Method for building multi-layer qkd constellation model and key distribution routing algorithm fused with SDN

By optimizing quantum key distribution through a three-layer orbital satellite network and SDN technology, the problems of low key generation rate and high latency in long-distance transmission are solved, achieving efficient and flexible quantum key distribution and resource management, and improving the network's request success rate and communication efficiency.

CN119544197BActive Publication Date: 2025-10-21CHONGQING UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411467009.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2025-10-21
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

In free-space quantum key distribution, existing technologies suffer from low key generation rates and high communication latency due to long-distance transmission, and lack effective resource management and network optimization, making them unable to support high-intensity security service requests.

Method used

Adopting a three-layer orbital satellite network constellation model (GEO/MEO/LEO) and combining it with software-defined networking (SDN) technology, we designed an adaptive quantum key stream-aware routing algorithm (AQKAR). By caching keys through the quantum key pool (QKP), we optimized key generation and consumption and dynamically managed network resources.

Benefits of technology

It significantly improves the success rate of quantum key distribution requests and reduces end-to-end communication latency, enhancing network resilience and resource utilization efficiency, especially under high load conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544197B_ABST
    Figure CN119544197B_ABST
Patent Text Reader

Abstract

The application discloses a multi-layer QKD constellation model fused with SDN and a building method of a key distribution routing algorithm, and relates to the technical field of quantum key distribution. The application proposes a trusted relay quantum key distribution constellation model fused with GEO / MEO / LEO three-layer orbits by deeply analyzing the orbit distribution and dynamic characteristics of satellites in free space, and introduces the software-defined network (Software-Defined Networking, SDN) technology into the model to realize centralized control and efficient management, and designs an adaptive quantum key stream aware routing algorithm (AQKAR) on the basis of the trusted relay quantum key distribution constellation model fused with GEO / MEO / LEO three-layer orbits to dynamically optimize the key distribution path; the simulation result shows that, compared with the traditional LEO single-layer network and GEO / LEO double-layer network, the architecture proposed in the application has a significant improvement in the request success rate, the end-to-end network delay is lower, and meanwhile, the algorithm proposed in the application can effectively improve the network flexibility in the case of extreme network congestion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum key distribution technology, and specifically to a method for building a multi-layer QKD constellation model and a key distribution routing algorithm integrated with SDN. Background Art

[0002] Free-space quantum key distribution is a technology based on the principles of quantum mechanics that securely generates and shares encryption keys by transmitting photons in free space.

[0003] Quantum Key Distribution (QKD) is an information encryption technology that uses the principles of quantum non-cloning and measurement destructiveness to achieve secure key distribution. It can provide a secure key distribution mechanism that cannot be eavesdropped or cracked for both communicating parties. [1] In the BB84 protocol, single-photon signals are often used to implement quantum key distribution. However, since the transmission loss of single-photon signals in optical fibers increases exponentially, it is difficult to avoid high loss and depolarization during long-distance transmission, which poses a challenge to the construction of optical fiber networks for quantum key distribution for intercontinental quantum secure communication. [2-3] Free-space Quantum Key Distribution (FSO QKD) will become a more effective solution in long-distance environments, providing ultra-long-distance quantum key security services worldwide. [4] With the increasing number of intercontinental security services, countries around the world have begun to attach great importance to the research on large-scale quantum satellite networking and quantum key distribution technology. Among them, research on how to build quantum satellite constellations and how to develop end-to-end satellite key distribution routing algorithms are the key to the future practical application of quantum satellite key distribution technology.

[0004] At present, research on free-space quantum satellite key distribution technology has achieved certain results. Villoresi et al., a research team from the University of Padova in Italy, [5] In 2008, the quantum communication experiment of single photon signal was successfully realized through the Low Earth Orbit (LEO) satellite, proving the feasibility of quantum key distribution between LEO satellite and the ground. [6] and another research institute in Italy [7]From 2017 to 2018, the team successfully detected and received single-photon signals that maintained quantum states through geostationary Earth Orbit (GEO) and medium Earth orbit (MEO) satellites, further verifying the feasibility of using high, medium and low orbit satellites for quantum key distribution. Subsequently, in 2019, Vergoossen et al. from the Center for Quantum Technology at the National University of Singapore [8] A satellite QKD constellation model is proposed. By establishing a key buffer in the link and using relay satellites to transmit quantum key pairs to ground stations, this model can provide low-latency symmetric keys between any two ground stations. [9] A dual-layer QKD network architecture combining geosynchronous orbit satellites and low earth orbit satellites is proposed, and a new joint GEO / LEO routing and key distribution algorithm is proposed for the new architecture. This method can improve the success rate of key relay services and is an effective key relay solution.

[10] Aiming at the resource allocation problem in the QKD network of GEO and LEO satellites, an optimization algorithm is proposed to maximize the minimum key exchange amount and minimize the key consumption between ground stations by modeling the QKD network as a graph and converting it into a linear programming problem. This algorithm optimizes the effective allocation of quantum key resources to a certain extent, but in some cases it will lead to waste of network resources.

[11] The satellite-to-ground link selection problem was modeled as an undirected graph solution problem, and the inter-satellite routing problem was transformed into a maximum flow problem. In the same year, He et al., a research team from Beijing University of Posts and Telecommunications, China

[12] To solve the problem of how to provide keys for remote multicast services, a quantum satellite network with a special node structure was designed to achieve point-to-multipoint key distribution and a point-to-multipoint satellite relay solution was proposed. The link weights were dynamically described through auxiliary topology, and a satellite relay tree was constructed. A multicast resource routing allocation algorithm based on satellite relay was proposed to improve the success rate of long-distance multicast requests. In 2023, Federico and his team from the University of Rome

[13] The orbit design of QKD satellite constellation was carried out for different ground networks, aiming to maximize the minimum key length shared by the ground station network within a fixed time by optimizing the satellite orbit.

[14] To address the problem of lack of effective scheduling schemes between GEO / LEO satellites due to the dynamic characteristics of satellites, a routing strategy based on topology abstraction is proposed to transform the dynamic network into a quasi-static network. Three new heuristic network scheduling algorithms are also proposed. This method can effectively improve the success probability of long-distance QKD.

[0005] The aforementioned research has achieved some success in constellation design, intersatellite link optimization, and key resource allocation for quantum satellite key distribution. However, it overlooks the exponential decay in quantum key generation rates over transmission distances of tens of thousands of kilometers in free space. It also fails to consider the significant end-to-end communication latency associated with long-distance signal transmission, and lacks a centralized resource management solution for the limited intersatellite quantum key resources. Specifically, the current quantum key generation rate in free-space quantum key distribution is low, and the key generation rate varies exponentially with transmission distance, making it incapable of supporting high-intensity security service requests. Furthermore, the end-to-end communication latency between communicating parties is generally high.

