A centralized quantum key relay network and a key storage method thereof
Through the coordinated operation of relay nodes and controllers, effective key management in the centralized quantum key relay network is achieved, the problems of key fragmentation and uneven consumption are solved, and the accuracy and effectiveness of the key system are ensured.
Patent Information
- Application Number
- CN202411954998.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-27
AI Technical Summary
In centralized quantum key relay networks, key management is difficult, and XOR key fragmentation and uneven consumption make them ineffective.
The relay node performs pairwise XOR on related quantum keys with the same generation time to generate an XOR key and transmit the characteristic information to the controller. After the shared key is issued, the controller notifies the relay node to delete the used part. The relay node deletes the corresponding key based on the characteristic information.
It avoids repeated use and confusion of keys and ensures the accuracy and effectiveness of the key system.
Smart Images

Figure CN119766442B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum communication, and in particular to a centralized quantum key relay network and a key storage method thereof. Background Art
[0002] Quantum cryptography, based on the quantum key distribution (QKD) protocol, has experienced rapid development in recent years. Unlike traditional cryptography, quantum cryptography is based on quantum mechanics and exploits quantum physical properties such as Heisenberg's uncertainty principle and the no-cloning theorem to enable secure negotiation of symmetric keys over long distances.
[0003] Multiple quantum key distribution nodes can form a quantum key distribution network (QKDN). Due to the limited distance between adjacent nodes, quantum key relay distribution is required in long-distance key generation scenarios, which is why centralized quantum key relay networks have emerged.
[0004] In a centralized quantum key relay network, the QKDN controller manages the XOR keys reported by all relay nodes. As the network operates and is used, the number of XOR keys stored in the QKDN controller inevitably increases, making it difficult to manage. Furthermore, a large number of random key requests can lead to uneven key consumption, and XOR keys uploaded on certain links can become fragmented and unusable. Therefore, how to implement key management in a centralized quantum key relay network has become a difficult problem for those skilled in the art. Summary of the Invention
[0005] The object of the present invention is to provide a centralized quantum key relay network and a key storage method thereof to improve the above-mentioned problems.
[0006] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0007] In a first aspect, an embodiment of the present invention provides a centralized quantum key relay network, comprising: a controller and multiple quantum key distribution nodes, wherein the multiple quantum key distribution nodes include at least one relay node, and the relay node is a quantum key distribution node connected to at least two quantum links;
[0008] The relay node is used to perform pairwise XOR on related quantum keys with the same generation time to obtain an XOR key, and transmit the first characteristic information of the XOR key to the controller;
[0009] The relevant quantum key is a quantum key generated by a quantum link connected to the relay node, and the first characteristic information of the XOR key includes the XOR key, an identifier of the relay node, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key;
[0010] The relay node is used to store characteristic information of a related quantum key corresponding to the XOR key, where the characteristic information of the related quantum key includes the related quantum key, a peer node identifier corresponding to the related quantum key, and a generation time of the related quantum key;
[0011] The controller is used to send a key usage notification to the relay node on the relay path after completing the issuance of the shared key, and delete the used part of the XOR key used in the process of issuing the shared key;
[0012] The key usage notification includes the second characteristic information of the XOR key used in the process of issuing the shared key, and the second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key;
[0013] The relay node is configured to delete the used portion of the corresponding quantum key according to the second characteristic information of the XOR key after receiving the key use notification.
