A key update method, apparatus, electronic device, and medium for optical transport network equipment.

By resetting the session key application time based on the unique identifier and key application cycle of the OTN device, the platform pressure problem caused by simultaneous session key applications from OTN devices is solved, and the even distribution and efficient generation of session key applications are achieved.

CN119070986BActive Publication Date: 2025-10-31中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411189872.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-27
Publication Date
2025-10-31
Estimated Expiration
2044-08-27

AI Technical Summary

Technical Problem

When a large number of OTN devices simultaneously apply for session keys, it puts excessive pressure on the quantum cryptography service platform, affecting server resources and session key generation efficiency, and posing a data security risk.

Method used

Based on the unique identifier of the OTN device and the key application cycle, the session key application time is reset to be evenly distributed at different times of the day. The base time and update time are determined by hash operation and modulo operation to apply for session keys in staggered peak times.

Benefits of technology

This reduces the pressure on the quantum cryptography service platform, improves the efficiency and success rate of session key application, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119070986B_ABST
    Figure CN119070986B_ABST
Patent Text Reader

Abstract

This invention provides a key update method, apparatus, electronic component, and medium for optical transport network equipment. The method includes: obtaining the unique identifier of the optical transport network equipment and the key application period; determining the base time for the initial application of a session key by the optical transport network equipment based on the unique identifier and the key application period; and determining the update time for the optical transport network equipment to apply for a session key again based on the base time and the key application period. This allows the timing of session key applications by the optical transport network equipment to be reset based on the unique identifier, ensuring that the application times of different optical transport network equipment are distributed as evenly as possible across different time points within a day, thus avoiding peak application times, reducing the pressure on the session key generator, and improving the efficiency and success rate of session key applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure communication technology, and in particular to a key update method, apparatus, device, and medium for optical transmission network equipment. Background Technology

[0002] OTN (Optical Transport Network) devices re-request session keys at regular intervals after going online, according to default timer scheduling rules. When many OTN devices simultaneously request session keys, it puts excessive pressure on the key generator (e.g., the quantum cryptography service platform). In severe cases, this can impact server resources such as disk I / O, CPU, memory, bandwidth, and connection count. This not only affects the quantum cryptography service platform's ability to provide other services but also impacts its efficiency in generating session keys. Furthermore, if the OTN devices' session keys are not updated in a timely manner, it poses a threat to data security. Excessive concurrency and traffic surges when a large number of OTN devices request session keys at the same time can prevent the quantum cryptography service platform from generating session keys promptly and effectively, thus affecting subsequent data encryption and decryption and posing a data security risk. Summary of the Invention

[0003] To address the aforementioned issues, embodiments of the present invention disclose a key update method, apparatus, electronic components, and media for optical transport network equipment.

[0004] In a first aspect, embodiments of the present invention provide a key update method for an optical transport network device, the method comprising:

[0005] Obtain the unique device identifier and key application period of the optical transport network equipment;

[0006] Based on the unique identifier of the device and the key application period, determine the reference time for the initial application of the session key by the optical transport network device;

[0007] Based on the reference time and the key application period, the update time for the optical transport network device to apply for the session key again is determined.

[0008] Optionally, determining the reference time for the initial request for a session key by the optical transport network device based on the device's unique identifier and the key request period includes:

[0009] A hash value is obtained by performing a hash operation on the unique identifier of the optical transport network equipment.

[0010] The reference time for the initial request of a session key by the optical transport network device is determined based on the hash value and the key request period.

[0011] Optionally, determining the reference time for the initial request for a session key by the optical transport network device based on the hash value and the key request period includes:

[0012] The time slice is obtained and the initial time at which the optical transport network device requests the session key;

[0013] The target value is obtained by multiplying the key request period and the time slice.

[0014] The target time interval is obtained by performing a modulo operation on the target value using the hash value;

[0015] The reference time for the initial request for a session key by the optical transport network device is determined based on the initial time and the target time interval.

[0016] Optionally, determining the reference time for the initial request for a session key by the optical transport network device based on the initial time and the target time interval includes:

[0017] The sum of the initial time and the target time interval is used as the reference time for the optical transport network device to initially request a session key.

[0018] Optionally, determining the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period includes:

[0019] The time after the reference time, each elapsed period of the key application cycle, shall be used as the update time for the optical transport network device to apply for the session key again.

