantum keys from the quantum cryptography service platform corresponding to the passive end. The cross-domain key application is completed through negotiation between OTN devices, without the need for synchronization between the two quantum cryptography service platforms, thus solving the problem of cross-domain quantum key distribution in the OTN transmission network; and the two quantum cryptography service platforms are not directly connected, thus solving the problem of centralized cross-domain key distribution in the quantum cryptography service platform.

[0021] (2) The OTN device uses a pre-set quantum key as the user master key. Based on the user master key, it applies for a working key from the quantum cryptography service platform. The working key is encrypted and distributed using the user master key and its integrity is verified. This solves the problem that the key distribution of traditional OTN transmission networks is not encrypted or the encryption depends on public key algorithms.

[0022] (3) Based on the information theory security of quantum key distribution, the negotiation and generation of quantum symmetric keys are realized, which remains secure even with the infinite computing resources of quantum computing; the quantum symmetric key is used as the key encryption key for the working key of the end-to-end OTN leased line service, and the existing public key cryptographic algorithm that is vulnerable to quantum computing attacks is replaced by the SM4 symmetric algorithm.

[0023] (4) The system modification is small. The OTN device uses a mature cryptographic module integration scheme to provide key storage and cryptographic algorithm functions. The quantum cryptography service platform implements symmetric quantum key pool caching based on the quantum key distribution network. The OTN device does not directly connect to the quantum key distribution network, which is easy to implement and does not have to worry about the problem of large key consumption on the server side.

[0024] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0025] Figure 1 This is a schematic flowchart of a cross-domain quantum key distribution method for an optical transport network proposed in an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of an OTN device according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a cross-domain quantum key distribution system for an optical transport network according to an embodiment of the present invention; Figure 4 This is a flowchart of cross-platform quantum key distribution in one embodiment of the present invention; Figure 5 This is a flowchart of cross-domain business management in one embodiment of the present invention; Figure 6 This is a flowchart of cross-domain session key distribution in one embodiment of the present invention. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] like Figure 1 As shown, the first embodiment of the present invention discloses a cross-domain quantum key distribution method for optical transport networks, the method comprising the following steps: S10. Send cross-domain session key application information to the corresponding first quantum cryptography service platform; S20. Receive session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag in the key filling and a cross-platform session key application value KeyBlock. The cross-platform session key application value is used to encode cross-platform session key application information. S30. The cross-platform key request field is transmitted to the peer OTN device through the overhead bytes of ODUk, so that the peer OTN device requests the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field.

[0028] This embodiment utilizes an OTN device acting as the active end to send cross-domain session key request information to its corresponding quantum cryptography service platform, generating and forwarding a KeyBlock to the OTN device acting as the passive end. This KeyBlock is then used by the passive OTN device to request a cross-domain quantum key from its corresponding quantum cryptography service platform. The cross-domain key request is negotiated between the OTN devices, eliminating the need for synchronization between the two quantum cryptography service platforms and solving the problem of cross-domain quantum key distribution in the OTN transmission network. Furthermore, since the two quantum cryptography service platforms are not directly connected, this solves the problem of centralized cross-domain key distribution in the quantum cryptography service platform.

[0029] In one embodiment, the cross-domain session key request information includes session ID, key length, peer OTN device information, and plaintext service policy configuration information; The plaintext of the business policy configuration information includes a unique business policy identifier, a business policy validity period, a local OTN device identifier, an identifier of the first quantum cryptography service platform corresponding to the local OTN device, an identifier of the peer OTN device, and an identifier of the second quantum cryptography service platform corresponding to the peer OTN device.

[0030] In one embodiment, before step S10: sending cross-domain session key request information to the corresponding first quantum cryptography service platform, the method further includes the following steps: S11. Establish a communication network between the DCN network and the first quantum business management platform; S12. Receive the encrypted service policy configuration information and the hash value of the plaintext service policy configuration information sent by the first quantum service management platform. It should be noted that the business management platform is responsible for the transparent transmission of encrypted information, and uses the user's master key to encrypt the plaintext of business policy configuration information.