[0014] In a second aspect, an embodiment of the present invention provides a key storage method for a centralized quantum key relay network, wherein the centralized quantum key relay network includes: a controller and multiple quantum key distribution nodes, wherein the multiple quantum key distribution nodes include at least one relay node, and the relay node is a quantum key distribution node connected to at least two quantum links. The method includes:
[0015] The relay node performs pairwise XOR on related quantum keys with the same generation time to obtain an XOR key, and transmits first characteristic information of the XOR key to the controller;
[0016] The relevant quantum key is a quantum key generated by a quantum link connected to the relay node, and the first characteristic information of the XOR key includes the XOR key, an identifier of the relay node, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key;
[0017] The relay node stores characteristic information of a related quantum key corresponding to the XOR key, where the characteristic information of the related quantum key includes the related quantum key, a peer node identifier corresponding to the related quantum key, and a generation time of the related quantum key;
[0018] After completing the issuance of the shared key, the controller sends a key usage notification to the relay node on the relay path, deleting the used portion of the XOR key used in the process of issuing the shared key;
[0019] The key usage notification includes the second characteristic information of the XOR key used in the process of issuing the shared key, and the second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key;
[0020] After receiving the key use notification, the relay node deletes the used part of the corresponding quantum key according to the second characteristic information of the XOR key.
[0021] Compared to the prior art, the embodiments of the present invention provide a centralized quantum key relay network and key storage method thereof. Relay nodes perform pairwise XOR on related quantum keys generated at the same time to obtain an XOR key, and transmit the first characteristic information of the XOR key to a controller. The relay nodes store the characteristic information of the related quantum key corresponding to the XOR key. After completing the distribution of the shared key, the controller sends a key use notification to the relay nodes on the relay path, deleting the used portion of the XOR key used in the process of distributing the shared key. After receiving the key use notification, the relay node deletes the used portion of the corresponding quantum key based on the second characteristic information of the XOR key. The controller deletes the used portion of the XOR key used in the process of distributing the shared key, and the relay node deletes the used portion of the corresponding quantum key based on the second characteristic information of the XOR key, thereby avoiding confusion caused by repeated key use and ensuring the accuracy and effectiveness of the key system.
[0022] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 A schematic diagram of the architecture of a centralized quantum key relay network provided by an embodiment of the present invention.
[0025] Figure 2 One of the flow charts of the key storage method for a centralized quantum key relay network provided in an embodiment of the present invention.
[0026] Figure 3 The second flowchart of the key storage method for a centralized quantum key relay network provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0028] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.
[0029] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are used only to distinguish the description and should not be understood as indicating or implying relative importance.
[0030] It should be noted that, in the present document, relational terms such as first and second and the like can be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0031] In the description of the application, it should be noted that the terms "upper", "lower", "inner", "outer", and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of the application is usually placed, only for the convenience of describing the application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the application.
[0032] In the description of the application, it should also be noted that, unless otherwise specified and limited, the terms "provided", "connected" should be understood broadly, for example, can be fixedly connected, can be detachably connected, or integrally connected; can be mechanically connected, can be electrically connected; can be directly connected, can be indirectly connected through an intermediate medium, and can be connected inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0033] Some embodiments of the application will be described in detail below with reference to the accompanying drawings. The following examples and features in the examples can be combined with each other without conflict.
[0034] Reference is made to Figure 1 , Figure 1 The centralized quantum key relay network provided by the embodiments of the application is shown in the schematic diagram of the architecture. The centralized quantum key relay network comprises a controller (also referred to as QKDNC) and a plurality of quantum key distribution nodes.
[0035] In the quantum key distribution node, a QKD device for quantum key distribution and a KM device for managing the key of the QKD device are arranged. All the quantum key distribution nodes are in communication connection with the controller to form a full-network connection topology. The controller is used for controlling and managing the centralized quantum key relay network to realize the routing control and resource scheduling of the nodes and links. The controller keeps time synchronization with each quantum key distribution node.
[0036] It should be noted that, Figure 1 Eight quantum key distribution nodes are shown in the figure, but this is not a limitation. The number of quantum key distribution nodes can be greater than or less than eight. All the quantum key distribution nodes are in communication connection with the controller, Figure 1 In the figure, some connections are omitted to make the display content clearer.
[0037] The plurality of quantum key distribution nodes includes at least one relay node, and the relay node is a quantum key distribution node connected to at least two quantum links.