[0020] Optionally, the method further includes:

[0021] When the time for updating the session key is reached and the optical transport network device requests the session key again, a session key request is sent to the optical transport network controller;

[0022] The system receives a new session key sent by the optical transport network controller; the optical transport network controller forwards the session key request to the key controller, the key controller applies for a session key to the quantum cryptography service platform, and the session key is generated by the quantum cryptography service platform.

[0023] Secondly, embodiments of the present invention provide a key update system for an optical transport network device, the system comprising: at least one optical transport network device, an optical transport network controller, a key controller, and a quantum cryptography service platform;

[0024] The optical transport network device is configured to: acquire the device's unique identifier and key application period; determine the base time for the initial application of a session key based on the device's unique identifier and the key application period; determine the update time for the device to apply for a session key again based on the base time and the key application period; send a session key application request to the optical transport network controller when the update time for the device to apply for a session key again is reached; and receive a new session key from the optical transport network controller.

[0025] The optical transport network controller is used to receive a session key request sent by the optical transport network device and forward the session key request to the key controller;

[0026] The key controller is used to receive the session key application request sent by the optical transport network controller, and to apply to the quantum cryptography service platform for a session key application;

[0027] The quantum cryptography service platform is used to generate the new session key.

[0028] Thirdly, embodiments of the present invention provide a key update apparatus for an optical transport network device, the apparatus comprising:

[0029] The device information acquisition module is used to acquire the unique device identifier and key application period of the optical transport network device;

[0030] The reference time determination module is used to determine the reference time for the initial application of a session key by the optical transport network device based on the device's unique identifier and the key application period.

[0031] The update time determination module is used to determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period.

[0032] Optionally, the reference time determination module includes:

[0033] The hash operation submodule is used to perform a hash operation on the unique device identifier of the optical transport network equipment to obtain a hash value;

[0034] The reference time determination submodule is used to determine the reference time for the initial application of the session key by the optical transport network device based on the hash value and the key application period.

[0035] Optionally, the reference time determination submodule includes:

[0036] The device information acquisition unit is used to acquire the time slice and the initial time when the optical transport network device applies for the session key;

[0037] The target value determination unit is used to multiply the key application period and the time slice to obtain the target value;

[0038] A time interval determination unit is used to perform a modulo operation on the target value using the hash value to obtain the target time interval;

[0039] The reference time determination unit is used to determine the reference time for the initial application of the session key by the optical transport network device based on the initial time and the target time interval.

[0040] Optionally, the reference time determination unit includes:

[0041] The reference time determination subunit is used to take the sum of the initial time and the target time interval as the reference time for the optical transport network device to apply for the session key for the first time.

[0042] Optionally, the update time determination module includes:

[0043] The update time determination submodule is used to take the time after the reference time, each time the key application cycle has elapsed, as the update time for the optical transport network device to apply for the session key again.

[0044] Optionally, the device further includes:

[0045] The request sending module is used to send a session key request to the optical transport network controller when the update time for the optical transport network device to request a session key again is reached.

[0046] The session key receiving module is used to receive a new session key sent by the optical transport network controller; the new session key is forwarded by the optical transport network controller to the key controller, the key controller applies for a session key to the quantum cryptography service platform, and the session key is generated by the quantum cryptography service platform.

[0047] Fourthly, the present invention discloses an electronic device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the key update method for an optical transport network device described above.

[0048] Fifthly, the present invention discloses a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described key update method for an optical transport network device.

[0049] The embodiments of the present invention have the following advantages:

[0050] This invention can obtain the unique identifier and key application period of an optical transport network device; determine the base time for the initial application of a session key by the optical transport network device based on the unique identifier and key application period; and determine the update time for the optical transport network device to apply for a session key again based on the base time and key application period. This allows the timing of session key applications by the optical transport network device to be reset based on the unique identifier, ensuring that the application times of different optical transport network devices are distributed as evenly as possible across different time points within a day. This staggered application of session keys reduces the pressure on the quantum cryptography service platform and improves the efficiency and success rate of session key applications. Attached Figure Description

[0051] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 This is a flowchart illustrating the steps of a key update method for an optical transport network device according to an embodiment of the present invention;

[0053] Figure 2 This is a flowchart of the steps of a key update method for an optical transport network device according to another embodiment of the present invention;

[0054] Figure 3 This is a logic diagram of a key update method for an optical transport network device according to an embodiment of the present invention;

[0055] Figure 4 This is a structural block diagram of a key update system for an optical transport network device according to an embodiment of the present invention;

[0056] Figure 5 This is a structural block diagram of a key update device for an optical transport network device according to an embodiment of the present invention.