[0006] Therefore, a new solution to the above problems needs to be proposed. Summary of the Invention

[0007] The purpose of the present invention is to provide a method for building a multi-layer QKD constellation model and a key distribution routing algorithm that integrates SDN to solve the technical problems raised in the background technology.

[0008] To achieve the above objectives, the present invention provides the following technical solution: a method for building a multi-layer QKD constellation model integrating SDN, comprising at least the following steps:

[0009] S1: Setting a trusted relay quantum key distribution constellation model, which is a three-layer orbit satellite network constellation model, giving full play to the characteristics of GEO, MEO and LEO orbit satellites;

[0010] S2: Based on S1, further propose a multi-layer architecture and dynamic management strategy for quantum satellite optical networks;

[0011] S3: Set up a key resource model and introduce a quantum key pool as a cache for quantum keys. The quantum key pool is QKP, which is used to store key pairs generated between each pair of quantum nodes. The keys are stored in the corresponding QKPs of the quantum nodes that appear in pairs. The keys in the QKPs are provided to the encryption and decryption modules when a security service request arrives, realizing the key relay function.

[0012] S4: key generation and consumption;

[0013] S5: Perform link state assessment to better describe the number and update status of quantum keys in the topology.

[0014] Furthermore, the S1 at least includes the following steps:

[0015] In the satellite network scenario model, the LEO layer of the quantum satellite network adopts a uniformly distributed Walker constellation, which contains orbital planes, with Q satellites evenly distributed on each orbit, for a total of low-orbit satellites;

[0016] Each LEO satellite is connected to four adjacent LEO orbits, two of which are in the same orbit and the other two are in different orbits. Satellites in the same orbital layer can be connected through inter-satellite links, while satellites in different orbital layers can be connected through inter-orbit links to ensure cross-orbit quantum key transmission;

[0017] LEO satellites establish quantum communication with ground stations via satellite-to-ground links. MEO satellites can establish auxiliary communication links with LEO satellites. The auxiliary communication links are used to assist the LEO layer in complex quantum key routing and forwarding, and are used to directly establish communication links with ground stations to enhance the redundancy and reliability of the quantum key distribution network.

[0018] The GEO satellite has a wide coverage capability and is used as a monitoring satellite to collect and forward topological resources and quantum key resource information of the LEO layer and MEO layer to the ground station, so that the ground station can update the satellite node and its link resource information in a timely manner;

[0019] The ground stations are distributed all over the world, and end-to-end secure service requests are established between the ground stations. By establishing connections with free-space relay satellites, point-to-point key distribution is carried out between the relay satellites, thereby realizing ultra-long-distance quantum key distribution services.

[0020] Furthermore, the multi-layer architecture of the quantum satellite optical network in S2 includes at least an application layer, an SDN control layer, a data layer, and a QKD layer;

[0021] The application layer is composed of ground stations, and ground users can generate security service requests;

[0022] The data layer has QKD capability, and the data layer includes a LEO layer and a MEO layer, the LEO layer is used to constitute the main QKD layer, and the MEO layer is used to serve as an auxiliary forwarding layer for the LEO data layer under the condition of scarce quantum key resources;

[0023] The SDN control layer has a network dynamic management function in the constellation model, and the SDN control layer includes a main controller and a domain controller;

[0024] The main controller is deployed on the ground and is responsible for the global management and resource scheduling of the entire quantum communication network. The tasks of the main controller include at least link optimization, path planning and load balancing.

[0025] Furthermore, the S4 at least includes the following steps:

[0026] Since the connection relationship of satellite topology is periodic, the satellite topology is divided into n static topologies {G|G l , G2, G3, ..., G n}, where G is a set of n sub-topologies, G1~G n The n sub-topologies are divided into n sub-topologies, and these n different topologies correspond to n different time periods {T|t1~t2, t1~t2, ..., t n-1 ~t n}, where T is the topological period, t1~t2, ...., t n-1 ~t n For n time slots, use L (i,j) represents the quantum link between quantum node i and quantum node j in the satellite topology;

[0027] Assuming that any two connected nodes can perform QKD, the number of keys generated and consumed is related to the duration of the link connection, and the number of keys cached in the QKP is related to the initial number of keys, the number of keys generated, and the number of keys consumed in the QKP. The mathematical notation is described in Equation 1:

[0028]

[0029] where K (i,j) (t) is the link L at time t (i,j) The number of QKP keys in the network, t0 is the arrival time of the current network topology, t1 is the end time of the current network topology, C (i,j) is the number of keys consumed in a single QKD link, R (i,j) (t) is the link L at time t (i,j) The key generation rate, R (i,j) (t) can be expressed by referring to formula 2:

[0030]

[0031] where R max Denotes the maximum key generation rate in the key generation rate set of the links in the QKD network, D (i,j) (t) represents the link L (i,j) The distance at time t, D min is the shortest link distance in the link distance set.

[0032] Furthermore, the S5 at least includes the following steps:

[0033] By establishing a link key matrix K(t), refer to Equation 3, the matrix can represent the QKP resource status of each link at time t in real time;

[0034]

[0035] When performing global QKD, due to the volume of business requests and the complexity of the network, the quantum key flow in the link may include three situations: link key supply exceeds demand, link key supply is less than demand, and link anomaly.

[20] ;

[0036] The situation where the link key supply exceeds the demand is: when there is no abnormality in the link, the number of security service requests is small, the quantum key in the QKP will be continuously updated, and its quantum key generation rate will continue to exceed the key consumption rate, refer to Formula 4:

[0037]

[0038] where K (ij) (t) is the link L at time t (i,j) The number of keys in QKP, K (i,j) (t0) represents the initial quantum key quantity, represents the quantum key generation amount, is the quantum key consumption.

[0039] The situation where the link key supply is less than the demand is: when there is no abnormality in the link, the number of security service requests is large, the quantum key in the QKP will be continuously updated, and its quantum key generation rate is less than the key consumption rate, and it cannot continuously support key services. Refer to Formula 5:

[0040]

[0041] The link abnormality is as follows: when the link is abnormal, the key quantity in the QKP will not be able to be updated, its initial quantum key will become invalid, and it will no longer be able to provide encryption and decryption services for the global QKP, see Equation 6:

[0042]

[0043] At the same time, a network congestion index is introduced, which can reflect the density and dispersion of requests at different time points;

[0044] The network congestion index needs to consider the total number of business requests and the number of network requests at a certain moment to determine whether the requests are evenly distributed. The network congestion index is expressed as follows:

[0045] NCI=μ x σ x R peak (7)

[0046] in:

[0047] μ xIndicates the average number of requests, representing the average number of requests at each time point. The larger the mean value, the higher the load level at each moment;

[0048] σ x The standard deviation reflects the volatility of the request volume distribution. A larger standard deviation indicates uneven load distribution at different time points.

[0049] R peak R is the peak ratio, which is used to reflect the impact of the highest peak load on the overall load. The higher the peak ratio, the more sudden peaks there are. peak Refer to Equation 8:

[0050]

[0051] In formula 8, δ is the normalization adjustment factor, (x1, x1, ..., x T ) represents the sequence of the number of requests occurring in time period T, and N represents the total number of requests.

