Method for managing a trusted classical communication network based on quantum communication verification
By embedding a board-level quantum communication module within the trusted domain and using the bit error rate to determine identity, combined with symmetric key password authentication, the problem of untrusted device access is solved, achieving dual protection at the physical and information layers, and improving the security and adaptability of the communication network.
Patent Information
- Application Number
- CN202411049137.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-01
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-08-01
AI Technical Summary
Existing technologies cannot effectively prevent untrusted devices from impersonating others to access classical communication networks, leading to potential network attack vulnerabilities. Furthermore, the transmission rate limitations of quantum communication prevent it from completely replacing classical fiber optic communication.
By embedding a board-level quantum communication module within the trusted domain, transmitting verification information through an optical fiber communication channel, determining the device's identity using the bit error rate, and combining it with a symmetric key password for dual authentication, a dual protection mechanism at both the physical and information layers is constructed.
It achieves dual protection of the physical and information layers for untrusted devices, improves the security of communication networks, adapts to the rate limitations of quantum communication, and is suitable for hybrid networks of quantum communication and classical communication.
Smart Images

Figure CN119030750B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the interdisciplinary field of quantum communication, quantum identity authentication, and classical communication networks. Specifically, it refers to a method for information interaction using a board-level embedded quantum communication module, providing a timed identity verification mechanism for classical communication network routers, and improving the trustworthiness of classical communication networks. In particular, it relates to a trusted classical communication network management method based on quantum communication verification. Background Technology
[0002] Quantum communication, based on fundamental properties of quantum mechanics such as the Heisenberg uncertainty principle, the quantum indivisibility principle, and the quantum no-cloning principle, is currently recognized as a technological solution capable of solving information security transmission problems at the channel transmission level. In particular, with the rapid advancements in quantum computing technology, traditional public-key cryptosystems based on conventional symmetric encryption algorithms or RSA large integer factorization encryption algorithms will face significant challenges. Quantum key distribution, as the most mature technology in the field of quantum communication, holds the promise of fundamentally countering the hyperparallel computing capabilities of quantum computing, providing a crucial secure transmission method for next-generation communication networks.
[0003] It's important to note that quantum communication signals typically use single photons as information carriers. Once a photon annihilates during transmission, it cannot be regenerated (this is one of the key guarantees of quantum communication security). Therefore, quantum communication cannot completely replace classical fiber optic communication in terms of either transmission rate or transmission distance. Even with quantum communication protocols that offer higher coding efficiency and longer transmission distances, the inherent rate bottleneck of quantum communication cannot be fundamentally overcome. On the other hand, with the rapid development of virtual gateways and software-defined network technologies, the virtualization of various classical communication devices is becoming an inevitable trend. This objectively brings security risks to classical communication networks. Eavesdroppers can hijack a third-party router, impersonate an attacker to access the target computer network, and launch network attacks that are impossible to trace. These impersonated "malicious routers" pose a serious threat once connected to a dedicated network. Summary of the Invention
[0004] To address the aforementioned shortcomings, the technical problem this invention aims to solve is how to determine whether an untrusted device is impersonating another user based on the bit error rate of the verification information transmission, thereby achieving a trusted classic communication network with dual protection at both the physical and information layers.
[0005] To address the aforementioned shortcomings and adapt to the objective reality of limited transmission rates in quantum communication systems, this invention proposes a trusted classical communication network management method based on quantum communication verification. This method groups classical communication network routers with clearly defined geographical locations and management information, along with various optical terminal devices, into a "trusted domain." Within this trusted domain, a virtual private network (VPN) is constructed to conduct various communication services. Simultaneously, board-level quantum communication modules are embedded into these devices within the trusted domain. Verification information is transmitted using optical fiber communication channels. The error rate of the transmitted verification information is used to determine whether any untrusted devices are impersonating the network, thus achieving a trusted classical communication network with dual protection at both the physical and information layers.
[0006] To achieve the above effects, the present invention provides a trusted classical communication network management method based on quantum communication verification. Step 1: Multiple communication network routers and various optical terminal devices are co-configured into a trusted domain. When establishing a virtual private network, only the routing devices in the trusted domain are used. The geographical location is used to construct a virtual private network and carry out various communication services using various devices in the trusted domain. Communication between the trusted domain and the untrusted domain is realized through a specific edge router. The edge router is subject to strict traffic monitoring and information exploration.