[0057] Explanation of reference numerals in the attached figures:

[0058] The optical transport network equipment includes a key update system 40, an optical transport network device 41, an optical transport network controller 42, a key controller 43, and a quantum cryptography service platform 44. Detailed Implementation

[0059] With the development of optical communication technology, the deployment and use of optical transport networks (OTNs) are becoming increasingly widespread. OTN is a type of network that refers to a transport network that transmits, multiplexes, routes, and monitors service signals within the optical domain, while ensuring its performance indicators and survivability. OTN technology is a compromise between electrical networks and all-optical networks. It transplants the powerful and comprehensive OAM&P (Operations, Administration, Maintenance, and Provisioning) concepts and functions of the Synchronous Digital Hierarchy (SDH) into Wavelength Division Multiplexing (WDM) optical networks, effectively compensating for the shortcomings of existing WDM systems in performance monitoring and maintenance management. OAM&P refers to dividing network management work into three categories based on the actual needs of operator network operations: Operation, Administration, and Maintenance (OAM for short). Provisioning is the provisioning guarantee, with the goal of achieving intelligent network management.

[0060] OTN technology supports transparent transmission of customer signals, high-bandwidth multiplexing, switching, and configuration (the smallest cross-connect granularity is ODU1, approximately 2.5 Gbit / s). It boasts robust overhead support capabilities, provides powerful OAM functionality, supports multi-layered nested Tandem Connection Monitor (TCM) functionality, and has Forward Error Correction (FEC) support. The OTN frame structure of the OTN optical path layer greatly enhances the digital monitoring capabilities of the OCh layer, making it possible to perform end-to-end and simultaneous performance monitoring across multiple segments during OTN networking.

[0061] Compared to SDH leased lines and WDM networks that use IPSec to address end-to-end security issues, OTN leased lines offer more technical means to solve problems such as key synchronization control, online key distribution, and encrypted payload framing, making it easier to achieve direct end-to-end encryption at OTN nodes. Currently, the emergence and continuous maturation of Quantum Key Distribution (QKD) technology also provides strong support for direct end-to-end encryption in OTN. Based on OTN and QKD co-fiber technology, the transmission of keys and encrypted data can be carried out on the same physical channel.

[0062] The OTN device key request module is used to request a session key from the quantum key distribution network and associate the session key with a corresponding encryption strategy. Requesting a session key from the quantum key distribution network includes: sending a key request message to the connected key controller and receiving a key distribution message returned by the connected key controller. The key distribution message is generated by the key controller querying the cryptographic service platform for the QKD node information of the peer OTN device and obtaining the session key and key start and end sequence numbers from the key pool corresponding to the QKD link between the local OTN device's QKD node and the peer OTN device's QKD node. The payload encryption / decryption module is used to encrypt any... The frame structure of the layer is divided into an overhead region and a payload region. When the current sending OTN device supports adding information to the overhead region, the session key sequence number used for encryption of this frame on the current port is added to the overhead region. Based on the encryption policy, the payload region of the current frame is encrypted using the session key, and the entire frame is sent to the peer OTN device. When the current sending OTN device does not support adding information to the overhead region, the payload region of the current frame is encrypted using the session key based on the encryption policy, and then sent to the peer OTN device. The key synchronization control module is used to periodically send session key synchronization messages to the peer OTN device when the current sending OTN device does not support adding information to the overhead region.

[0063] This invention proposes a key update method for optical transport network (OTN) devices. The aim is to address the problem of excessive concurrency and traffic surges caused by a large number of OTN devices simultaneously requesting session keys, which prevents the quantum cryptography service platform from generating session keys in a timely and efficient manner. To achieve this goal, embodiments of this invention reset the session key request time of the OTN devices based on their unique identifiers. This ensures that the session key requests from different OTN devices are distributed as evenly as possible across different time points within a day, thus reducing the pressure on the quantum cryptography service platform and improving the efficiency and success rate of session key requests.

