Device-side deployment method and system for quantum key distribution and ICT integration
By positioning and configuring intermediate nodes, building a communication channel in the debug mode, and quantum key distribution and combination are solved, the problem of distance limitation of quantum key generation is solved, and safe, stable and continuous quantum key distribution and communication processing is achieved.
Patent Information
- Application Number
- CN202510192963.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-21
AI Technical Summary
In the prior art, the generation of quantum keys is limited by distance, resulting in errors in communication between the two ends whose distance exceeds the preset standard, causing interference in the generation of the key.
By acquiring and analyzing the communication end-side information between the first end-side node and the second end-side node, positioning the intermediate node of quantum communication, and configuring working parameters to build a communication debugging mode communication channel. Quantum key distribution and combination are performed in communication debugging mode, a security key of the communication channel is generated, and the ciphertext protocol is deployed according to the key, and the communication channel is switched to the communication execution mode.
Through quantum key distribution, we ensure the security of the key distribution process, prevent eavesdropping and man-in-the-middle attacks, seamless switching between debugging and execution modes, ensure the continuity and stability of the communication process, effectively integrate quantum communication with traditional ICT technology, and improve the security level of existing communication systems.
Smart Images

Figure CN119696783B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum keys, and in particular to a terminal-side deployment method and system for integrating quantum key distribution with ICT. Background Art
[0002] In existing communication technologies, information security can be guaranteed through information encryption, which relies on the distribution of keys. The key distribution method in traditional communication technologies is vulnerable to attacks and eavesdropping. However, the distribution of keys through quantum technology can ensure the security of information. The use of quantum technology to distribute keys is limited by distance, that is, there will be errors in the communication between the two ends when the distance exceeds the preset standard, which will interfere with the generation of keys. Summary of the invention
[0003] The purpose of the present invention is to provide a terminal-side deployment method and system for quantum key distribution and ICT integration, aiming to solve the problem of distance limitation in the generation of quantum keys in the prior art.
[0004] The present invention is implemented in this way. In a first aspect, the present invention provides a terminal-side deployment method for integrating quantum key distribution and ICT, comprising:
[0005] Acquire communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function;
[0006] Performing working parameter configuration on the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information respectively, so that the first end-side node, the second end-side node and the intermediate node jointly construct a communication channel in a communication debugging mode;
[0007] The communication channel in the communication debugging mode is required to perform quantum key distribution and combination from both end sides toward the intermediate node to obtain the security key of the communication channel;
[0008] The first end-side node and the second end-side node are deployed with a ciphertext protocol according to the security key, so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
[0009] In a second aspect, the present invention provides a terminal-side deployment system for quantum key distribution and ICT fusion, which is used to implement a terminal-side deployment method for quantum key distribution and ICT fusion as described in any one of the first aspects, including:
[0010] A node positioning module, used to obtain communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function;
[0011] A channel construction module, used to configure working parameters of the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node and the intermediate node jointly construct a communication channel in a communication debugging mode;
[0012] A key generation module, used to enable the communication channel in the communication debugging mode to distribute and combine quantum keys from both ends to the intermediate node to obtain a security key for the communication channel;
[0013] A key deployment module is used to perform a ciphertext protocol deployment operation on the first end-side node and the second end-side node according to the security key, so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
[0014] The present invention provides a terminal-side deployment method for integrating quantum key distribution and ICT, which has the following beneficial effects:
[0015] The present invention acquires and analyzes communication end-side information of a first end-side node and a second end-side node, locates an intermediate node of quantum communication, configures working parameters to construct a communication channel in a communication debugging mode, performs quantum key distribution and combination to generate a security key for the communication channel in the communication debugging mode, and switches the communication channel to a communication execution mode according to a security key deployment ciphertext protocol for subsequent communication processing. Through quantum key distribution, the security of the key distribution process is ensured to prevent eavesdropping and man-in-the-middle attacks, and seamlessly switches between debugging and execution modes to ensure the continuity and stability of the communication process. The present invention effectively integrates quantum communication and traditional ICT technology, improves the security level of existing communication systems, and solves the problem of distance limitation in the generation of quantum keys in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic diagram of the steps of a terminal-side deployment method for quantum key distribution and ICT integration provided by an embodiment of the present invention;
[0017] Figure 2 It is a structural diagram of a terminal-side deployment system for quantum key distribution and ICT integration provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0019] The implementation of the present invention is described in detail below in conjunction with specific embodiments.
[0020] Reference Figure 1 , Figure 2 As shown, a preferred embodiment of the present invention is provided.
[0021] In a first aspect, the present invention provides a terminal-side deployment method for quantum key distribution and ICT integration, comprising:
[0022] S1: Acquire communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function;
[0023] S2: respectively configuring working parameters for the first end-side node, the second end-side node, and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node, and the intermediate node jointly construct a communication channel in a communication debugging mode;
[0024] S3: The communication channel in the communication debugging mode is required to perform quantum key distribution and combination from both ends to the intermediate node to obtain the security key of the communication channel;
[0025] S4: Perform a deployment operation of the ciphertext protocol on the first end-side node and the second end-side node according to the security key, so that the communication channel switches from the communication debugging mode to the communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
[0026] Specifically, in step S1 of the embodiment provided by the present invention, relevant information of the first end-side node and the second end-side node is obtained and described, including but not limited to the location (geographic coordinates) of the node, device type, hardware configuration, supported quantum communication protocols (such as BB84, E91, etc.), and communication capabilities of the node (bandwidth, latency, etc.), and the existing network topology information is collected, including the physical connection status between each node, the quality of the optical fiber link, the link length and its loss.