[0038] Please refer to Figure 1 The quantum key distribution node 2, the quantum key distribution node 3, the quantum key distribution node 4, the quantum key distribution node 6, and the quantum key distribution node 7 in the figure are all relay nodes. Taking the quantum key distribution node 2 as an example, the quantum links connected by the quantum key distribution node 2 include the link between the quantum key distribution node 1 and the quantum key distribution node 2, the link between the quantum key distribution node 2 and the quantum key distribution node 3, and the link between the quantum key distribution node 2 and the quantum key distribution node 6.
[0039] It should be noted that the plurality of quantum key distribution nodes also includes a user node, which is a quantum key distribution node connected to a business system. The user node can receive the communication demand transmitted by the business system and issue the key to the business system.
[0040] Figure 1 Ki (K1-K8) in the figure represents the quantum key generated by the i-th quantum link at a certain time. The architecture of the centralized quantum key relay network in the embodiment of the application is introduced above. How to realize key storage in the centralized quantum key relay network is further described below. Please refer to the following.
[0041] The relay node is used for performing XOR operation on the related quantum keys generated at the same time to obtain an XOR key, and transmitting the first feature information of the XOR key to the controller.
[0042] The relevant quantum key is a quantum key generated by a quantum link connected to a relay node. The first characteristic information of the XOR key includes the XOR key, an identifier of the relay node, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key. The controller is configured to store the XOR key in combination with the first characteristic information of the XOR key.
[0043] It should be noted that once a quantum link is formed, it will continuously generate quantum keys. Figure 1 Taking the relay node (quantum key distribution node 2) shown in the figure as an example, at a certain moment, the relevant quantum keys corresponding to quantum key distribution node 2 are quantum keys K1, quantum key K2, and quantum key K3. After pairwise XOR, the resulting XOR keys include K1⊕K2, K1⊕K3, and K2⊕K3. The generation time of the XOR keys is the same as the generation time of the relevant quantum keys. The identifier of the quantum key distribution node can be, but is not limited to, the node ID.
[0044] The relay nodes corresponding to the XOR keys K1⊕K2, K1⊕K3, and K2⊕K3 are all quantum key distribution nodes 2. The generation times corresponding to the XOR keys K1⊕K2, K1⊕K3, and K2⊕K3 are the generation times of quantum keys K1, K2, and K3, respectively. The nodes on the quantum link associated with the XOR key K1⊕K2 are quantum key distribution nodes 1 and 6, the nodes on the quantum link associated with the XOR key K1⊕K3 are quantum key distribution nodes 1 and 3, and the nodes on the quantum link associated with the XOR key K2⊕K3 are quantum key distribution nodes 6 and 3.
[0045] The relay node is used to store characteristic information of the relevant quantum key corresponding to the XOR key, where the characteristic information of the relevant quantum key includes the relevant quantum key, the peer node identifier corresponding to the relevant quantum key, and the generation time of the relevant quantum key.
[0046] Continue with Figure 1 Taking the relay node (quantum key distribution node 2) shown as an example, the quantum keys corresponding to quantum key distribution node 2 are quantum key K1, quantum key K2, and quantum key K3. The peer node corresponding to quantum key K1 is quantum key distribution node 1, the peer node corresponding to quantum key K2 is quantum key distribution node 6, and the peer node corresponding to quantum key K3 is quantum key distribution node 3.
[0047] It should be noted that when a relay node connects to a business system as a user node and needs to issue a shared key, it may need to use the quantum key it stores, so it needs to be stored.
[0048] The controller is used to send a key usage notification to the relay node on the relay path after completing the shared key distribution, and delete the used part of the XOR key used in the process of sharing the key distribution.
[0049] The key usage notification includes the second characteristic information of the XOR key used during the shared key delivery process. The second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link associated with the XOR key, the generation time of the XOR key, and the usage length of the XOR key. The relay path is the path formed by the relay nodes corresponding to the XOR key used during the shared key delivery process.
[0050] The relay node is used to delete the used part of the corresponding quantum key according to the second characteristic information of the XOR key after receiving the notification that the key has been used.