[0064] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0065] Reference Figure 1 The diagram illustrates a flowchart of a key update method for an optical transport network device according to an embodiment of the present invention. The method may specifically include the following steps:

[0066] Step 101: Obtain the unique device identifier and key application period of the optical transport network device;

[0067] In this embodiment of the invention, the OTN device can obtain its own unique device identifier and key application period. The unique device identifier is a unique identification code used to distinguish devices from different OTN devices. The unique device identifier can be a device serial number, MAC address, UUID (Universally Unique Identifier), IMEI (International Mobile Equipment Identity), UDID (Unique Device Identifier), etc. The key application period can be a key application period pre-set by the technical personnel for each OTN device. Different OTN devices can have the same or different key application periods, which can be 1 / 6 / 12 / 24 hours. Those skilled in the art can set the key application period to other appropriate values ​​according to the concept of this invention, and this invention does not limit this.

[0068] The device serial number is a unique serial number assigned during manufacturing. This serial number is usually printed somewhere on the OTN device and can also be read by software. Each OTN device can have a unique MAC address, which is a 48-bit binary number, usually represented as 12 hexadecimal digits, such as '00:1A:2B:3C:4D:5E'. The UUID is a 128-bit number, typically used for unique identification at the software level. The UUID can be generated using an algorithm to ensure global uniqueness. For mobile devices, each device can have a unique IMEI number, which is a 15-bit number. For iOS devices, the UDID is a 40-character hexadecimal string used to uniquely identify each device.

[0069] Step 102: Determine the reference time for the initial request of a session key by the optical transport network device based on the device's unique identifier and the key request period;

[0070] In this embodiment of the invention, the OTN device can determine the base time for the initial request of a session key by the optical transport network device based on the device's unique identifier and key application cycle. This base time can be used to indicate the new time for the optical transport network device to apply for the session key. By resetting the time when the optical transport network device applies for the session key, this embodiment of the invention distributes the application times of different optical transport network devices as evenly as possible across different time points within a day, thus staggering session key applications, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of session key applications.

[0071] Step 103: Determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period.

[0072] In this embodiment of the invention, the OTN device can determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application cycle. Since the reference time is determined based on the unique identifier of the OTN device, different OTN devices have different reference times. Consequently, the update time for re-applying for the session key determined by different OTN devices based on the reference time and the key application cycle is also different. This allows different OTN devices to apply for session keys at off-peak times, reducing the pressure on the quantum cryptography service platform and improving the efficiency and success rate of session key applications.

[0073] In this embodiment of the invention, the OTN device can obtain its own unique device identifier and key application period; based on the unique device identifier and key application period, the base time for the OTN device to initially apply for a session key is determined; based on the base time and key application period, the update time for the OTN device to apply for a session key again is determined. Thus, based on the unique device identifier, the time for optical transport network devices to apply for session keys can be reset, so that the time for different optical transport network devices to apply for session keys is distributed as evenly as possible at different times of the day, staggering the application of session keys, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of session key application.

[0074] Reference Figure 2 The diagram illustrates a flowchart of another key update method for an optical transport network device according to an embodiment of the present invention. The method may specifically include the following steps:

[0075] Step 201: Obtain the unique device identifier and key application period of the optical transport network device;

[0076] In this embodiment of the invention, the OTN device can obtain its own unique device identifier and key application period. The unique device identifier is a unique identification code used to distinguish devices from different OTN devices. The unique device identifier can be a device serial number, MAC address, UUID (Universally Unique Identifier), IMEI (International Mobile Equipment Identity), UDID (Unique Device Identifier), etc. The key application period can be a key application period pre-set by the technical personnel for each OTN device. Different OTN devices can have the same or different key application periods, which can be 1 / 6 / 12 / 24 hours. Those skilled in the art can set the key application period to other appropriate values ​​according to the concept of this invention, and this invention does not limit this.

[0077] The device serial number is a unique serial number assigned during manufacturing. This serial number is usually printed somewhere on the OTN device and can also be read by software. Each OTN device can have a unique MAC address, which is a 48-bit binary number, usually represented as 12 hexadecimal digits, such as '00:1A:2B:3C:4D:5E'. The UUID is a 128-bit number, typically used for unique identification at the software level. The UUID can be generated using an algorithm to ensure global uniqueness. For mobile devices, each device can have a unique IMEI number, which is a 15-digit number. For iOS devices, the UDID is a 40-character hexadecimal string used to uniquely identify each device.