[0027] More specifically, based on the information on the communication end side, a quantum channel demand model is established to clarify the communication requirements that need to be met, such as communication distance, bandwidth requirements, bit error rate, etc., and to analyze the functions that each node needs to perform, including quantum key distribution (QKD), classical communication support, key management, etc. Based on the geographical location and topological structure, candidate nodes that may serve as intermediate nodes are preliminarily screened out. These nodes should be located between the first end side node and the second end side node and have the physical conditions to access the quantum channel.
[0028] More specifically, the resource availability of candidate nodes is analyzed, including computing power, storage capacity, existing quantum communication equipment, etc., and the link performance of the initially screened candidate nodes is evaluated, including the transmission loss, noise level, quantum bit error rate (QBER) of the quantum channel. Based on the performance evaluation results, the optimal intermediate node is selected, which involves solving the path optimization problem and finding the path with the smallest comprehensive transmission loss and channel noise.
[0029] More specifically, appropriate quantum communication equipment is configured for the selected intermediate nodes, and the quantum communication protocols and classical communication protocols required by the intermediate nodes are configured to ensure that they can correctly perform the transit and transmission functions.
[0030] It can be understood that by accurately locating and configuring intermediate nodes, the quantum communication path is optimized, transmission loss and noise are reduced, the efficiency and reliability of quantum key distribution are improved, and accurate node description and performance analysis help identify and avoid potential physical attack points, enhancing the overall security of the quantum communication network.
[0031] Specifically, in step S2 of the embodiment provided by the present invention, the initial configuration information of the first end-side node, the second end-side node and the intermediate node is collected, including hardware configuration, software version, supported communication protocols, physical location, etc., and the physical link information between each node is obtained, including optical fiber length, transmission loss, connection status, etc.
[0032] More specifically, the quantum signal transmitter of the first end-side node is configured, including parameters such as transmission power, wavelength, modulation format, etc., and the classical communication module for quantum signal synchronization and control is configured, including bandwidth, modulation method, synchronization method, etc. A preliminary calibration is performed to ensure that the transmitter is in normal working condition, and a preliminary communication connection is established with the intermediate node.
[0033] More specifically, configure the quantum signal receiver of the second end-side node, including the sensitivity, operating temperature, filter settings, etc. of the detector, configure a module for receiving and processing classical control signals, ensure synchronization with the intermediate node and the first end-side node, and perform preliminary calibration of the receiver to ensure that it can correctly receive and demodulate quantum signals.
[0034] More specifically, the intermediate node is an interferometer and related equipment, which is used to receive quantum signals from the first end side node and the second end side node to perform interference operations between each other, and generate corresponding security keys by detecting and recording the interference operations, thereby realizing the relay function as an intermediate node.
[0035] More specifically, configure the synchronization and clock parameters of the intermediate nodes to ensure clock synchronization with the end-side nodes, start the synchronization process of all nodes, ensure clock synchronization of the first end-side node, the second end-side node, and the intermediate nodes, start transmitting test quantum signals and classical control signals, monitor signal quality, adjust the transmit power, receive sensitivity, and relay parameters to optimize signal transmission, analyze the bit error rate (QBER) of the test transmission, check the noise level and signal loss of the channel, and make corresponding parameter adjustments.
[0036] It is understandable that the rapid establishment and optimization of quantum communication channels through intermediate nodes to ensure efficient collaboration between nodes belongs to the dual-field quantum key distribution protocol technology, that is, by generating coherent photons between two distant sites and using single-photon interference technology to achieve long-distance quantum key distribution. The protocol improves signal transmission efficiency and noise resistance by optimizing photon sources, detectors, and interferometric measurement devices, solves the problems of signal attenuation and noise accumulation in long-distance optical fiber transmission, and achieves a safe coding distance of more than 500 kilometers.
[0037] Specifically, in step S3 of the embodiment provided by the present invention, the clock synchronization of the first end-side node, the second end-side node and the intermediate node is ensured to perform accurate quantum signal and classical signal transmission, and the quantum signal transmission and reception parameters, classical signal control parameters, etc. of each node are set according to the results of the previous debugging mode.
[0038] More specifically, the first end-side node generates and sends quantum signals (such as photons) to the intermediate node. At the same time, the second end-side node also generates and sends quantum signals to the intermediate node. These signals can be in the form of single photons, entangled photon pairs, etc. The intermediate node receives quantum signals from the two end nodes and stores, converts or forwards the signals according to the system design.