[0031] S13. Decrypt the encrypted business strategy configuration information and verify the hash value to obtain the plaintext business strategy configuration information.

[0032] In one embodiment, the encrypted business policy configuration information in step S12 is obtained by encrypting the plaintext business policy configuration information using the Chinese national cryptographic symmetric encryption algorithm CBC mode; The hash value of the plaintext of the business strategy configuration information in step S13 is obtained by performing a hash operation on the plaintext of the business strategy configuration information using the national cryptographic hash algorithm SM3.

[0033] In one embodiment, the first quantum cryptography service platform and the second quantum cryptography service platform pre-cache a symmetric key pool, which stores quantum keys distributed by a quantum key distribution network; The symmetric key pool in the first quantum cryptography service platform stores the identifier of the first quantum cryptography service platform and the key identifier key_tag; The symmetric key pool in the second quantum cryptography service platform stores the identifier of the second quantum cryptography service platform and the key identifier key_tag.

[0034] In one embodiment, the KeyValue is a working key of the corresponding length obtained by the first quantum cryptography service platform or the second quantum cryptography service platform from its own cross-domain key pool based on the key length.

[0035] In one embodiment, the OTN device has a pre-installed quantum key as a user master key, and applies for the working key from the first quantum cryptography service platform based on the user master key, specifically by applying for the working key based on the key tag associated with the user master key.

[0036] In one embodiment, the working key included in the session key information is encrypted using the user master key.

[0037] It should be noted that the OTN device terminal is pre-installed with a quantum key as the user master key. When applying for a working key from the quantum cryptography service platform based on the user master key, the working key is encrypted and distributed using the user master key and its integrity is verified. That is, after receiving the working key, the master key and key_tag information are used to decrypt the key and perform a hash operation. The integrity of the working key is verified by comparing the hash values. This solves the problem that traditional OTN transmission network key distribution is not encrypted or relies on public key algorithms for encryption.

[0038] In one embodiment, after both the local OTN device and the remote OTN device have obtained the working key, the method further includes: The payload data of ODUk is encrypted and decrypted based on the working key and the national cryptographic SM4 algorithm.

[0039] Specifically, the ODUk is an optical path data unit, which mainly includes the ODUk frame structure, ODUk bit rate, and bit rate tolerance.

[0040] like Figure 2 As shown, a second embodiment of the present invention discloses an OTN device, the OTN device comprising: The session key application module 10 is used to send cross-domain session key application information to the corresponding first quantum cryptography service platform; The session key information receiving module 20 is used to receive session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag, and a cross-platform session key request value Keyblock. The cross-domain forwarding module 30 is used to transmit the cross-platform key request field to the peer OTN device through the overhead bytes of ODUk, so that the peer OTN device can request the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field.

[0041] This embodiment utilizes an OTN device acting as the active end to send cross-domain session key request information to its corresponding quantum cryptography service platform, generating and forwarding a key_block to the OTN device acting as the passive end. This key_block is used by the passive OTN device to request a cross-domain quantum key from its corresponding quantum cryptography service platform. The cross-domain key request is negotiated between the OTN devices, eliminating the need for synchronization between the two quantum cryptography service platforms, thus solving the problem of cross-domain quantum key distribution in the OTN transmission network. Furthermore, since the two quantum cryptography service platforms are not directly connected, this solves the problem of centralized cross-domain key distribution in the quantum cryptography service platform.

[0042] In one embodiment, the cross-domain session key request information includes session ID, key length, peer OTN device information, and plaintext service policy configuration information; The plaintext of the business policy configuration information includes a unique business policy identifier, a business policy validity period, a local OTN device identifier, an identifier of the first quantum cryptography service platform corresponding to the local OTN device, an identifier of the peer OTN device, and an identifier of the second quantum cryptography service platform corresponding to the peer OTN device.