[0078] Step 202: Determine the reference time for the initial request of a session key by the optical transport network device based on the device's unique identifier and the key request period;

[0079] In one embodiment, the step of determining the reference time for the initial request of a session key by the optical transport network device based on the device's unique identifier and the key request period may further include the following sub-steps:

[0080] Sub-step S11: Perform a hash operation on the unique identifier of the optical transport network device to obtain a hash value;

[0081] Sub-step S12: Determine the reference time for the initial request of a session key by the optical transport network device based on the hash value and the key request period.

[0082] In this embodiment of the invention, the OTN device can determine the base time for the initial request of a session key by an optical transport network device based on its unique device identifier and key application period. This base time can be used to indicate the new time for the optical transport network device to apply for a session key. Specifically, the OTN device can perform a hash operation on its own unique device identifier to obtain a hash value, and then determine the base time for the initial request of a session key by the hash value and the key application period. This embodiment of the invention, by resetting the time when optical transport network devices apply for session keys, distributes the times of session key applications as evenly as possible across different time points within a day, staggering session key applications, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of session key applications.

[0083] In one embodiment, determining the reference time for the initial request for a session key by the optical transport network device based on the hash value and the key request period may further include the following sub-steps:

[0084] Sub-step S1 21: Obtain the time slice and the initial time when the optical transport network device requests the session key;

[0085] In this embodiment of the invention, the OTN device can obtain a time slice and the initial time when the OTN device requests a session key. The time slice can be 3600, used to divide the time period of each key request into time slices that are 3600 times the key request period, so that the times when different OTN devices request keys are scattered across different time slices, minimizing key request conflicts. The initial time when the OTN device requests a session key can be the current time when the OTN device first goes online or when the service is activated, and when it makes its first session key request. Those skilled in the art can set the time slice to other appropriate values ​​according to the concept of this invention, and can also set the initial time when the OTN device requests a session key to other times, such as the time of the last session key request; this invention does not limit this.

[0086] Sub-step S1 22: Multiply the key application period and the time slice to obtain the target value;

[0087] In this embodiment of the invention, the OTN device can multiply the key application period X and the time slice 3600 to obtain the target value X*3600.

[0088] Sub-step S123: Perform a modulo operation on the target value using the hash value to obtain the target time interval;

[0089] In this embodiment of the invention, the OTN device can obtain the target time interval by performing a modulo operation on the target value using a hash value. Specifically, by performing a modulo operation on the target value X*3600 using the hash value A, the target time interval B = A%(X*3600) is obtained, where B is the remainder of A%(X*3600).

[0090] Sub-step S1 24: Determine the reference time for the initial request for a session key by the optical transport network device based on the initial time and the target time interval.

[0091] In one embodiment, the step of determining the reference time for the initial application of a session key by the optical transport network device based on the initial time and the target time interval may include: using the sum of the initial time and the target time interval as the reference time for the initial application of a session key by the optical transport network device.

[0092] In this embodiment of the invention, the OTN device can determine the reference time for the initial request of a session key by the optical transport network device based on the initial time and the target time interval. Specifically, the sum of the initial time and the target time interval can be used as the reference time for the initial request of a session key by the OTN device. Those skilled in the art can set the reference time to other appropriate values, such as the sum of a preset multiple of the initial time and the target time interval, or the difference between the initial time and the target time interval, etc., and the present invention does not limit this.

[0093] In this embodiment of the invention, the initial time for the OTN device to apply for a session key can be the current time when the OTN device first goes online or when the service is activated, and when it makes its first session key application. The reference time can be used to indicate the new time for the optical transport network device to apply for a session key. This embodiment of the invention adjusts the initial time for the OTN device to apply for a session key using the reference time, so that the times when different optical transport network devices apply for session keys are distributed as evenly as possible across different time points within a day, thus staggering session key applications, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of session key applications.

[0094] Step 203: Determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period;

[0095] In one embodiment, the step of determining the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period may further include the following sub-steps:

[0096] Sub-step S2 1: The time after the reference time, each time the key application cycle has elapsed, is taken as the update time for the optical transport network device to apply for the session key again.

[0097] In this embodiment of the invention, the OTN device can determine the update time for the optical transport network device to re-apply for the session key based on a reference time and a key application cycle. Specifically, the time after each key application cycle following the reference time can be used as the update time for the optical transport network device to re-apply for the session key. Since the reference time is determined based on the unique identifier of the OTN device, the reference times of different OTN devices are different. Consequently, the update times for re-applying for the session key determined by different OTN devices based on the reference time and the key application cycle are also different. This allows different OTN devices to apply for the session key at staggered times, reducing the pressure on the quantum cryptography service platform and improving the efficiency and success rate of session key applications.