[0052] A method for constructing a key distribution routing algorithm, wherein the key distribution routing algorithm is based on a multi-layer QKD constellation model integrated with SDN, and is used to ensure that the multi-layer QKD constellation model integrated with SDN achieves efficient quantum key distribution under different network loads.

[0053] Furthermore, the input of the key distribution routing algorithm is x(S i ,d i ,k i ) and G(V t ,E t ,K0,R t );

[0054] Where x(S i , d i , k i ) represents the slave service node S i To the target node d i Quantum key distribution request, where k i is the number of keys requested;

[0055] Where G(V t , E t , K0, R t ) represents a graph model, where V t is the vertex set, E t is the edge set, i.e., the optical link, K0 is the minimum number of available keys, R t A collection of transport resources.

[0056] Furthermore, the key distribution routing algorithm includes at least the following steps:

[0057] S1: Initialize each optical link resource and initialize each optical link resource in the graph G(V t , E t , K0, R t );

[0058] S2: Calculate the routing set, calculate the routing set P from the service node s i to the target node d i and limit the maximum number of hops;

[0059] S3: Check if a route is found. If no suitable path is found in the routing set P, stop the request and report that no suitable path can be found;

[0060] S4: Traverse each shortest-hop path. For each shortest-hop path p i in the path set P;

[0061] S5: Check if a path is found: When the path discovery flag is True, perform the quantum key relay service;

[0062] S6: Handle the case where no path is found. In the case where no suitable path is found, add the MEO layer to the graph to assist the LEO layer in QKD and re-execute the above steps;

[0063] S7: Check the number of keys on the LEO layer link, and re-evaluate whether the LEO layer link meets the key number requirement. If the number of keys on the LEO layer link and the LEO ground station link is k i < K0, perform QKD using the MEO layer alone and re-execute the above steps;

[0064] S8: Perform the final path check. If the path flag is still False, report that the key distribution fails because there is no available path.

[0065] Furthermore, the S4 at least includes the following steps:

[0066] S4.1: Obtain the passed link and obtain the optical links passed in the path p i ;

[0067] S4.2: Check the number of keys on the link. When the number of keys k i on each link in the path is < K0, set the path discovery flag to True, indicating that an available path is found, and then exit the loop;

[0068] S4.3: Continue to check other paths. If no suitable number of keys is found for the current path, continue to check the next path.

[0069] Compared with the prior art, the beneficial effects of the present invention are:

[0070] 1. By deeply analyzing the orbital distribution and dynamic characteristics of satellites in free space, this paper proposes a trusted relay quantum key distribution constellation model that integrates the three-layer orbits of GEO / MEO / LEO, and introduces software-defined networking (SDN) technology into this model to achieve centralized control and efficient management.

[0071] 2. The present invention designs an adaptive quantum key stream-aware routing algorithm (AQKAR) based on a trusted relay quantum key distribution constellation model that integrates the GEO / MEO / LEO three-layer orbits to dynamically optimize the key distribution path; simulation results show that compared with the traditional LEO single-layer network and the GEO / LEO two-layer network, the architecture proposed by the present invention has a significant improvement in request success rate and lower end-to-end network latency. At the same time, under extremely congested network conditions, the algorithm proposed by the present invention can effectively improve network resilience.

[0072] 3. This paper proposes a quantum key distribution constellation model that integrates GEO / MEO / LEO three-layer orbital satellites. In combination with software-defined networking (SDN) technology, an adaptive quantum key stream-aware routing algorithm is designed. Simulation results show that, with the same key consumption, the average request success rate is 17.34% higher than that of a GEO / LEO two-layer network and 32.47% higher than that of a LEO single-layer network. At the same time, its communication latency is lower than that of both GEO / LEO two-layer and LEO single-layer networks. Furthermore, the request success rate of the adaptive key stream-aware routing algorithm is improved by 18.46% and 26.08% compared to the baseline algorithms SA-MFP and Dijkstra, respectively. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0074] Figure 1 Schematic diagram of a trusted relay constellation model in a three-layer orbit satellite network according to the present invention;

[0075] Figure 2 Schematic diagram of the QKD architecture under the software-defined network of the present invention;

[0076] Figure 3 Schematic diagram of the QKD process based on trusted relay in the present invention;

[0077] Figure 4Schematic diagram of the routing method for the MEO-LEO data layer combination of the present invention;

[0078] Figure 5 This is a comparison diagram of the request success rates of different QKD architectures;

[0079] Figure 6 Schematic diagram of request success rate under different forwarding numbers of the present invention;

[0080] Figure 7 Schematic diagram of delay performance under different architectures of the present invention;

[0081] Figure 8 Schematic diagram showing the results of different routing algorithms of the present invention under MEO / LEO architecture;

[0082] Figure 9 Schematic diagram showing the comparison of the anti-network congestion performance of the routing algorithm of the present invention. DETAILED DESCRIPTION

[0083] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments.

[0084] Example 1:

[0085] This embodiment discloses a method for building a multi-layer QKD constellation model integrated with SDN. The three-layer orbit satellite network constellation model proposed in the present invention fully utilizes the characteristics of the three orbit satellites of GEO / MEO / LEO, such as Figure 1 shown.

[0086] The method for building a multi-layer QKD constellation model integrating SDN includes at least the following steps:

[0087] S1: Set up a trusted relay quantum key distribution constellation model. The trusted relay quantum key distribution constellation model is a three-layer orbit satellite network constellation model, giving full play to the characteristics of GEO, MEO and LEO orbit satellites;

[0088] In the satellite network scenario model, the LEO layer of the quantum satellite network adopts a uniformly distributed Walker constellation, which contains orbital planes, with Q satellites evenly distributed on each orbit, for a total of low-orbit satellites;

[0089] Each LEO satellite is connected to four adjacent LEO orbits, two of which are in the same orbit and the other two are in different orbits. Satellites in the same orbital layer can be connected via inter-satellite links (ISL), while satellites in different orbital layers can be connected via inter-orbital links (IOL) to ensure cross-orbit quantum key transmission;

[0090] LEO satellites establish quantum communication with ground stations via Satellite Ground Links (SGLs). MEO satellites can establish Auxiliary Satellite Links (ASLs) with LEO satellites. Auxiliary communication links are used to assist the LEO layer in complex quantum key routing and forwarding, and to directly establish communication links with ground stations to enhance the redundancy and reliability of the quantum key distribution network.

[0091] GEO satellites have a wide coverage capability and are used as monitoring satellites. They are responsible for collecting and forwarding topological resources and quantum key resource information of the LEO and MEO layers to ground stations, so that ground stations can update satellite nodes and their link resource information in a timely manner.