[0039] More specifically, each node exchanges classical information (such as basis selection, measurement results, etc.) for key negotiation through a classical communication channel. The intermediate node plays a role of routing and aggregation in this process, analyzes the bit error rate (QBER) generated during the transmission process, and adjusts system parameters to optimize the transmission quality. According to the measurement results of the quantum signal, each node extracts a preliminary key. These preliminary keys are erroneous under certain circumstances. Error correction is performed between nodes through the classical communication channel, and error correction codes (such as LDPC codes) are used to correct errors in the preliminary keys to obtain the corrected keys. In order to resist potential eavesdropping attacks, each node performs privacy amplification processing on the corrected keys to reduce information leakage in the keys, so that the final keys have higher security.
[0040] More specifically, the intermediate node combines the keys obtained by the two end-side nodes to ensure that both parties share the same security key. This process involves coordination through the intermediate node in classical communication. The final generated security key is stored by each end-side node for subsequent encrypted communications. The intermediate node distributes the final combined security key to the first end-side node and the second end-side node to ensure that both parties have the same key.
[0041] It can be understood that the keys generated by quantum key distribution technology are based on the basic principles of quantum mechanics and provide security in the information theory sense. Even if there are eavesdroppers, they cannot obtain the effective information of the key. By using the optimized parameter settings and synchronization methods in the debugging mode, high-quality quantum keys can be generated efficiently and the key generation rate of the system can be improved.
[0042] Specifically, in step S4 of the embodiment provided by the present invention, it is ensured that the first end-side node and the second end-side node have successfully received and stored the security key distributed by the intermediate node, and the consistency of the key is confirmed through the classic communication channel to ensure that the keys received by both parties are completely consistent. According to system requirements and security requirements, a suitable encryption algorithm (such as AES, ChaCha20, etc.) and related parameters are selected, and the generated security key is imported into the encryption module of the first end-side node and the second end-side node as the key of the encryption algorithm.
[0043] More specifically, a mode switching instruction is sent through the classic communication channel to notify each node to switch the communication channel from debug mode to execution mode. The classic communication channel is used to confirm that each node has successfully switched to ensure that all nodes have entered the communication execution mode. A handshake protocol based on a security key (such as a TLS handshake) is executed, and both parties authenticate each other's identities and establish a secure communication session. During the handshake process, a session key is generated using the security key and the handshake protocol for subsequent encrypted communications.
[0044] More specifically, the first end-side node and the second end-side node begin to use the selected encryption algorithm and session key to encrypt and transmit data, ensure the integrity and authenticity of the transmitted data through data integrity verification (such as HMAC), monitor the status and performance of the communication channel, ensure the quality and security of communication, and update the key regularly or when necessary according to the preset strategy to maintain communication security.
[0045] It can be understood that the security keys and powerful encryption algorithms generated by quantum key distribution ensure the confidentiality of communication content and prevent unauthorized access and eavesdropping. The data integrity verification mechanism ensures that the communication data is not tampered with during transmission, thereby improving the reliability and credibility of communication. It supports multiple encryption algorithms and protocols, and can be flexibly configured and expanded according to different application requirements to adapt to various communication environments.
[0046] The present invention provides a terminal-side deployment method for integrating quantum key distribution and ICT, which has the following beneficial effects:
[0047] The present invention acquires and analyzes communication end-side information of a first end-side node and a second end-side node, locates an intermediate node of quantum communication, configures working parameters to construct a communication channel in a communication debugging mode, performs quantum key distribution and combination to generate a security key for the communication channel in the communication debugging mode, and switches the communication channel to a communication execution mode according to a security key deployment ciphertext protocol for subsequent communication processing. Through quantum key distribution, the security of the key distribution process is ensured to prevent eavesdropping and man-in-the-middle attacks, and seamlessly switches between debugging and execution modes to ensure the continuity and stability of the communication process. The present invention effectively integrates quantum communication and traditional ICT technology, improves the security level of existing communication systems, and solves the problem of distance limitation in the generation of quantum keys in the prior art.
[0048] Preferably, the step of obtaining communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and performing positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function includes:
[0049] S11: Acquire communication terminal side information, and perform request initiating terminal and request receiving terminal parsing processing on the communication terminal side information to obtain terminal side information of initiating communication request and receiving communication request;
[0050] S12: performing information summarization processing in a preset format on the end-side information of the initiating communication request and the receiving communication request obtained by parsing, and obtaining a first end-side node corresponding to the end initiating the communication request and a second end-side node corresponding to the end receiving the communication request;
[0051] S13: performing correlation analysis of node geographic information on the first end-side node and the second end-side node to obtain node position correlation features of the first end-side node and the second end-side node;
[0052] S14: pre-selecting intermediate nodes between the first end-side node and the second end-side node according to the node position association feature to obtain a distribution of intermediate node pre-selected regions between the first end-side node and the second end-side node; wherein the distribution of intermediate node pre-selected regions includes a plurality of intermediate node pre-selected regions and a first selection weight corresponding to each of the intermediate node pre-selected regions;
[0053] S15: searching and processing the intermediate nodes according to the distribution of the intermediate node pre-selected areas to obtain the pre-selected nodes in each of the node pre-selected areas and the second selection weights corresponding to each of the pre-selected nodes;
[0054] S16: performing a weighted comprehensive analysis on the first selection weight of the intermediate node pre-selected area where each of the pre-selected nodes is located and the second selection weight of each of the pre-selected nodes, and confirming the intermediate node from each of the pre-selected nodes according to the result of the weighted comprehensive analysis.