[0043] In one embodiment, the OTN device further includes a cross-domain service management module, specifically used to implement quantum service policy configuration distribution with the corresponding quantum service management platform based on the DCN network, and to control the cross-domain key application of the OTN terminal. The cross-domain service management module is specifically used for: A communication network was established between the DCN network and the First Quantum business management platform; Receive the encrypted business policy configuration information and the hash value of the plaintext business policy configuration information sent by the first quantum business management platform; The encrypted business strategy configuration information is decrypted and the hash value is verified to obtain the plaintext business strategy configuration information.

[0044] Specifically, the First Quantum Service Management Platform establishes a connection with the OTN device based on the DCN network. The First Quantum Service Management Platform constructs service policy configuration information, which includes a unique service policy identifier, the service policy validity period, the active OTN device identifier, the CSP identifier to which the active OTN device belongs, the passive OTN device identifier, and the CSP identifier to which the passive OTN device belongs.

[0045] Furthermore, considering the security of business policy configuration distribution, the business policy configuration information is encrypted using SM4 CBC to generate ciphertext, and the hash value of the plaintext business policy configuration information is calculated using the SM3 algorithm. The corresponding quantum service management platform then distributes the ciphertext and hash value of the business policy configuration information to the corresponding OTN device.

[0046] It should be noted that SM4 CBC refers to the CBC mode of the Chinese national cryptographic symmetric encryption algorithm. CBC is the abbreviation for Cipher Block Chaining, which means ciphertext block chaining mode. SM3 is the abbreviation for the Chinese national cryptographic hash algorithm, and hash is the abbreviation for one-way hash function.

[0047] In one embodiment, the first quantum cryptography service platform and the second quantum cryptography service platform pre-cache a symmetric key pool, which stores quantum keys distributed by a quantum key distribution network; The symmetric key pool in the first quantum cryptography service platform stores the identifier of the first quantum cryptography service platform and the key identifier key_tag; The symmetric key pool in the second quantum cryptography service platform stores the identifier of the second quantum cryptography service platform and the key identifier key_tag.

[0048] Specifically, the quantum keys stored in the symmetric key pool are distributed across quantum cryptography service platforms via a quantum key distribution network (QKD). The distribution process is as follows: After the first and second quantum cryptography service platforms connect to the QKD, the first QKD, as the active end, initiates a key request to the QKD, including a CSP-A identifier and a key tag. The CSP-A identifier and key tag are then transmitted through the QKD to the corresponding second QKD side, where the second QKD's CSP-B side stores the CSP-A identifier and key tag. Similarly, the first QKD's CSP-A side also obtains the CSP-B identifier and key tag. The QKD then distributes the quantum keys using a "request-push" method, and both the first and second QKD service platforms obtain the quantum keys and cache them in the cross-domain symmetric quantum key pool keycacheAB.

[0049] In one embodiment, the KeyValue is a working key of the corresponding length obtained by the first quantum cryptography service platform or the second quantum cryptography service platform from its own cross-domain key pool based on the key length.

[0050] In one embodiment, the OTN device has a pre-installed quantum key as a user master key, and applies for the working key from the first quantum cryptography service platform based on the user master key.

[0051] In one embodiment, the working key included in the session key information is encrypted using the user master key.

[0052] In one embodiment, the OTN device further includes an encryption / decryption processing module, specifically used to: encrypt and decrypt the payload data of ODUk based on the working key and the national cryptographic SM4 algorithm.

[0053] like Figure 3 As shown, the third embodiment of the present invention also discloses a cross-domain quantum key distribution system for optical transport networks. The system includes a first OTN device, a second OTN device, a first quantum service management platform, a second quantum service management platform, a first quantum cryptography service platform, a second quantum cryptography service platform, and a quantum key distribution network. The first OTN device is connected to the first quantum service management platform and the first quantum cryptography service platform via the DCN network; the second OTN device is connected to the second quantum service management platform and the second quantum cryptography service platform via the DCN network; the first quantum cryptography service platform is connected to both the first quantum service management platform and the quantum key distribution network; the second quantum cryptography service platform is connected to both the second quantum service management platform and the quantum key distribution network. The first OTN device and the second OTN device are used to perform the cross-domain quantum key distribution method for optical transport networks as described in the first embodiment above.