[0007] Step 2: Verify the information-level identity of devices within the trusted domain. Provide verification data to each device through a symmetric key password distribution method. Authenticate the identity of various devices within the trusted domain by comparing the verification data. Embed a board-level quantum communication module into various devices within the trusted domain. Reserve an optical port within the device so that the quantum communication module can establish a communication link with quantum communication modules in other devices through this optical port. Use the quantum communication module to transmit verification data periodically.
[0008] Preferably, the above method specifically includes the following steps:
[0009] S101. The establishment of a trusted domain involves grouping communication network routers and various optical terminal devices with clear geographical locations and management information into a trusted domain, and using various devices within the trusted domain to build a virtual private network and carry out various communication services.
[0010] S102. Information-level identity verification of devices within the trusted domain is achieved by providing verification data to each device through a symmetric key password distribution method. Under normal conditions, the identity authentication of various devices within the trusted domain is realized by comparing the verification data.
[0011] S103. Signal-level identity verification of devices within the trusted domain: embedding a board-level quantum communication module into various devices within the trusted domain, reserving an optical port within the device so that the quantum communication module can establish a communication link with quantum communication modules in other devices through the optical port, and using the quantum communication module to transmit verification data periodically.
[0012] Preferably, in the above S101, the communication between the trusted domain and the untrusted domain is implemented through a specific edge router, which is subject to strict traffic monitoring and information probing.
[0013] Preferably, in addition to verifying the content of the verification data, the above-mentioned S103 also needs to determine the success rate of the verification data transmission.
[0014] A trusted classical communication network management method based on quantum communication verification, comprising multiple routers, specifically including:
[0015] S201. Compile multiple routers, their corresponding switches, and optical transceivers, whose geographical locations and management information are all within a controllable range, into a single trusted domain.
[0016] S202. Embed the quantum communication module into various devices in the trusted domain, wherein the quantum communication module transmits information through an optical fiber channel;
[0017] S203. The signaling is compiled using a symmetric key and used as the basis for identity verification between any two devices in a trusted domain;
[0018] S204. Utilize a quantum communication module to transmit identity verification data, enabling timed identity authentication of various devices within the trusted domain to prevent attacks.
[0019] Preferably, in S201, a router is reserved as an edge router, which interconnects with other routers outside the untrusted domain through a firewall.
[0020] Preferably, in the normal state described in S203 above, the two communicating parties authenticate each other through this signaling.
[0021] Preferably, the attack behavior in S204 above is that after the eavesdropper accesses the trusted domain through the optical fiber channel, it causes a change in the bit error rate of quantum communication transmission, which is detected by the devices in the trusted domain. The devices on both sides of the corresponding optical cable line simultaneously generate alarm information and declare each other as untrusted devices until the eavesdropping fault is eliminated.
[0022] Preferably, the attack behavior in S204 above is that when the eavesdropper uses a third-party router to impersonate a router in the trusted domain to access the classic communication network, he is unable to complete the closed loop of identity verification data transmission because he is not equipped with a quantum communication module. He is identified and removed from the trusted domain during the timed verification process.
[0023] The present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method.
[0024] Compared with the prior art, the present invention achieves the following technical effects:
[0025] First, this invention proposes a device-level identity authentication method based on quantum communication verification. It is the first to propose a method for constructing a device mutual trust system from a physical level. The prerequisite for this method to be cracked is that the attacker directly obtains the quantum communication module (which also means that the relevant device has been obtained by the attacker) or the attacker can obtain the key parameters in the quantum communication module through reverse tracing and reproduce it (theoretically, this is almost impossible). It has important protection capabilities against attack methods that use virtual routers to access the network and third-party devices as springboards to carry out network attacks.
[0026] Secondly, this invention proposes a protection method of physical-level + information-level dual authentication, which combines the classical information-level device mutual trust and recognition method based on symmetric key passwords and the physical-level device mutual trust and recognition method based on quantum state bit error rate analysis, which can further improve the security of existing communication network device management.