[0098] For example, suppose the OTN device first requests a session key at time T0 = 00:00:00; suppose the OTN device serial number is 003; the hexadecimal number obtained after hashing is 9e107d9d372bb6826bd8 1d3542a4 19d6; converting the hexadecimal number to decimal gives 13474929378068736387302425433374; suppose the OTN device is configured with a key request interval of X = 20 hours; perform a modulo operation on the above decimal number with (X*3600) to obtain a remainder B = 53374 seconds = 14.83 hours = 14:49:48; the new start time for requesting a session key is T1 = T0 + B = 14:49:98; the OTN device can re-request a session key after time T1, every X = 20 hours.

[0099] Step 204: When the time for updating the session key is reached again by the optical transport network device, a session key request is sent to the optical transport network controller;

[0100] In this embodiment of the invention, the OTN device can also send a session key request to the optical transport network controller to obtain a new session key when the time for updating the session key is reached. Specifically, the OTN device can send the session key request to a message queue. The OTN controller can listen for key request messages in the message queue. Upon receiving the session key request, it forwards the request to the key controller. The key controller can then request a session key from the quantum cryptography service platform based on the session key request. The quantum cryptography service platform can then generate a session key based on the session key request.

[0101] Step 205: Receive a new session key sent by the optical transport network controller; the optical transport network controller forwards the session key request to the key controller, the key controller applies for a session key to the quantum cryptography service platform, and the session key is generated by the quantum cryptography service platform.

[0102] In this embodiment of the invention, the OTN device can receive a new session key sent by the optical transport network controller. Specifically, the optical transport network controller forwards a session key request to the key controller, which then requests a session key from the quantum cryptography service platform, which generates the new session key. The specific process of the OTN device receiving the new session key can be as follows: after the quantum cryptography service platform generates the new session key, it transmits it to the key controller, which then transmits it to the OTN controller. Finally, the OTN controller transmits the new session key to the OTN device.

[0103] According to the embodiments of the present invention, the timing of optical transport network devices applying for session keys can be reset based on the unique device identifier, so that the timing of different optical transport network devices applying for session keys is distributed as evenly as possible at different times of the day, staggering the application of session keys, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of session key application.

[0104] Reference Figure 3 The diagram illustrates a logic diagram of a key update method for an optical transport network device according to an embodiment of the present invention. To enable those skilled in the art to better understand the embodiments of the present invention, the following explanation is provided... Figure 3 The embodiments of the present invention are described below:

[0105] Step 301: When the OTN device goes online for the first time or when the service is activated, it will complete a session key application and record the current time as T0. Thereafter, the OTN device will update the session key every X hours during a key application cycle.

[0106] Step 301: The OTN device performs a hash calculation on the device's unique identifier to obtain a hash value A, where A is a random integer.

[0107] Step 302: Perform a modulo operation on the product of the key application period X and the time slice using the hash value A, A%(X*3600), to obtain the target time interval B, where B is the remainder of A%(X*3600).

[0108] Step 303: Based on the sum of the initial time TO and the target time interval B, a reference time T1 is obtained. The time after the reference time T1, each time the key application cycle has elapsed, is used as the update time for the OTN device to apply for the session key again.

[0109] Step 304: When the time for the OTN device to request a session key again is reached, the OTN device sends the session key request to the message queue.

[0110] Step 305: The OTN controller listens to the message queue. Upon receiving a session key request, it forwards the request to the key controller.

[0111] Step 306: The key controller requests a new session key from the quantum cryptography service platform and then returns it layer by layer to the OTN device.

[0112] Step 307: Repeat steps 305-307 every X hours after each key application period.

[0113] In this embodiment of the invention, the OTN device can perform a hash operation on its own unique device identifier and the unique device identifier of the key application period to obtain a hash value. The hash value is then used to perform a modulo operation on the product of the key application period and the time slice to obtain the target time interval. The sum of the initial time when the OTN device first applies for the session key and the target time interval is used as the base time when the OTN device first applies for the session key. The time after the base time, each elapsed key application period, is used as the update time when the OTN device applies for the session key again. Thus, based on the unique device identifier, the time when the optical transport network device applies for the session key can be reset, so that the time when different optical transport network devices apply for the session key is distributed as evenly as possible at different times of the day, staggering the application of the session key, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of the session key application.