[0092] Ground stations are distributed all over the world, and end-to-end secure service requests are established between the ground stations. By establishing connections with free-space relay satellites, point-to-point key distribution is carried out between relay satellites, thereby realizing ultra-long-distance quantum key distribution services.

[0093] S2: Based on S1, further propose a multi-layer architecture and dynamic management strategy for quantum satellite optical networks;

[0094] The multi-layer architecture of the quantum satellite optical network in S2 includes at least the application layer, SDN control layer, data layer and QKD layer. Figure 2 ;

[0095] The application layer consists of ground stations, where ground users can generate secure service requests;

[0096] The data layer has QKD capabilities and includes the LEO layer and the MEO layer. The LEO layer is used to form the main QKD layer, and the MEO layer is used as an auxiliary forwarding layer for the LEO data layer when quantum key resources are scarce.

[0097] The SDN control layer has the function of dynamic network management in the constellation model. The SDN control layer includes the main controller and the domain controller;

[0098] The main controller is deployed on the ground and is responsible for the global management and resource scheduling of the entire quantum communication network. The main controller's tasks include at least link optimization, path planning, and load balancing.

[0099] The main controller monitors the network status in real time and dynamically adjusts the resource allocation strategy of each domain based on the communication needs and satellite link status of different regions to ensure network stability and communication efficiency;

[0100] Because GEO satellites offer wide coverage and are stationary relative to the Earth, they can continuously and reliably manage and monitor LEO and MEO satellites over a wide area. Acting as domain controllers, GEO satellites collect link status information between quantum satellites and report this data to the master controller. They are also responsible for executing commands issued by the master controller within their coverage area, such as switching communication paths for quantum key distribution or reconfiguring resources. Hierarchical management between the master and domain controllers effectively improves network flexibility and scalability, reduces reliance on ground stations, and enables more efficient cross-regional quantum key distribution.

[0101] S3: Set up the key resource model;

[0102] Due to the low key generation rate, when the number of security service requests is large and the network is busy, there will usually be insufficient quantum keys. [15-17] Therefore, the Quantum Key Pool (QKP) is introduced as a cache for quantum keys. QKP is mainly used to store the key pairs generated between each pair of quantum nodes. The keys are stored in the corresponding QKP of the quantum nodes that appear in pairs.

[18] The key in QKP can be provided to the encryption and decryption module when a security service request arrives, realizing the key relay function.

[0103] Figure 3 For the basic process of quantum satellite QKD based on trusted relays, the quantum key required for the security request from GS1 to GS2 will be stored in the QKP of the corresponding link in advance. Through continuous encryption and decryption on the trusted relay, the key K can be relayed from GS1 to GS2.

[0104] S4: key generation and consumption;

[0105] Satellites are highly dynamic and their topology will change over time, so it is not easy to describe a real-time updated satellite network topology. Since the connection relationship of satellite topology is periodic, the satellite topology is divided into n static topologies {G|G l , G2, G3, .., G n}

[19] , where G is a set of n sub-topologies, G1~G n The n sub-topologies are divided into n sub-topologies, and these n different topologies correspond to n different time periods {T|t1~t2, t1~t2, ..., t n-1 ~tn}, where T is the topological period, t1~t2, ...., t n-1 ~t n For n time slots, use L (i,j) represents the quantum link between quantum node i and quantum node j in the satellite topology;

[0106] Assuming that any two connected nodes can perform QKD, the number of keys generated and consumed is related to the duration of the link connection, and the number of keys cached in the QKP is related to the initial number of keys, the number of keys generated, and the number of keys consumed in the QKP. The mathematical notation is described in Equation 1:

[0107]

[0108] where K (i,j) (t) is the link L at time t (i,j) The number of QKP keys in the network, t0 is the arrival time of the current network topology, t1 is the end time of the current network topology, C (i,j) is the number of keys consumed in a single QKD link, R (i,j) (t) is the link L at time t (i,j) The key generation rate, R (i,j) (t) can be expressed by referring to formula 2:

[0109]

[0110] where R max Denotes the maximum key generation rate in the key generation rate set of the links in the QKD network, D (i,j) (t) represents the link L (i,j) The distance at time t, D min is the shortest link distance in the link distance set.

[0111] S5: Perform link state assessment to better describe the number and update status of quantum keys in the topology;

[0112] By establishing a link key matrix K(t), refer to Equation 3, the matrix can represent the QKP resource status of each link at time t in real time;

[0113]

[0114] When performing global QKD, due to the volume of service requests and network complexity, the quantum key flow in the link may include three situations: link key supply exceeds demand, link key supply falls short of demand, and link anomalies.

[0115] The situation where the link key supply exceeds the demand is: when there is no abnormality in the link, the number of security service requests is small, the quantum key in the QKP will be continuously updated, and its quantum key generation rate will continue to exceed the key consumption rate, refer to Equation 4:

[0116]

[0117] where K (ij) (t) is the link L at time t (i,j) The number of keys in QKP, K (i,j) (t0) represents the initial quantum key quantity, represents the quantum key generation amount, is the quantum key consumption.

[0118] The situation where the link key supply is less than the demand is: when there is no abnormality in the link, the number of security service requests is large, the quantum key in the QKP will be continuously updated, and its quantum key generation rate is less than the key consumption rate, and it cannot continuously support key services. Refer to Equation 5:

[0119]

[0120] In the case of link abnormality, when a link abnormality occurs, the key quantity in the QKP will not be able to be updated, its initial quantum key will become invalid, and it will no longer be able to provide encryption and decryption services for the global QKP. See Equation 6:

[0121]

[0122] At the same time, the Network Congestion Index (NCI) is introduced. The NCI can reflect the density and dispersion of requests at different time points.

[0123] The network congestion index needs to consider the total number of business requests and the number of network requests at a certain moment to determine whether the requests are evenly distributed. The network congestion index is expressed as follows:

[0124] NCI=μ x σ x R peak (7)

[0125] in:

[0126] μ x Indicates the average number of requests, representing the average number of requests at each time point. The larger the mean value, the higher the load level at each moment;

[0127] σ x The standard deviation reflects the volatility of the request volume distribution. A larger standard deviation indicates uneven load distribution at different time points.

[0128] R peak R is the peak ratio, which is used to reflect the impact of the highest peak load on the overall load. The higher the peak ratio, the more sudden peaks there are. peak Refer to Equation 8:

[0129]

[0130] In formula 8, δ is the normalization adjustment factor, (x1, x1, .., x T ) represents the sequence of the number of requests occurring in time period T, and N represents the total number of requests.

[0131] Example 2:

[0132] Based on the above embodiment 1, a method for building a key distribution routing algorithm is proposed;

[0133] In large-scale quantum key distribution networks, the dynamic changes in link key resources and the fluctuations in business demand place extremely high demands on the network's transmission efficiency and latency. Especially in the case of high communication density and low latency in low-Earth orbit satellites, traditional single-layer network architectures often find it difficult to balance load and resource allocation, and are unable to effectively respond to complex business requests and dynamic link states. To address this problem, the present invention proposes an adaptive quantum key stream-aware routing algorithm (AQKAR), which aims to optimize the key distribution path by flexibly mobilizing key resources in multi-layer satellite networks, ensuring efficient quantum key distribution under different network load conditions.