[0051] In the centralized quantum key relay network provided by an embodiment of the present invention, the controller deletes the used part of the XOR key used in the process of issuing the shared key, and the relay node deletes the used part of the corresponding quantum key based on the second characteristic information of the XOR key, thereby avoiding confusion caused by repeated use of the key and ensuring the accuracy and effectiveness of the key system.
[0052] Based on the foregoing, regarding how the relay node deletes the used portion of the corresponding quantum key, the embodiment of the present invention also provides an optional implementation method, please refer to the following.
[0053] The relay node is used to determine the quantum key to be adjusted according to the identifier of the relay node corresponding to the XOR key in the second characteristic information of the XOR key, the identifier of the node on the quantum link related to the XOR key, and the generation time of the XOR key after receiving the notification that the key has been used.
[0054] The relay node is used to delete the content related to the used part of the XOR key in the quantum key to be adjusted according to the usage length of the XOR key in the second characteristic information of the XOR key.
[0055] In some optional scenarios, the key may not be sent through the controller. In this scenario, the embodiment of the present invention also provides an optional implementation method, please refer to the following.
[0056] When two adjacent quantum key distribution nodes distribute the quantum key corresponding to the quantum link between them to the corresponding business system, if there is a relay node between the two adjacent quantum key distribution nodes.
[0057] Please continue to refer to Figure 1Assume that quantum key distribution node 2 is also connected to a business system. When the business system connected to quantum key distribution node 1 and the business system connected to quantum key distribution node 2 need to communicate, quantum key distribution node 1 directly sends a portion of the quantum key K1 generated at a certain moment to the corresponding business system, and quantum key distribution node 2 directly sends the same portion of the quantum key K1 generated at the same moment to the corresponding business system, allowing the two business systems to interact based on the quantum key. This process does not go through the controller.
[0058] The relay node is used to report the key usage status to the controller. The key usage status includes the relay node identifier, the peer node identifier corresponding to the quantum key, the generation time of the quantum key, and the usage length of the quantum key.
[0059] The controller is used to determine the XOR key to be adjusted according to the identifier of the relay node, the identifier of the opposite node corresponding to the quantum key, and the generation time of the quantum key after receiving the key usage status.
[0060] It should be noted that there may be multiple XOR keys to be adjusted, such as XOR key K1⊕K2 and XOR key K1⊕K3.
[0061] The controller is used to delete the content related to the used part of the quantum key in the XOR key to be adjusted according to the usage length of the quantum key.
[0062] The relay node is also used to delete the used part of the quantum key.
[0063] Based on the foregoing, regarding the process of issuing a remote shared key via a controller, the embodiment of the present invention further provides an optional implementation method, which is described below.
[0064] The demand initiating node sends a key distribution request to the controller, where the key distribution request includes an identifier of the demand destination node.
[0065] In an optional embodiment, the key distribution request also includes an exclusive OR key of a quantum key and a quantum random number between the demand initiating node and the next node in the relay path, wherein the quantum random number is generated by the demand initiating node and is the same as the number of the demand key.
[0066] The controller determines the relay path based on the identifiers of the demand-initiating node and the demand-destination node, performs layer-by-layer XOR operations based on the XOR keys between adjacent quantum links on the relay path to obtain the target XOR key, and sends the target XOR key to the demand-destination node. The demand-destination node is used to perform XOR processing based on the target XOR key and the quantum key of the last quantum link in the relay path to obtain the shared key and complete the distribution of the shared key.
[0067] Optionally, the controller also sends the second characteristic information of the last XOR object in the target XOR key calculation process to the required destination node.
[0068] Among them, adjacent quantum links are two quantum links that share a relay node, the target XOR key is the XOR key between the shared key and the quantum key of the last quantum link in the relay path, and the last quantum link in the relay path is the quantum link between the required destination node and the last relay node in the relay path.