[0054] Specifically, the quantum key distribution network (QKD) is a key distribution process that achieves information-theoretically secure key distribution by transmitting quantum states between communicating parties. Any eavesdropping will be detected promptly due to the disturbance of the quantum states. A QKD is a hardware and software system used to implement the quantum optical processes (including QKD protocol, synchronization, key distillation, etc.) and cryptographic functions required for quantum key distribution. As endpoint modules that directly generate keys, QKDs can be interconnected via QKD links. Two typical types of QKDs are QKD transmitters (QKD-Tx) and QKD receivers (QKD-Rx).

[0055] The aforementioned OTN equipment refers to optical transport network equipment, primarily including "customer access points" and "aggregation rooms." Customer access points are selected as end-point OTN CPE devices with SDH, FE / GE / 10GE / 100GE service access capabilities. Aggregation rooms deploy OTN CPE aggregation equipment in service-intensive areas to complete uplink aggregation or wavelength division multiplexing (WDM) connections to existing networks within the area, and downlink connections to customer access point OTN CPEs.

[0056] The service branch board on the OTN equipment is an OTN branch board, which enables customer-side services to be added / dropped on the local WDM side. It is used to integrate cryptographic modules and connect to the quantum service management platform and the quantum cryptography service platform.

[0057] In this embodiment, the connection between the OTN terminal and the quantum service management platform and the quantum cryptography service platform is provided through the DCN network, which carries quantum-related data such as quantum key distribution, quantum data acquisition, and control. The DCN network is a data communication network and a key technology for transport network management.

[0058] Furthermore, the OTN device integrates a cryptographic module, which is pre-loaded with a quantum key via a quantum key distribution network as the user's master key. This cryptographic module conforms to national commercial cryptographic product standards and can take the form of a hardware security chip, a soft key, or other similar devices, directly integrated into the OTN terminal. It provides a secure medium with basic functions such as key storage and cryptographic computation, and can interface with a quantum cryptography service platform to achieve functions such as key loading and key application within the secure chip.

[0059] In one embodiment, the cross-domain quantum key distribution process of the optical transport network includes the following steps: (1) Cross-platform quantum key distribution: Quantum key distribution between quantum cryptography service platforms is realized based on quantum key distribution network.

[0060] (2) Cross-domain business management: The quantum business management platform implements quantum business policy configuration and distribution based on the DCN network, and realizes cross-domain key application control of OTN terminals.

[0061] (3) Cross-domain session key distribution: The OTN device integrates a cryptographic module with a pre-set quantum key as the user master key. Based on the user master key, the user applies for a session key from the quantum key management platform. The session key is encrypted and distributed using the user master key and its integrity is verified.

[0062] Furthermore, such as Figure 4 As shown, (1) the specific process of cross-platform quantum key distribution includes: quantum cryptography service platform A and quantum cryptography service platform B are respectively connected to the key management layer of the quantum key distribution network. Either quantum cryptography service platform initiates the quantum key distribution process as the active end, and the passive end obtains the symmetric key pool by pushing, and caches information such as symmetric key and key identifier on both quantum cryptography service platforms respectively. The implementation steps are as follows: 1-1) After the first quantum cryptography service platform CSP-A and the second quantum cryptography service platform CSP-B are connected to the quantum key distribution network, CSP-A, as the active end, initiates a key request to the quantum key distribution network. The request information includes the CSP-A identifier and the key identifier key_tag.

[0063] 1-2) The request information CSP-A identifier and key_tag are transmitted through the quantum key distribution network to the corresponding CSP-B side, and the CSP-B side stores the CSP-A identifier and key_tag; similarly, the CSP-A side also obtains the CSP-B identifier and key_tag.

[0064] 1-3) The active end CSP-A reads the key from the key management system of the local quantum key distribution network through the key acquisition interface and waits for the return from the local key management system; 1-4) The active-end key management system and the passive-end key management system complete key negotiation, verification and other operations, and return the key and additional information to the quantum cryptography service platform; 1-5) The active end CSP-A obtains the key and additional information through the key acquisition interface. 1-6) The passive CSP-B listens and waits for the local key management system to return key information; 1-7) The active and passive ends of the quantum cryptography service platform will cache the acquired keys in their local key cache pools for use by the corresponding OTN devices.