[0055] Specifically, the communication end-side information of the first end-side node (the end initiating the communication request) and the second end-side node (the end receiving the communication request) is collected, and the information generally includes the network address, device identification, geographic location, etc. of the node.
[0056] More specifically, the collected communication end-side information is parsed, and the end-side information of initiating communication requests and receiving communication requests is extracted respectively, and the specific information of the first end-side node and the second end-side node is clarified. The parsed information of the end initiating the communication request and the information of the end receiving the communication request are summarized in a preset format to be systematically organized into a description of the first end-side node and the second end-side node.
[0057] More specifically, the geographic location information of the first end-side node and the second end-side node is analyzed, and the geographic location correlation characteristics between the two nodes are obtained by calculating the geographic distance or using a geographic information system (GIS) tool. Based on the geographic location correlation characteristics, one or more intermediate node areas are pre-selected, and these areas are potential transit areas between the first end-side node and the second end-side node. A first selection weight is assigned to each intermediate node pre-selected area, and the weight can be based on factors such as geographic distance, network latency, and node availability.
[0058] More specifically, the actual intermediate nodes are searched in the pre-selected area, and detailed information of these nodes, such as network performance, load conditions, etc., is obtained, and a second selection weight is assigned to each pre-selected node. Based on the performance indicators of the nodes and the preset selection criteria, a weighted comprehensive analysis is performed on the first selection weight and the second selection weight of the pre-selected nodes. The weighted comprehensive analysis can be performed by weighted average, analytic hierarchy process (AHP), etc. According to the results of the comprehensive analysis, the optimal intermediate node is selected and confirmed to be used for the communication relay transmission function.
[0059] It can be understood that by reasonably selecting intermediate nodes, the optimal transmission path can be ensured, communication delays can be reduced, and data transmission efficiency can be improved. By comprehensively analyzing the performance and load of the nodes, reliable intermediate nodes can be selected to improve communication stability and reliability. Through pre-selection and weighted analysis, network resources can be reasonably allocated to avoid excessive concentration or waste of resources, thereby improving the resource utilization of the overall network.
[0060] Preferably, the step of respectively configuring working parameters for the first end-side node, the second end-side node, and the intermediate node corresponding to the communication end-side information so that the first end-side node, the second end-side node, and the intermediate node jointly construct a communication channel in a communication debugging mode includes:
[0061] S21: performing node pointing locking processing on the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node and the intermediate node establish a communication channel;
[0062] S22: performing synchronization calibration processing on the clock signal of the communication channel so that the first end-side node, the second end-side node and the intermediate node constituting the communication channel have a synchronized clock reference standard;
[0063] S23: performing node debugging task allocation processing on the first end-side node, the second end-side node, and the intermediate node respectively based on the clock reference standard, and obtaining node debugging tasks of the first end-side node, the second end-side node, and the intermediate node; wherein the node debugging task is used to control the first end-side node, the second end-side node, and the intermediate node to perform quantum key distribution and combination from both end-sides toward the intermediate node;
[0064] S24: performing calibration processing on a laser module, a polarization module, and a modulation module on the first end-side node and the second end-side node respectively according to the node debugging tasks of the first end-side node and the second end-side node, so that the first end-side node and the second end-side node are in a communication debugging mode;
[0065] S25: performing calibration processing of an interference module and a detection module on the intermediate node according to the node debugging task of the intermediate node, so that the intermediate node is in a communication debugging mode;
[0066] S26: The first end-side node, the second end-side node and the intermediate node in the communication debugging mode jointly construct a communication channel in the communication debugging mode.
[0067] Specifically, first obtain and confirm the communication end-side information of the first end-side node, the second end-side node and the intermediate node, and perform direction locking processing on the first end-side node, the second end-side node and the intermediate node, so that each node can accurately point to each other and establish a preliminary communication link.
[0068] More specifically, clock signals are transmitted between nodes, and preliminary synchronization calibration is performed to establish a unified clock reference. High-precision clock synchronization technology, such as GPS synchronization or optical fiber synchronization, is used to ensure that the clock signals of all nodes are synchronized with high precision.
[0069] More specifically, according to the clock reference standard, corresponding node debugging tasks are respectively assigned to the first end-side node, the second end-side node and the intermediate node, and the node debugging tasks include controlling the first end-side node and the second end-side node to distribute and combine quantum keys.
[0070] More specifically, the laser modules of the first end-side node and the second end-side node are calibrated to ensure that the wavelength, power and other parameters of the laser emission meet the requirements, the polarization module is calibrated so that the polarization state of the laser meets the requirements of quantum key distribution, and the modulation module is calibrated to ensure the accuracy and stability of the modulated signal.
[0071] More specifically, the interference module of the intermediate node is calibrated to ensure that the coherence and interference effect of the optical signal reach the optimal state, and the detection module is calibrated to ensure that the sensitivity and response speed of the detector meet the requirements.