[0027] Finally, the method proposed in this invention is also particularly suitable for hybrid networks of quantum communication and classical communication. That is, a portion of the bandwidth resources can be extracted from the quantum communication data stream for transmitting identity verification information. This deployment method can realize the dual use of quantum communication and provides a solution to combat the information security risks brought about by quantum computing. Attached Figure Description
[0028] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0029] Figure 1 A schematic diagram of an embodiment of the trusted classical communication network management method based on quantum communication verification of the present invention is shown;
[0030] Figure 2 A schematic diagram of another embodiment of the trusted classical communication network management method based on quantum communication verification of the present invention is shown;
[0031] Figure 3 A schematic diagram of another embodiment of the trusted classical communication network management method based on quantum communication verification of the present invention is shown. Detailed Implementation
[0032] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only configured to explain the present invention and are not configured to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely intended to provide a better understanding of the present invention by illustrating examples of the invention.
[0033] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0034] This invention provides an embodiment of a trusted classical communication network management method based on quantum communication verification, specifically including:
[0035] Step 1: Combine multiple routers with clearly identifiable geographical locations and management information into a single "trusted domain". When establishing a virtual private network, only the routing devices within the trusted domain will be used.
[0036] Step 2: Embed the board-level quantum communication module into the routing device in the trusted domain. Use the fiber optic communication link to periodically transmit quantum communication verification information with other devices. When the accuracy of the verification information transmission exceeds the threshold, the router is determined to belong to the "trusted domain". Otherwise, the router (lacking the quantum communication module) is marked as "untrusted" and access is denied.
[0037] In some embodiments, the board-level quantum communication module supports the transmission of quantum states. The transmission process satisfies the fundamental principles of quantum mechanics, such as the Heisenberg uncertainty principle, the quantum indivisibility principle, and the quantum no-cloning principle. It can generate a certain code rate, analyze the bit error rate to determine whether there is wiretapping, and transmit plaintext information or achieve key distribution through post-processing. The board-level quantum communication module has requirements for miniaturization, low power consumption, and high integration. The implementation method is not limited to various processes such as fiber optic integration and semiconductor chip integration. The specific protocol and implementation method of the board-level quantum communication module are not limited, nor are the interconnection methods between the quantum communication module and classical network devices, the connection methods with fiber optic channels, and the specific control protocol interfaces.
[0038] In some embodiments, the verification information transmission uses symmetric key-compiled signaling, which is used as the basis for identity verification between any two devices in a trusted domain. Under normal conditions, the two communicating parties use this signaling for identity authentication. The quantum communication module is used to transmit identity verification data, and preferably, the reachability of the identity verification data is used to determine whether the two communicating parties are devices in a trusted domain.
[0039] In some embodiments, it is preferable to determine whether there is wiretapping in the optical cable line by the bit error rate of the identity verification data, without limiting various technical details such as the length of the verification information transmission instruction, the password update cycle, the reconnection time after password update failure, and the routing table update method after multiple reconnection failures.
[0040] In some embodiments, the trusted domain consists of a series of hardware networking devices, each with an optical port or capable of outputting optical signals through photoelectric conversion. These hardware networking devices include, but are not limited to, routers, switches, and optical transceivers. The geographical location and management information of each device within the trusted domain must be clearly defined. The trusted domain is only open to successfully registered devices, and the virtual private network (VPN) only uses devices within the trusted domain. When interconnection between the VPN and the external network is involved, a strictly controlled edge device within the trusted domain must be used as the access interface to achieve interconnection with the external network edge device through robust monitoring methods. The number and type of devices within the trusted domain are not limited, nor are the monitoring methods for interconnection between devices inside and outside the domain limited.
[0041] This invention provides an embodiment of a trusted classical communication network management method based on quantum communication verification, comprising:
[0042] Step 1: Combine multiple communication network routers and various optical terminal devices into a trusted domain. When establishing a virtual private network, only the routing devices in the trusted domain are used. The virtual private network is constructed using various devices within the trusted domain, and various communication services are carried out. Communication between the trusted domain and the untrusted domain is achieved through a specific edge router. Strict traffic monitoring and information exploration are performed on the edge router.
[0043] Step 2: Verify the information-level identity of devices within the trusted domain. Provide verification data to each device through a symmetric key password distribution method. Authenticate the identity of various devices within the trusted domain by comparing the verification data. Embed a board-level quantum communication module into various devices within the trusted domain. Reserve an optical port within the device so that the quantum communication module can establish a communication link with quantum communication modules in other devices through this optical port. Use the quantum communication module to transmit verification data periodically.