[0065] Furthermore, such as Figure 4 As shown, (2) the specific process of cross-domain service management includes: the first quantum service management platform and the second quantum service management platform establish connections with the corresponding OTN devices based on the DCN network, the first quantum service management platform and the second quantum service management platform issue encryption service policy configurations to the corresponding OTN devices, the OTN devices construct cross-domain key distribution KeyBlocks according to the configuration information, and forward them to the peer OTN devices. The implementation steps are as follows: 2-1) The first quantum business management platform and the second quantum business management platform establish connection relationships with OTN equipment based on the DCN network.

[0066] 2-2) The first quantum business management platform and the second quantum business management platform respectively construct business policy configuration information. The business policy configuration information includes a unique identifier for the business policy, the validity period of the business policy, the identifier of the active OTN device, the identifier of the CSP to which the active OTN device belongs, the identifier of the passive OTN device, and the identifier of the CSP to which the passive OTN device belongs.

[0067] 2-3) Considering the security of business policy configuration distribution, the business policy configuration information is encrypted using SM4 CBC to generate ciphertext, and the hash value of the plaintext business policy configuration information is calculated using the SM3 algorithm.

[0068] 2-4) The first quantum business management platform and the second quantum business management platform respectively send the hash values ​​of the encrypted and plaintext business policy configuration information to the corresponding OTN device side.

[0069] Furthermore, such as Figure 6 As shown, (3) Cross-domain session key distribution: The OTN branch board integrates a cryptographic module with a pre-set quantum key as the user master key. Based on the user master key, it applies for a session key from the quantum key management platform. The session key is encrypted and distributed using the user master key and its integrity is verified. After obtaining the session key, the branch board implements ODUk payload data encryption and decryption based on the national cryptographic algorithm. The specific implementation steps are as follows: 3-1) After receiving the encrypted and hash values ​​of the service policy configuration information, the OTN-A1 device terminal decrypts and verifies the integrity of the information to obtain the plaintext of the service policy configuration information.

[0070] 3-2) The OTN-A1 device terminal requests a cross-domain session key from the corresponding CSP-A in plaintext according to the service policy configuration information, and submits the session ID, key length, peer OTN device information, and service policy configuration information.

[0071] 3-3) CSP-A obtains a key of the corresponding length from the cross-domain key pool keycacheAB in the first phase as KeyValue, and returns the keyValue, KeyID, key_tag and KeyBlock of the key to the OTN-A1 device terminal. KeyBlock is valid when applying for cross-platform session keys, and this value is obtained by the caller when applying for session keys.

[0072] 3-4) The OTN-A1 device terminal, acting as the active end, forwards Keyblock, KeyID, and key_tag to the passive end OTN-B1 device terminal. These fields are transmitted in a specific format through the overhead bytes of ODUk.

[0073] 3-5) The OTN-B1 device terminal pushes Keyblock information to CSP-B to request and obtain the session key.

[0074] 3-6) CSP-B searches for the key in the cross-domain key pool keycacheAB based on Keyblock, KeyID, and key_tag, and returns the key value to the OTN-B1 terminal. The key value transmission process is protected by encryption using the charging key of the OTN-B1 terminal.

[0075] 3-7) After obtaining the session key, the OTN-A1 and OTN-B1 terminals send the corresponding session key to the host software of the tributary board through the internal channel. The host software uses the obtained session key in combination with the national cryptographic SM4 algorithm to encrypt and decrypt the payload data of ODUk.