[0072] More specifically, after completing the calibration and task allocation of the above-mentioned nodes, the first end-side node, the second end-side node and the intermediate node jointly build a communication channel, confirm that all nodes are in communication debugging mode, and start quantum key distribution and communication quality testing.
[0073] It can be understood that through pointing locking processing, the optical paths between nodes are ensured to be accurately aligned, signal loss and errors are reduced, clock signal synchronization calibration ensures the clock consistency of all nodes, and avoids communication errors and data packet loss due to clock asynchrony. The reasonable allocation of debugging tasks enables each node to efficiently perform its required functions, improving the overall system efficiency. The precise calibration of each module improves the reliability and security of quantum key distribution and ensures the stability and consistency of optical signals during communication.
[0074] Preferably, the steps of performing node debugging task allocation processing on the first end-side node, the second end-side node, and the intermediate node based on the clock reference standard, and obtaining the node debugging tasks of the first end-side node, the second end-side node, and the intermediate node include:
[0075] S231: performing commonality analysis of node performance on the first end-side node, the second end-side node, and the intermediate node to obtain a debugging execution standard for the communication channel;
[0076] S232: performing node debugging operation allocation processing on the first end-side node, the second end-side node, and the intermediate node respectively according to the debugging execution standard, and performing debugging operation time allocation processing on the first end-side node, the second end-side node, and the intermediate node according to the clock reference standard;
[0077] S233: Combine the node debugging operations and debugging operation times allocated to the first end-side node, the second end-side node, and the intermediate node to obtain node debugging tasks for the first end-side node, the second end-side node, and the intermediate node.
[0078] Specifically, basic performance data of the first end-side node, the second end-side node and the intermediate node are collected, including but not limited to signal strength, noise level, response time, etc., and commonality analysis is performed on the collected data to find out the commonalities and differences in performance of each node, especially the key performance indicators that affect communication quality.
[0079] More specifically, debugging execution standards for the communication channels are formulated based on the common analysis results. These standards include signal strength requirements, synchronization accuracy requirements, bit error rate standards, etc. Based on the debugging execution standards, specific debugging operations are assigned to the first end-side node, the second end-side node, and the intermediate node, respectively. The debugging operations include but are not limited to laser calibration, polarization adjustment, bit error rate testing, synchronization signal calibration, etc.
[0080] More specifically, according to the clock reference standard, the debugging operation time of each node is allocated to ensure that each node completes the assigned debugging task within the predetermined time window, thereby achieving overall synchronous debugging, and the debugging operation allocated to each node and the corresponding debugging time are combined to form a specific debugging task. Ensure that the debugging operation and time arrangement of each node meet the overall debugging execution standard, and generate specific node debugging tasks for the first end-side node, the second end-side node and the intermediate node according to the combination result, which include detailed operation steps and time arrangements.
[0081] It is understandable that by conducting common analysis of node performance and formulating debugging execution standards, it is ensured that the debugging operations of all nodes are consistent and standardized, thereby improving the accuracy and reliability of debugging. The debugging operation time is allocated according to the clock reference standard to ensure that the debugging tasks of each node are completed within a reasonable time frame, avoiding time conflicts and waste of resources, and improving debugging efficiency. By analyzing the performance of each node and allocating debugging operations, customized debugging can be performed according to the specific situation of each node, thereby improving the performance of the node and ensuring the overall stability of the communication channel.
[0082] Preferably, the step of causing the communication channel in the communication debugging mode to perform quantum key distribution and combination from both end sides toward the intermediate node to obtain the security key of the communication channel comprises:
[0083] S31: driving the laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance to generate photoelectric pulses to the intermediate node at a specified time, so as to obtain a first photoelectric pulse and a second photoelectric pulse in a quantum state;
[0084] S32: driving the polarization module and the modulation module in the first end-side node and the second end-side node that have completed the calibration work in advance to perform polarization processing and modulation processing on the first photoelectric pulse and the second photoelectric pulse respectively, so as to obtain a first debugging pulse and a second debugging pulse;
[0085] S33: receiving the first debugging pulse and the second debugging pulse by an interference module that has completed calibration in advance in the intermediate node, so that the first debugging pulse and the second debugging pulse perform pulse interference in the interference module;
[0086] S34: performing interference detection and event recording on the pulse interference in the interference module by using the detection module that has completed the calibration work in advance in the intermediate node to obtain an interference detection record;
[0087] S35: analyzing the information exchange coordination of the communication channel according to the interference detection record to obtain information exchange coordination features of the first end-side node, the second end-side node, and the intermediate node in the communication channel;
[0088] S36: Analyze the privacy security and transmission efficiency of the information exchange collaboration characteristics of the first end-side node, the second end-side node and the intermediate node in the communication channel, and analyze and process the compensation scheme of the information exchange collaboration characteristics based on the analysis results to obtain a security key for compensating the security of the communication channel.
[0089] Specifically, at a specified time, the laser modules in the first end-side node and the second end-side node that have completed calibration work in advance are driven to send photoelectric pulses to the intermediate node. The generated photoelectric pulses are respectively referred to as first photoelectric pulses and second photoelectric pulses.