[0069] Please continue to refer to Figure 1 For example, the request initiating node is quantum key distribution node 1, and the request destination node is quantum key distribution node 5. The corresponding relay paths are path 1 and path 2. Path 1 is: quantum key distribution node 1 - quantum key distribution node 2 - quantum key distribution node 3 - quantum key distribution node 4 - quantum key distribution node 5; path 2 is: quantum key distribution node 1 - quantum key distribution node 2 - quantum key distribution node 6 - quantum key distribution node 7 - quantum key distribution node 4 - quantum key distribution node 5.
[0070] When the key distribution request also includes the XOR key of the quantum key between the initiating node and the next node in the relay path and the quantum random number, the controller can perform layer-by-layer XOR operations on the key distribution request with the XOR keys between adjacent quantum links on the relay path to obtain the target XOR key. Taking path 1 as an example, assuming the quantum random number is Kx, the key distribution request includes the XOR key Kx⊕K1. The XOR keys between adjacent quantum links on the relay path include: XOR keys K1⊕K3, K3⊕K5, and K5⊕K8. After layer-by-layer XOR operations, the target XOR key Kx⊕K8 is obtained. Among them, XOR key K5⊕K8 is the last XOR object in the target XOR key calculation process.
[0071] The second characteristic information of the last XOR key K5⊕K8 in the target XOR key calculation process (the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key) is sent to the desired destination node. The desired destination node can determine the corresponding quantum key K8 and perform XOR on it to obtain the quantum random number Kx as the shared key.
[0072] If the demand-initiating node doesn't generate a quantum random number, the controller can perform layer-by-layer XOR operations based on the XOR keys between adjacent quantum links along the relay path to obtain the target XOR key. Continuing with path 1 as an example, in this case, the target XOR key K1⊕K8 is obtained, and the final shared key is the quantum key K1.
[0073] It should be noted that the demand initiating node and the demand destination node will send the corresponding shared key to the corresponding business system to achieve encryption.
[0074] Based on the foregoing, in order to avoid key timeout and prevent a large number of keys from being stored in relay nodes for too long, the embodiment of the present invention also provides an optional implementation method, please refer to the following.
[0075] The relay node is further used to check whether the time difference between the generation time of the quantum key stored therein and the current time exceeds the first validity period.
[0076] If the first validity period is exceeded, the relay node is used to delete the expired quantum key and report a key expiration notification to the controller, where the key expiration notification includes an identifier of the relay node, an identifier of the peer node corresponding to the expired quantum key, and a generation time of the expired quantum key;
[0077] The controller is used to mark the XOR key corresponding to the expired quantum key as a non-distributed state after receiving a key expiration notification. The non-distributed state indicates that the corresponding XOR key is only used for calculations in the shared key distribution and cannot be used as the last XOR object in the target XOR key calculation process.
[0078] In an optional implementation, the controller is configured to check whether a time difference between the generation time of the stored XOR key and the current time exceeds a second validity period.
[0079] If the second validity period is exceeded, the controller is used to delete the expired XOR key.
[0080] The second validity period is greater than or equal to the first validity period.
[0081] In an optional embodiment, the relay node is further configured to, when the total data volume of the quantum keys stored therein exceeds a second threshold, clear some quantum keys in order of generation time of the quantum keys so that the total data volume of the quantum keys stored therein is less than the first threshold.
[0082] The second threshold is greater than or equal to the first threshold. The second threshold can address the capacity of the key storage space set in the relay node. Clearing some quantum keys can be performed by overwriting. The quantum keys are cleared sequentially, sorted by generation time, from the earliest to the latest.
[0083] Optionally, the relay node is further configured to upload a key clearing notification to the controller when clearing part of the quantum key, the key clearing notification including the identifier of the relay node, the identifier of the peer node corresponding to the cleared quantum key, and the generation time of the cleared quantum key.
[0084] After receiving the key clear notification, the controller marks the XOR key corresponding to the cleared quantum key as a non-distributed state. The non-distributed state indicates that the corresponding XOR key is only used for calculations in the shared key distribution and cannot be used as the last XOR object in the target XOR key calculation process.