[0076] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0077] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0078] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A cross-domain quantum key distribution method for optical transport networks, characterized in that, Applied to OTN devices, the method includes: A cross-domain session key request is sent to the corresponding first quantum cryptography service platform. The cross-domain session key request information includes a session ID, key length, peer OTN device information, and plaintext service policy configuration information. The plaintext service policy configuration information includes a unique service policy identifier, service policy validity period, local OTN device identifier, identifier of the first quantum cryptography service platform corresponding to the local OTN device, peer OTN device identifier, and identifier of the second quantum cryptography service platform corresponding to the peer OTN device. The system receives session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag, and a cross-platform session key request value KeyBlock. The cross-platform key request field is transmitted to the peer OTN device through the overhead bytes of ODUk, so that the peer OTN device can request the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field. The first quantum cryptography service platform and the second quantum cryptography service platform pre-cache symmetric key pools, which store quantum keys distributed by the quantum key distribution network. The symmetric key pool in the first quantum cryptography service platform stores the identifier of the first quantum cryptography service platform and the key identifier key_tag; The symmetric key pool in the second quantum cryptography service platform stores the identifier of the second quantum cryptography service platform and the key identifier key_tag.

2. The cross-domain quantum key distribution method for optical transport networks as described in claim 1, characterized in that, Before sending the cross-domain session key request information to the corresponding first quantum cryptography service platform, the method further includes: A communication network was established between the DCN network and the First Quantum business management platform; Receive the encrypted business policy configuration information and the hash value of the plaintext business policy configuration information sent by the first quantum business management platform; The encrypted business strategy configuration information is decrypted and the hash value is verified to obtain the plaintext business strategy configuration information.

3. The cross-domain quantum key distribution method for optical transport networks as described in claim 2, characterized in that, The encrypted business strategy configuration information is obtained by encrypting the plaintext business strategy configuration information using the Chinese national cryptographic symmetric encryption algorithm CBC mode; The hash value of the plaintext of the business strategy configuration information is obtained by performing a hash operation on the plaintext of the business strategy configuration information using the national cryptographic hash algorithm SM3.

4. The cross-domain quantum key distribution method for optical transport networks as described in claim 1, characterized in that, The KeyValue is a working key of the corresponding length obtained by the first quantum cryptography service platform or the second quantum cryptography service platform from its own cross-domain key pool based on the key length.

5. The cross-domain quantum key distribution method for optical transport networks as described in claim 1, characterized in that, The OTN device has a pre-installed quantum key as the user master key, and applies for the working key from the first quantum cryptography service platform based on the user master key.

6. The cross-domain quantum key distribution method for optical transport networks as described in claim 5, characterized in that, The working key included in the session key information is encrypted using the user's master key.

7. The cross-domain quantum key distribution method for optical transport networks as described in claim 1, characterized in that, After both the local OTN device and the remote OTN device have obtained the working key, the method further includes: The payload data of ODUk is encrypted and decrypted based on the working key and the national cryptographic SM4 algorithm.

8. An OTN device, characterized in that, The OTN device is used to perform the cross-domain quantum key distribution method for optical transport networks as described in any one of claims 1-7, including: The session key request module is used to send cross-domain session key request information to the corresponding first quantum cryptography service platform; The session key information receiving module is used to receive session key information returned by the first quantum cryptography service platform. The session key information includes a working key KeyValue and a cross-platform key request field. The cross-platform key request field includes a working key identifier KeyID, a key identifier key_tag, and a cross-platform session key request value KeyBlock. The cross-domain forwarding module is used to transmit the cross-platform key request field to the peer OTN device through the overhead bytes of ODUk, so that the peer OTN device can request the working key KeyValue from its corresponding second quantum cryptography service platform based on the cross-platform key request field.

9. A cross-domain quantum key distribution system for an optical transport network, characterized in that, The system includes a first OTN device, a second OTN device, a first quantum service management platform, a second quantum service management platform, a first quantum cryptography service platform, a second quantum cryptography service platform, and a quantum key distribution network; The first OTN device is connected to the first quantum service management platform and the first quantum cryptography service platform via the DCN network, and the second OTN device is connected to the second quantum service management platform and the second quantum cryptography service platform via the DCN network. The first quantum cryptography service platform is connected to the first quantum business management platform and the quantum key distribution network, respectively; the second quantum cryptography service platform is connected to the second quantum business management platform and the quantum key distribution network, respectively. The first OTN device and the second OTN device are used to perform the cross-domain quantum key distribution method for optical transport networks as described in any one of claims 1-7.