[0090] More specifically, the pre-calibrated polarization module is driven to perform polarization processing on the first photoelectric pulse and the second photoelectric pulse to convert them into optical signals with a specific polarization state, and the modulation module is driven to perform modulation processing on the polarization-processed photoelectric pulse to embed quantum information and generate a first debugging pulse and a second debugging pulse.
[0091] More specifically, the first debugging pulse and the second debugging pulse are received by an interference module that has completed calibration work in advance in the intermediate node, so that they perform pulse interference in the interference module. During the interference process, the phase difference between the two pulses is used to form an interference pattern.
[0092] More specifically, the pulse interference in the interference module is interfered with by the detection module in the intermediate node, and the detection result is recorded as an interference detection record, which contains important quantum state information.
[0093] More specifically, based on the interference detection records, the coordination analysis of information exchange of the communication channel is performed, and the analysis results reveal the information exchange coordination characteristics of the first end-side node, the second end-side node and the intermediate node. The information exchange coordination characteristics are used to describe the exchange characteristics of the first end-side node and the second end-side node when exchanging information through the intermediate node, so as to provide feedback on the information exchange status between the first end-side node and the second end-side node.
[0094] More specifically, privacy and security analysis is conducted on the collaborative features of information exchange to ensure that quantum keys are not leaked during information transmission, and the transmission efficiency is evaluated to ensure that the communication channel can transmit data under the premise of high efficiency.
[0095] More specifically, based on the results of the privacy security and transmission efficiency analysis, a compensation plan is formulated to perform necessary compensation processing on the collaborative characteristics of information exchange. Based on the results of the compensation processing, a security key is generated for the final communication channel. This key ensures the overall security and data integrity of the communication channel.
[0096] It can be understood that through precise polarization and modulation processing, it is ensured that the photoelectric pulses in the quantum state can be accurately transmitted and interfered, thereby improving the accuracy and reliability of quantum key distribution. Through the analysis of the collaborative characteristics of information exchange, it is possible to optimize the information exchange between nodes, improve the coordination and synchronization of the communication channel, and conduct privacy and security analysis on the collaborative characteristics of information exchange to ensure that there is no information leakage during the quantum key distribution process, thereby ensuring the security of data transmission. Through transmission efficiency analysis, it is possible to identify and optimize bottlenecks in the communication channel, improve the overall transmission efficiency, and make the quantum key distribution process more efficient. The compensation plan formulated according to the analysis results can effectively deal with the uncertainty and potential threats in information exchange, thereby generating secure keys and ensuring the security of the communication channel.
[0097] Preferably, the step of driving the laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance to generate photoelectric pulses to the intermediate node at a specified time to obtain the first photoelectric pulse and the second photoelectric pulse in a quantum state includes:
[0098] S311: Photon entanglement and detection are performed through a high-speed quantum random number generator, and a random number sequence is obtained according to the detection results;
[0099] S312: performing debugging information conversion processing on the random number sequence to obtain original data of the photoelectric pulse signal converted from the random number sequence;
[0100] S313: Instruct the laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance to perform timing setting processing of laser generation parameters on the original data of the photoelectric pulse signal, so that the laser modules can perform the photoelectric pulse generation operation at the specified time to obtain the first photoelectric pulse and the second photoelectric pulse in the quantum state.
[0101] Specifically, photon entanglement is generated and detected through a high-speed quantum random number generator (QRNG), and a series of random number sequences are generated based on the detection results. The random number sequences obtained above are converted and processed to generate the original data of the photoelectric pulse signal.
[0102] More specifically, using a laser module that has been calibrated in advance, the raw data of the photoelectric pulse signal is converted into parameters for laser generation, including timing settings, which will be used to generate precise photoelectric pulses at a specified time.
[0103] More specifically, at a specified time, the laser module is driven to send a photoelectric pulse to the intermediate node to generate a first photoelectric pulse and a second photoelectric pulse in a quantum state.
[0104] It can be understood that the random numbers generated by the quantum random number generator are highly random and unpredictable, which improves the security of the system. Through the calibrated laser module and precise timing setting, it ensures that the photoelectric pulses are accurately emitted at the specified time, which improves the reliability and synchronization of the system. Through the generation and detection of photon entanglement, the system can realize the transmission and measurement of quantum states, which is suitable for quantum communication applications such as quantum key distribution.
[0105] Preferably, the step of performing a deployment operation of a ciphertext protocol on the first end-side node and the second end-side node according to the security key so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node perform subsequent communication processing through the communication channel in the communication execution mode includes:
[0106] S41: Distribute the security key to the first end-side node and the second end-side node, and instruct the first end-side node and the second end-side node to analyze and process the security key according to a preset symmetric encryption algorithm, obtain the execution steps performed by the first end-side node and the second end-side node when using the security key to encrypt data, and deploy corresponding programs on the first end-side node and the second end-side node according to the execution steps, so that the communication channel switches from the communication debugging mode to the communication execution mode.
[0107] Specifically, the generated security key is securely transmitted and distributed to the first end-side node and the second end-side node. Both end nodes hold the same security key to ensure that they can perform encryption and decryption operations. On both end nodes, a preset symmetric encryption algorithm (such as AES, DES, etc.) is used to analyze and process the security key to determine the specific execution steps and processing flow required for data encryption using the security key.