[0085] In the centralized quantum key relay network provided by the present invention, XOR keys and quantum keys stored in the controller and relay nodes are managed and promptly cleared after consumption or timeout to prevent repeated use. Furthermore, taking into account the different keys and usage patterns of the controller and relay nodes, the network ensures that keys are fully utilized as much as possible during key synchronization between the controller and relay nodes, avoiding key waste. This provides guidance for key storage in quantum networks with centralized control and key relay architectures.
[0086] The embodiment of the present invention also provides a key storage method for a centralized quantum key relay network, which is applied to the above-mentioned centralized quantum key relay network. Figure 2 , Figure 2 This is a flow chart of a key storage method for a centralized quantum key relay network provided by an embodiment of the present invention. The key storage method for a centralized quantum key relay network includes steps S11, S12, S13, and S14, which are described in detail below.
[0087] S11, the relay node performs XOR on two related quantum keys with the same generation time to obtain an XOR key, and transmits the first characteristic information of the XOR key to the controller.
[0088] Among them, the relevant quantum key is the quantum key generated by the quantum link connected to the relay node, and the first characteristic information of the XOR key includes the XOR key, the identifier of the relay node, the identifier of the node on the quantum link related to the XOR key, and the generation time of the XOR key.
[0089] S12, the relay node stores the characteristic information of the relevant quantum key corresponding to the XOR key.
[0090] The characteristic information of the relevant quantum key includes the relevant quantum key, the peer node identifier corresponding to the relevant quantum key, and the generation time of the relevant quantum key.
[0091] S13, after completing the issuance of the shared key, the controller sends a key used notification to the relay node on the relay path, and deletes the used part of the XOR key used in the process of issuing the shared key.
[0092] Among them, the key use notification includes the second characteristic information of the XOR key used in the process of issuing the shared key. The second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key.
[0093] S14, after receiving the key use notification, the relay node deletes the used part of the corresponding quantum key according to the second characteristic information of the XOR key.
[0094] Please refer to Figure 3 , Figure 3 This is a second flow diagram of a key storage method for a centralized quantum key relay network provided by an embodiment of the present invention. When two adjacent quantum key distribution nodes distribute the quantum key corresponding to the quantum link between them to corresponding service systems, if a relay node exists between the two adjacent quantum key distribution nodes, the key storage method for the centralized quantum key relay network further includes: S21, S22, S23, and S24, as described in detail below.
[0095] S21, the relay node reports the key usage to the controller.
[0096] Among them, the key usage includes the identifier of the relay node, the identifier of the peer node corresponding to the quantum key, the generation time of the quantum key, and the usage length of the quantum key.
[0097] S22, after receiving the key usage information, the controller determines the XOR key to be adjusted according to the identifier of the relay node, the identifier of the opposite node corresponding to the quantum key, and the generation time of the quantum key.
[0098] S23, the controller deletes the content related to the used part of the quantum key in the XOR key to be adjusted according to the usage length of the quantum key.
[0099] S24, the relay node deletes the used part of the quantum key.
[0100] It should be noted that the key storage method for a centralized quantum key relay network provided in this embodiment can perform the functions and uses described in the aforementioned centralized quantum key relay network embodiment to achieve the corresponding technical effects. For the sake of brevity, any details not mentioned in this embodiment can be referred to the corresponding content in the aforementioned embodiment.
[0101] In summary, the embodiments of the present invention provide a centralized quantum key relay network and key storage method thereof. Relay nodes perform pairwise XOR on related quantum keys generated at the same time to obtain an XOR key, and transmit the first characteristic information of the XOR key to a controller. The relay nodes store the characteristic information of the related quantum key corresponding to the XOR key. After completing the issuance of the shared key, the controller sends a key use notification to the relay nodes on the relay path, deleting the used portion of the XOR key used in the process of issuing the shared key. After receiving the key use notification, the relay node deletes the used portion of the corresponding quantum key based on the second characteristic information of the XOR key. The controller deletes the used portion of the XOR key used in the process of issuing the shared key, and the relay node deletes the used portion of the corresponding quantum key based on the second characteristic information of the XOR key, thereby avoiding confusion caused by repeated key use and ensuring the accuracy and effectiveness of the key system.