[0114] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0115] Reference Figure 4 This diagram illustrates a structural block diagram of a key update system for an optical transport network device according to an embodiment of the present invention. The system 40 includes: at least one optical transport network device 41, an optical transport network controller 42, a key controller 43, and a quantum cryptography service platform 44;

[0116] The optical transport network device 41 is configured to: acquire the device's unique identifier and key application period; determine the base time for the initial application of a session key by the optical transport network device based on the device's unique identifier and the key application period; determine the update time for the optical transport network device to apply for a session key again based on the base time and the key application period; when the update time for the optical transport network device to apply for a session key again is reached, send a session key application request to the optical transport network controller; and receive a new session key sent by the optical transport network controller.

[0117] The optical transport network controller 42 is used to receive a session key request sent by the optical transport network device and forward the session key request to the key controller;

[0118] The key controller 43 is used to receive the session key application request sent by the optical transport network controller, and to apply to the quantum cryptography service platform for a session key application;

[0119] The quantum cryptography service platform 44 is used to generate the new session key.

[0120] In this embodiment of the invention, the OTN device can perform a hash operation on its own unique device identifier and the unique device identifier of the key application period to obtain a hash value. The hash value is then used to perform a modulo operation on the product of the key application period and the time slice to obtain the target time interval. The sum of the initial time when the OTN device first applies for the session key and the target time interval is used as the base time when the OTN device first applies for the session key. The time after the base time, each elapsed key application period, is used as the update time when the OTN device applies for the session key again. Thus, based on the unique device identifier, the time when the optical transport network device applies for the session key can be reset, so that the time when different optical transport network devices apply for the session key is distributed as evenly as possible at different times of the day, staggering the application of the session key, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of the session key application.

[0121] As the system implementation is basically similar to the method implementation, it is described in a relatively simple way. For relevant details, please refer to the description in the method implementation section.

[0122] Reference Figure 5 The diagram illustrates a structural block diagram of a key update device for an optical transport network device according to an embodiment of the present invention, which may specifically include the following modules:

[0123] The device information acquisition module 501 is used to acquire the unique device identifier and key application period of the optical transport network device;

[0124] The reference time determination module 502 is used to determine the reference time for the initial application of the session key by the optical transport network device based on the device's unique identifier and the key application period;

[0125] The update time determination module 503 is used to determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period.

[0126] In this embodiment of the invention, the reference time determination module 502 includes:

[0127] The hash operation submodule is used to perform a hash operation on the unique device identifier of the optical transport network equipment to obtain a hash value;

[0128] The reference time determination submodule is used to determine the reference time for the initial application of the session key by the optical transport network device based on the hash value and the key application period.

[0129] In this embodiment of the invention, the reference time determination submodule includes:

[0130] The device information acquisition unit is used to acquire the time slice and the initial time when the optical transport network device applies for the session key;

[0131] The target value determination unit is used to multiply the key application period and the time slice to obtain the target value;

[0132] A time interval determination unit is used to perform a modulo operation on the target value using the hash value to obtain the target time interval;

[0133] The reference time determination unit is used to determine the reference time for the initial application of the session key by the optical transport network device based on the initial time and the target time interval.

[0134] In this embodiment of the invention, the reference time determination unit includes:

[0135] The reference time determination subunit is used to take the sum of the initial time and the target time interval as the reference time for the optical transport network device to apply for the session key for the first time.

[0136] In this embodiment of the invention, the update time determination module 503 includes:

[0137] The update time determination submodule is used to take the time after the reference time, each time the key application cycle has elapsed, as the update time for the optical transport network device to apply for the session key again.

[0138] In this embodiment of the invention, the device further includes:

[0139] The request sending module is used to send a session key request to the optical transport network controller when the update time for the optical transport network device to request a session key again is reached.

[0140] The session key receiving module is used to receive a new session key sent by the optical transport network controller; the new session key is forwarded by the optical transport network controller to the key controller, the key controller applies for a session key to the quantum cryptography service platform, and the session key is generated by the quantum cryptography service platform.