[0044] like Figure 1 As shown, this invention provides an embodiment of a trusted classical communication network management method based on quantum communication verification, comprising:
[0045] S101. The establishment of a trusted domain involves grouping classic communication network routers and various optical terminal devices with clear geographical locations and management information into a "trusted domain". Various devices within the trusted domain are used to build a virtual private network and carry out various communication services. Communication between the trusted domain and the untrusted domain is achieved through a specific edge router, which is subject to strict traffic monitoring and information probing.
[0046] S102. Information-level identity verification of devices within the trusted domain: Verification data is provided to each device through symmetric key password distribution. Under normal conditions, identity authentication of various devices within the trusted domain can also be achieved by comparing the verification data.
[0047] S103. Signal-level identity verification of devices within the trusted domain: The board-level quantum communication module is embedded into various devices within the trusted domain. An optical port is reserved in the device so that the quantum communication module can establish a communication link with the quantum communication module in other devices through this optical port. Verification data is transmitted periodically using the quantum communication module. In addition to verifying the content of the verification data, the success rate of the verification data transmission also needs to be judged.
[0048] like Figure 2 As shown, this embodiment also provides a trusted classical communication network management method based on quantum communication verification, specifically including:
[0049] 1. The five routers shown in the diagram are all within a controllable range in terms of their geographical location and management information. These five routers and their corresponding switches, optical transceivers, and other devices are compiled into a "trusted domain". Only the rightmost router is retained as an edge router, which communicates and interconnects with other routers outside the untrusted domain through a firewall.
[0050] 2. The quantum communication module is embedded into various devices in the trusted domain, and the quantum communication module transmits information through optical fiber channels;
[0051] 3. By compiling signaling with a symmetric key, this signaling can be used as the basis for identity verification between devices in any two trusted domains. Under normal circumstances, the two communicating parties use this signaling for identity authentication.
[0052] 4. By using a quantum communication module to transmit identity verification data, timed identity authentication of various devices within the trusted domain can be achieved. This can prevent two main types of attacks: First, when an eavesdropper accesses the trusted domain through a fiber optic channel, the changes in parameters such as the bit error rate of quantum communication transmission will be detected by devices within the trusted domain. At this time, devices on both sides of the corresponding fiber optic cable will simultaneously generate alarm information, declaring each other as untrusted devices until the eavesdropping fault is resolved. Second, when an eavesdropper uses a third-party router to impersonate a router within the trusted domain to access the classical communication network, the lack of a quantum communication module will prevent the completion of the closed loop transmission of identity verification data. The eavesdropper will be identified and removed from the trusted domain during the timed verification process.
[0053] In some embodiments, communication between the trusted domain and the untrusted domain in S101 is achieved through a specific edge router, which is subject to strict traffic monitoring and information probing.
[0054] In some embodiments, in addition to verifying the content of the verification data, S103 also needs to determine the success rate of the verification data transmission.
[0055] like Figure 3 As shown, this embodiment illustrates a trusted classical communication network management method based on quantum communication verification, including multiple routers. The method specifically includes:
[0056] S201. Compile multiple routers, their corresponding switches, and optical transceivers, whose geographical locations and management information are all within a controllable range, into a single trusted domain.
[0057] S202. Embed the quantum communication module into various devices in the trusted domain, wherein the quantum communication module transmits information through an optical fiber channel;
[0058] S203. The signaling is compiled using a symmetric key and used as the basis for identity verification between any two devices in a trusted domain;
[0059] S204. Utilize a quantum communication module to transmit identity verification data, enabling timed identity authentication of various devices within the trusted domain to prevent attacks.
[0060] In some embodiments, S201 reserves a router as an edge router to interconnect with other routers outside the untrusted domain through a firewall.
[0061] In some embodiments, during the normal state in S203, the two communicating parties authenticate each other through this signaling.
[0062] In some embodiments, the attack behavior in S204 is that after the eavesdropper accesses the trusted domain through the optical fiber channel, it causes a change in the bit error rate of quantum communication transmission, which is detected by the devices in the trusted domain. The devices on both sides of the corresponding optical cable line simultaneously generate alarm information and declare each other as untrusted devices until the eavesdropping fault is eliminated.
[0063] In some embodiments, the attack in S204 is that when an eavesdropper uses a third-party router to impersonate a router within the trusted domain to access the classical communication network, the eavesdropper is unable to complete the closed loop of identity verification data transmission because it is not equipped with a quantum communication module. As a result, the eavesdropper is identified and removed from the trusted domain during the timed verification process.