[0108] More specifically, according to the execution steps obtained from the above analysis, the corresponding encryption and decryption programs are deployed on the first end-side node and the second end-side node respectively, and the two end nodes are configured with programs to execute these encryption algorithms, ready for encrypted communication, and the communication channel is switched from debug mode to execution mode. The communication channel enters the execution mode, and the system is ready for formal and secure data transmission.
[0109] It can be understood that the distributed security keys and deployed symmetric encryption algorithms ensure the security of the communication channel, prevent unauthorized access and data leakage, and deploy the same encryption and decryption programs on both end nodes to ensure that the data can be correctly encrypted and decrypted during the communication process, ensuring the consistency and integrity of the data. The data encryption measures of the symmetric encryption algorithm ensure the privacy protection of the transmitted data and prevent sensitive information from being stolen or tampered with.
[0110] Reference Figure 2 As shown, in a second aspect, the present invention provides a terminal-side deployment system for quantum key distribution and ICT fusion, which is used to implement a terminal-side deployment method for quantum key distribution and ICT fusion as described in any one of the first aspects, including:
[0111] A node positioning module, used to obtain communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function;
[0112] A channel construction module, used to configure working parameters of the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node and the intermediate node jointly construct a communication channel in a communication debugging mode;
[0113] A key generation module, used to enable the communication channel in the communication debugging mode to distribute and combine quantum keys from both ends to the intermediate node to obtain a security key for the communication channel;
[0114] A key deployment module is used to perform a ciphertext protocol deployment operation on the first end-side node and the second end-side node according to the security key, so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
[0115] In this embodiment, for the specific implementation of each module in the above system embodiment, please refer to the above method embodiment, which will not be repeated here.
[0116] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A terminal-side deployment method for integrating quantum key distribution and ICT, characterized in that: include: Acquire communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function; Performing working parameter configuration on the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information respectively, so that the first end-side node, the second end-side node and the intermediate node jointly construct a communication channel in a communication debugging mode; The communication channel in the communication debugging mode is required to perform quantum key distribution and combination from both end sides toward the intermediate node to obtain the security key of the communication channel; The first end-side node and the second end-side node are deployed with a ciphertext protocol according to the security key, so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
2. The terminal-side deployment method for quantum key distribution and ICT integration according to claim 1, characterized in that: The steps of obtaining communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and performing positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function include: Acquire communication terminal side information, and perform request initiator and request receiver parsing processing on the communication terminal side information to obtain terminal side information of initiating communication request and receiving communication request; The parsed end-side information of the initiating communication request and the receiving communication request is summarized in a preset format to obtain a first end-side node corresponding to the end initiating the communication request and a second end-side node corresponding to the end receiving the communication request; Performing correlation analysis on node geographic information of the first end-side node and the second end-side node to obtain node position correlation features of the first end-side node and the second end-side node; Preselecting the intermediate nodes between the first end-side node and the second end-side node according to the node position association feature to obtain a distribution of intermediate node preselected areas between the first end-side node and the second end-side node; wherein the distribution of intermediate node preselected areas includes a plurality of intermediate node preselected areas and a first selection weight corresponding to each of the intermediate node preselected areas; Searching and processing the intermediate nodes according to the distribution of the intermediate node pre-selected areas to obtain the pre-selected nodes in each of the node pre-selected areas and the second selection weights corresponding to each of the pre-selected nodes; A weighted comprehensive analysis is performed on the first selection weight of the intermediate node pre-selected area where each of the pre-selected nodes is located and the second selection weight of each of the pre-selected nodes, and the intermediate node is confirmed from each of the pre-selected nodes according to the result of the weighted comprehensive analysis.
3. The terminal-side deployment method for quantum key distribution and ICT integration according to claim 1, characterized in that: The step of respectively configuring working parameters for the first end-side node, the second end-side node, and the intermediate node corresponding to the communication end-side information so that the first end-side node, the second end-side node, and the intermediate node jointly construct a communication channel in a communication debugging mode includes: Performing node pointing locking processing on the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node and the intermediate node establish a communication channel; Performing synchronization calibration processing on the communication channel for the clock signal so that the first end-side node, the second end-side node and the intermediate node constituting the communication channel have a synchronized clock reference standard; Based on the clock reference standard, node debugging tasks are respectively allocated to the first end-side node, the second end-side node, and the intermediate node to obtain node debugging tasks of the first end-side node, the second end-side node, and the intermediate node; wherein the node debugging task is used to control the first end-side node, the second end-side node, and the intermediate node to perform quantum key distribution and combination from both end-side nodes toward the intermediate node; According to the node debugging tasks of the first end-side node and the second end-side node, calibration processing of a laser module, a polarization module, and a modulation module is performed on the first end-side node and the second end-side node respectively, so that the first end-side node and the second end-side node are in a communication debugging mode; Performing calibration processing of an interference module and a detection module on the intermediate node according to a node debugging task of the intermediate node, so that the intermediate node is in a communication debugging mode; The first end-side node, the second end-side node and the intermediate node in the communication debugging mode jointly construct a communication channel in the communication debugging mode.