[0141] In this embodiment of the invention, the OTN device can perform a hash operation on its own unique device identifier and the unique device identifier of the key application period to obtain a hash value. The hash value is then used to perform a modulo operation on the product of the key application period and the time slice to obtain the target time interval. The sum of the initial time when the OTN device first applies for the session key and the target time interval is used as the base time when the OTN device first applies for the session key. The time after the base time, each elapsed key application period, is used as the update time when the OTN device applies for the session key again. Thus, based on the unique device identifier, the time when the optical transport network device applies for the session key can be reset, so that the time when different optical transport network devices apply for the session key is distributed as evenly as possible at different times of the day, staggering the application of the session key, reducing the pressure on the quantum cryptography service platform, and improving the efficiency and success rate of the session key application.

[0142] As the device embodiment is basically similar to the method embodiment, it is described in a relatively simple way. For relevant details, please refer to the description in the method embodiment section.

[0143] This invention also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the key update method for an optical transport network device described above.

[0144] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the key update method for an optical transport network device described above.

[0145] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0146] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products embodied on one or more machine-readable media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0147] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0148] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0149] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0150] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0151] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0152] The key update method and key update device for an optical transport network device provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principle and implementation of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core idea of ​​the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation and application scope based on the idea of ​​the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A key update method for an optical transport network device, characterized in that, The method includes: Obtain the unique device identifier and key application period of the optical transport network equipment; A hash value is obtained by performing a hash operation on the unique identifier of the optical transport network equipment. The time slice is obtained and the initial time at which the optical transport network device requests the session key; The target value is obtained by multiplying the key request period and the time slice. The target time interval is obtained by performing a modulo operation on the target value using the hash value; Based on the initial time and the target time interval, the reference time for the optical transport network device to initially request a session key is determined; Based on the reference time and the key application period, the update time for the optical transport network device to apply for the session key again is determined.

2. The method according to claim 1, characterized in that, The step of determining the reference time for the initial request for a session key by the optical transport network device based on the initial time and the target time interval includes: The sum of the initial time and the target time interval is used as the reference time for the optical transport network device to initially request a session key.

3. The method according to claim 1, characterized in that, The step of determining the update time for the optical transport network device to re-apply for a session key based on the reference time and the key application period includes: The time after the reference time, each elapsed period of the key application cycle, shall be used as the update time for the optical transport network device to apply for the session key again.

4. The method according to claim 1, characterized in that, The method further includes: When the time for updating the session key is reached and the optical transport network device requests the session key again, a session key request is sent to the optical transport network controller; The system receives a new session key sent by the optical transport network controller; the optical transport network controller forwards the session key request to the key controller, the key controller applies for a session key to the quantum cryptography service platform, and the session key is generated by the quantum cryptography service platform.

5. A key update system for an optical transport network device, characterized in that, The system includes: at least one optical transport network device, an optical transport network controller, a key controller, and a quantum cryptography service platform; The optical transport network device is configured to: obtain its unique device identifier and key application period; perform a hash operation on the unique device identifier to obtain a hash value; obtain a time slice and the initial time when the optical transport network device applies for a session key; multiply the key application period and the time slice to obtain a target value; perform a modulo operation on the target value using the hash value to obtain a target time interval; determine a base time for the initial application of a session key by the optical transport network device based on the initial time and the target time interval; determine an update time for the optical transport network device to apply for a session key again based on the base time and the key application period; send a session key application request to the optical transport network controller when the update time for the optical transport network device to apply for a session key again is reached; and receive a new session key sent by the optical transport network controller. The optical transport network controller is used to receive a session key request sent by the optical transport network device and forward the session key request to the key controller; The key controller is used to receive the session key application request sent by the optical transport network controller, and to apply to the quantum cryptography service platform for a session key application; The quantum cryptography service platform is used to generate the new session key.

6. A key update device for an optical transport network, characterized in that, The device includes: The device information acquisition module is used to acquire the unique device identifier and key application period of the optical transport network device; The reference time determination module is used to perform a hash operation on the unique identifier of the optical transport network device to obtain a hash value; obtain the time slice and the initial time when the optical transport network device applies for a session key; multiply the key application period and the time slice to obtain a target value; perform a modulo operation on the target value using the hash value to obtain a target time interval; and determine the reference time when the optical transport network device first applies for a session key based on the initial time and the target time interval. The update time determination module is used to determine the update time for the optical transport network device to re-apply for the session key based on the reference time and the key application period.

7. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of a key update method for an optical transport network device as described in any one of claims 1-4.

8. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the steps of a key update method for an optical transport network device as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Method and apparatus for key maintenance

    CN109274494A

  • Key updating method and device, storage medium and electronic equipment

    CN117295065A