[0134] The key distribution routing algorithm is based on a multi-layer QKD constellation model integrated with SDN, and is used to ensure that the multi-layer QKD constellation model integrated with SDN achieves efficient quantum key distribution under different network loads.

[0135] Propose multi-layer satellite key routing:

[0136] Since the communication delay between LEO satellites and ground stations is relatively low, when the LEO layer has sufficient quantum key resources and the service demand is not high, the ground control center will give priority to the LEO data layer as the first access layer for key relay. Figure 4 As shown in Figure (a), when an end-to-end secure communication request is generated between ground station S1 and ground station S2, the LEO layer will find a suitable access quantum satellite via the LEO-GS link. The key information is then uploaded to the LEO satellite layer via this link. The controller then searches for an available inter-satellite link (ISL) within the LEO layer and transmits the key information to the satellite connected to the target ground station S2, completing the key distribution and transmission of the service request.

[0137] When the business requests are busy and the key resources of the link are scarce, the relay nodes of the LEO layer alone cannot bear the high-load business traffic. At this time, the ground control center will mobilize the key resources of the MEO data layer to assist the LEO data layer in relaying, such as Figure 4 (b) Even after finding a suitable access satellite in the LEO layer, if a path to the destination cannot be found in the LEO layer due to insufficient key resources or path anomalies, the controller will incorporate the nodes in the MEO layer into the key distribution topology. After the key information is transmitted to the LEO layer, it is transmitted to the available quantum satellites in the MEO layer using the ASL link. Then, a suitable inter-satellite path is found and the key information is finally returned to the LEO layer via the ASL link and delivered to the destination ground station.

[0138] If the number of keys in the LEO-GS link is insufficient and the access link cannot be established through the LEO satellite, the MEO-GS link can also be used to set the access satellite to a MEO satellite. The MEO satellite will be used directly as the access node, and the key data will be transmitted to the destination ground station through the MEO-GS link. The specific process is shown in Figure 4 (c) Although the MEO-GS link has a higher latency and lower key generation rate due to the longer communication distance, this strategy can still effectively improve the success rate of the overall quantum key distribution network under resource constraints.

[0139] To reduce end-to-end network communication latency, the algorithm sets a maximum forwarding count for each path. Within the set of available paths from ground station S1 to S2, the controller prioritizes the path with the fewest hops. When the key resources on that path fall below the number of keys required for the next service, the controller switches to a path with a larger number of hops. If no paths within the LEO layer meet the maximum forwarding count, the MEO layer introduces an auxiliary relay. When sufficient key resources are restored at the LEO layer, the data layer switches back to the LEO single-layer QKD, minimizing latency and maximizing resource utilization within the key distribution network.

[0140] The input of the key distribution routing algorithm is x(S i , d i , k i ) and G(V t , E t , K0, R t );

[0141] Where x(S i , d i , k i ) represents the slave service node S i To the target node d i Quantum key distribution request, where k i is the number of keys requested;

[0142] Where G(V t , E t , K0, R t ) represents a graph model, where V t is the vertex set, E t is the edge set, i.e., the optical link, K0 is the minimum number of available keys, R t A collection of transport resources.

[0143] The key distribution routing algorithm includes at least the following steps:

[0144] S1: Initialize each optical link resource, in Figure G (V t , E t , K0, R t ) initialize each optical link resource;

[0145] S2: Calculate the routing set and calculate the slave service node s i To the target node d i The routing set P and limit the maximum number of hops;

[0146] S3: Check whether the route is found. If no suitable path is found in the routing set P, stop the request and report that no suitable path can be found.

[0147] S4: Traverse each shortest hop path, for each shortest hop path p in the path set P i ;

[0148] S5: Check whether the path is found: When the path discovery flag is True, execute the quantum key relay service;

[0149] S6: Handle the case where no path is found. If no suitable path is found, add a MEO layer to the graph to assist the LEO layer in performing QKD, and re-execute the above steps;

[0150] S7: Check the number of keys of the LEO layer link and re-evaluate whether the LEO layer link meets the key number requirement. If the number of keys of the LEO layer link and the LEO ground station link is k i <K0, use the MEO layer alone for QKD and repeat the above steps;

[0151] S8: Perform a final path check. If the path flag is still False, report that the key distribution failed because there is no available path.

[0152] S4 includes at least the following steps:

[0153] S4.1: Get the passed links and path p i The optical link passing through;

[0154] S4.2: Check the number of keys on the link. When the number of keys k on each link in the path i <K0, set the path discovery flag to True, indicating that an available path has been found, and then exit the loop;

[0155] S4.3: Continue to check other paths. If the appropriate number of keys is not found for the current path, continue to check the next path.

[0156] To elaborate on the implementation mechanism of the Adaptive Quantum Key Flow-Aware Routing Algorithm (AQKAR), the present invention provides the pseudocode of this algorithm. The pseudocode demonstrates the process of AQKAR dynamically adjusting key resources and optimizing route selection in a multi-layer satellite network. The pseudocode of this algorithm is as follows:

[0157]

[0158] The time complexity analysis of the AQKAR algorithm shows that in the worst case, the complexity of the algorithm is O(E + V + h|P|), where E and V are the number of edges and nodes in the graph G(V t , E t , K0, R t ), h represents the maximum number of hops of the path, and |P| represents the number of calculated paths. In the worst case, the algorithm needs to traverse all nodes and edges to determine the available path set P, which leads to an increase in complexity. On the other hand, in general cases, although the formal complexity of the algorithm is still O(E + V + h|P|), in practical applications, the number of paths |P| and the maximum number of hops h are usually small, and the actual running time of the algorithm is often better than the worst case.

[0159] Based on the above two embodiments, the following experimental verification is further proposed:

[0160] 1. Experimental Environment and Parameter Settings <​​​​​​​​

[0164] 2. Analysis of experimental results

[0165] Figure 5 This study demonstrates the success probability of relay services in a quantum satellite network topology under varying key consumption conditions and at varying request volumes. The results show that as the number of requests increases, the success probability of each request gradually decreases. Increased key consumption further reduces the overall success probability of each request. Further observation reveals that, at the same key consumption, the MEO / LEO network significantly outperforms the GEO / MEO network, especially when the number of requests is high. When the key consumption is between 3 and 5 and the number of requests reaches 9,000, the success probability of the GEO / LEO network begins to fall below that of the MEO / LEO network. As the key consumption increases to 4 to 6 and the number of requests drops to 6,000, the GEO / LEO network's success probability again falls below that of the MEO / LEO network. This difference becomes apparent at 5,000 requests, with a key consumption of 5 to 7. This difference is primarily due to the difference in communication distance between GEO / LEO and MEO / LEO links. The quantum key generation rate is inversely proportional to the communication distance between two quantum nodes; the longer the communication distance, the lower the key generation rate. The communication distance between high-orbit satellites and low-orbit satellites is tens of thousands of kilometers, so as service key consumption increases, performance degradation accelerates. Furthermore, with higher key consumption, performance degradation occurs earlier. Simulation results show that, with the same key consumption, the average request success rate of the MEO / LEO dual-layer network is 17.34% higher than that of the GEO / LEO dual-layer network and 32.47% higher than that of the LEO single-layer network.