[0064] Compared with the prior art, the present invention has the following advantages:
[0065] (1) This invention proposes a device-level identity authentication method based on quantum communication verification. For the first time, it proposes a method for constructing a device mutual trust system from a physical level. The prerequisite for this method to be cracked is that the attacker directly obtains the quantum communication module (which also means that the relevant device has been obtained by the attacker) or the attacker can obtain the key parameters in the quantum communication module through reverse tracing and reproduce it (theoretically, it is almost impossible). It has important protection capabilities against attack methods that use virtual routers to access the network and third-party devices as springboards to carry out network attacks.
[0066] (2) This invention proposes a protection method of physical-level + information-level dual authentication, which combines the classical information-level device mutual trust and recognition method based on symmetric key password and the physical-level device mutual trust and recognition method based on quantum state bit error rate analysis, which can further improve the security of existing communication network device management.
[0067] (3) The method proposed in this invention is also particularly suitable for hybrid networks of quantum communication and classical communication. That is, a portion of the bandwidth resources can be extracted from the quantum communication data stream for transmitting identity verification information. This deployment method can realize the dual use of quantum communication and provides a solution to combat the information security risks brought about by quantum computing.
[0068] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0069] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0070] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0071] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0072] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0073] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0074] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0075] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0076] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0077] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0078] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0079] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A trusted classical communication network management method based on quantum communication verification, characterized in that... include: Step 1: Assemble communication network routers and various optical terminal devices with clear geographical locations and management information into a trusted domain. When establishing a virtual private network, only the routing devices in the trusted domain are used. Utilize the various devices in the trusted domain to build the virtual private network and carry out various communication services. Communication between the trusted domain and the untrusted domain is realized through a specific edge router. Strict traffic monitoring and information probing are performed on the edge router. Step 2: For information-level identity verification of devices within the trusted domain, verification data is provided to each device through a symmetric key password distribution method. The identity authentication of various devices within the trusted domain is achieved by comparing the verification data. For signal-level identity verification of devices within the trusted domain, a board-level quantum communication module is embedded into various devices within the trusted domain. An optical port is reserved in the device so that the quantum communication module can establish a communication link with the quantum communication modules in other devices through the optical port. The verification data is transmitted periodically using the quantum communication module.
2. The trusted classical communication network management method based on quantum communication verification according to claim 1, characterized in that, In addition to verifying the content of the verification data, step two also requires judging the success rate of the verification data transmission.
3. The trusted classical communication network management method based on quantum communication verification according to claim 1, comprising multiple routers, characterized in that... The method specifically includes: S201. Compile multiple routers, their corresponding switches, and optical transceivers, whose geographical locations and management information are all within a controllable range, into a single trusted domain. S202. Embed the quantum communication module into various devices in the trusted domain, wherein the quantum communication module transmits information through an optical fiber channel; S203. The signaling is compiled using a symmetric key and used as the basis for identity verification between any two devices in a trusted domain; S204. Utilize a quantum communication module to transmit identity verification data, enabling timed identity authentication of various devices within the trusted domain to prevent attacks.
4. The trusted classical communication network management method based on quantum communication verification according to claim 3, characterized in that, S201 reserves one router as an edge router, which interconnects with other routers outside the untrusted domain through a firewall.
5. The trusted classical communication network management method based on quantum communication verification according to claim 3, characterized in that, In the normal state described in S203, the two communicating parties authenticate each other through this signaling.
6. The trusted classical communication network management method based on quantum communication verification according to claim 3, characterized in that, The attack behavior in S204 is that after the eavesdropper accesses the trusted domain through the optical fiber channel, it causes a change in the bit error rate of quantum communication transmission, which is detected by the devices in the trusted domain. The devices on both sides of the corresponding optical cable line simultaneously generate alarm information, mutually declaring each other as untrusted devices until the eavesdropping fault is eliminated.
7. The trusted classical communication network management method based on quantum communication verification according to claim 3, characterized in that, The attack described in S204 is that when an eavesdropper uses a third-party router to impersonate a router within the trusted domain to access a classic communication network, the eavesdropper is unable to complete the closed loop of identity verification data transmission because it is not equipped with a quantum communication module. During the timed verification process, the eavesdropper is identified and removed from the trusted domain.
8. A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the method of any one of claims 1-7.