[0102] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
[0103] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.
Claims
1. A centralized quantum key relay network, characterized in that: The centralized quantum key relay network includes: a controller and multiple quantum key distribution nodes, wherein the multiple quantum key distribution nodes include at least one relay node, and the relay node is a quantum key distribution node connected to at least two quantum links; The relay node is used to perform pairwise XOR on related quantum keys with the same generation time to obtain an XOR key, and transmit the first characteristic information of the XOR key to the controller; The relevant quantum key is a quantum key generated by a quantum link connected to the relay node, and the first characteristic information of the XOR key includes the XOR key, an identifier of the relay node, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key; The relay node is used to store characteristic information of a related quantum key corresponding to the XOR key, where the characteristic information of the related quantum key includes the related quantum key, a peer node identifier corresponding to the related quantum key, and a generation time of the related quantum key; The controller is used to send a key usage notification to the relay node on the relay path after completing the issuance of the shared key, and delete the used part of the XOR key used in the process of issuing the shared key; The key usage notification includes the second characteristic information of the XOR key used in the process of issuing the shared key, and the second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key; The relay node is configured to delete the used portion of the corresponding quantum key according to the second characteristic information of the XOR key after receiving the key use notification.
2. The centralized quantum key relay network according to claim 1, wherein: The relay node is configured to, after receiving the key use notification, determine the quantum key to be adjusted based on an identifier of the relay node corresponding to the XOR key in the second characteristic information of the XOR key, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key; The relay node is used to delete the content related to the used part of the XOR key in the quantum key to be adjusted according to the usage length of the XOR key in the second characteristic information of the XOR key.
3. The centralized quantum key relay network according to claim 1, wherein: When two adjacent quantum key distribution nodes distribute the quantum key corresponding to the quantum link between them to the corresponding business system, if there is a relay node between the two adjacent quantum key distribution nodes; The relay node is used to report key usage to the controller, where the key usage includes an identifier of the relay node, an identifier of a peer node corresponding to the quantum key, a generation time of the quantum key, and a usage length of the quantum key; The controller is configured to, after receiving the key usage information, determine the XOR key to be adjusted according to the identifier of the relay node, the identifier of the opposite node corresponding to the quantum key, and the generation time of the quantum key; The controller is configured to delete content related to a used portion of the quantum key in the XOR key to be adjusted according to the usage length of the quantum key; The relay node is further configured to delete the used portion of the quantum key.
4. The centralized quantum key relay network according to claim 1, wherein: The process of issuing the shared key includes: The demand initiating node sends a key distribution request to the controller, wherein the key distribution request includes an identifier of the demand destination node; The controller determines a relay path based on the identifier of the demand initiating node and the identifier of the demand destination node, performs layer-by-layer XOR processing based on the XOR keys between adjacent quantum links on the relay path to obtain a target XOR key, and sends the target XOR key to the demand destination node. The demand destination node is configured to perform XOR processing based on the target XOR key and the quantum key of the last quantum link in the relay path to obtain the shared key, thereby completing the distribution of the shared key. Among them, adjacent quantum links are two quantum links that share a relay node, the target XOR key is the XOR key between the shared key and the quantum key of the last quantum link in the relay path, and the last quantum link in the relay path is the quantum link between the required destination node and the last relay node in the relay path.