[0166] Flexible scheduling of key resources between quantum satellite nodes is a key factor influencing the success rate of quantum key relay services. The number of routing hops directly affects the amount of key resources available in the routing path between Alice and Bob. Setting a low maximum hop count reduces the number of shared routing paths that Alice and Bob can find. As the number of relay requests between Alice and Bob continues to increase, and the link key generation rate between quantum satellite nodes is lower than the link key consumption rate, the QKP resources in the link between the quantum satellite nodes will rapidly decrease, affecting the success rate of requests between Alice and Bob. Conversely, gradually relaxing the maximum hop count limit allows Alice and Bob to find more shared routing paths, distributing the network load on paths with fewer hops and improving the overall success rate of the relay service.

[0167] Figure 6The performance of a single-layer LEO network and a dual-layer MEO / LEO network under different maximum hop counts is demonstrated. The results show that, for both single-layer and dual-layer networks, the relay service success rate decreases with increasing load. Furthermore, the relay service success rate for both topologies significantly improves with increasing maximum hop counts. For the dual-layer network, when the maximum hop count increases to 6, the relay service success rate remains close to 1 even at a load of 5,000. However, in the single-layer network, when the maximum hop count is 6, the service success rate only reaches 1 when the number of visits is under 1,000. Under the same maximum hop count, the dual-layer network consistently achieves a higher relay service success rate than the single-layer network. This superior performance is due to the dual-layer QKD network's superior physical layer key resource reserves and key generation rate per unit time compared to the single-layer network. Increasing the maximum hop count from 4 to 5 in the single-layer network increases the relay service success rate by 29.1%, and from 5 to 6, the success rate increases by 13.1%. Correspondingly, increasing the maximum number of hops in the two-layer network from 4 to 5 increased the success rate by 32.4%, and increasing it from 5 to 6 further increased the success rate by 20.7%. This shows that increasing the maximum number of hops significantly increases the gain of the two-layer network compared to the single-layer network.

[0168] The purpose of limiting the maximum number of forwarding is to control the service delay between Alice and Bob. Figure 7 (a) shows the average latency between Alice and Bob in a MEO / LEO dual-layer network under different maximum forwarding numbers. Experimental data shows that even under the same maximum hop count, as the number of requests increases, the cumulative effect of network congestion and satellite processing delay causes the average latency of a single service to increase, thereby increasing the overall service latency. Furthermore, increasing the maximum forwarding number does not lead to a linear increase in service latency. When the maximum forwarding number increases from 4 to 5, the average latency increases the most, and the average latency increases with further increases in the maximum forwarding number. This indicates that when performing global quantum key distribution services, the path with a forwarding number of 5 is the most common. Further increasing the forwarding number can further improve the success probability of QKD at the expense of a smaller increase in latency, thereby enhancing the network's resilience and stability.

[0169] Figure 7(b) shows a latency comparison between a LEO single-layer network, MEO / LEO, and a GEO / LEO dual-layer network under a routing algorithm with a fixed maximum forwarding count of 6. The MEO / LEO dual-layer network exhibits lower service latency than the GEO / LEO dual-layer network under all load conditions. This is due to the GEO / LEO dual-layer network having a longer communication range than the MEO / LEO dual-layer network. Furthermore, the MEO / LEO dual-layer network, with a MEO network layer further from the ground station than the LEO single-layer network, experiences higher latency over communication distance than the LEO single-layer key distribution network. However, a single-layer network has lower overload resistance and network resilience. In the event of a dramatic increase in traffic, the network becomes more susceptible to congestion, and the processing latency of quantum nodes is greater than that of a dual-layer network. As can be seen from the figure, when the number of visits reaches 1,000, the average latency of the LEO single-layer network and the MEO / LEO dual-layer network is similar. However, as the number of network requests increases, the latency gap between the two gradually widens. When the number of requests reaches 10,000, the average latency gap between the LEO single-layer network and the MEO / LEO dual-layer network reaches approximately 30ms. Comparing the GEO / LEO and LEO networks, when the number of requests reaches 5,000, the latency of the LEO single-layer network even gradually exceeds that of the GEO / LEO network.

[0170] In the experiment, the shortest path algorithm (Dijkstra) and the maximum flow algorithm (SA-MFP) were selected as the benchmark algorithms. Figure 8 (a) shows the performance of the three algorithms under different loads. The results show that the AQKAR algorithm performs best, followed by the SA-MFP algorithm, while the Dijkstra algorithm performs worst under high load conditions, especially in the early stages where significant performance degradation occurs. The AQKAR algorithm can flexibly call the key resources of the intersatellite QKD data layer and can flexibly change them under the highly dynamic satellite topology. The SA-MFP algorithm is a maximum flow algorithm, and it is difficult to achieve real-time updates under the highly dynamic satellite topology. In the case of high network load or congestion, the path update lag will further reduce the utilization of quantum key resources. Experimental results show that the AQKAR algorithm has an average request success rate that is 18.46% higher than the SA-MFP algorithm and 26.08% higher than the Dijkstra algorithm.

[0171] Figure 8(b) shows the average communication delay of the AQKAR algorithm, SA-MFP algorithm, and Dijkstra algorithm under different business request volumes. It can be found that the average delay of the AQKAR algorithm is significantly lower than that of the other two algorithms, and the Dijkstra algorithm has the worst delay effect. This is because the AQKAR algorithm calls quantum key resources in layers and gives priority to calling data layers with lower orbital heights. The other two algorithms do not take this into consideration, and their own routing mechanisms have their own shortcomings. From the analysis of the figure, it is found that when the network request volume is large, the delay of the other two algorithms (especially the Dijkstra algorithm) increases significantly faster than the AQKAR algorithm, and their overall delay performance is not as good as the AQKAR algorithm.

[0172] In order to verify the stability of the AQKAR algorithm under QKD network congestion, the performance of the AQKAR algorithm, SA-MFP algorithm and Dijkstra algorithm in the NCI range of [0.2, 0.5] was compared. Figure 9 (a) shows the results of the three algorithms when the number of visits is 4000. The success probability of the AQKAR algorithm in the [0.2, 0.5] NCI range remains at around 0.87 without showing significant changes. In contrast, the success probability of the SA-MFP algorithm decreases as the network congestion increases. The initial performance of the Dijkstra algorithm is not as good as the previous two algorithms, and it shows a greater decay rate as the congestion value increases. When the number of visits increases to 10,000, as shown in Figure 9 As shown in (b), the success probability of the AQKAR algorithm begins to slowly decline, indicating that it maintains a certain degree of stability under network congestion. Compared with the SA-MFP algorithm, the success rate of the AQKAR algorithm is approximately 0.05 higher than that of the SA-MFP algorithm when NCI = 0.2, and approximately 0.1 higher when NCI = 0.5. These results show that the AQKAR algorithm is more stable than the SA-MFP and Dijkstra algorithms in network congestion.