4. The terminal-side deployment method for quantum key distribution and ICT integration as claimed in claim 3 is characterized in that: The steps of performing node debugging task allocation processing on the first end-side node, the second end-side node, and the intermediate node based on the clock reference standard to obtain the node debugging tasks of the first end-side node, the second end-side node, and the intermediate node include: Performing a commonality analysis of node performance on the first end-side node, the second end-side node, and the intermediate node to obtain a debugging execution standard for the communication channel in the communication debugging mode; performing node debugging operation allocation processing on the first end-side node, the second end-side node, and the intermediate node respectively according to the debugging execution standard, and performing debugging operation time allocation processing on the first end-side node, the second end-side node, and the intermediate node according to the clock reference standard; The node debugging operations and debugging operation times allocated to the first end-side node, the second end-side node, and the intermediate node are combined to obtain node debugging tasks of the first end-side node, the second end-side node, and the intermediate node.
5. The terminal-side deployment method for quantum key distribution and ICT integration according to claim 1, characterized in that: The step of causing a communication channel in a communication debugging mode to perform quantum key distribution and combination from both end sides toward an intermediate node to obtain a security key of the communication channel includes: Driving the laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance to generate photoelectric pulses to the intermediate node at a specified time, so as to obtain a first photoelectric pulse and a second photoelectric pulse in a quantum state; Driving the polarization module and the modulation module in the first end-side node and the second end-side node that have completed the calibration work in advance to perform polarization processing and modulation processing on the first photoelectric pulse and the second photoelectric pulse respectively, so as to obtain a first debugging pulse and a second debugging pulse; Receiving the first debugging pulse and the second debugging pulse by an interference module that has completed calibration work in advance in the intermediate node, so that the first debugging pulse and the second debugging pulse perform pulse interference in the interference module; Perform interference detection and event recording on the pulse interference in the interference module by using a detection module that has completed calibration in advance in the intermediate node to obtain an interference detection record; Analyzing the information exchange coordination of the communication channel according to the interference detection record to obtain information exchange coordination features of the first end-side node, the second end-side node, and the intermediate node in the communication channel; The privacy security and transmission efficiency of the information exchange collaboration characteristics of the first end-side node, the second end-side node and the intermediate node in the communication channel are analyzed, and the compensation scheme of the information exchange collaboration characteristics is analyzed and processed according to the analysis results to obtain a security key for security compensation of the communication channel.
6. The terminal-side deployment method for quantum key distribution and ICT integration as claimed in claim 5, characterized in that: The step of driving the laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance to generate photoelectric pulses to the intermediate node at a specified time to obtain the first photoelectric pulse and the second photoelectric pulse in a quantum state includes: Photon entanglement and detection are performed through a high-speed quantum random number generator, and a random number sequence is obtained based on the detection results; Performing conversion processing of debugging information on the random number sequence to obtain original data of the photoelectric pulse signal converted from the random number sequence; The laser modules in the first end-side node and the second end-side node that have completed the calibration work in advance are required to perform timing setting processing of the laser generation parameters on the original data of the photoelectric pulse signal, so that the laser modules can perform the photoelectric pulse generation operation at the specified moment to obtain the first photoelectric pulse and the second photoelectric pulse in the quantum state.
7. The terminal-side deployment method for quantum key distribution and ICT integration according to claim 1, characterized in that: The step of performing a deployment operation of a ciphertext protocol on the first end-side node and the second end-side node according to the security key so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node perform subsequent communication processing through the communication channel in the communication execution mode includes: The security key is distributed to the first end-side node and the second end-side node, and the first end-side node and the second end-side node are ordered to analyze and process the security key according to a preset symmetric encryption algorithm for data encryption measures, and the execution steps performed by the first end-side node and the second end-side node when using the security key for data encryption are obtained, and corresponding programs are deployed on the first end-side node and the second end-side node according to the execution steps, so that the communication channel is switched from a communication debugging mode to a communication execution mode.
8. A terminal deployment system integrating quantum key distribution and ICT, characterized in that: A terminal-side deployment method for implementing a quantum key distribution and ICT integration method as described in any one of claims 1 to 7, comprising: A node positioning module, used to obtain communication end-side information describing a first end-side node and a second end-side node participating in quantum communication, and perform positioning analysis on an intermediate node of quantum communication according to the communication end-side information to obtain an intermediate node for performing a communication relay transmission function; A channel construction module, used to configure working parameters of the first end-side node, the second end-side node and the intermediate node corresponding to the communication end-side information, so that the first end-side node, the second end-side node and the intermediate node jointly construct a communication channel in a communication debugging mode; A key generation module, used to enable the communication channel in the communication debugging mode to distribute and combine quantum keys from both ends to the intermediate node to obtain a security key for the communication channel; A key deployment module is used to perform a ciphertext protocol deployment operation on the first end-side node and the second end-side node according to the security key, so that the communication channel is switched from a communication debugging mode to a communication execution mode, so that the first end-side node and the second end-side node can perform subsequent communication processing through the communication channel in the communication execution mode.
Citation Information
Patent Citations
Quantum encryption communication method based on multi-party security computing
CN114257314A
Short message channel test configuration method and device, equipment and storage medium
CN119136229A