5. The centralized quantum key relay network according to claim 4, wherein: The relay node is further configured to check whether a time difference between the generation time of the stored quantum key and the current time exceeds a first validity period; If the first validity period is exceeded, the relay node is used to delete the expired quantum key and report a key expiration notification to the controller, where the key expiration notification includes an identifier of the relay node, an identifier of a peer node corresponding to the expired quantum key, and a generation time of the expired quantum key; The controller is used to mark the XOR key corresponding to the expired quantum key as a non-distribution state after receiving the key expiration notification. The non-distribution state indicates that the corresponding XOR key is only used for calculation in the shared key distribution and cannot be used as the last XOR object in the target XOR key calculation process.
6. The centralized quantum key relay network according to claim 5, characterized in that: The controller is used to check whether the time difference between the generation time of the XOR key stored therein and the current time exceeds a second validity period; If the second validity period is exceeded, the controller is used to delete the expired XOR key; The second validity period is greater than or equal to the first validity period.
7. The centralized quantum key relay network according to claim 4, wherein: The relay node is further configured to, when the total data volume of the quantum keys stored therein exceeds a second threshold, sort the quantum keys according to their generation time and clear some of the quantum keys so that the total data volume of the quantum keys stored therein is less than the first threshold.
8. The centralized quantum key relay network according to claim 7, wherein: The relay node is further configured to upload a key clearing notification to the controller when clearing part of the quantum key, wherein the key clearing notification includes an identifier of the relay node, an identifier of a peer node corresponding to the cleared quantum key, and a generation time of the cleared quantum key; After receiving the key clearing notification, the controller marks the XOR key corresponding to the cleared quantum key as a non-dispatching state. The non-dispatching state indicates that the corresponding XOR key is only used for calculation in the shared key distribution and cannot be used as the last XOR object in the target XOR key calculation process.
9. A key storage method for a centralized quantum key relay network, characterized in that: The centralized quantum key relay network includes: a controller and multiple quantum key distribution nodes, the multiple quantum key distribution nodes include at least one relay node, and the relay node is a quantum key distribution node connected to at least two quantum links. The method includes: The relay node performs pairwise XOR on related quantum keys with the same generation time to obtain an XOR key, and transmits first characteristic information of the XOR key to the controller; The relevant quantum key is a quantum key generated by a quantum link connected to the relay node, and the first characteristic information of the XOR key includes the XOR key, an identifier of the relay node, an identifier of a node on the quantum link related to the XOR key, and a generation time of the XOR key; The relay node stores characteristic information of a related quantum key corresponding to the XOR key, where the characteristic information of the related quantum key includes the related quantum key, a peer node identifier corresponding to the related quantum key, and a generation time of the related quantum key; After completing the issuance of the shared key, the controller sends a key usage notification to the relay node on the relay path, deleting the used portion of the XOR key used in the process of issuing the shared key; The key usage notification includes the second characteristic information of the XOR key used in the process of issuing the shared key, and the second characteristic information of the XOR key includes the identifier of the relay node corresponding to the XOR key, the identifier of the node on the quantum link related to the XOR key, the generation time of the XOR key, and the usage length of the XOR key; After receiving the key use notification, the relay node deletes the used part of the corresponding quantum key according to the second characteristic information of the XOR key.
10. The key storage method for a centralized quantum key relay network according to claim 9, wherein: When two adjacent quantum key distribution nodes distribute the quantum key corresponding to the quantum link between them to the corresponding business system, if there is a relay node between the two adjacent quantum key distribution nodes, the method further includes: The relay node reports key usage information to the controller, where the key usage information includes an identifier of the relay node, an identifier of a peer node corresponding to the quantum key, a generation time of the quantum key, and a usage length of the quantum key; After receiving the key usage information, the controller determines the XOR key to be adjusted according to the identifier of the relay node, the identifier of the opposite node corresponding to the quantum key, and the generation time of the quantum key; The controller deletes, according to the usage length of the quantum key, content related to the used portion of the quantum key in the XOR key to be adjusted; The relay node deletes the used part of the quantum key.
Citation Information
Patent Citations
Quantum key relay service method
CN109995510A
Quantum key global relay method and system based on dispatching center
CN114900293A