[0173] In summary:

[0174] For free-space quantum key distribution, the present invention proposes a trusted relay constellation model based on the GEO / MEO / LEO three-layer orbit, and combines it with software-defined network technology. In order to ensure that the model achieves efficient quantum key distribution under different network loads, an adaptive key stream-aware routing algorithm (AQKAR algorithm) is designed. Simulation results show that under the same key consumption, the average request success rate of the MEO / LEO two-layer network is 17.34% higher than that of the GEO / LEO two-layer network and 32.47% higher than that of the LEO single-layer network; at the same time, under the same routing algorithm, the average delay of the MEO / LEO two-layer network is lower than that of the GEO / LEO two-layer and LEO single-layer networks. In addition, the request success rate of the AQKAR algorithm is improved by 18.46% compared with the SA-MFP algorithm and 26.08% compared with the Dijkstra algorithm, and it can flexibly call key resources at different layers and between layers, effectively reducing network overhead.

[0175] References

[0176] [1]De Grossi F,Alberico S,Circi C.Orbit design of satellite quantumkey distribution constellations in different ground stations networks[J].Advances in Space Research,2024,73(11):5446-5463.

[0177] [2]Cao Y, Zhao Y, Colman-Meixner C, et al. Key on demand (KoD) for software-defined optical networks secured by quantum key distribution (QKD) [J]. Optics express, 2017, 25 (22): 26453-26467.

[0178] [3]Nauerth S, Moll F, Rau M, et al. Air-to-ground quantum communication [J]. Nature Photonics, 2013, 7(5): 382-386.

[0179] [4]Vallone G,Bacco D,Dequal D,et al.Experimental satellite quantumcommunications[J].Physical Review Letters,2015,115(4):040502.

[0180] [5]Villoresi P,Jennewein T,Tamburini F,et al.Experimentalverification of the feasibility of a quantum channel between space and Earth[J].New Journal of Physics,2008,10(3):033038.

[0181] [6]Günthner K,Khan I,Elser D,et al.Quantum-limited measurements ofoptical signals from a geostationary satellite[J].Optica,2017,4(6):611-616.

[0182] [7]Calderaro L,Agnesi C,Dequal D,et al.Towards quantum communicationfrom global navigation satellite system[J].Quantum Science and Technology,2018,4(1):015012.

[0183] [8]Vergoossen T,Loarte S,Bedington R,et al.Modelling of satelliteconstellations for trusted node QKD networks[J].Acta Astronautica,2020,173:164-171.

[0184] [9]Huang D,Zhao Y,Yang T,et al.Quantum key distribution over double-layer quantum satellite networks[J].IEEE Access,2020,8:16087-16098.

[0185]

[10] Grillo M,Dowhuszko A A,Khalighi M A,et al.Resource allocation ina quantum key distribution network with LEO and GEO trusted-repeaters[C] / / 202117th International Symposium on Wireless Communication Systems(ISWCS).IEEE,2021:1-6.

[0186]

[11] Wang J,Chang L,Chen H,et al.Networking Feasibility of Quantum KeyDistribution Constellation Networks[J].Entropy,2022,24(2):298.

[0187]

[12] He X,Li L,Han D,et al.Routing and secret key assignment forsecure multicast services in quantum satellite networks[J].Journal of OpticalCommunications and Networking,2022,14(4):190-203.

[0188]

[13] De Grossi F,Alberico S,Circi C.Orbit design of satellite quantumkey distribution constellations in different ground stations networks[J].Advances in Space Research,2024,73(11):5446-5463.

[0189]

[14] Guo M,Cao Y,Zhu J,et al.Topology Abstraction-Based Routing Schemefor Secret-Key Provisioning in Hybrid GEO / LEO Quantum Satellite Networks[J].Entropy,2023,25(7):1047.

[0190]

[15] Mora J,Amaya W,Ruiz-Alba A,et al.Simultaneous transmission of20x2 WDM / SCM-QKD and 4 bidirectional classical channels over a PON[J].OpticsExpress,2012,20(15):16358-16365.

[0191]

[16] Yoshino K,Fujiwara M,Tanaka A,et al.High-speed wavelength-division multiplexing quantum key distribution system[J].Optics letters,2012,37(2):223-225.

[0192]

[17] Choi I,Young R J,Townsend P D.Quantum key distribution on a 10Gb / s WDM-PON[J].Optics express,2010,18(9):9600-9612.

[0193]

[18] Cao Y,Zhao Y,Wu Y,et al.Time-scheduled quantum key distribution(QKD)over WDM networks[J].Journal of Lightwave Technology,2018,36(16):3382-3395.

[0194]

[19] Huang J, Su YX, Huang L, et al. An optimized snapshot division strategy for satellite network in GNSS[J]. IEEE Communications Letters, 2016, 20(12): 2406-2409.

[0195]

[20] Wang H, Zhao Y, Yu X, et al. Resilient quantum key distribution (QKD)-integrated optical networks with secret-key recovery strategy [J]. IEEE Access, 2019,7:60079-60090.

[0196] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.

Claims

1. A method for building a multi-layer QKD constellation model integrating SDN, characterized by: At least the following steps are included: S1: Setting a trusted relay quantum key distribution constellation model, which is a three-layer orbit satellite network constellation model, giving full play to the characteristics of GEO, MEO and LEO orbit satellites; S2: Based on S1, further propose a multi-layer architecture and dynamic management strategy for quantum satellite optical networks; S3: Set up a key resource model and introduce a quantum key pool as a cache for quantum keys. The quantum key pool is QKP, which is used to store key pairs generated between each pair of quantum nodes. The keys are stored in the corresponding QKPs of the quantum nodes that appear in pairs. The keys in the QKPs are provided to the encryption and decryption modules when a security service request arrives, realizing the key relay function. S4: key generation and consumption; S5: Perform link state assessment to better describe the number and update status of quantum keys in the topology; Said S1 at least comprises the following steps: In the satellite network scenario model, the LEO layer of the quantum satellite network adopts a uniformly distributed Walker constellation, which contains orbital planes, with Q satellites evenly distributed on each orbit, for a total of low-orbit satellites; Each LEO satellite is connected to four adjacent LEO orbits, two of which are in the same orbit and the other two are in different orbits. Satellites in the same orbital layer can be connected through inter-satellite links, while satellites in different orbital layers can be connected through inter-orbit links to ensure cross-orbit quantum key transmission; LEO satellites establish quantum communication with ground stations via satellite-to-ground links. MEO satellites can establish auxiliary communication links with LEO satellites. The auxiliary communication links are used to assist the LEO layer in complex quantum key routing and forwarding, and are used to directly establish communication links with ground stations to enhance the redundancy and reliability of the quantum key distribution network. The GEO satellite has a wide coverage capability and is used as a monitoring satellite to collect and forward topological resources and quantum key resource information of the LEO layer and MEO layer to the ground station, so that the ground station can update the satellite node and its link resource information in a timely manner; The ground stations are distributed around the world, and end-to-end secure service requests are established between the ground stations. By establishing connections with free-space relay satellites, point-to-point key distribution is performed between the relay satellites, thereby realizing ultra-long-distance quantum key distribution services; The multi-layer architecture of the quantum satellite optical network in S2 includes at least an application layer, an SDN control layer, a data layer, and a QKD layer; The application layer is composed of ground stations, and ground users can generate security service requests; The data layer has QKD capability, and the data layer includes a LEO layer and a MEO layer, the LEO layer is used to constitute the main QKD layer, and the MEO layer is used to serve as an auxiliary forwarding layer for the LEO data layer under the condition of scarce quantum key resources; The SDN control layer has a network dynamic management function in the constellation model, and the SDN control layer includes a main controller and a domain controller; The main controller is deployed on the ground and is responsible for the global management and resource scheduling of the entire quantum communication network. The tasks of the main controller include at least link optimization, path planning and load balancing.

2. The method for constructing a multi-layer QKD constellation model integrating SDN according to claim 1, characterized in that: The S4 at least includes the following steps: Since the connection relationship of satellite topology is periodic, the satellite topology is divided into Static topology ,in for A collection of subtopologies, For the division Subtopology, this Different topologies correspond to Different time periods ,in is a topological cycle, for time slots, using Represents quantum nodes in satellite topology With quantum nodes quantum links between them; Assuming that any two connected nodes can perform QKD, the number of keys generated and consumed is related to the duration of the link connection, and the number of keys cached in the QKP is related to the initial number of keys, the number of keys generated, and the number of keys consumed in the QKP, as shown in the following formula (1): ; in for Time Link The number of keys in QKP, is the arrival time of the current network topology, is the end time of the current network topology, The number of keys required for a single QKD link, for Time Link The key generation rate, As shown in formula (2): ; in represents the maximum key generation rate in the set of key generation rates of the links in the QKD network, Representative link exist The distance of time, is the shortest link distance in the link distance set.

3. The method for constructing a multi-layer QKD constellation model integrated with SDN according to claim 2, characterized in that: The S5 at least includes the following steps: By establishing a link key matrix , as shown in formula (3), the matrix can be expressed in real time QKP resource status of each link at all times; ; When performing global QKD, due to the volume of service requests and network complexity, the quantum key flow in the link may include three situations: link key supply exceeds demand, link key supply falls short of demand, and link anomalies. The situation where the link key supply exceeds the demand is: when there is no abnormality in the link, the number of security service requests is small, the quantum key in the QKP will be continuously updated, and its quantum key generation rate will continue to be greater than the key consumption rate, as shown in the following formula (4): (4); in: for Time Link The number of keys in QKP, represents the initial quantum key quantity, represents the quantum key generation amount, is the quantum key consumption; The situation where the link key supply is less than the demand is: when there is no abnormality in the link, the number of security service requests is large, the quantum key in the QKP will be continuously updated, and its quantum key generation rate is less than the key consumption rate, and it cannot continuously support key services, as shown in the following formula (5): (5); The link abnormality is as follows: when the link is abnormal, the key quantity in the QKP will not be able to be updated, its initial quantum key will become invalid, and it will no longer be able to provide encryption and decryption services for the global QKP, as shown in the following formula (6): (6); At the same time, a network congestion index is introduced, which can reflect the density and dispersion of requests at different time points; The network congestion index needs to consider the total number of business requests and the number of network requests at a certain moment to determine whether the requests are evenly distributed. The network congestion index is expressed as follows (7): (7); in: Indicates the average number of requests, representing the average number of requests at each time point. The larger the mean value, the higher the load level at each moment; The standard deviation reflects the volatility of the request volume distribution. A larger standard deviation indicates uneven load distribution at different time points. The peak ratio is used to reflect the impact of the highest peak load on the overall load. The higher the peak ratio, the more sudden peaks there are. It is expressed as follows (8): (8); In formula 8, is the normalization adjustment factor, represents the sequence of the number of requests occurring in time period T, Represents the total number of requests.

4. A method for constructing a key distribution routing algorithm, for use in a method for constructing a multi-layer QKD constellation model for SDN integration as described in any one of claims 1-3, characterized in that: The key distribution routing algorithm is based on a multi-layer QKD constellation model integrated with SDN, and is used to ensure that the multi-layer QKD constellation model integrated with SDN achieves efficient quantum key distribution under different network loads.

5. The method for constructing a key distribution routing algorithm according to claim 4, characterized in that: The input of the key distribution routing algorithm is and ; in Indicates that the slave service node To the target node A quantum key distribution request, where is the number of keys requested; in Represents a graph model where is a set of vertices, The edge set is the optical link, is the minimum number of keys available, A collection of transport resources.

6. The method for constructing a key distribution routing algorithm according to claim 5, characterized in that: The key distribution routing algorithm comprises at least the following steps: S1: Initialize each optical link resource. Initialize each optical link resource; S2: Calculate the routing set and calculate the slave service node To the target node Route collection , and limit the maximum number of hops; S3: Check if the route is found. If it is in the route set If no suitable path is found, the request is stopped and a report is issued that no suitable path can be found. S4: Traverse each shortest hop path, for the path set Each shortest hop path in ; S5: Check whether the path is found: When the path discovery flag is True, execute the quantum key relay service; S6: Handle the case where no path is found. If no suitable path is found, add a MEO layer to the graph to assist the LEO layer in performing QKD, and re-execute the above steps; S7: Check the number of keys in the LEO layer link and re-evaluate whether the LEO layer link meets the key number requirement. If the number of keys in the LEO layer link and the LEO ground station link is , use the MEO layer alone for QKD and repeat the above steps; S8: Perform a final path check. If the path flag is still False, report that the key distribution failed because there is no available path.

7. The method for constructing a multi-layer QKD constellation model and key distribution routing algorithm integrated with SDN according to claim 6, characterized in that: The S4 at least includes the following steps: S4.1: Get the passed links and path The optical link passing through; S4.2: Check the number of keys of the link. When the number of keys of each link in the path is , set the path discovery flag to True, indicating that a usable path has been found, and then exit the loop; S4.3: Continue to check other paths. If the current path does not find the appropriate number of keys, continue to check the next path.

Citation Information

Patent Citations

  • Key service routing method and system of quantum satellite network

    CN116707617A

  • A system and method for satellite quantum key distribution

    GB201916308D0